3 KiB
3 KiB
Gateway
Nginx reverse proxy that serves as the single entry point for all didiAI services. All requests (except /health) require Bearer token authentication.
Prerequisites
- All global prerequisites (see main README.md)
- Docker network
didi-network(shared with other modules) - At least one backend service running (llm-inference, audio, web, catalog-api)
Routes
Only the routes whose upstream containers exist on this host are active. The
others are present in nginx.conf.template but commented out (upstream + location
blocks), because nginx resolves upstream hostnames at config load and a missing
name aborts startup.
| Route | Upstream | Status | Description |
|---|---|---|---|
/health |
(nginx direct) | active | Health check, no auth required |
/web/ |
didiAI-web-api:51100 |
active | Web Fact-checking API |
/catalog/ |
didiAI-catalog-api:11000 |
active | Catalog API (service discovery) |
/llm/ |
didiAI-llm-api:14011 |
disabled (upstream commented) | LLM Inference API (SSE streaming) — re-enable when deployed |
/audio/ |
didiAI-audio:54300 |
disabled (upstream commented) | Audio Transcription API (10M body buffer) — re-enable when deployed |
/embeddings/ |
didiAI-embeddings-api:14100 |
disabled (upstream commented) | Embeddings API (OpenAI-compatible) — re-enable when deployed |
/rerank/ |
didiAI-rerank-api:14200 |
disabled (upstream commented) | Rerank API (Cohere/Jina-compatible) — re-enable when deployed |
Authentication
All routes except /health require a Bearer token:
Authorization: Bearer <GATEWAY_API_TOKEN>
Unauthorized requests receive:
{"error": "unauthorized", "message": "Invalid or missing Bearer token"}
Configuration
| Variable | Required | Description |
|---|---|---|
GATEWAY_API_TOKEN |
Yes | Bearer token for authentication |
Quick Start
cd deploy/
# Configure
cp .env.example .env
# Edit .env and set GATEWAY_API_TOKEN
# Start
docker compose up -d
# Test
curl http://localhost:11000/health
curl -H "Authorization: Bearer <token>" http://localhost:11000/catalog/health
Port
| Port | Service | Description |
|---|---|---|
| 11000 | Gateway | Only externally exposed port for the platform |
Proxy Settings
- Connect timeout: 60s
- Send timeout: 300s
- Read timeout: 600s
- Max upload size: 500MB
- Request ID: Auto-generated
X-Request-IDheader on all requests
Architecture
Client
|
v
Gateway (nginx :11000) ---> Bearer token check
|
+-- /web/ --> didiAI-web-api:51100 (active)
+-- /catalog/ --> didiAI-catalog-api:11000 (active)
|
+-- /llm/ --> didiAI-llm-api:14011 (disabled — upstream commented)
+-- /audio/ --> didiAI-audio:54300 (disabled — upstream commented)
+-- /embeddings/ --> didiAI-embeddings-api:14100 (disabled — upstream commented)
+-- /rerank/ --> didiAI-rerank-api:14200 (disabled — upstream commented)