feat(deploy): docker images, compose, roles SQL, local workspace

- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
This commit is contained in:
User
2026-07-12 16:49:03 +02:00
parent 3fd4b0db86
commit 67d030b24d
13 changed files with 436 additions and 0 deletions
+22
View File
@@ -0,0 +1,22 @@
# ThothII core — env di runtime (compose env_file).
# Copiare in deploy/thothii.env e completare. NON committare thothii.env.
# --- DWH (direct, ruolo read-only su schema datawarehouse) ---
THT_DB_HOST=host.docker.internal
THT_DB_PORT=5438
THT_DB_NAME=postgres
THT_DB_USER=thoth_dwh_reader
THT_DB_PASSWORD=__CHANGE_ME__
# --- Vector (direct, ruolo read+write su schema vectors; stessa istanza del DWH) ---
THT_VEC_HOST=host.docker.internal
THT_VEC_PORT=5438
THT_VEC_USER=thoth_vector_rw
THT_VEC_PASSWORD=__CHANGE_ME__
# --- Embeddings (Ollama sull'host, modello nomic-embed-text-v2-moe) ---
THT_OLLAMA_URL=http://host.docker.internal:11434
# --- Backend ---
AUTH_MODE=none # none | mock | oidc (in embedded l'auth è al bordo del portale)
MAX_PI_PROCESSES=4