fix: close deployment decoupling review
This commit is contained in:
@@ -12,7 +12,7 @@ The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). T
|
||||
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_VEC_API_KEY`,
|
||||
`THT_VEC_WRITE_API_KEY`, and the four `THT_VECTOR_*_PASSWORD` role passwords. Values must be
|
||||
non-empty and contain no whitespace. Do not put secrets in the root `.env`, workspace YAML,
|
||||
URLs, logs, or `docker compose config` output.
|
||||
URLs, logs, or rendered Compose output.
|
||||
|
||||
Compose mounts the bundle read-only as `/run/secrets/thothii.secrets`. The host file must be a
|
||||
regular non-symlink file with mode `0600` or `0400`; Docker's normal `0444` mode is accepted
|
||||
@@ -20,7 +20,9 @@ only for the runtime mount beneath `/run/secrets`. The core runs as UID 10001. V
|
||||
without printing its contents:
|
||||
|
||||
```sh
|
||||
docker compose run --rm core sh -c 'id && test -r /run/secrets/thothii.secrets'
|
||||
docker compose --env-file deploy/env/local.env \
|
||||
-f compose.yaml -f deploy/compose.local.yaml \
|
||||
run --rm core sh -c 'id && test -r /run/secrets/thothii.secrets'
|
||||
```
|
||||
|
||||
A private CA PEM chain is not a bundle value: PEM whitespace is rejected by the strict parser.
|
||||
@@ -31,9 +33,10 @@ Compose files intentionally do not create this mount.
|
||||
## Migration from separate secret files
|
||||
|
||||
Older installations used `THT_*_SECRET_FILE` variables and one file per value. Migrate by
|
||||
copying each value to its bundle key, validating with `docker compose config --quiet`, and only
|
||||
copying each value to its bundle key, validating with the complete base+profile command, and only
|
||||
then deleting the old files. The old variables remain a compatibility path for staged upgrades,
|
||||
but the documented and tested default is `THT_SECRETS_FILE=deploy/secrets/thothii.secrets`.
|
||||
but the documented and tested default is an absolute `THT_SECRETS_FILE` path to the protected
|
||||
bundle.
|
||||
|
||||
The local-vector bootstrap rotation helper still accepts an old/new password file as its
|
||||
maintenance interface. Run it only with files protected by `0600`, then copy the resulting
|
||||
|
||||
Reference in New Issue
Block a user