fix: harden compose Pi auth mounts

This commit is contained in:
2026-08-04 14:55:05 +02:00
parent 2e67568282
commit 2ce2e0089a
6 changed files with 32 additions and 0 deletions
+24
View File
@@ -26,6 +26,18 @@ if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify
throw new Error("forbidden application coupling");
}
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
if (!Object.hasOwn(config.services.core.environment || {}, "THT_LLM_URL")) {
throw new Error("core must expose a generic THT_LLM_URL endpoint contract");
}
if (/docker\.sock|\/var\/run\/docker|docker[-_]?daemon/i.test(JSON.stringify(config.services))) {
throw new Error("Compose must not mount the Docker socket or daemon");
}
const piAuthMounts = (config.services.core.volumes || []).filter(
(mount) => mount.target === "/home/thoth/.pi/agent/auth.json",
);
if (piAuthMounts.length !== 1 || piAuthMounts[0].type !== "bind" || !piAuthMounts[0].read_only) {
throw new Error("Pi auth must be one read-only file bind");
}
const ports = Object.fromEntries(
Object.entries(config.services).map(([name, service]) => [name, service.ports || []]),
@@ -74,6 +86,18 @@ if (!config.networks || !config.networks.thothii) throw new Error("base stack mu
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions"]) {
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
}
if (!Object.hasOwn(config.services.core.environment || {}, "THT_LLM_URL")) {
throw new Error("core must expose a generic THT_LLM_URL endpoint contract");
}
if (/docker\.sock|\/var\/run\/docker|docker[-_]?daemon/i.test(JSON.stringify(config.services))) {
throw new Error("Compose must not mount the Docker socket or daemon");
}
const piAuthMounts = (config.services.core.volumes || []).filter(
(mount) => mount.target === "/home/thoth/.pi/agent/auth.json",
);
if (piAuthMounts.length !== 1 || piAuthMounts[0].type !== "bind" || !piAuthMounts[0].read_only) {
throw new Error("Pi auth must be one read-only file bind");
}
NODE
render_profile local deploy/env/local.env.example deploy/compose.local.yaml