fix(auth): complete Task 13 deployment review

This commit is contained in:
2026-08-17 22:15:41 +02:00
parent 7e52df2702
commit 0d0c15b4b8
11 changed files with 228 additions and 50 deletions
+11 -1
View File
@@ -68,11 +68,20 @@ for (const serviceName of ["embedding", "embedding-model-init"]) {
throw new Error(`${serviceName} image must be pinned by version and digest`);
}
}
for (const serviceName of ["qdrant", "embedding", "embedding-model-init"]) {
for (const serviceName of ["embedding", "embedding-model-init"]) {
if ((config.services[serviceName].ports || []).length !== 0) {
throw new Error(`${serviceName} must not publish a host port`);
}
}
const qdrantPorts = config.services.qdrant.ports || [];
if (profile === "local") {
if (qdrantPorts.length !== 1 || qdrantPorts[0].host_ip !== "127.0.0.1"
|| Number(qdrantPorts[0].published) !== 6333 || Number(qdrantPorts[0].target) !== 6333) {
throw new Error("local qdrant may publish only 127.0.0.1:6333");
}
} else if (qdrantPorts.length !== 0) {
throw new Error("server qdrant must not publish a host port");
}
if ((config.services.qdrant.expose || []).join(",") !== "6333") throw new Error("qdrant must expose only 6333");
if ((config.services.embedding.expose || []).join(",") !== "11434") throw new Error("embedding must expose only 11434");
if (!config.services.qdrant.healthcheck) throw new Error("qdrant must define a healthcheck");
@@ -155,6 +164,7 @@ assert_remote_required() {
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git \
PI_AUTH_FILE=/dev/null \
THT_SECRETS_FILE=/dev/null \
THT_AUTH_CONFIG_ROOT=/tmp/thothii-auth \
docker compose -f compose.yaml config --format json >"$tmp/base.json"
node - "$tmp/base.json" <<'NODE'
const fs = require("fs");