# Sanitized, version-pinned example for Helical Insight Community Edition v7.0.0.
# Copy this file and env.example into a private directory, then create the paths
# beneath DATA_ROOT before deploying it through Coolify or Docker Compose.
# Do not commit a real .env, an Oracle wallet, or downloaded JDBC artifacts.
#
# Important PostgreSQL contract: v7.0.0 embeds the hiuser/hiee datasource in the
# packaged application. On a fresh PostgreSQL volume, POSTGRES_PASSWORD must be
# the private value compatible with that package contract; an arbitrary password
# causes hi-ee to fail authentication. Do not publish that value.

configs:
  hiee-entrypoint:
    content: |
      #!/bin/bash
      set -e
      mkdir -p "/usr/local/tomcat/webapps/hi-ee"
      cp -f "/host-hi/hi-ee.war" "/usr/local/tomcat/webapps/hi-ee.war"
      cp -a "/host-config/tomcat/conf/." "/usr/local/tomcat/conf/"
      rm -f "/usr/local/Helical Insight/hi/hi-repository/hi.lock"
      # Oracle JDBC JARs are prepared by oracle-jdbc-bootstrap in a persistent bind mount.
      # Copy into Tomcat's top-level lib directory; mounting over that directory would hide Tomcat's own JARs.
      find /host-oracle-jdbc -maxdepth 1 -type f -name '*.jar' -exec cp -f {} /usr/local/tomcat/lib/ \;
      test -s /usr/local/tomcat/lib/ojdbc11-23.4.0.24.05.jar || { echo "ERROR: Oracle JDBC bootstrap artifacts are missing"; exit 1; }
      exec /bin/bash "/host-config/entry/entrypoint.sh" "$@"

# Helical Insight Community Edition v7.0.0
# Private-access deployment. PostgreSQL and Instant BI do not publish host ports.
# The bootstrap service downloads the official Docker package once into DATA_ROOT.

services:
  bootstrap:
    image: alpine:3.20
    restart: "no"
    environment:
      HELICAL_VERSION: "v7.0.0"
      HELICAL_PACKAGE_URL: "https://github.com/helicalinsight/helicalinsight/releases/download/v7.0.0/helicalinsight-docker.zip"
    volumes:
      - ${DATA_ROOT:?set_DATA_ROOT}/hi:/data/hi
      - ${DATA_ROOT:?set_DATA_ROOT}/config:/data/config
      - ${DATA_ROOT:?set_DATA_ROOT}/instantbi:/data/instantbi
      - ${DATA_ROOT:?set_DATA_ROOT}/.bootstrap:/data/bootstrap
    command:
      - /bin/sh
      - -ec
      - |
        apk add --no-cache ca-certificates wget unzip
        if [ -f /data/bootstrap/$${HELICAL_VERSION}.complete ]; then
          echo "Helical package $${HELICAL_VERSION} already bootstrapped"
          exit 0
        fi
        rm -rf /tmp/helical /tmp/helical.zip
        for dir in /data/hi /data/config /data/instantbi; do
          find "$${dir}" -mindepth 1 -maxdepth 1 -exec rm -rf {} +
        done
        mkdir -p /tmp/helical /data/hi /data/config /data/instantbi /data/bootstrap
        echo "Downloading Helical Insight $${HELICAL_VERSION} Docker package..."
        wget -q --show-progress -O /tmp/helical.zip "$${HELICAL_PACKAGE_URL}"
        unzip -q /tmp/helical.zip -d /tmp/helical
        echo "Archive extracted; top-level files:"
        find /tmp/helical -maxdepth 4 -type f | head -n 80
        WAR_PATH="$(find /tmp/helical -type f -path '*/hi/hi-ee.war' | head -n 1)"
        ROOT="$(dirname "$(dirname "$${WAR_PATH}")")"
        echo "Detected package root: [$${ROOT}]"
        test -n "$${WAR_PATH}" || { echo "ERROR: hi-ee.war not found"; exit 1; }
        for required in hi/hi-ee.war config/entry/entrypoint.sh instantbi/helicalbi/app.py; do
          if [ -f "$${ROOT}/$${required}" ]; then
            echo "OK: $${required}"
          else
            echo "ERROR: missing $${ROOT}/$${required}"
            exit 1
          fi
        done
        cp -a "$${ROOT}/hi/." /data/hi/
        cp -a "$${ROOT}/config/." /data/config/
        cp -a "$${ROOT}/instantbi/." /data/instantbi/
        # v7.0.0 imports ChatOllama from the old namespace; current LangChain uses langchain-ollama.
        sed -i 's|from langchain_community\.chat_models import ChatOllama|from langchain_ollama import ChatOllama|' /data/instantbi/helicalbi/helicalbi/integration/ollama/OllamaFactory.py
        grep -qxF 'langchain-ollama' /data/instantbi/helicalbi/requirements.txt || echo 'langchain-ollama' >> /data/instantbi/helicalbi/requirements.txt
        chmod +x /data/config/entry/entrypoint.sh
        # Direct Tailscale access is HTTP on the mapped private port.
        # Keep this package-level compatibility note in sync with INSTALL.md.
        sed -i 's|https://|http://|g' /data/config/entry/entrypoint.sh
        touch /data/bootstrap/$${HELICAL_VERSION}.complete
        echo "Helical package $${HELICAL_VERSION} installed in persistent bind mounts"

