Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 13 additions & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,26 @@
# Copy to .env and adjust values

# ── Neo4j ──
NEO4J_PASSWORD=beyond-ai-2026
NEO4J_PASSWORD=

# ── yente / Elasticsearch ──
# Use a strong URL-safe password because it is embedded into YENTE_INDEX_URL.
YENTE_ES_PASSWORD=

# ── Beyond AI access protection ──
BEYOND_AI_BASIC_AUTH_USER=
BEYOND_AI_BASIC_AUTH_PASSWORD=
BEYOND_AI_AUTH_REQUIRED=true
BEYOND_AI_RATE_LIMIT_REQUESTS=30
BEYOND_AI_RATE_LIMIT_WINDOW_SECONDS=60

# ── Ollama (Primary LLM) ──
OLLAMA_URL=http://localhost:11434
OLLAMA_MODEL=kimi-k2.5

# ── Claude API (Fallback LLM) ──
ANTHROPIC_API_KEY=
BEYOND_AI_ALLOW_EXTERNAL_LLM_FALLBACK=false

# ── OpenSanctions ──
# Nur für kommerzielle Nutzung:
Expand Down
13 changes: 13 additions & 0 deletions .env.prod.example
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,22 @@
NEO4J_CONTAINER_NAME=neo4j
NEO4J_PASSWORD=DEIN_NEO4J_PASSWORT_HIER

# ─── yente / Elasticsearch ─────────────────────────────────────
# URL-safe Passwort verwenden, da es in YENTE_INDEX_URL eingebettet wird.
YENTE_ES_PASSWORD=SETZE_EIN_LANGES_URL_SICHERES_PASSWORT

# ─── Beyond AI Zugriffsschutz ──────────────────────────────────
BEYOND_AI_BASIC_AUTH_USER=screening
BEYOND_AI_BASIC_AUTH_PASSWORD=SETZE_EIN_LANGES_PASSWORT
BEYOND_AI_AUTH_REQUIRED=true
BEYOND_AI_RATE_LIMIT_REQUESTS=30
BEYOND_AI_RATE_LIMIT_WINDOW_SECONDS=60
BEYOND_AI_TRUST_PROXY_HEADERS=true

# ─── Ollama (bestehende ollama-eksw-Instanz) ──────────────────
# Container-Namen prüfen: docker ps --format '{{.Names}}' | grep ollama
OLLAMA_CONTAINER_NAME=ollama-eksw-ollama-1

# ─── Optional: Claude API als LLM-Fallback ────────────────────
ANTHROPIC_API_KEY=
BEYOND_AI_ALLOW_EXTERNAL_LLM_FALLBACK=false
5 changes: 5 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,11 @@ RUN pip install --no-cache-dir -r requirements.txt
COPY shared/ ./shared/
COPY sanctions/ ./sanctions/

RUN addgroup --system beyondai && adduser --system --ingroup beyondai beyondai \
&& chown -R beyondai:beyondai /app

USER beyondai

EXPOSE 8000

CMD ["uvicorn", "sanctions.src.main:app", "--host", "0.0.0.0", "--port", "8000"]
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -125,6 +125,11 @@ git clone https://github.com/endvater/beyond-ai.git
cd beyond-ai

cp .env.example .env
# Pflichtfelder in .env setzen:
# - NEO4J_PASSWORD
# - YENTE_ES_PASSWORD
# - BEYOND_AI_BASIC_AUTH_USER
# - BEYOND_AI_BASIC_AUTH_PASSWORD
docker compose up -d
```

Expand All @@ -140,6 +145,7 @@ Danach verfügbar:

