refactor: retire external vector deployment

This commit is contained in:
2026-08-08 19:05:57 +02:00
parent 8f4ec1e1a3
commit 4e3fecbe8e
44 changed files with 370 additions and 1710 deletions
+30 -1
View File
@@ -57,6 +57,9 @@ if [[ -d scripts ]]; then
contract_test_files+=("${file#./}")
continue
;;
compose-with-preflight.sh|generate-connector-secrets-override.sh|unified-deployment-smoke.sh|vector-backup.sh|vector-restore.sh|vector-rotate-bootstrap-password.sh)
continue
;;
verify-*.sh) continue ;;
esac
operator_files+=("${file#./}")
@@ -86,25 +89,51 @@ scan_category() {
}
for forbidden_file in \
deploy/compose.local-vector.yaml \
deploy/compose.preprocess-local-vector.yaml \
deploy/compose.production.yaml \
deploy/compose.psd-local.yaml.example \
deploy/compose.psd-local.yaml \
deploy/sql/20-vector-roles.sql \
deploy/vector/reconcile-roles.sh \
deploy/vector/rotate-bootstrap-password.py \
deploy/vector/secret-policy.sh \
deploy/vector/vector-db-entrypoint.sh \
scripts/bootstrap-local-psd-docker-config.sh \
scripts/local-vector-smoke.sh \
scripts/test-qwen-network-config.sh \
scripts/test-local-vector-smoke-safety.sh \
scripts/test-local-vector-smoke-live-collision.sh \
scripts/test-vector-bootstrap-rotation.sh \
scripts/test-vector-migration-image.sh \
scripts/test-vector-secret-policy.sh \
harness/tests/test_psd_local_compose_contract.py; do
[[ ! -e "$forbidden_file" ]] \
|| offenders+=("active filename: $forbidden_file (superseded deployment contract)")
done
forbidden='omics_portal|chirone|localllm_default|datamart-builder|compose\.production\.yaml|compose\.psd-local\.yaml|\bpsd\b'
retired_semantic='local-vector|THT_VECTOR_(BOOTSTRAP|MIGRATOR|READER|WRITER|DATABASE|HOST|PORT|USER|ADMIN_URL|OPERATOR_ENV_FILE)|THT_OLLAMA_URL|VECTOR_API_KEY_(FILE|SOURCE)|vector-api-key|(^|[^A-Za-z0-9_])THT_VEC_(REST_URL|WRITE_REST_URL)'
scan_category runtime "$forbidden" "${runtime_files[@]}"
scan_category install "$forbidden" "${install_files[@]}"
scan_category operator "$forbidden" "${operator_files[@]}"
scan_category runtime "$retired_semantic" "${runtime_files[@]}"
scan_category install "$retired_semantic" "${install_files[@]}"
scan_category operator "$retired_semantic" "${operator_files[@]}"
# Contract tests legitimately quote forbidden names in negative assertions. Scan their positive
# deployment wiring constructs instead, so a provider-owned network or retired overlay cannot be
# required under a different test filename.
positive_contract='networks(\?|\.)?\.?localllm_default|services(\?|\.)?\.?core(\?|\.)?\.?networks(\?|\.)?\.?localllm_default|docker compose[^\n]*(compose\.psd-local|compose\.production)|THT_PSD_[A-Z0-9_]*='
scan_category contract-test "$positive_contract" "${contract_test_files[@]}"
contract_scan_files=()
for file in "${contract_test_files[@]}"; do
case "${file#scripts/}" in
test-compose-secret-policy.sh|test-preprocess-compose-config.sh) continue ;;
esac
contract_scan_files+=("$file")
done
retired_semantic_contract='docker compose[^\n]*(compose\.local-vector|compose\.preprocess-local-vector)|THT_VECTOR_(BOOTSTRAP|MIGRATOR|READER|WRITER|DATABASE|HOST|PORT|USER|ADMIN_URL|OPERATOR_ENV_FILE)=|THT_OLLAMA_URL=|THT_WS_[A-Z0-9_]*_VECTOR_(TRANSPORT|API_KEY_(FILE|SOURCE))=|vector-api-key'
scan_category contract-test "$retired_semantic_contract" "${contract_scan_files[@]}"
if [[ -f scripts/run-stack.sh ]]; then
set +e
@@ -128,4 +157,4 @@ if ((${#offenders[@]})); then
exit 1
fi
echo "no active PSD, Chirone, or portal deployment coupling found."
echo "no active retired deployment or external semantic coupling found."