feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
-- ThothII — ruolo DWH read-only (schema datawarehouse).
|
||||
-- Eseguire sulla stessa istanza Postgres usata da ThothII (porta 5438, accesso diretto).
|
||||
-- Sostituire :PWD con un secret forte al momento dell'esecuzione:
|
||||
-- psql -h localhost -p 5438 -U postgres -d postgres -v PWD='<secret>' -f 10-dwh-roles.sql
|
||||
DO $$
|
||||
BEGIN
|
||||
IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'thoth_dwh_reader') THEN
|
||||
CREATE ROLE thoth_dwh_reader LOGIN PASSWORD :'PWD';
|
||||
END IF;
|
||||
END $$;
|
||||
|
||||
GRANT USAGE ON SCHEMA datawarehouse TO thoth_dwh_reader;
|
||||
GRANT SELECT ON ALL TABLES IN SCHEMA datawarehouse TO thoth_dwh_reader;
|
||||
ALTER DEFAULT PRIVILEGES IN SCHEMA datawarehouse
|
||||
GRANT SELECT ON TABLES TO thoth_dwh_reader;
|
||||
@@ -0,0 +1,23 @@
|
||||
-- ThothII — ruolo vector read+write (schema vectors).
|
||||
-- Stessa istanza del DWH (porta 5438). ThothII indicizza (write) + ricerca (read) direttamente.
|
||||
-- La separazione reader/writer resta rilevante solo per il path REST (non usato in Profile A).
|
||||
-- psql -h localhost -p 5438 -U postgres -d postgres -v PWD='<secret>' -f 20-vector-roles.sql
|
||||
DO $$
|
||||
BEGIN
|
||||
IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'thoth_vector_rw') THEN
|
||||
CREATE ROLE thoth_vector_rw LOGIN PASSWORD :'PWD';
|
||||
END IF;
|
||||
END $$;
|
||||
|
||||
CREATE SCHEMA IF NOT EXISTS vectors;
|
||||
|
||||
-- L'estensione pgvector deve esistere (già presente nell'istanza di produzione).
|
||||
-- CREATE EXTENSION IF NOT EXISTS vector;
|
||||
|
||||
GRANT USAGE, CREATE ON SCHEMA vectors TO thoth_vector_rw;
|
||||
GRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA vectors TO thoth_vector_rw;
|
||||
GRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA vectors TO thoth_vector_rw;
|
||||
ALTER DEFAULT PRIVILEGES IN SCHEMA vectors
|
||||
GRANT SELECT, INSERT, UPDATE, DELETE ON TABLES TO thoth_vector_rw;
|
||||
ALTER DEFAULT PRIVILEGES IN SCHEMA vectors
|
||||
GRANT USAGE, SELECT ON SEQUENCES TO thoth_vector_rw;
|
||||
@@ -0,0 +1,22 @@
|
||||
# ThothII core — env di runtime (compose env_file).
|
||||
# Copiare in deploy/thothii.env e completare. NON committare thothii.env.
|
||||
|
||||
# --- DWH (direct, ruolo read-only su schema datawarehouse) ---
|
||||
THT_DB_HOST=host.docker.internal
|
||||
THT_DB_PORT=5438
|
||||
THT_DB_NAME=postgres
|
||||
THT_DB_USER=thoth_dwh_reader
|
||||
THT_DB_PASSWORD=__CHANGE_ME__
|
||||
|
||||
# --- Vector (direct, ruolo read+write su schema vectors; stessa istanza del DWH) ---
|
||||
THT_VEC_HOST=host.docker.internal
|
||||
THT_VEC_PORT=5438
|
||||
THT_VEC_USER=thoth_vector_rw
|
||||
THT_VEC_PASSWORD=__CHANGE_ME__
|
||||
|
||||
# --- Embeddings (Ollama sull'host, modello nomic-embed-text-v2-moe) ---
|
||||
THT_OLLAMA_URL=http://host.docker.internal:11434
|
||||
|
||||
# --- Backend ---
|
||||
AUTH_MODE=none # none | mock | oidc (in embedded l'auth è al bordo del portale)
|
||||
MAX_PI_PROCESSES=4
|
||||
Reference in New Issue
Block a user