fix: harden compose Pi auth mounts
This commit is contained in:
@@ -26,6 +26,18 @@ if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify
|
||||
throw new Error("forbidden application coupling");
|
||||
}
|
||||
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
|
||||
if (!Object.hasOwn(config.services.core.environment || {}, "THT_LLM_URL")) {
|
||||
throw new Error("core must expose a generic THT_LLM_URL endpoint contract");
|
||||
}
|
||||
if (/docker\.sock|\/var\/run\/docker|docker[-_]?daemon/i.test(JSON.stringify(config.services))) {
|
||||
throw new Error("Compose must not mount the Docker socket or daemon");
|
||||
}
|
||||
const piAuthMounts = (config.services.core.volumes || []).filter(
|
||||
(mount) => mount.target === "/home/thoth/.pi/agent/auth.json",
|
||||
);
|
||||
if (piAuthMounts.length !== 1 || piAuthMounts[0].type !== "bind" || !piAuthMounts[0].read_only) {
|
||||
throw new Error("Pi auth must be one read-only file bind");
|
||||
}
|
||||
|
||||
const ports = Object.fromEntries(
|
||||
Object.entries(config.services).map(([name, service]) => [name, service.ports || []]),
|
||||
@@ -74,6 +86,18 @@ if (!config.networks || !config.networks.thothii) throw new Error("base stack mu
|
||||
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions"]) {
|
||||
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
|
||||
}
|
||||
if (!Object.hasOwn(config.services.core.environment || {}, "THT_LLM_URL")) {
|
||||
throw new Error("core must expose a generic THT_LLM_URL endpoint contract");
|
||||
}
|
||||
if (/docker\.sock|\/var\/run\/docker|docker[-_]?daemon/i.test(JSON.stringify(config.services))) {
|
||||
throw new Error("Compose must not mount the Docker socket or daemon");
|
||||
}
|
||||
const piAuthMounts = (config.services.core.volumes || []).filter(
|
||||
(mount) => mount.target === "/home/thoth/.pi/agent/auth.json",
|
||||
);
|
||||
if (piAuthMounts.length !== 1 || piAuthMounts[0].type !== "bind" || !piAuthMounts[0].read_only) {
|
||||
throw new Error("Pi auth must be one read-only file bind");
|
||||
}
|
||||
NODE
|
||||
|
||||
render_profile local deploy/env/local.env.example deploy/compose.local.yaml
|
||||
|
||||
Reference in New Issue
Block a user