feat: add AI catalog description generation

This commit is contained in:
Codex
2026-08-29 16:42:56 +02:00
parent b0afba81ca
commit 376dd5a09d
76 changed files with 14860 additions and 102 deletions
+1
View File
@@ -6,6 +6,7 @@ THOTH_CORE_HTTP_PORT=8787
MAX_PI_PROCESSES=4
PI_AUTH_FILE=/absolute/path/to/pi-auth.json
THT_SECRETS_FILE=/absolute/path/to/thothii.secrets
THT_INSTALLATION_CONFIG_SOURCE=/absolute/path/to/thothii-installation.yaml
THT_AUTH_CONFIG_ROOT=/absolute/path/to/thothii-auth
THT_CATALOG_RUNTIME_PASSWORD_SOURCE=/absolute/path/to/catalog-runtime-password
THT_CATALOG_MIGRATOR_PASSWORD_SOURCE=/absolute/path/to/catalog-migrator-password
+1
View File
@@ -5,6 +5,7 @@ THOTH_HTTP_PORT=8080
MAX_PI_PROCESSES=4
PI_AUTH_FILE=/absolute/path/to/pi-auth.json
THT_SECRETS_FILE=/absolute/path/to/thothii.secrets
THT_INSTALLATION_CONFIG_SOURCE=/absolute/path/to/thothii-installation.yaml
THT_AUTH_CONFIG_ROOT=/absolute/path/to/thothii-auth
THT_CATALOG_RUNTIME_PASSWORD_SOURCE=/absolute/path/to/catalog-runtime-password
THT_CATALOG_MIGRATOR_PASSWORD_SOURCE=/absolute/path/to/catalog-migrator-password
+1
View File
@@ -8,6 +8,7 @@ THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=<abs>/deploy/psd/secrets/git-known-hosts
# App
THT_SECRETS_FILE=<abs>/deploy/psd/secrets/thothii.secrets
THT_INSTALLATION_CONFIG_SOURCE=<abs>/deploy/psd/thothii-installation.yaml
PI_AUTH_FILE=<abs>/deploy/psd/secrets/pi-auth.json
THT_AUTH_CONFIG_ROOT=<abs>/deploy/psd/auth
# DWH and Evidence credentials are entered later in Workspace management and stored encrypted
@@ -8,6 +8,32 @@ workspaceRepository:
remote: git@github.com:mptyl/tht-workspace-psd.git
branch: main
access: ssh
metadataGeneration:
default: glm-53
models:
- id: deepseek-v4-pro
label: DeepSeek V4 Pro
litellm:
provider: deepseek
model: deepseek-v4-pro
apiKeyEnv: DEEPSEEK_API_KEY
- id: glm-53
label: GLM 5.3
litellm:
provider: openai
model: glm-5.3
endpoint:
baseUrl: https://api.z.ai/api/coding/paas/v4
apiKeyEnv: ZAI_API_KEY
- id: qwen-36
label: AritmoLab Qwen 3.6 35B A3B
litellm:
provider: openai
model: qwen3.6-35b-a3b
disableThinking: true
endpoint:
baseUrl: https://ml-aritmolab.policlinicosandonato.it/v1
# Qwen omette apiKeyEnv: l'endpoint VPN non autentica le richieste.
authentication:
configDirectory: "<abs>/projects/ThothII/deploy/psd/auth"
overrides:
+18 -5
View File
@@ -9,11 +9,24 @@ chmod 600 deploy/secrets/thothii.secrets
```
The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). The supported
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, `THT_SSL_CA`,
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. The two authentication keys are fixed
empty entries for local authentication and must be populated only in a protected OIDC installation.
Other configured values must be non-empty and contain no whitespace. Do not put secrets
in the root `.env`, workspace YAML, URLs, logs, or rendered Compose output.
installation keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, `THT_SSL_CA`,
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. Metadata-generation models may reference
exactly one of `THT_METADATA_API_KEY`, `ANTHROPIC_API_KEY`, `AZURE_API_KEY`, `GEMINI_API_KEY`,
`DEEPSEEK_API_KEY`, `OPENAI_API_KEY`, `OPENROUTER_API_KEY`, or `ZAI_API_KEY` through their
descriptor `apiKeyEnv`. An entry for an explicitly configured endpoint that accepts unauthenticated
requests may omit `apiKeyEnv`; hosted/default endpoints must always reference a key.
OpenAI-compatible Qwen endpoints that emit reasoning in `content` can additionally set
`litellm.disableThinking: true`; the adapter sends the server's bounded chat-template flag so the
strict JSON result remains parseable.
The two authentication keys must be omitted until they have non-empty values in a protected OIDC
installation. Other configured values must be non-empty and contain no
whitespace. Do not put secrets in the root `.env`, installation YAML, workspace YAML, URLs, logs,
or rendered Compose output.
`THT_MODEL_API_KEY` remains the generic Pi child credential. Metadata generation is a separate
backend-owned runtime and reads only the key named by its own `metadataGeneration.models[].apiKeyEnv`
(when present);
it does not read Pi settings, `PI_AUTH_FILE`, or workspace `llm_policy`.
Do not add vector or embedding endpoint credentials to the bundle. Active operator manuals use
internal Qdrant and Ollama services, so vector/embedding runtime endpoint secrets are not part of
+9 -3
View File
@@ -5,12 +5,18 @@
# Hosted model provider (single-key providers only).
# THT_MODEL_API_KEY=replace-me
# Description Generation only. The selected name must match apiKeyEnv in metadataGeneration.
# Allowed names: THT_METADATA_API_KEY, ANTHROPIC_API_KEY, AZURE_API_KEY, GEMINI_API_KEY,
# DEEPSEEK_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, or ZAI_API_KEY.
# OPENAI_API_KEY=replace-me
# A model with an explicit unauthenticated endpoint omits apiKeyEnv and needs no bundle entry.
# External DWH adapter.
# THT_DWH_API_KEY=replace-me
# Optional CA material/path understood by the configured adapter.
# THT_CA=/run/secrets/ca-chain.pem
# OIDC/Authentik references. Keep these fixed keys empty until OIDC is configured.
THT_OIDC_CLIENT_SECRET=
THT_AUTHENTIK_API_TOKEN=
# OIDC/Authentik references. Uncomment only with non-empty values when configured.
# THT_OIDC_CLIENT_SECRET=replace-me
# THT_AUTHENTIK_API_TOKEN=replace-me