Merge origin/codex/portable-deployment into feat/docker-local-deploy

Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
This commit is contained in:
User
2026-07-12 21:13:20 +02:00
211 changed files with 23270 additions and 415 deletions
+11
View File
@@ -33,6 +33,14 @@ deploy/thothii.env
ca-chain.pem
config/ca-chain.pem
# ThothII deployment configuration and secret values (keep only the README tracked)
deploy/.env
deploy/compose.psd-local.yaml
deploy/workspaces/psd.yaml
deploy/secrets/*
!deploy/secrets/README.md
!deploy/secrets/*.example
# === Runtime data (sessions contain PII; indexes are derived) ===
harness/sessions/
harness/indexes/
@@ -55,3 +63,6 @@ htmlcov/
# === MkDocs build output ===
site/
# Generated container inventory / SBOM-equivalent verification artifacts
.artifacts/