Files
pidevremote/DEPLOY.md
T
Frank Schwenk f7d3df128f feat: Docker stack for PI WEB + Pi behind Traefik/Authelia
Compose services, Dockerfile, and deploy notes for pi.schwenk.online with OpenRouter and external Authelia middleware.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 11:10:16 +02:00

1.7 KiB

Deploy — pi.schwenk.online

Stack: Pi Coding Agent + PI WEB in Docker, Traefik ingress, Authelia ForwardAuth (authelia@docker).

Prerequisites (boka)

  • Docker + Compose
  • External network traefik exists
  • Authelia running; ACL for pi.schwenk.onlinetwo_factor
  • DNS: pi.schwenk.online → boka
  • Portal: https://auth.schwenk.online

First deploy

ssh frank-schwenk.de
# clone or sync this repo to:
cd /home/frank/pi.schwenk.online

cp .env.example .env
# edit OPENROUTER_API_KEY
# set WORKSPACE_HOST_PATH to the host dirs Pi should edit, e.g. /home/frank

mkdir -p data/pi-web data/pi-agent workspaces
# Container runs as uid 1000 (node); fix ownership if needed:
sudo chown -R 1000:1000 data workspaces

docker compose build
docker compose up -d
docker compose logs -f --tail=100

Verify

  1. Incognito: https://pi.schwenk.online → redirect to Authelia login
  2. Password + Google Authenticator (TOTP)
  3. PI WEB UI loads
  4. Add project under /workspaces/..., start a session — agent runs inside the container
  5. Optional: docker compose exec sessiond pi --version
  6. Packages: Settings → Pi packages, or
    docker compose exec sessiond pi install npm:<package>
    (persists in data/pi-agent)

Ops

docker compose ps
docker compose logs web sessiond
docker compose restart
docker compose pull   # N/A — local build; rebuild after Dockerfile changes:
docker compose build --no-cache && docker compose up -d

Notes

  • No host port publish; only Traefik on network traefik reaches :8504
  • Middleware is referenced only (authelia@docker); ForwardAuth is defined on Authelia
  • pi-coding-agent pinned to 0.82.1 for current pi-web peer range