feat(deploy): docker images, compose, roles SQL, local workspace

- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
This commit is contained in:
User
2026-07-12 16:49:03 +02:00
parent 3fd4b0db86
commit 67d030b24d
13 changed files with 436 additions and 0 deletions
+27
View File
@@ -0,0 +1,27 @@
#!/usr/bin/env bash
# Entrypoints logici del container thothii-core:
# server (default) | check | tht <args...> | preprocess <args...>
# THT_CONFIG punta al workspace attivo (local.yaml nel deploy co-locato).
set -euo pipefail
export THT_CONFIG="${THT_CONFIG:-/app/harness/workspaces/local.yaml}"
cmd="${1:-server}"
case "$cmd" in
check)
# Diagnostica di wiring: validazione config/env + ping DWH (read-only).
shift
tht config check -c "$THT_CONFIG"
tht db ping -c "$THT_CONFIG" || echo "(db ping non verde: verificare .env/ruoli/VPN)"
;;
tht)
shift
exec tht "$@"
;;
preprocess)
shift
exec tht evidence index "$@"
;;
*)
exec "$@"
;;
esac