fix: close deployment decoupling review

This commit is contained in:
2026-08-05 07:52:32 +02:00
parent 5d037e97c4
commit 09834d5cd4
45 changed files with 1082 additions and 791 deletions
+12 -1
View File
@@ -6,7 +6,8 @@
## Portable deployment decoupling — LIVE 2026-08-05
- **Mandatory stack.** The supported Compose stack is exactly `frontend` plus `core`; use the
base file with `deploy/compose.local.yaml` or `deploy/compose.server.yaml`. `run-stack.sh`
base file with `deploy/compose.local.yaml`, or with `deploy/compose.server.yaml` plus the
required public-server session overlay. `run-stack.sh`
invokes the base+local Compose command and the core image provides Pi, so no host Pi binary is
part of the launch contract.
- **External boundaries.** DWH, vector DB, embedding, LLM, and reverse-proxy services are
@@ -18,6 +19,16 @@
remaining live contract checks were renamed for the generic local Compose profile. The coupling
gate rejects stale active deployment filenames and content while deliberately excluding
historical plans/specs, canonical workspace descriptors, and non-runtime migration helpers.
- **Fresh provider and secret contract.** Local, server, and standalone development mount the
protected Pi auth JSON plus tracked declarative model/settings files read-only under
`/home/thoth/.pi/agent`. The existing strict application bundle is a core-only Docker secret at
`/run/secrets/thothii.secrets`; operator env files contain only its absolute source path.
Provider readiness is exercised from a fresh Compose volume through model listing, configuration,
and sanitized credential status.
- **Install and scan closure.** Superseded copied one-service installation examples and the
provider-owned-network test are retired. Active manuals use the canonical base plus local/server
and optional overrides, while the category-based coupling scan covers runtime, Docker smoke,
install, operator, and positive deployment-test contracts and propagates scanner errors.
## Portable Git workspace registry — source integration (2026-08-04)