  oracle-jdbc-bootstrap:
    image: alpine:3.20
    restart: "no"
    environment:
      ORACLE_JDBC_VERSION: "23.4.0.24.05"
      MAVEN_REPOSITORY: "https://repo.maven.apache.org/maven2"
    volumes:
      - ${DATA_ROOT:?set_DATA_ROOT}/oracle-jdbc:/data/oracle-jdbc
    command:
      - /bin/sh
      - -ec
      - |
        apk add --no-cache ca-certificates curl
        # This is a Tomcat-global classpath. Keep only the Oracle JDBC mTLS set
        # plus FAN support; optional NLS/XML modules inject providers or have
        # unresolved companion JARs in Maven Central and can prevent the WAR
        # from deploying.
        marker="/data/oracle-jdbc/.oracle-jdbc-$${ORACLE_JDBC_VERSION}-mtls-core.complete"
        required="ojdbc11 ucp11 oraclepki ons simplefan"
        complete=true
        for artifact in $${required}; do
          test -s "/data/oracle-jdbc/$${artifact}-$${ORACLE_JDBC_VERSION}.jar" || complete=false
        done
        if [ -f "$${marker}" ] && [ "$${complete}" = true ]; then
          echo "Oracle JDBC mTLS core $${ORACLE_JDBC_VERSION} already bootstrapped"
          exit 0
        fi
        rm -f /data/oracle-jdbc/*.jar /data/oracle-jdbc/SHA256SUMS /data/oracle-jdbc/.oracle-jdbc-*.complete
        fetch() {
          group="$${1}"; artifact="$${2}"
          url="$${MAVEN_REPOSITORY}/$${group}/$${artifact}/$${ORACLE_JDBC_VERSION}/$${artifact}-$${ORACLE_JDBC_VERSION}.jar"
          echo "Downloading $${artifact}"
          curl --fail --location --retry 3 --retry-delay 2 --output "/data/oracle-jdbc/$${artifact}-$${ORACLE_JDBC_VERSION}.jar" "$${url}"
        }
        fetch com/oracle/database/jdbc ojdbc11
        fetch com/oracle/database/jdbc ucp11
        fetch com/oracle/database/security oraclepki
        fetch com/oracle/database/ha ons
        fetch com/oracle/database/ha simplefan
        test "$$(find /data/oracle-jdbc -maxdepth 1 -type f -name '*.jar' | wc -l)" -eq 5
        sha256sum /data/oracle-jdbc/*.jar > /data/oracle-jdbc/SHA256SUMS
        touch "$${marker}"
        echo "Oracle JDBC mTLS core $${ORACLE_JDBC_VERSION} prepared"

  postgres:
    image: postgres:15.8-alpine3.20
    restart: unless-stopped
    # Internal metadata/scheduling database; it is not a copy of business data.
    # The official v7.0.0 WAR embeds a fixed Hibernate datasource in
    # application-context.xml (jdbc:postgresql://postgres:5432/hiee, user hiuser)
    # with a package-specific password. On a FRESH volume the role is created
    # from POSTGRES_* below, so POSTGRES_PASSWORD must match that private package
    # contract. POSTGRES_USER and POSTGRES_DB are deterministic (hiuser/hiee).
    deploy:
      resources:
        limits:
          memory: 384M
        reservations:
          memory: 192M
    depends_on:
      bootstrap:
        condition: service_completed_successfully
    environment:
      POSTGRES_USER: hiuser
      POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
      POSTGRES_DB: hiee
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB}"]
      interval: 10s
      timeout: 5s
      retries: 12
    volumes:
      - ${DATA_ROOT:?set_DATA_ROOT}/postgres:/var/lib/postgresql/data
      - ${DATA_ROOT:?set_DATA_ROOT}/config/init-scripts:/docker-entrypoint-initdb.d:ro
    networks:
      - hinet

