feat(preprocess): add deployment jobs and S3 source

This commit is contained in:
2026-07-12 05:42:07 +02:00
parent 6656a69630
commit 4028ef7821
12 changed files with 380 additions and 10 deletions
+17
View File
@@ -53,6 +53,23 @@ volume is independent of application state. Reader, writer,
migrator, and bootstrap credentials remain separate; password files must be mode `0600` and
must not be passed as URL arguments.
## Preprocessing jobs and S3 Evidence
Run one-shot jobs through the explicit overlay, which is inert for normal external/local runtime:
```sh
docker compose -f compose.yaml -f deploy/compose.preprocess.yaml --profile preprocess \
run --rm preprocess-evidence
docker compose -f compose.yaml -f deploy/compose.preprocess.yaml --profile preprocess \
run --rm preprocess-dwh
```
S3 Evidence uses the optional `tht[s3]` dependency and canonical `s3://bucket/key` provenance.
TLS and public endpoints are required by default; private or HTTP S3-compatible endpoints require
separate explicit opt-ins. Store access key, secret key, and session token as secret references in
deployment configuration—never in Compose environment values or source URIs. Discovery and reads
are bounded by configured page, object, and byte limits.
Create a versioned PostgreSQL custom-format backup (the filename is operator-controlled, so use
an immutable timestamp or release identifier):