feat: resolve workspace bindings into runtime configs

This commit is contained in:
2026-08-03 21:49:57 +02:00
parent 5a654939a5
commit 049f8675c6
6 changed files with 528 additions and 3 deletions
+116
View File
@@ -0,0 +1,116 @@
import { constants, realpathSync, statSync, accessSync } from "node:fs";
import { isAbsolute, relative } from "node:path";
import { buildInstallationContract, type InstallationRole, type InstallationSuffix } from "./contracts.js";
import {
DWH_TRANSPORTS,
VECTOR_TRANSPORTS,
validateCanonicalWorkspace,
type CanonicalWorkspace,
type DwhTransport,
type VectorTransport,
} from "./schema.js";
export interface ResolvedBinding {
transport: DwhTransport | VectorTransport;
values: Record<string, string>;
missing: string[];
}
const REQUIRED_SUFFIXES: Record<"DWH" | "VECTOR", Record<string, readonly InstallationSuffix[]>> = {
DWH: {
postgres_direct: ["HOST", "PORT", "USER", "PASSWORD_FILE"],
rest_api: ["BASE_URL", "API_KEY_FILE"],
ssh_tunnel: [
"USER", "PASSWORD_FILE", "SSH_HOST", "SSH_PORT", "SSH_USER",
"SSH_PRIVATE_KEY_FILE", "SSH_KNOWN_HOSTS_FILE", "SSH_TARGET_HOST", "SSH_TARGET_PORT",
],
},
VECTOR: {
pgvector_direct: ["HOST", "PORT", "USER", "PASSWORD_FILE"],
rest_api: ["BASE_URL", "API_KEY_FILE"],
ssh_tunnel: [
"USER", "PASSWORD_FILE", "SSH_HOST", "SSH_PORT", "SSH_USER",
"SSH_PRIVATE_KEY_FILE", "SSH_KNOWN_HOSTS_FILE", "SSH_TARGET_HOST", "SSH_TARGET_PORT",
],
},
};
const EMBEDDING_REQUIRED_SUFFIXES: readonly InstallationSuffix[] = ["BASE_URL"];
function isTransport(value: string | undefined): value is DwhTransport | VectorTransport {
return value !== undefined
&& ([...DWH_TRANSPORTS, ...VECTOR_TRANSPORTS] as readonly string[]).includes(value);
}
function isInside(path: string, root: string): boolean {
const pathRelative = relative(root, path);
return pathRelative !== "" && !pathRelative.startsWith("..") && !isAbsolute(pathRelative);
}
function isSafeSecretFile(path: string, secretRoots: readonly string[]): boolean {
if (!isAbsolute(path)) return false;
try {
const resolvedPath = realpathSync(path);
const resolvedRoots = secretRoots.map((root) => realpathSync(root));
if (!resolvedRoots.some((root) => isInside(resolvedPath, root))) return false;
if (!statSync(resolvedPath).isFile()) return false;
accessSync(resolvedPath, constants.R_OK);
return true;
} catch {
return false;
}
}
function requiredSuffixes(
role: InstallationRole,
transport: DwhTransport | VectorTransport,
): readonly InstallationSuffix[] {
if (role === "EMBEDDING") return EMBEDDING_REQUIRED_SUFFIXES;
return REQUIRED_SUFFIXES[role][transport] ?? [];
}
/**
* Resolve only installation-local values. Secret files remain file paths: their contents are
* deliberately left for the harness secret-file loader, so bindings cannot leak credentials.
*/
export function resolveBinding(
workspace: CanonicalWorkspace,
role: InstallationRole,
env: NodeJS.ProcessEnv,
secretRoots: readonly string[],
): ResolvedBinding {
const canonical = validateCanonicalWorkspace(workspace);
const contract = buildInstallationContract(canonical);
const variables = contract.variables.filter((variable) => variable.role === role);
const transportVariable = variables.find((variable) => variable.suffix === "TRANSPORT");
const supported = role === "DWH"
? canonical.dwh.supported_transports
: role === "VECTOR"
? canonical.semantic_index.vector_store.supported_transports
: ["rest_api"] as const;
const selectedValue = transportVariable ? env[transportVariable.name] : undefined;
const selectedTransport = isTransport(selectedValue) ? selectedValue : supported[0];
const missing: string[] = [];
if (transportVariable && (!isTransport(selectedValue) || !supported.includes(selectedTransport as never))) {
missing.push(transportVariable.name);
}
const required = new Set(requiredSuffixes(role, selectedTransport));
const values: Record<string, string> = {};
for (const variable of variables) {
if (variable.suffix === "TRANSPORT") continue;
if (variable.transports && !variable.transports.includes(selectedTransport as never)) continue;
const value = env[variable.name];
const present = value !== undefined && value.trim() !== "";
const safe = !variable.secret || (present && isSafeSecretFile(value, secretRoots));
if ((required.has(variable.suffix) && !present) || (present && !safe)) {
missing.push(variable.name);
}
if (present && safe) values[variable.name] = value;
}
return { transport: selectedTransport, values, missing };
}
+146
View File
@@ -0,0 +1,146 @@
import { stringify } from "yaml";
import { buildInstallationContract } from "./contracts.js";
import { validateCanonicalWorkspace, type CanonicalWorkspace } from "./schema.js";
import type { ResolvedBinding } from "./bindings.js";
export interface RuntimeBindings {
dwh: ResolvedBinding;
vector: ResolvedBinding;
embedding: ResolvedBinding;
}
export interface RuntimePaths {
sessions: string;
artifacts: string;
