fix(deploy): isolate local vector compose secrets
This commit is contained in:
@@ -47,3 +47,13 @@ the in-process validated `DatabaseConfig` used to establish PostgreSQL connectio
|
||||
serialized by doctor/Compose/inspect paths. Docker Desktop file-backed secrets may appear as bind
|
||||
mounts; the safe runtime exception is therefore based on the read-only service mount location
|
||||
`/run/secrets`, while source files remain owner-only on the host.
|
||||
|
||||
## External-profile regression follow-up
|
||||
|
||||
Local pgvector is now an explicit `deploy/compose.local-vector.yaml` overlay. The base Compose and
|
||||
production external override contain no direct vector password declarations, mounts, or `_FILE`
|
||||
variables, so external deployments do not resolve or require local password files. A real lifecycle
|
||||
gate unsets all local secret-file variables, renders external config, builds and starts core, waits
|
||||
for health, and inspects the live container for absence of local direct-vector secret paths. The
|
||||
local overlay retains its live inspect assertion (paths present, values absent), rotation, restart
|
||||
persistence, and transactional backup/restore drill.
|
||||
|
||||
Reference in New Issue
Block a user