```bash
curl -X POST http://localhost:8000/api/screen \
-u "$BEYOND_AI_BASIC_AUTH_USER:$BEYOND_AI_BASIC_AUTH_PASSWORD" \
-H "Content-Type: application/json" \
-d '{"name": "Wladimir Putin"}'
```
Expand Down
16 changes: 13 additions & 3 deletions docker-compose.prod.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,12 +23,15 @@ services:
- "9200"
environment:
discovery.type: single-node
xpack.security.enabled: "false"
xpack.security.enabled: "true"
xpack.security.autoconfiguration.enabled: "false"
xpack.security.http.ssl.enabled: "false"
ELASTIC_PASSWORD: ${YENTE_ES_PASSWORD:?Set YENTE_ES_PASSWORD in .env}
ES_JAVA_OPTS: "-Xms1g -Xmx1g" # KVM 2 (bei Upgrade auf KVM 4 → -Xms2g -Xmx2g)
volumes:
- yente_es_data:/usr/share/elasticsearch/data
healthcheck:
test: ["CMD", "curl", "-sf", "http://localhost:9200/_cluster/health"]
test: ["CMD-SHELL", "curl -sf -u elastic:$$ELASTIC_PASSWORD http://localhost:9200/_cluster/health >/dev/null"]
interval: 10s
timeout: 5s
retries: 10
Expand All @@ -48,7 +51,7 @@ services:
yente-es:
condition: service_healthy
environment:
YENTE_INDEX_URL: http://yente-es:9200
YENTE_INDEX_URL: http://elastic:${YENTE_ES_PASSWORD:?Set YENTE_ES_PASSWORD in .env}@yente-es:9200
YENTE_MANIFEST: /data/manifest.yml
volumes:
- ./data/yente:/data:ro
Expand Down Expand Up @@ -80,6 +83,13 @@ services:
OLLAMA_MODEL: kimi-k2.5:cloud
# Optional: Claude API als Fallback
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}
BEYOND_AI_AUTH_REQUIRED: ${BEYOND_AI_AUTH_REQUIRED:-true}
BEYOND_AI_BASIC_AUTH_USER: ${BEYOND_AI_BASIC_AUTH_USER:?Set BEYOND_AI_BASIC_AUTH_USER in .env}
BEYOND_AI_BASIC_AUTH_PASSWORD: ${BEYOND_AI_BASIC_AUTH_PASSWORD:?Set BEYOND_AI_BASIC_AUTH_PASSWORD in .env}
BEYOND_AI_RATE_LIMIT_REQUESTS: ${BEYOND_AI_RATE_LIMIT_REQUESTS:-30}
BEYOND_AI_RATE_LIMIT_WINDOW_SECONDS: ${BEYOND_AI_RATE_LIMIT_WINDOW_SECONDS:-60}
BEYOND_AI_TRUST_PROXY_HEADERS: ${BEYOND_AI_TRUST_PROXY_HEADERS:-true}
BEYOND_AI_ALLOW_EXTERNAL_LLM_FALLBACK: ${BEYOND_AI_ALLOW_EXTERNAL_LLM_FALLBACK:-false}
volumes:
- ./shared:/app/shared
- ./sanctions:/app/sanctions
Expand Down
28 changes: 19 additions & 9 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,14 +11,14 @@ services:
image: neo4j:5-community
container_name: beyond-ai-neo4j
ports:
- "7474:7474" # Browser
- "7687:7687" # Bolt
- "127.0.0.1:7474:7474" # Browser
- "127.0.0.1:7687:7687" # Bolt
volumes:
- neo4j_data:/data
- neo4j_logs:/logs
- ./data/neo4j-import:/var/lib/neo4j/import
environment:
NEO4J_AUTH: neo4j/${NEO4J_PASSWORD:-beyond-ai-2026}
NEO4J_AUTH: neo4j/${NEO4J_PASSWORD:?Set NEO4J_PASSWORD in .env}
NEO4J_PLUGINS: '["apoc"]'
NEO4J_server_memory_heap_initial__size: 1G
NEO4J_server_memory_heap_max__size: 2G
Expand All @@ -31,12 +31,12 @@ services:
image: ghcr.io/opensanctions/yente:latest