indexes: string;
}
function seconds(timeoutMs: number | undefined): number | undefined {
return timeoutMs === undefined ? undefined : Math.max(1, Math.ceil(timeoutMs / 1_000));
}
function bindingValue(binding: ResolvedBinding, name: string): string | undefined {
return binding.values[name];
}
function requireBinding(binding: ResolvedBinding, name: string): string {
const value = bindingValue(binding, name);
if (value === undefined) throw new Error(`runtime binding is missing ${name}`);
return value;
}
function legacyDirectConnection(
binding: ResolvedBinding,
names: { host: string; port: string; user: string; passwordFile: string },
identity: { database: string; schema: string },
): Record<string, unknown> {
return {
host: requireBinding(binding, names.host),
port: Number(requireBinding(binding, names.port)),
database: identity.database,
schema: identity.schema,
user: requireBinding(binding, names.user),
password_file: requireBinding(binding, names.passwordFile),
};
}
function legacyRestEndpoint(
binding: ResolvedBinding,
names: { baseUrl: string; apiKeyFile: string; tlsCaFile: string },
): Record<string, unknown> {
const endpoint: Record<string, unknown> = {
base_url: requireBinding(binding, names.baseUrl),
api_key_file: requireBinding(binding, names.apiKeyFile),
};
const tlsCaFile = bindingValue(binding, names.tlsCaFile);
if (tlsCaFile !== undefined) endpoint.ssl_ca_file = tlsCaFile;
return endpoint;
}
function placeholderConnection(identity: { database: string; schema: string }): Record<string, unknown> {
return {
host: "localhost",
port: 5432,
database: identity.database,
schema: identity.schema,
user: "rest",
password: "",
transport: "rest",
};
}
/** Render the compatibility fields consumed by the current Python harness. */
export function renderRuntimeConfig(
workspace: CanonicalWorkspace,
bindings: RuntimeBindings,
paths: RuntimePaths,
): string {
const canonical = validateCanonicalWorkspace(workspace);
if ([...bindings.dwh.missing, ...bindings.vector.missing, ...bindings.embedding.missing].length > 0) {
throw new Error("runtime configuration requires complete bindings");
}
const contract = buildInstallationContract(canonical);
const name = (role: "DWH" | "VECTOR" | "EMBEDDING", suffix: string) => {
const variable = contract.variables.find((entry) => entry.role === role && entry.suffix === suffix);
if (!variable) throw new Error(`workspace contract is missing ${role}_${suffix}`);
return variable.name;
};
const dwhIdentity = { database: canonical.dwh.database, schema: canonical.dwh.schema };
const vectorIdentity = dwhIdentity;
const dwhDirect = bindings.dwh.transport === "postgres_direct";
const vectorDirect = bindings.vector.transport === "pgvector_direct";
const database = dwhDirect
? { ...legacyDirectConnection(bindings.dwh, {
host: name("DWH", "HOST"), port: name("DWH", "PORT"), user: name("DWH", "USER"),
passwordFile: name("DWH", "PASSWORD_FILE"),
}, dwhIdentity), transport: "direct" }
: placeholderConnection(dwhIdentity);
const vectorDb = vectorDirect
? legacyDirectConnection(bindings.vector, {
host: name("VECTOR", "HOST"), port: name("VECTOR", "PORT"), user: name("VECTOR", "USER"),
passwordFile: name("VECTOR", "PASSWORD_FILE"),
}, vectorIdentity)
: placeholderConnection(vectorIdentity);
const embedding: Record<string, unknown> = {
base_url: requireBinding(bindings.embedding, name("EMBEDDING", "BASE_URL")),
model: canonical.semantic_index.embedding.model,
dim: canonical.semantic_index.embedding.dimensions,
};
const embeddingTimeout = seconds(canonical.semantic_index.embedding.timeout_ms);
if (embeddingTimeout !== undefined) embedding.timeout = embeddingTimeout;
const rendered: Record<string, unknown> = {
language: canonical.workspace.language,
database,
vector_db: vectorDb,
embeddings: embedding,
paths,
};
if (dwhDirect) {
rendered.dwh = { type: "postgres_direct", connection: database };
} else if (bindings.dwh.transport === "rest_api") {
const rest = legacyRestEndpoint(bindings.dwh, {
baseUrl: name("DWH", "BASE_URL"), apiKeyFile: name("DWH", "API_KEY_FILE"),
tlsCaFile: name("DWH", "TLS_CA_FILE"),
});
rendered.rest = rest;
rendered.dwh = { type: "thoth_rest", database: dwhIdentity, endpoint: rest };
} else {
throw new Error("ssh_tunnel runtime configuration requires a diagnostic tunnel");
}
if (vectorDirect) {
rendered.vectors = { type: "pgvector_direct", connection: vectorDb };
} else if (bindings.vector.transport === "rest_api") {
const vectorRest = legacyRestEndpoint(bindings.vector, {
baseUrl: name("VECTOR", "BASE_URL"), apiKeyFile: name("VECTOR", "API_KEY_FILE"),
tlsCaFile: name("VECTOR", "TLS_CA_FILE"),
});
rendered.vector_rest = vectorRest;
rendered.vectors = { type: "thoth_vector_http", reader: vectorRest };
} else {
throw new Error("ssh_tunnel runtime configuration requires a diagnostic tunnel");
}
return stringify(rendered, { lineWidth: 0, sortMapEntries: false });
}