build(compose): make root startup the default

This commit is contained in:
2026-07-12 11:14:36 +02:00
parent 3807c65a41
commit 32a2b71687
10 changed files with 161 additions and 79 deletions
+16 -15
View File
@@ -6,12 +6,15 @@ cd "$(dirname "$0")/.."
tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
docker compose --profile external config >"$tmp/base.yaml"
docker compose config >"$tmp/base.yaml"
grep -q '^ core:' "$tmp/base.yaml"
grep -q '^ frontend:' "$tmp/base.yaml"
grep -q 'host_ip: 127.0.0.1' "$tmp/base.yaml"
grep -q 'AUTH_MODE: none' "$tmp/base.yaml"
grep -q 'THOTH_PUBLIC_EXPOSURE: "false"' "$tmp/base.yaml"
if grep -q 'env_file:' "$tmp/base.yaml"; then
echo "base/production-neutral Compose must not load the local env file" >&2
grep -q 'THT_SECRETS_FILE: /run/secrets/thothii.secrets' "$tmp/base.yaml"
if grep -q 'THT_[A-Z0-9_]*_SECRET_FILE:' "$tmp/base.yaml"; then
echo "base Compose must not require legacy secret-file variables" >&2
exit 1
fi
@@ -34,24 +37,22 @@ fi
docker compose -f compose.yaml -f deploy/compose.local.yaml \
--profile external config >"$tmp/local.yaml"
grep -q 'env_file:' deploy/compose.local.yaml
if grep -q 'env_file:' "$tmp/local.yaml"; then
echo "local Compose must use the root .env interpolation file" >&2
exit 1
fi
for secret in dwh reader writer ca model; do printf '%s\n' "test-$secret" >"$tmp/$secret"; done
THT_DWH_API_KEY_SECRET_FILE="$tmp/dwh" \
THT_VEC_API_KEY_SECRET_FILE="$tmp/reader" \
THT_VEC_WRITE_API_KEY_SECRET_FILE="$tmp/writer" \
THT_CA_SECRET_FILE="$tmp/ca" \
THT_MODEL_API_KEY_SECRET_FILE="$tmp/model" \
printf '%s\n' 'THT_MODEL_API_KEY=test-model' >"$tmp/thothii.secrets"
chmod 0600 "$tmp/thothii.secrets"
THT_SECRETS_FILE="$tmp/thothii.secrets" \
THT_DB_NAME=test THT_DWH_REST_URL=https://dwh.example.test \
THT_VEC_REST_URL=https://vector.example.test THT_OLLAMA_URL=https://embed.example.test \
docker compose -f compose.yaml -f deploy/compose.production.yaml \
--profile external config >"$tmp/production.yaml"
grep -q 'AUTH_MODE: upstream' "$tmp/production.yaml"
grep -q 'THOTH_PUBLIC_EXPOSURE: "true"' "$tmp/production.yaml"
grep -q 'target: thoth_ca.pem' "$tmp/production.yaml"
grep -q 'THT_DWH_API_KEY_FILE: /run/secrets/dwh_api_key' "$tmp/production.yaml"
grep -q 'THT_MODEL_API_KEY_FILE: /run/secrets/model_api_key' "$tmp/production.yaml"
grep -q 'target: model_api_key' "$tmp/production.yaml"
grep -q 'THT_SECRETS_FILE: /run/secrets/thothii.secrets' "$tmp/production.yaml"
grep -q 'target: thothii.secrets' "$tmp/production.yaml"
if grep -q 'test-model' "$tmp/production.yaml"; then
echo "rendered production config leaked the model API key" >&2
exit 1
@@ -66,7 +67,7 @@ if grep -q 'must-not-leak' "$tmp/legacy-model.err"; then
echo "legacy model credential leaked through entrypoint diagnostics" >&2
exit 1
fi
if grep -q 'THT_VECTOR_READER_PASSWORD_FILE\|THT_VECTOR_WRITER_PASSWORD_FILE\|target: vector_reader_password\|target: vector_writer_password' "$tmp/production.yaml"; then
if grep -q 'THT_VECTOR_READER_PASSWORD_FILE\|THT_VECTOR_WRITER_PASSWORD_FILE\|target: vector_reader_password\|target: vector_writer_password\|dwh_api_key\|model_api_key' "$tmp/production.yaml"; then
echo "production external config contains local direct vector secrets" >&2
exit 1
fi