container_name: beyond-ai-yente
ports:
- "8100:8000"
- "127.0.0.1:8100:8000"
depends_on:
yente-es:
condition: service_healthy
environment:
YENTE_INDEX_URL: http://yente-es:9200
YENTE_INDEX_URL: http://elastic:${YENTE_ES_PASSWORD:?Set YENTE_ES_PASSWORD in .env}@yente-es:9200
YENTE_MANIFEST: /data/manifest.yml
# Für kommerzielle Nutzung: YENTE_DATA_TOKEN setzen
# YENTE_DATA_TOKEN: ${OPENSANCTIONS_TOKEN:-}
Expand All @@ -49,12 +49,15 @@ services:
container_name: beyond-ai-yente-es
environment:
discovery.type: single-node
xpack.security.enabled: "false"
xpack.security.enabled: "true"
xpack.security.autoconfiguration.enabled: "false"
xpack.security.http.ssl.enabled: "false"
ELASTIC_PASSWORD: ${YENTE_ES_PASSWORD:?Set YENTE_ES_PASSWORD in .env}
ES_JAVA_OPTS: "-Xms1g -Xmx1g"
volumes:
- yente_es_data:/usr/share/elasticsearch/data
healthcheck:
test: ["CMD", "curl", "-sf", "http://localhost:9200/_cluster/health"]
test: ["CMD-SHELL", "curl -sf -u elastic:$$ELASTIC_PASSWORD http://localhost:9200/_cluster/health >/dev/null"]
interval: 10s
timeout: 5s
retries: 10
Expand All @@ -69,18 +72,25 @@ services:
dockerfile: Dockerfile
container_name: beyond-ai-api
ports:
- "8000:8000"
- "127.0.0.1:8000:8000"
depends_on:
- neo4j
- yente
environment:
NEO4J_URI: bolt://neo4j:7687
NEO4J_USER: neo4j
NEO4J_PASSWORD: ${NEO4J_PASSWORD:-beyond-ai-2026}
NEO4J_PASSWORD: ${NEO4J_PASSWORD:?Set NEO4J_PASSWORD in .env}
YENTE_URL: http://yente:8000
OLLAMA_URL: ${OLLAMA_URL:-http://host.docker.internal:11434}
OLLAMA_MODEL: ${OLLAMA_MODEL:-kimi-k2.5}
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}
BEYOND_AI_AUTH_REQUIRED: ${BEYOND_AI_AUTH_REQUIRED:-true}
BEYOND_AI_BASIC_AUTH_USER: ${BEYOND_AI_BASIC_AUTH_USER:?Set BEYOND_AI_BASIC_AUTH_USER in .env}
BEYOND_AI_BASIC_AUTH_PASSWORD: ${BEYOND_AI_BASIC_AUTH_PASSWORD:?Set BEYOND_AI_BASIC_AUTH_PASSWORD in .env}
BEYOND_AI_RATE_LIMIT_REQUESTS: ${BEYOND_AI_RATE_LIMIT_REQUESTS:-30}
BEYOND_AI_RATE_LIMIT_WINDOW_SECONDS: ${BEYOND_AI_RATE_LIMIT_WINDOW_SECONDS:-60}
BEYOND_AI_TRUST_PROXY_HEADERS: "false"
BEYOND_AI_ALLOW_EXTERNAL_LLM_FALLBACK: ${BEYOND_AI_ALLOW_EXTERNAL_LLM_FALLBACK:-false}
volumes:
- ./shared:/app/shared
- ./sanctions:/app/sanctions
Expand Down
1 change: 1 addition & 0 deletions requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4,3 +4,4 @@ httpx>=0.27.0
neo4j>=5.0.0
pydantic>=2.0.0
python-dotenv>=1.0.0
python-multipart>=0.0.20
1 change: 1 addition & 0 deletions sanctions/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,7 @@ python src/api.py

# Einzelnen Namen screenen
curl -X POST http://localhost:8000/api/screen \
-u "$BEYOND_AI_BASIC_AUTH_USER:$BEYOND_AI_BASIC_AUTH_PASSWORD" \
-H "Content-Type: application/json" \
-d '{"name": "Wladimir Wladimirowitsch Putin", "threshold": 0.7}'

Expand Down
Loading