feat: run qdrant and ollama inside thothii
This commit is contained in:
@@ -25,17 +25,65 @@ const fs = require("fs");
|
||||
const [configPath, profile] = process.argv.slice(2);
|
||||
const config = JSON.parse(fs.readFileSync(configPath, "utf8"));
|
||||
const services = Object.keys(config.services).sort();
|
||||
if (services.join(",") !== "core,frontend") throw new Error("mandatory stack must be core,frontend");
|
||||
if (services.join(",") !== "core,embedding,embedding-model-init,frontend,qdrant") {
|
||||
throw new Error("mandatory stack must include core, frontend, qdrant, embedding, and embedding-model-init");
|
||||
}
|
||||
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
|
||||
throw new Error("forbidden application coupling");
|
||||
}
|
||||
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
|
||||
if (!Object.hasOwn(config.services.core.environment || {}, "THT_LLM_URL")) {
|
||||
for (const volume of ["qdrant-data", "embedding-models"]) {
|
||||
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
|
||||
}
|
||||
if (profile === "local") {
|
||||
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions"]) {
|
||||
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing local required volume: ${volume}`);
|
||||
}
|
||||
}
|
||||
const coreEnv = config.services.core.environment || {};
|
||||
if (!Object.hasOwn(coreEnv, "THT_LLM_URL")) {
|
||||
throw new Error("core must expose a generic THT_LLM_URL endpoint contract");
|
||||
}
|
||||
for (const [key, value] of Object.entries({
|
||||
THT_INTERNAL_QDRANT_URL: "http://qdrant:6333",
|
||||
THT_INTERNAL_EMBEDDING_URL: "http://embedding:11434",
|
||||
THT_INTERNAL_EMBEDDING_MODEL: "qwen3-embedding:0.6b",
|
||||
THT_INTERNAL_EMBEDDING_DIMENSIONS: "1024",
|
||||
})) {
|
||||
if (coreEnv[key] !== value) throw new Error(`unexpected core ${key}: ${coreEnv[key]}`);
|
||||
}
|
||||
for (const forbidden of ["THT_VEC_REST_URL", "THT_VEC_WRITE_REST_URL", "THT_OLLAMA_URL"]) {
|
||||
if (Object.hasOwn(coreEnv, forbidden) && coreEnv[forbidden] !== "") {
|
||||
throw new Error(`core must not require external semantic binding ${forbidden}`);
|
||||
}
|
||||
}
|
||||
if (/docker\.sock|\/var\/run\/docker|docker[-_]?daemon/i.test(JSON.stringify(config.services))) {
|
||||
throw new Error("Compose must not mount the Docker socket or daemon");
|
||||
}
|
||||
if (config.services.qdrant.image !== "qdrant/qdrant:v1.18.2@sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c") {
|
||||
throw new Error("qdrant image must be pinned by version and digest");
|
||||
}
|
||||
for (const serviceName of ["embedding", "embedding-model-init"]) {
|
||||
if (config.services[serviceName].image !== "ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a") {
|
||||
throw new Error(`${serviceName} image must be pinned by version and digest`);
|
||||
}
|
||||
}
|
||||
for (const serviceName of ["qdrant", "embedding", "embedding-model-init"]) {
|
||||
if ((config.services[serviceName].ports || []).length !== 0) {
|
||||
throw new Error(`${serviceName} must not publish a host port`);
|
||||
}
|
||||
}
|
||||
if ((config.services.qdrant.expose || []).join(",") !== "6333") throw new Error("qdrant must expose only 6333");
|
||||
if ((config.services.embedding.expose || []).join(",") !== "11434") throw new Error("embedding must expose only 11434");
|
||||
if (config.services.core.depends_on?.qdrant?.condition !== "service_healthy") {
|
||||
throw new Error("core must wait for qdrant health");
|
||||
}
|
||||
if (config.services.core.depends_on?.["embedding-model-init"]?.condition !== "service_completed_successfully") {
|
||||
throw new Error("core must wait for embedding-model-init success");
|
||||
}
|
||||
if (JSON.stringify(config.services.embedding).includes('"devices"')) {
|
||||
throw new Error("base embedding service must stay CPU-only");
|
||||
}
|
||||
const piAuthMounts = (config.services.core.volumes || []).filter(
|
||||
(mount) => mount.target === "/home/thoth/.pi/agent/auth.json",
|
||||
);
|
||||
@@ -108,17 +156,40 @@ const fs = require("fs");
|
||||
|
||||
const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8"));
|
||||
const services = Object.keys(config.services).sort();
|
||||
if (services.join(",") !== "core,frontend") throw new Error("mandatory stack must be core,frontend");
|
||||
if (services.join(",") !== "core,embedding,embedding-model-init,frontend,qdrant") {
|
||||
throw new Error("mandatory stack must include core, frontend, qdrant, embedding, and embedding-model-init");
|
||||
}
|
||||
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
|
||||
throw new Error("forbidden application coupling");
|
||||
}
|
||||
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
|
||||
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions"]) {
|
||||
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions", "qdrant-data", "embedding-models"]) {
|
||||
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
|
||||
}
|
||||
if (!Object.hasOwn(config.services.core.environment || {}, "THT_LLM_URL")) {
|
||||
throw new Error("core must expose a generic THT_LLM_URL endpoint contract");
|
||||
}
|
||||
for (const [key, value] of Object.entries({
|
||||
THT_INTERNAL_QDRANT_URL: "http://qdrant:6333",
|
||||
THT_INTERNAL_EMBEDDING_URL: "http://embedding:11434",
|
||||
THT_INTERNAL_EMBEDDING_MODEL: "qwen3-embedding:0.6b",
|
||||
THT_INTERNAL_EMBEDDING_DIMENSIONS: "1024",
|
||||
})) {
|
||||
if (config.services.core.environment?.[key] !== value) {
|
||||
throw new Error(`unexpected core ${key}: ${config.services.core.environment?.[key]}`);
|
||||
}
|
||||
}
|
||||
for (const serviceName of ["qdrant", "embedding", "embedding-model-init"]) {
|
||||
if ((config.services[serviceName].ports || []).length !== 0) {
|
||||
throw new Error(`${serviceName} must not publish a host port`);
|
||||
}
|
||||
}
|
||||
if (config.services.core.depends_on?.qdrant?.condition !== "service_healthy") {
|
||||
throw new Error("core must wait for qdrant health");
|
||||
}
|
||||
if (config.services.core.depends_on?.["embedding-model-init"]?.condition !== "service_completed_successfully") {
|
||||
throw new Error("core must wait for embedding-model-init success");
|
||||
}
|
||||
if (/docker\.sock|\/var\/run\/docker|docker[-_]?daemon/i.test(JSON.stringify(config.services))) {
|
||||
throw new Error("Compose must not mount the Docker socket or daemon");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user