fix(docs): enforce compose preflight workflow
This commit is contained in:
@@ -80,10 +80,10 @@ file; a reader credential is never repurposed for writing.
|
||||
## Direct PostgreSQL, REST, and SSH tunnel bindings
|
||||
|
||||
Set only fields for the selected transport in the dedicated bindings env file. Canonical YAML keeps
|
||||
database/schema/collection, distance, embedding model, and dimensions shared in Git. Copy and
|
||||
review [the connector-secret override](examples/connector-secrets.workspace-registry.yaml) for the
|
||||
selected transport: every `*_FILE=/run/secrets/<target>` binding needs one matching Docker secret
|
||||
target and one host-only `*_SOURCE` path in operator `.env`.
|
||||
database/schema/collection, distance, embedding model, and dimensions shared in Git. Every
|
||||
`*_FILE=/run/secrets/<target>` binding needs one matching host-only `*_SOURCE` path in operator
|
||||
`.env`. Generate the untracked connector override from those two files during bootstrap; do not
|
||||
copy or maintain a workspace-specific Compose override.
|
||||
|
||||
```dotenv
|
||||
# Direct PostgreSQL and pgvector
|
||||
@@ -134,23 +134,26 @@ before creating sessions. Git pull/push over SSH remains fully supported and is
|
||||
|
||||
## Bootstrap, first pull, and diagnostics
|
||||
|
||||
Copy [the local Compose example](examples/local-compose.workspace-registry.yaml) and exactly one
|
||||
selected [SSH Git override](examples/git-ssh.workspace-registry.yaml) or [HTTPS Git override](examples/git-https.workspace-registry.yaml)
|
||||
plus [the bindings env example](examples/workspace-bindings.env.example) and a reviewed
|
||||
[connector-secret override](examples/connector-secrets.workspace-registry.yaml) into an untracked
|
||||
operator directory. Set `THT_SOURCE_ROOT` and the absolute `THT_WORKSPACE_BINDINGS_ENV_FILE` in
|
||||
its `.env`; this keeps the copied Compose file buildable and confines `THT_WS_*` values to `core`.
|
||||
Create only the host secret files named by the selected Git/connector override, then render it.
|
||||
Copy [the local Compose example](examples/local-compose.workspace-registry.yaml), exactly one
|
||||
selected [SSH Git override](examples/git-ssh.workspace-registry.yaml) or [HTTPS Git override](examples/git-https.workspace-registry.yaml),
|
||||
and [the bindings env example](examples/workspace-bindings.env.example) into an untracked operator
|
||||
directory. Set `THT_SOURCE_ROOT` and the absolute `THT_WORKSPACE_BINDINGS_ENV_FILE` in its `.env`;
|
||||
this keeps the copied Compose file buildable and confines `THT_WS_*` values to `core`. Create the
|
||||
host secret files named by the selected Git transport and every declared connector `*_SOURCE`, then
|
||||
generate the connector override and render through the preflight wrapper. The wrapper is required:
|
||||
it rejects unsafe source paths and a combined SSH+HTTPS Git selection before Compose runs.
|
||||
|
||||
<!-- verify:command -->
|
||||
```sh
|
||||
THT_SOURCE_ROOT="$(pwd -P)" THT_WORKSPACE_BINDINGS_ENV_FILE="$(pwd -P)/docs/install/examples/workspace-bindings.env.example" docker compose -f docs/install/examples/local-compose.workspace-registry.yaml config --quiet
|
||||
"$THT_SOURCE_ROOT/scripts/generate-connector-secrets-override.sh" --bindings-env "$THT_WORKSPACE_BINDINGS_ENV_FILE" --operator-env .env --output connector-secrets.local.yaml
|
||||
"$THT_SOURCE_ROOT/scripts/compose-with-preflight.sh" --env-file .env \
|
||||
-f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml -f connector-secrets.local.yaml config --quiet
|
||||
```
|
||||
|
||||
From the operator directory:
|
||||
|
||||
```sh
|
||||
docker compose -f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml -f connector-secrets.workspace-registry.yaml up --build -d
|
||||
"$THT_SOURCE_ROOT/scripts/compose-with-preflight.sh" --env-file .env \
|
||||
-f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml -f connector-secrets.local.yaml up --build -d
|
||||
curl --fail --silent http://127.0.0.1:8787/health
|
||||
curl --fail --silent http://127.0.0.1:8787/workspace-registry/status
|
||||
curl --fail --silent http://127.0.0.1:8787/workspaces
|
||||
|
||||
Reference in New Issue
Block a user