fix(vector): close local pgvector final review

This commit is contained in:
2026-07-12 02:48:10 +02:00
parent 407c4a6faf
commit 6c67235caf
16 changed files with 265 additions and 28 deletions
+3 -1
View File
@@ -5,7 +5,9 @@ repository and point the `*_SECRET_FILE` variables documented in the root README
Compose mounts each file read-only beneath `/run/secrets`. The core process runs as UID 10001;
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
mounted read-only with mode `0444`; verify with:
mounted read-only with mode `0444`. This mode is accepted only for runtime paths beneath
`/run/secrets`, where the container mount is read-only and scoped to services that declare the
secret. Source files on the host must have no group/other bits (`0600` or `0400`). Verify with:
```sh
docker compose -f compose.yaml -f deploy/compose.production.yaml \