diff --git a/.superpowers/sdd/task-4-report.md b/.superpowers/sdd/task-4-report.md index a4850adc..0ac3a0ad 100644 --- a/.superpowers/sdd/task-4-report.md +++ b/.superpowers/sdd/task-4-report.md @@ -27,6 +27,9 @@ Updated: - `scripts/test-container-deployment.sh` now validates the bundle mount and rejects legacy per-secret references; `.dockerignore` explicitly re-includes only the required vector policy helper so the Docker build context remains safe. +- The Mac/Windows/local-vector and remote-server snippets now include required DWH/database and + Evidence-root settings. `deploy/env.example` is explicitly deprecated and no longer selects a + different Compose overlay. The docs explicitly state that a PEM CA chain cannot be put in the strict single-line bundle. A reviewed Compose override/secret-manager mount is required for `THT_SSL_CA`. Direct PostgreSQL diff --git a/deploy/env.example b/deploy/env.example index 05e4d1f3..1a1da078 100644 --- a/deploy/env.example +++ b/deploy/env.example @@ -1,9 +1,10 @@ -# Deprecated compatibility template. -# New installations should copy ../.env.example to ../.env and run -# `docker compose up --build -d` from the repository root. +# Deprecated compatibility template; it is not loaded by Docker Compose automatically. +# New installations must copy ../.env.example to ../.env and run +# `docker compose up --build -d` from the repository root. Keep this file only for +# staged upgrades that still invoke `--env-file deploy/env.example` explicitly. # Never put secret values in this file. -COMPOSE_FILE=compose.yaml:deploy/compose.local.yaml +COMPOSE_FILE=compose.yaml COMPOSE_PROFILES= THT_SECRETS_FILE=deploy/secrets/thothii.secrets diff --git a/docs/installazione-docker-4-contesti.md b/docs/installazione-docker-4-contesti.md index ea38f1dd..b268bb4f 100644 --- a/docs/installazione-docker-4-contesti.md +++ b/docs/installazione-docker-4-contesti.md @@ -150,7 +150,10 @@ Installare Docker Desktop e, se usato, Ollama sul Mac. Nel `.env` selezionare il ```dotenv COMPOSE_FILE=compose.yaml:deploy/compose.local-vector.yaml COMPOSE_PROFILES=local-vector +THT_DB_NAME=warehouse +THT_DWH_REST_URL=https://dwh.example.test THT_OLLAMA_URL=http://host.docker.internal:11434 +THT_DOCS_ROOT=/data/source/evidence ``` Nel bundle aggiungere quattro password generate localmente: @@ -171,7 +174,10 @@ Usare Docker Desktop con backend WSL2 e abilitare la condivisione della director ```dotenv COMPOSE_FILE=compose.yaml;deploy/compose.local-vector.yaml COMPOSE_PROFILES=local-vector +THT_DB_NAME=warehouse +THT_DWH_REST_URL=https://dwh.example.test THT_OLLAMA_URL=http://host.docker.internal:11434 +THT_DOCS_ROOT=/data/source/evidence ``` Creare `deploy/secrets/thothii.secrets` con un editor locale protetto (ACL leggibile solo dall'utente Docker) e le stesse quattro chiavi pgvector del profilo Mac. Non usare `ConvertFrom-SecureString`: il bundle deve contenere il valore in chiaro per il servizio, con accesso limitato al file. Da PowerShell, dalla radice del clone, eseguire: @@ -190,6 +196,7 @@ Usare il profilo production e consentire dal firewall solo le destinazioni neces ```dotenv COMPOSE_FILE=compose.yaml:deploy/compose.production.yaml COMPOSE_PROFILES= +THT_DB_NAME=warehouse THT_DWH_REST_URL=https://dwh.example.test THT_VEC_REST_URL=https://vectors.example.test THT_OLLAMA_URL=https://embeddings.example.test