refactor: retire external vector deployment
This commit is contained in:
@@ -5,9 +5,3 @@ THT_WS_NORTH_STAR_RESEARCH_DWH_HOST=dwh.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_PORT=5432
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_USER=thoth_reader
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE=/run/secrets/north-star-research-dwh-password
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_TRANSPORT=pgvector_direct
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_HOST=vector.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_PORT=5432
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_USER=thoth_vector_reader
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_PASSWORD_FILE=/run/secrets/north-star-research-vector-password
|
||||
THT_WS_NORTH_STAR_RESEARCH_EMBEDDING_BASE_URL=https://embeddings.internal.example
|
||||
|
||||
@@ -80,30 +80,21 @@ is `THT_WS_<NAMESPACE>_<ROLE>_<SUFFIX>`. Copy
|
||||
[the bindings env example](examples/workspace-bindings.env.example) to an untracked operator file
|
||||
and set its absolute path as `THT_WORKSPACE_BINDINGS_ENV_FILE`. It is loaded only into `core`.
|
||||
Credentials and certificates use `*_FILE` path variables that must point inside `/run/secrets`.
|
||||
If declared, `THT_WS_NORTH_STAR_RESEARCH_VECTOR_WRITER_API_KEY_FILE` is distinct from the vector reader
|
||||
file; a reader credential is never repurposed for writing.
|
||||
|
||||
## Direct PostgreSQL, REST, and SSH tunnel bindings
|
||||
|
||||
Set only fields for the selected transport in the dedicated bindings env file. Canonical YAML keeps
|
||||
database/schema/collection, distance, embedding model, and dimensions shared in Git. Every
|
||||
`*_FILE=/run/secrets/<target>` binding needs one matching host-only `*_SOURCE` path in operator
|
||||
`.env`. Generate the untracked connector override from those two files during bootstrap; do not
|
||||
copy or maintain a workspace-specific Compose override.
|
||||
database/schema shared in Git. Every `*_FILE=/run/secrets/<target>` binding needs one matching
|
||||
host-only `*_SOURCE` path in operator `.env`. Generate the untracked connector override from those
|
||||
two files during bootstrap; do not copy or maintain a workspace-specific Compose override.
|
||||
|
||||
```dotenv
|
||||
# Direct PostgreSQL and pgvector
|
||||
# Direct PostgreSQL
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT=postgres_direct
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_HOST=dwh.example.invalid
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_PORT=5432
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_USER=thoth_reader
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE=/run/secrets/north-star-research-dwh-password
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_TRANSPORT=pgvector_direct
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_HOST=vector.example.invalid
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_PORT=5432
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_USER=thoth_vector_reader
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_PASSWORD_FILE=/run/secrets/north-star-research-vector-password
|
||||
THT_WS_NORTH_STAR_RESEARCH_EMBEDDING_BASE_URL=https://embeddings.example.invalid
|
||||
```
|
||||
|
||||
```dotenv
|
||||
@@ -111,9 +102,6 @@ THT_WS_NORTH_STAR_RESEARCH_EMBEDDING_BASE_URL=https://embeddings.example.invalid
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT=rest_api
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_BASE_URL=https://dwh.example.invalid
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_API_KEY_FILE=/run/secrets/north-star-research-dwh-api-key
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_TRANSPORT=rest_api
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_BASE_URL=https://vectors.example.invalid
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_FILE=/run/secrets/north-star-research-vector-api-key
|
||||
```
|
||||
|
||||
```dotenv
|
||||
@@ -130,8 +118,8 @@ THT_WS_NORTH_STAR_RESEARCH_DWH_SSH_TARGET_HOST=dwh.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_SSH_TARGET_PORT=5432
|
||||
```
|
||||
|
||||
Repeat the SSH names for `VECTOR` where needed. REST diagnostics reject a private per-request CA
|
||||
rather than weakening TLS; use runtime-trusted HTTPS or verified direct/SSH native TLS. See the
|
||||
REST diagnostics reject a private per-request CA rather than weakening TLS; use runtime-trusted
|
||||
HTTPS or verified direct/SSH native TLS. See the
|
||||
[diagnostic protocol](../workspace-diagnostic-protocol.md).
|
||||
|
||||
An SSH connector can prove installation reachability, host-key verification, authentication, and
|
||||
|
||||
@@ -109,17 +109,12 @@ Select only a transport allowed by canonical YAML; preserve database/schema/coll
|
||||
dimensions, and distance as Git-shared identity.
|
||||
|
||||
```dotenv
|
||||
# Direct PostgreSQL/pgvector with verified native TLS if a CA path is supplied.
|
||||
# Direct PostgreSQL with verified native TLS if a CA path is supplied.
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT=postgres_direct
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_HOST=dwh.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_PORT=5432
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_USER=thoth_reader
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE=/run/secrets/north-star-research-dwh-password
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_TRANSPORT=pgvector_direct
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_HOST=vector.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_PORT=5432
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_USER=thoth_vector_reader
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_PASSWORD_FILE=/run/secrets/north-star-research-vector-password
|
||||
```
|
||||
|
||||
```dotenv
|
||||
@@ -127,10 +122,6 @@ THT_WS_NORTH_STAR_RESEARCH_VECTOR_PASSWORD_FILE=/run/secrets/north-star-research
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT=rest_api
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_BASE_URL=https://dwh.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_API_KEY_FILE=/run/secrets/north-star-research-dwh-api-key
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_TRANSPORT=rest_api
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_BASE_URL=https://vectors.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_FILE=/run/secrets/north-star-research-vector-api-key
|
||||
THT_WS_NORTH_STAR_RESEARCH_EMBEDDING_BASE_URL=https://embeddings.internal.example
|
||||
```
|
||||
|
||||
```dotenv
|
||||
@@ -147,7 +138,7 @@ THT_WS_NORTH_STAR_RESEARCH_DWH_SSH_TARGET_HOST=dwh.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_SSH_TARGET_PORT=5432
|
||||
```
|
||||
|
||||
Repeat SSH variables for `VECTOR` when selected. REST diagnostics refuse private per-request CAs
|
||||
REST diagnostics refuse private per-request CAs
|
||||
rather than disable verification; use runtime-trusted HTTPS or verified direct/SSH native TLS. See
|
||||
the [diagnostic protocol](../workspace-diagnostic-protocol.md) for its read-only checks and optional
|
||||
reversible writer probe.
|
||||
|
||||
Reference in New Issue
Block a user