fix: bind workspace connector configuration safely
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
# Reviewed direct PostgreSQL/pgvector connector-secret override for workspace-bindings.env.example.
|
||||
# Source variables are absolute host paths. Add only matching entries for the selected transport;
|
||||
# targets must equal the corresponding THT_WS_*_FILE paths in the bindings env file.
|
||||
services:
|
||||
core:
|
||||
secrets:
|
||||
- source: psd_clinical_dwh_password
|
||||
target: psd-clinical-dwh-password
|
||||
- source: psd_clinical_vector_password
|
||||
target: psd-clinical-vector-password
|
||||
|
||||
secrets:
|
||||
psd_clinical_dwh_password:
|
||||
file: ${THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE:?set THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE}
|
||||
psd_clinical_vector_password:
|
||||
file: ${THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE:?set THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE}
|
||||
@@ -8,6 +8,9 @@ services:
|
||||
build:
|
||||
context: ${THT_SOURCE_ROOT:?set THT_SOURCE_ROOT to the absolute ThothII source checkout}
|
||||
dockerfile: docker/core.Dockerfile
|
||||
env_file:
|
||||
- path: ${THT_WORKSPACE_BINDINGS_ENV_FILE:?set THT_WORKSPACE_BINDINGS_ENV_FILE to an absolute THT_WS bindings file}
|
||||
required: true
|
||||
environment:
|
||||
HOST: 0.0.0.0
|
||||
PORT: "8787"
|
||||
|
||||
@@ -8,6 +8,9 @@ services:
|
||||
build:
|
||||
context: ${THT_SOURCE_ROOT:?set THT_SOURCE_ROOT to the absolute ThothII source checkout}
|
||||
dockerfile: docker/core.Dockerfile
|
||||
env_file:
|
||||
- path: ${THT_WORKSPACE_BINDINGS_ENV_FILE:?set THT_WORKSPACE_BINDINGS_ENV_FILE to an absolute THT_WS bindings file}
|
||||
required: true
|
||||
environment:
|
||||
HOST: 0.0.0.0
|
||||
PORT: "8787"
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
# Copy to an untracked operator file. This file contains only non-secret THT_WS_* bindings.
|
||||
# Every *_FILE value is a container path supplied by a reviewed connector-secret override.
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT=postgres_direct
|
||||
THT_WS_PSD_CLINICAL_DWH_HOST=dwh.internal.example
|
||||
THT_WS_PSD_CLINICAL_DWH_PORT=5432
|
||||
THT_WS_PSD_CLINICAL_DWH_USER=thoth_reader
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE=/run/secrets/psd-clinical-dwh-password
|
||||
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT=pgvector_direct
|
||||
THT_WS_PSD_CLINICAL_VECTOR_HOST=vector.internal.example
|
||||
THT_WS_PSD_CLINICAL_VECTOR_PORT=5432
|
||||
THT_WS_PSD_CLINICAL_VECTOR_USER=thoth_vector_reader
|
||||
THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_FILE=/run/secrets/psd-clinical-vector-password
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL=https://embeddings.internal.example
|
||||
@@ -55,7 +55,8 @@ and branch are non-secret; every `*_FILE` is a local path whose content never en
|
||||
| Location | Contains | Never contains |
|
||||
| --- | --- | --- |
|
||||
| Git workspace repository | schema v2 YAML, generated binding names, LLM policy, model/index identity | installation hostnames, keys, passwords, certificates, SSH keys |
|
||||
| local `.env` | remote, branch, installation ID, selected transport and endpoints | secret contents |
|
||||
| local `.env` | remote, branch, installation ID, `THT_WORKSPACE_BINDINGS_ENV_FILE`, and secret source paths | secret contents or `THT_WS_*` values |
|
||||
| workspace bindings env file | only `THT_WS_*` transport, endpoint, user, and `/run/secrets/...` path bindings | secret contents or unrelated application settings |
|
||||
| local secret directory | Git credentials/key, known hosts, CA, connector secret files | a copied registry checkout |
|
||||
| Docker volumes | registry checkout/snapshots/state/locks and local data | host-only secret source files |
|
||||
|
||||
@@ -69,14 +70,20 @@ locks/ # short-lived publish locks
|
||||
```
|
||||
|
||||
Installation variables are deterministic: `psd-clinical` becomes `PSD_CLINICAL`, and every name
|
||||
is `THT_WS_<NAMESPACE>_<ROLE>_<SUFFIX>`. Credentials and certificates use `*_FILE` path variables.
