feat(cli): validate prerequisites and seal installation plans

This commit is contained in:
Codex
2026-09-28 17:03:25 +02:00
parent b9c3369e7b
commit 55f3569e55
30 changed files with 2271 additions and 4 deletions
+19
View File
@@ -75,6 +75,25 @@ fixtures and removes host tools from the subprocess PATH. Platform acceptance an
real external credentials remain separate gates. See the IT/EN guides for the
complete parameter collection procedure, default `admin` account and local-auth scope.
## Host preflight and installation plan (issue #45)
`tht installation preflight --directory PATH [--release MANIFEST] [--json]` checks
the prepared directory and host without creating a stack. After completing the
documents, use `tht --installation ABS_PATH installation plan --workspaces PATH
--release MANIFEST --output NEW_PLAN [--bootstrap PATH] [--json]` for the full plan.
The manifest, bounded external reads, private input seal and mandatory runtime
obligations are specified in the
[preflight reference](../../docs/install/installation-preflight.md).
The native end-to-end test supplies a controlled Docker executable and real local
HTTPS Git/HTTP database services. No application container is created:
```sh
cd tools/tht
THT_INSTALLATION_TEST_CLI=/absolute/path/dist/workspace-tools/darwin-arm64/tht \
go test ./cmd/tht -run TestNativeInstallationPlanBeforeContainersExist -count=1
```
## Shell configuration
The schema-v2 `thothii-installation.yaml` accepts this optional section: