fix(deploy): isolate local vector compose secrets

This commit is contained in:
2026-07-12 02:56:00 +02:00
parent 6c67235caf
commit 532073d550
8 changed files with 141 additions and 108 deletions
@@ -47,3 +47,13 @@ the in-process validated `DatabaseConfig` used to establish PostgreSQL connectio
serialized by doctor/Compose/inspect paths. Docker Desktop file-backed secrets may appear as bind
mounts; the safe runtime exception is therefore based on the read-only service mount location
`/run/secrets`, while source files remain owner-only on the host.
## External-profile regression follow-up
Local pgvector is now an explicit `deploy/compose.local-vector.yaml` overlay. The base Compose and
production external override contain no direct vector password declarations, mounts, or `_FILE`
variables, so external deployments do not resolve or require local password files. A real lifecycle
gate unsets all local secret-file variables, renders external config, builds and starts core, waits
for health, and inspects the live container for absence of local direct-vector secret paths. The
local overlay retains its live inspect assertion (paths present, values absent), rotation, restart
persistence, and transactional backup/restore drill.