|
||||
is `THT_WS_<NAMESPACE>_<ROLE>_<SUFFIX>`. Copy
|
||||
[the bindings env example](examples/workspace-bindings.env.example) to an untracked operator file
|
||||
and set its absolute path as `THT_WORKSPACE_BINDINGS_ENV_FILE`. It is loaded only into `core`.
|
||||
Credentials and certificates use `*_FILE` path variables that must point inside `/run/secrets`.
|
||||
If declared, `THT_WS_PSD_CLINICAL_VECTOR_WRITER_API_KEY_FILE` is distinct from the vector reader
|
||||
file; a reader credential is never repurposed for writing.
|
||||
|
||||
## Direct PostgreSQL, REST, and SSH tunnel bindings
|
||||
|
||||
Set only fields for the selected transport. Canonical YAML keeps database/schema/collection,
|
||||
distance, embedding model, and dimensions shared in Git.
|
||||
Set only fields for the selected transport in the dedicated bindings env file. Canonical YAML keeps
|
||||
database/schema/collection, distance, embedding model, and dimensions shared in Git. Copy and
|
||||
review [the connector-secret override](examples/connector-secrets.workspace-registry.yaml) for the
|
||||
selected transport: every `*_FILE=/run/secrets/<target>` binding needs one matching Docker secret
|
||||
target and one host-only `*_SOURCE` path in operator `.env`.
|
||||
|
||||
```dotenv
|
||||
# Direct PostgreSQL and pgvector
|
||||
@@ -125,19 +132,21 @@ rather than weakening TLS; use runtime-trusted HTTPS or verified direct/SSH nati
|
||||
|
||||
Copy [the local Compose example](examples/local-compose.workspace-registry.yaml) and exactly one
|
||||
selected [SSH Git override](examples/git-ssh.workspace-registry.yaml) or [HTTPS Git override](examples/git-https.workspace-registry.yaml)
|
||||
into an untracked operator directory. Set `THT_SOURCE_ROOT` in its `.env` to the absolute source
|
||||
checkout path; this keeps the copied Compose file buildable. Create only the secret files used by
|
||||
the selected override, then render it before start.
|
||||
plus [the bindings env example](examples/workspace-bindings.env.example) and a reviewed
|
||||
[connector-secret override](examples/connector-secrets.workspace-registry.yaml) into an untracked
|
||||
operator directory. Set `THT_SOURCE_ROOT` and the absolute `THT_WORKSPACE_BINDINGS_ENV_FILE` in
|
||||
its `.env`; this keeps the copied Compose file buildable and confines `THT_WS_*` values to `core`.
|
||||
Create only the host secret files named by the selected Git/connector override, then render it.
|
||||
|
||||
<!-- verify:command -->
|
||||
```sh
|
||||
THT_SOURCE_ROOT="$(pwd -P)" docker compose -f docs/install/examples/local-compose.workspace-registry.yaml config --quiet
|
||||
THT_SOURCE_ROOT="$(pwd -P)" THT_WORKSPACE_BINDINGS_ENV_FILE="$(pwd -P)/docs/install/examples/workspace-bindings.env.example" docker compose -f docs/install/examples/local-compose.workspace-registry.yaml config --quiet
|
||||
```
|
||||
|
||||
From the operator directory:
|
||||
|
||||
```sh
|
||||
docker compose -f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml up --build -d
|
||||
docker compose -f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml -f connector-secrets.workspace-registry.yaml up --build -d
|
||||
curl --fail --silent http://127.0.0.1:8787/health
|
||||
curl --fail --silent http://127.0.0.1:8787/workspace-registry/status
|
||||
curl --fail --silent http://127.0.0.1:8787/workspaces
|
||||
|
||||
@@ -61,8 +61,10 @@ restarting `core`, and performing pull/status; never put the material in an envi
|
||||
|
||||
Git describes workspace schema, immutable ID, DWH/vector identity, semantic-index dimensions and
|
||||
distance, embedding contract, and LLM policy. The installation supplies remote/branch/installation
|
||||
ID, transport, endpoints, users, ports, and `THT_WS_*` bindings. Secret contents are only in files,
|
||||
never the values stored in Git or browser-local drafts.
