build(compose): make root startup the default

This commit is contained in:
2026-07-12 11:14:36 +02:00
parent 3807c65a41
commit 32a2b71687
10 changed files with 161 additions and 79 deletions
+4 -3
View File
@@ -1,5 +1,6 @@
services:
core:
env_file:
- path: ./deploy/.env
required: false
environment:
# Non-secret settings come from the root .env interpolation file.
AUTH_MODE: "${AUTH_MODE:-none}"
THT_SECRETS_FILE: /run/secrets/thothii.secrets
+1 -28
View File
@@ -8,31 +8,4 @@ services:
THT_VEC_REST_URL: ${THT_VEC_REST_URL:?set THT_VEC_REST_URL}
THT_OLLAMA_URL: ${THT_OLLAMA_URL:?set THT_OLLAMA_URL}
THT_DOCS_ROOT: ${THT_DOCS_ROOT:-/data/workspaces/example/evidence-source}
THT_DWH_API_KEY_FILE: /run/secrets/dwh_api_key
THT_VEC_API_KEY_FILE: /run/secrets/vector_reader_api_key
THT_VEC_WRITE_API_KEY_FILE: /run/secrets/vector_writer_api_key
THT_MODEL_API_KEY_FILE: /run/secrets/model_api_key
THT_SSL_CA: /run/secrets/thoth_ca.pem
secrets:
- source: dwh_api_key
target: dwh_api_key
- source: vector_reader_api_key
target: vector_reader_api_key
- source: vector_writer_api_key
target: vector_writer_api_key
- source: thoth_ca
target: thoth_ca.pem
- source: model_api_key
target: model_api_key
secrets:
dwh_api_key:
file: ${THT_DWH_API_KEY_SECRET_FILE:?set THT_DWH_API_KEY_SECRET_FILE}
vector_reader_api_key:
file: ${THT_VEC_API_KEY_SECRET_FILE:?set THT_VEC_API_KEY_SECRET_FILE}
vector_writer_api_key:
file: ${THT_VEC_WRITE_API_KEY_SECRET_FILE:?set THT_VEC_WRITE_API_KEY_SECRET_FILE}
thoth_ca:
file: ${THT_CA_SECRET_FILE:?set THT_CA_SECRET_FILE}
model_api_key:
file: ${THT_MODEL_API_KEY_SECRET_FILE:?set THT_MODEL_API_KEY_SECRET_FILE}
THT_SECRETS_FILE: /run/secrets/thothii.secrets
+10 -31
View File
@@ -1,47 +1,26 @@
# LOCAL/PRODUCTION CONFIGURATION TEMPLATE. Copy to deploy/.env.
# Never commit deploy/.env or the files under deploy/secrets/.
# Deprecated compatibility template.
# New installations should copy ../.env.example to ../.env and run
# `docker compose up --build -d` from the repository root.
# Never put secret values in this file.
COMPOSE_FILE=compose.yaml:deploy/compose.local.yaml
COMPOSE_PROFILES=
THT_SECRETS_FILE=deploy/secrets/thothii.secrets
# Optional application defaults
PI_PROVIDER=
PI_MODEL=
PI_THINKING=
# Container-only path is assigned by deploy/compose.production.yaml.
THT_MODEL_API_KEY_SECRET_FILE=deploy/secrets/model-api-key
MAX_PI_PROCESSES=4
AUTH_MODE=none
# External DWH (example workspace uses the HTTP adapters)
THT_DB_NAME=
THT_DWH_REST_URL=
THT_DWH_API_KEY=
THT_DWH_API_KEY_SECRET_FILE=deploy/secrets/dwh-api-key
# External vector service. Use a distinct write key where the service supports one.
THT_VEC_REST_URL=
THT_VEC_API_KEY=
THT_VEC_WRITE_API_KEY=
THT_VEC_API_KEY_SECRET_FILE=deploy/secrets/vector-reader-api-key
THT_VEC_WRITE_API_KEY_SECRET_FILE=deploy/secrets/vector-writer-api-key
THT_CA_SECRET_FILE=deploy/secrets/ca-chain.pem
THT_OLLAMA_URL=
THT_DOCS_ROOT=/data/workspaces/example/evidence-source
# Optional local-vector profile. Keep these secret files outside Git and readable by Docker.
THT_VECTOR_DATABASE=thoth
THT_VECTOR_BOOTSTRAP_USER=postgres
THT_VECTOR_MIGRATOR_USER=thoth_vector_migrator
THT_VECTOR_READER_USER=thoth_vector_reader
THT_VECTOR_WRITER_USER=thoth_vector_writer
THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE=deploy/secrets/vector_bootstrap_password
# Changing the file alone does not rotate an initialized DB; use
# scripts/vector-rotate-bootstrap-password.sh OLD_SECRET_FILE NEW_SECRET_FILE.
THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE=deploy/secrets/vector_migrator_password
THT_VECTOR_READER_PASSWORD_SECRET_FILE=deploy/secrets/vector_reader_password
THT_VECTOR_WRITER_PASSWORD_SECRET_FILE=deploy/secrets/vector_writer_password
# External embeddings service
THT_OLLAMA_URL=
# Evidence source visible inside the persistent data volume
THT_DOCS_ROOT=/data/workspaces/example/evidence-source
# Optional CA file mounted separately by an operator, for example via a Compose override.
THT_SSL_CA=
+20
View File
@@ -0,0 +1,20 @@
# Copy to deploy/secrets/thothii.secrets and chmod 600.
# Values are read as literal strings (no shell expansion or command substitution).
# Leave unused keys out of the file.
# Hosted model provider (single-key providers only).
# THT_MODEL_API_KEY=replace-me
# External DWH and vector adapters.
# THT_DWH_API_KEY=replace-me
# THT_VEC_API_KEY=replace-me
# THT_VEC_WRITE_API_KEY=replace-me
# Optional local-vector roles.
# THT_VECTOR_BOOTSTRAP_PASSWORD=replace-me
# THT_VECTOR_MIGRATOR_PASSWORD=replace-me
# THT_VECTOR_READER_PASSWORD=replace-me
# THT_VECTOR_WRITER_PASSWORD=replace-me
# Optional CA material/path understood by the configured adapter.
# THT_CA=/run/secrets/ca-chain.pem