Deploys SearxNG on ai-server-4080 (10.0.0.128) for chat_backend#62 / PR #65 grounded search.
New roles/searxng/ (compose + JSON-enabled settings.yml), gated by searxng_stack: true, wired into site.yml.
Host port 8088 (not 8080 — that is dta_webapp on this host). UFW allows 10.0.0.0/24 → 8088/tcp only.
Ops after merge
./scripts/provision.sh ai-server-4080
# or targeted:
ansible-playbook playbooks/site.yml --limit ai-server-4080 --tags never # full site play includes searxng when searxng_stack
Then set in chat_backend_prod.env / chat_backend_beta.env:
Confirm :8088 responds with JSON; :8080 still serves dta_webapp
Confirm UFW rule is LAN-only
From adama/roslin container network, curl SearxNG succeeds
Update chat_backend secrets to :8088 and redeploy beta
## Summary
- Closes [#10](https://git.aimloperations.com/ai_ml_operations/server-infra/issues/10).
- Deploys **SearxNG** on **ai-server-4080** (`10.0.0.128`) for [chat_backend#62](https://git.aimloperations.com/ai_ml_operations/chat_backend/issues/62) / [PR #65](https://git.aimloperations.com/ai_ml_operations/chat_backend/pulls/65) grounded search.
- New `roles/searxng/` (compose + JSON-enabled `settings.yml`), gated by `searxng_stack: true`, wired into `site.yml`.
- **Host port 8088** (not 8080 — that is `dta_webapp` on this host). UFW allows `10.0.0.0/24` → `8088/tcp` only.
## Ops after merge
```bash
./scripts/provision.sh ai-server-4080
# or targeted:
ansible-playbook playbooks/site.yml --limit ai-server-4080 --tags never # full site play includes searxng when searxng_stack
```
Then set in `chat_backend_prod.env` / `chat_backend_beta.env`:
```text
SEARCH_PROVIDER=searxng
SEARCH_FAILOVER_PROVIDER=ddgs
SEARXNG_BASE_URL=http://10.0.0.128:8088
```
Smoke test from any app host:
```bash
curl -sG 'http://10.0.0.128:8088/search' --data-urlencode 'q=test' -d 'format=json' | head
```
## Test plan
- [ ] Provision ai-server-4080; confirm `docker ps` shows `searxng`
- [ ] Confirm `:8088` responds with JSON; `:8080` still serves dta_webapp
- [ ] Confirm UFW rule is LAN-only
- [ ] From adama/roslin container network, curl SearxNG succeeds
- [ ] Update chat_backend secrets to `:8088` and redeploy beta
Add roles/searxng (compose + JSON-enabled settings), gate with searxng_stack
on ai-server-4080, open UFW 8088/tcp from the LAN. Port 8088 avoids the
dta_webapp :8080 clash; chat_backend must use SEARXNG_BASE_URL=http://10.0.0.128:8088.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
10.0.0.128) for chat_backend#62 / PR #65 grounded search.roles/searxng/(compose + JSON-enabledsettings.yml), gated bysearxng_stack: true, wired intosite.yml.dta_webappon this host). UFW allows10.0.0.0/24→8088/tcponly.Ops after merge
Then set in
chat_backend_prod.env/chat_backend_beta.env:Smoke test from any app host:
Test plan
docker psshowssearxng:8088responds with JSON;:8080still serves dta_webapp:8088and redeploy beta