fix(vector): close local pgvector final review
This commit is contained in:
@@ -24,8 +24,6 @@ THT_VECTOR_BOOTSTRAP_USER=postgres
|
||||
THT_VECTOR_MIGRATOR_USER=thoth_vector_migrator
|
||||
THT_VECTOR_READER_USER=thoth_vector_reader
|
||||
THT_VECTOR_WRITER_USER=thoth_vector_writer
|
||||
THT_VECTOR_READER_PASSWORD=
|
||||
THT_VECTOR_WRITER_PASSWORD=
|
||||
THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE=/absolute/path/to/vector_bootstrap_password
|
||||
# Changing the file alone does not rotate an initialized DB; use
|
||||
# scripts/vector-rotate-bootstrap-password.sh OLD_SECRET_FILE NEW_SECRET_FILE.
|
||||
|
||||
@@ -5,7 +5,9 @@ repository and point the `*_SECRET_FILE` variables documented in the root README
|
||||
|
||||
Compose mounts each file read-only beneath `/run/secrets`. The core process runs as UID 10001;
|
||||
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
|
||||
mounted read-only with mode `0444`; verify with:
|
||||
mounted read-only with mode `0444`. This mode is accepted only for runtime paths beneath
|
||||
`/run/secrets`, where the container mount is read-only and scoped to services that declare the
|
||||
secret. Source files on the host must have no group/other bits (`0600` or `0400`). Verify with:
|
||||
|
||||
```sh
|
||||
docker compose -f compose.yaml -f deploy/compose.production.yaml \
|
||||
|
||||
@@ -11,6 +11,11 @@ validate_secret_file() {
|
||||
echo "$secret_name must contain no whitespace" >&2
|
||||
return 2
|
||||
fi
|
||||
mode=$(stat -c '%a' "$secret_path" 2>/dev/null || stat -f '%Lp' "$secret_path" 2>/dev/null) || return 2
|
||||
case "$secret_path:$mode" in
|
||||
/run/secrets/*:444|/run/secrets/*:400|/run/secrets/*:600|*:600|*:400) ;;
|
||||
*) echo "$secret_name must have mode 0600 or stricter (Docker secrets may be 0444)" >&2; return 2 ;;
|
||||
esac
|
||||
}
|
||||
|
||||
read_secret_file() {
|
||||
|
||||
@@ -17,14 +17,14 @@ vectors:
|
||||
database: ${THT_VECTOR_DATABASE}
|
||||
schema: vectors
|
||||
user: ${THT_VECTOR_READER_USER}
|
||||
password: ${THT_VECTOR_READER_PASSWORD}
|
||||
password_file: ${THT_VECTOR_READER_PASSWORD_FILE}
|
||||
writer:
|
||||
host: vector-db
|
||||
port: 5432
|
||||
database: ${THT_VECTOR_DATABASE}
|
||||
schema: vectors
|
||||
user: ${THT_VECTOR_WRITER_USER}
|
||||
password: ${THT_VECTOR_WRITER_PASSWORD}
|
||||
password_file: ${THT_VECTOR_WRITER_PASSWORD_FILE}
|
||||
|
||||
roots:
|
||||
artifacts: artifacts
|
||||
|
||||
Reference in New Issue
Block a user