fix(vector): close local pgvector final review

This commit is contained in:
2026-07-12 02:48:10 +02:00
parent 407c4a6faf
commit 6c67235caf
16 changed files with 265 additions and 28 deletions
+4 -2
View File
@@ -119,8 +119,10 @@ docker compose -f compose.yaml -f deploy/compose.production.yaml \
```
The secrets and public CA chain are mounted read-only under `/run/secrets` and must be readable by
the core's UID 10001. See [`deploy/secrets/README.md`](deploy/secrets/README.md) for the verification
command. The frontend remains on loopback; the authenticated host proxy is the only public listener.
the core's UID 10001. Host secret files must be `0600` or `0400`; Docker's runtime `0444` mount is
accepted only beneath `/run/secrets`. See [`deploy/secrets/README.md`](deploy/secrets/README.md) for
the verification command. The frontend remains on loopback; the authenticated host proxy is the
only public listener.
## Reproducible image verification