|
||||
ID and one absolute `THT_WORKSPACE_BINDINGS_ENV_FILE` containing only `THT_WS_*` transport,
|
||||
endpoint, user, and `/run/secrets/...` path bindings. The base Compose loads that file only into
|
||||
`core`. Secret contents are only in host files, never the values stored in Git or browser-local
|
||||
drafts.
|
||||
|
||||
The runtime registry layout is persistent and must be backed up together:
|
||||
|
||||
@@ -76,6 +78,10 @@ The runtime registry layout is persistent and must be backed up together:
|
||||
Variable names derive from the immutable ID: `psd-clinical` becomes `PSD_CLINICAL`, producing
|
||||
`THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE`. A declared vector writer uses the distinct
|
||||
`THT_WS_PSD_CLINICAL_VECTOR_WRITER_API_KEY_FILE`; a reader file is never a writer substitute.
|
||||
Copy [the bindings env example](examples/workspace-bindings.env.example) to the protected operator
|
||||
directory. Every path-valued `*_FILE` entry must be supplied by a reviewed
|
||||
[connector-secret override](examples/connector-secrets.workspace-registry.yaml) with a matching
|
||||
Docker secret target below `/run/secrets` and an absolute host-only `*_SOURCE` path.
|
||||
|
||||
## Direct PostgreSQL, REST, and SSH tunnel bindings
|
||||
|
||||
@@ -132,7 +138,9 @@ Copy [the server Compose example](examples/server-compose.workspace-registry.yam
|
||||
selected Git override to the protected operator directory. Set `THT_SOURCE_ROOT` to the absolute
|
||||
ThothII checkout; a copied file cannot use a relative build context. Copy
|
||||
`deploy/workspaces/server-sessions.yaml.example` into that operator directory, review it, then set
|
||||
the absolute `THT_SERVER_WORKSPACE_CONFIG` path. The same `.env` must set
|
||||
the absolute `THT_SERVER_WORKSPACE_CONFIG` path. Copy the bindings env example and a reviewed
|
||||
connector-secret override, then set absolute `THT_WORKSPACE_BINDINGS_ENV_FILE` and connector
|
||||
`*_SOURCE` paths. The same `.env` must set
|
||||
`THT_SESSION_DB_HOST`, `THT_SESSION_DB_NAME`, `THT_SESSION_RUNTIME_USER`,
|
||||
`THT_SESSION_RUNTIME_PASSWORD_SOURCE`, and `THT_SESSION_CA_SOURCE`; the base Compose file wires
|
||||
`postgres`, `verify-full`, and the two Docker secret mount paths. This is the public server profile,
|
||||
@@ -148,7 +156,7 @@ forwards the trusted identity expected by `AUTH_MODE=upstream`; it is the only p
|
||||
From a trusted maintenance shell:
|
||||
|
||||
```sh
|
||||
docker compose -f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml up --build -d
|
||||
docker compose -f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml -f connector-secrets.workspace-registry.yaml up --build -d
|
||||
docker compose -f compose.workspace-registry.yaml exec -T core curl --fail --silent http://127.0.0.1:8787/health
|
||||
docker compose -f compose.workspace-registry.yaml exec -T core curl --fail --silent http://127.0.0.1:8787/workspace-registry/status
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user