fix(vector): close local pgvector final review

This commit is contained in:
2026-07-12 02:48:10 +02:00
parent 407c4a6faf
commit 6c67235caf
16 changed files with 265 additions and 28 deletions
-2
View File
@@ -24,8 +24,6 @@ THT_VECTOR_BOOTSTRAP_USER=postgres
THT_VECTOR_MIGRATOR_USER=thoth_vector_migrator
THT_VECTOR_READER_USER=thoth_vector_reader
THT_VECTOR_WRITER_USER=thoth_vector_writer
THT_VECTOR_READER_PASSWORD=
THT_VECTOR_WRITER_PASSWORD=
THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE=/absolute/path/to/vector_bootstrap_password
# Changing the file alone does not rotate an initialized DB; use
# scripts/vector-rotate-bootstrap-password.sh OLD_SECRET_FILE NEW_SECRET_FILE.
+3 -1
View File
@@ -5,7 +5,9 @@ repository and point the `*_SECRET_FILE` variables documented in the root README
Compose mounts each file read-only beneath `/run/secrets`. The core process runs as UID 10001;
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
mounted read-only with mode `0444`; verify with:
mounted read-only with mode `0444`. This mode is accepted only for runtime paths beneath
`/run/secrets`, where the container mount is read-only and scoped to services that declare the
secret. Source files on the host must have no group/other bits (`0600` or `0400`). Verify with:
```sh
docker compose -f compose.yaml -f deploy/compose.production.yaml \
+5
View File
@@ -11,6 +11,11 @@ validate_secret_file() {
echo "$secret_name must contain no whitespace" >&2
return 2
fi
mode=$(stat -c '%a' "$secret_path" 2>/dev/null || stat -f '%Lp' "$secret_path" 2>/dev/null) || return 2
case "$secret_path:$mode" in
/run/secrets/*:444|/run/secrets/*:400|/run/secrets/*:600|*:600|*:400) ;;
*) echo "$secret_name must have mode 0600 or stricter (Docker secrets may be 0444)" >&2; return 2 ;;
esac
}
read_secret_file() {
+2 -2
View File
@@ -17,14 +17,14 @@ vectors:
database: ${THT_VECTOR_DATABASE}
schema: vectors
user: ${THT_VECTOR_READER_USER}
password: ${THT_VECTOR_READER_PASSWORD}
password_file: ${THT_VECTOR_READER_PASSWORD_FILE}
writer:
host: vector-db
port: 5432
database: ${THT_VECTOR_DATABASE}
schema: vectors
user: ${THT_VECTOR_WRITER_USER}
password: ${THT_VECTOR_WRITER_PASSWORD}
password_file: ${THT_VECTOR_WRITER_PASSWORD_FILE}
roots:
artifacts: artifacts