docs: document internal semantic infrastructure
This commit is contained in:
@@ -9,10 +9,14 @@ chmod 600 deploy/secrets/thothii.secrets
|
||||
```
|
||||
|
||||
The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). The supported
|
||||
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, `THT_SSL_CA`, and
|
||||
`PI_PROVIDER_API_KEY`. Values must be non-empty and contain no whitespace. Do not put secrets
|
||||
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, and `THT_SSL_CA`. Values must be
|
||||
non-empty and contain no whitespace. Do not put secrets
|
||||
in the root `.env`, workspace YAML, URLs, logs, or rendered Compose output.
|
||||
|
||||
Do not add vector or embedding endpoint credentials to the bundle. Active operator manuals use
|
||||
internal Qdrant and Ollama services, so vector/embedding runtime endpoint secrets are not part of
|
||||
the supported installation contract.
|
||||
|
||||
Compose mounts the bundle read-only as `/run/secrets/thothii.secrets`. The host file must be a
|
||||
regular non-symlink file with mode `0600` or `0400`; Docker's normal `0444` mode is accepted
|
||||
only for the runtime mount beneath `/run/secrets`. The core runs as UID 10001. Verify the mount
|
||||
@@ -37,9 +41,9 @@ and only then deleting the old files. The old variables remain a compatibility p
|
||||
upgrades, but the documented and tested default is an absolute `THT_SECRETS_FILE` path to the
|
||||
protected bundle.
|
||||
|
||||
Hosted Pi providers must use a single provider key. Compound providers (Bedrock, Azure OpenAI
|
||||
Responses, Cloudflare Workers AI/Gateway) fail closed until a provider-specific credential
|
||||
adapter is implemented.
|
||||
Hosted Pi providers must use a single model key through `THT_MODEL_API_KEY`. Compound providers
|
||||
(Bedrock, Azure OpenAI Responses, Cloudflare Workers AI/Gateway) fail closed until a
|
||||
provider-specific credential adapter is implemented.
|
||||
|
||||
## User-owned session database secrets
|
||||
|
||||
|
||||
Reference in New Issue
Block a user