build: сборка в docker

- Dockerfile: python 3.12, Google Chrome (patchright), Xvfb, tini как PID 1 против зомби-процессов
- docker-compose: volume для extra/, shm_size 2gb, порт через API_PORT
- requirements: добавлены playwright и camoufox
- docs: Deployment.md, README и доки актуализированы под Chrome

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
protokeyandClaude Opus 5.5 committed 2026-10-11 00:17:28 +04:00
1 parent 4e930caccb
commit 08a6b52b9d
8 files changed
+162 -21

No files matched your search

+30 -18
View File
@@ -13,15 +13,15 @@ Early MVP (v0), under active development. Single browser engine, no queue, no bi
Client → Caddy (TLS) → FastAPI → API-key auth → semaphore acquire
│
▼
Camoufox browser context
Chrome (Patchright) context
(run actions, collect result)
│
▼
release semaphore → response
```
- **Engine**: [Camoufox](https://camoufox.com/) (stealth Firefox, driven via Playwright). Chosen for v1 because
Firefox-based fingerprinting is less commoditized against anti-bot vendors than patched Chromium.
- **Engine**: real Google Chrome (`channel="chrome"`) driven via [Patchright](https://github.com/Kaliiiiiiiiii-Vinyzu/patchright-python)
(undetected Playwright fork), headful under Xvfb. Firefox is not supported yet.
- **API**: FastAPI, single versioned endpoint (`POST /v1/solve`).
- **Concurrency**: bounded by an `asyncio.Semaphore` over browser contexts — no external job queue in v1. Simpler to
run, hard ceiling on throughput per instance (see Roadmap for scaling out).
@@ -29,28 +29,30 @@ Client → Caddy (TLS) → FastAPI → API-key auth → semaphore acquire
- **Logging**: every request's outcome (success/failure/duration) is persisted — this becomes the success-rate data used
to evaluate the service and talk to clients about reliability.
- **Proxies**: not managed by the service in v1 — the client supplies their own proxy per request if they need one.
- **Deployment**: single Docker container behind a Caddy reverse proxy.
- **Deployment**: single Docker container behind a Caddy reverse proxy — see [Docker](#docker) and
[docs/Deployment.md](docs/Deployment.md).
- **Canvas fingerprint** по дизайну генерируется каждую сессию новый.
### Planned project layout
### Project layout
```
src/
main.py # FastAPI app + router wiring
config.py # settings (env vars)
main.py # FastAPI app, POST /v1/solve
api/
solve.py # POST /v1/solve
deps.py # API-key auth dependency
engine/
browser.py # Camoufox context pool + semaphore
actions.py # fill / click / wait_for execution
schemas.py # SolveRequest / SolveResponse / Action models
db/
models.py # api_keys, request_logs
session.py
schemas.py # SolveRequest / Action models
geoip.py # proxy → locale / timezone
engine/
stealthy.py # AsyncStealthySession (Patchright + Chrome)
session.py # browser / context launch options
page_pool.py # page pool
antibot/ # anti-bot detection & bypass orchestrator (Cloudflare, reCAPTCHA)
captcha/ # captcha solvers (Turnstile, reCAPTCHA, hCaptcha)
tests/
wheels/ # whl библиотеки для оффлайн установки под Ubuntu Noble
Dockerfile
docker-compose.yml
.dockerignore
requirements.txt
env.example
```
@@ -74,7 +76,7 @@ X-API-Key: <key>
"proxy": "socks5://user:pass@host:port",
"screen": "1280x920",
"user_agent": "Firefox",
"user_agent": "Mozilla/5.0 (...) Chrome/...",
"timeout": 120
}
```
@@ -131,7 +133,7 @@ Deliberately out of scope for v1:
- Job queue (Redis/RabbitMQ) + multiple worker VPS for horizontal scaling
- Real billing/usage plans beyond a flat API-key check
- Broader action vocabulary beyond fill/click/wait_for
- Second engine (Patchright/Chromium) for targets where the Firefox fingerprint doesn't fit
- Second engine (Firefox, e.g. Camoufox) for targets where the Chrome fingerprint doesn't fit
## Local development
@@ -139,5 +141,15 @@ Deliberately out of scope for v1:
python -m venv .venv
source .venv/bin/activate
make sync-offline
uvicorn app.main:app --reload
cd src && uvicorn main:app --reload
```
## Docker
```bash
docker compose up -d --build
```
The API listens on `http://localhost:8000`. Browser profiles (`extra/user_data_dir`) and the GeoIP cache live in the
`extra` named volume, so sessions survive container restarts. Details (Xvfb, tini, `/dev/shm`) —
[docs/Deployment.md](docs/Deployment.md).