feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
This commit is contained in:
@@ -0,0 +1,73 @@
|
||||
# Workspace ThothII — Profilo A (server co-locato). DWH + vector BOTH direct, no REST.
|
||||
# Segreti SOLO in env (compose env_file: deploy/thothii.env). Path assoluti interni al container (/data).
|
||||
language: it
|
||||
|
||||
database:
|
||||
host: ${THT_DB_HOST} # host.docker.internal
|
||||
port: ${THT_DB_PORT} # 5438 (stessa istanza del vector)
|
||||
database: ${THT_DB_NAME} # postgres
|
||||
schema: datawarehouse
|
||||
user: ${THT_DB_USER} # thoth_dwh_reader
|
||||
password: ${THT_DB_PASSWORD}
|
||||
transport: direct # Postgres diretto, niente PostgREST/CA
|
||||
|
||||
# Nessuna sezione `rest`: non usata con transport=direct.
|
||||
|
||||
paths:
|
||||
sessions: /data/sessions
|
||||
artifacts: /data/artifacts
|
||||
indexes: /data/indexes
|
||||
|
||||
examples:
|
||||
max_per_column: 10
|
||||
|
||||
lsh:
|
||||
signature_size: 64
|
||||
n_gram: 3
|
||||
threshold: 0.5
|
||||
max_values_per_column: 1000
|
||||
|
||||
eligibility:
|
||||
max_declared_len: 128
|
||||
max_avg_length: 40
|
||||
max_sampled_len: 200
|
||||
ignore_columns: [etl_last_update]
|
||||
|
||||
evidence:
|
||||
source_root: /data # il corpus è montato a /data/evidence
|
||||
evidence_dir: evidence # → /data/evidence
|
||||
|
||||
embeddings:
|
||||
base_url: ${THT_OLLAMA_URL} # http://host.docker.internal:11434
|
||||
model: nomic-embed-text-v2-moe
|
||||
dim: 768
|
||||
batch_size: 32
|
||||
|
||||
# Vector: diretto (read+write). L'assenza di vector_rest/vector_write_rest fa sì che
|
||||
# open_searcher()/open_store() (harness/tht/cli/vector_cmd.py) selezionino DirectSearcher/VectorStore.
|
||||
vector_db:
|
||||
host: ${THT_VEC_HOST} # host.docker.internal
|
||||
port: ${THT_VEC_PORT} # 5438
|
||||
database: postgres
|
||||
schema: vectors
|
||||
user: ${THT_VEC_USER} # thoth_vector_rw
|
||||
password: ${THT_VEC_PASSWORD}
|
||||
|
||||
# Nessuna sezione vector_rest / vector_write_rest: tutto diretto in locale.
|
||||
|
||||
vector:
|
||||
max_chunk_chars: 4000
|
||||
|
||||
search:
|
||||
rrf_k: 60
|
||||
top_schema_tables: 12
|
||||
schema_chunk_pool: 150
|
||||
|
||||
execution:
|
||||
allow: [cte_test, explain, preview, aggregate, export]
|
||||
max_preview_rows: 10
|
||||
max_export_rows: 100000
|
||||
statement_timeout_ms: 30000
|
||||
warn_execution_ms: 5000
|
||||
max_aggregate_cells: 20
|
||||
forbidden_functions: [set_config, dblink, dblink_exec, lo_import]
|
||||
Reference in New Issue
Block a user