  hiee:
    image: hiee/helicalinsight:nitrogen-j25t11
    restart: unless-stopped
    # JVM heap + Tomcat/native overhead fit below this cgroup ceiling.
    deploy:
      resources:
        limits:
          memory: 1536M
        reservations:
          memory: 768M
    depends_on:
      bootstrap:
        condition: service_completed_successfully
      oracle-jdbc-bootstrap:
        condition: service_completed_successfully
      postgres:
        condition: service_healthy
    environment:
      HOST_IP: ${HOST_IP}
      INSTALL_CHROME: ${INSTALL_CHROME:-false}
      # 768 MiB JVM heap leaves room for Tomcat and native overhead within the 1536 MiB container limit.
      # TNS_ADMIN points at the read-only Oracle wallet bind mount; it has no effect until an Oracle Data Source is configured.
      CATALINA_OPTS: "-Xms256m -Xmx768m -Djdk.internal.httpclient.disableHostnameVerification=true -Doracle.net.tns_admin=/opt/oracle/wallet -Doracle.net.ssl_server_dn_match=true"
    entrypoint: ["/bin/bash", "/entrypoint-coolify.sh"]
    command: ["/usr/local/tomcat/bin/catalina.sh", "run"]
    healthcheck:
      test: ["CMD-SHELL", "curl -f http://localhost:8080/hi-ee/applicationSettings || exit 1"]
      interval: 30s
      timeout: 10s
      retries: 8
      start_period: 90s
    volumes:
      - ${DATA_ROOT:?set_DATA_ROOT}/hi/db:/usr/local/Helical Insight/hi/db
      - ${DATA_ROOT:?set_DATA_ROOT}/hi/hi-repository:/usr/local/Helical Insight/hi/hi-repository
      - ${DATA_ROOT:?set_DATA_ROOT}/hi:/host-hi:ro
      - ${DATA_ROOT:?set_DATA_ROOT}/config:/host-config:ro
      - ${DATA_ROOT:?set_DATA_ROOT}/hirepo-root:/root
      - ${DATA_ROOT:?set_DATA_ROOT}/tomcat-temp:/usr/local/tomcat/temp
      - ${DATA_ROOT:?set_DATA_ROOT}/logs:/usr/local/tomcat/logs
      - ${DATA_ROOT:?set_DATA_ROOT}/oracle-jdbc:/host-oracle-jdbc:ro
      - ${ORACLE_WALLET_DIR:?set_ORACLE_WALLET_DIR}:/opt/oracle/wallet:ro
    configs:
      - source: hiee-entrypoint
        target: /entrypoint-coolify.sh
    ports:
      - "${TAILSCALE_IP}:${HELICAL_HOST_PORT}:8080"
    networks:
      - hinet

  instantbi:
    image: python:3.13-slim
    restart: unless-stopped
    # Python API is idle most of the time; retain room for requests and imports.
    deploy:
      resources:
        limits:
          memory: 512M
        reservations:
          memory: 256M
    depends_on:
      bootstrap:
        condition: service_completed_successfully
    environment:
      HELICALBI_LLM_MODE: ${HELICALBI_LLM_MODE:-stub}
    volumes:
      - ${DATA_ROOT:?set_DATA_ROOT}/instantbi/helicalbi:/app
    working_dir: /app
    command:
      - /bin/bash
      - -ec
      - |
        sed -i 's|from langchain_community.chat_models import ChatOllama|from langchain_ollama import ChatOllama|' /app/helicalbi/integration/ollama/OllamaFactory.py
        grep -qxF 'langchain-ollama' requirements.txt || echo 'langchain-ollama' >> requirements.txt
        pip install --no-cache-dir -r requirements.txt
        exec python app.py
    healthcheck:
      test: ["CMD-SHELL", "python -c \"import urllib.request; urllib.request.urlopen('http://localhost:8000/')\""]
      interval: 30s
      timeout: 10s
      retries: 8
      start_period: 180s
    expose:
      - "8000"
    networks:
      - hinet

networks:
  hinet:
    driver: bridge
