fix(vector): close local pgvector final review
This commit is contained in:
@@ -32,8 +32,6 @@ export THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE="$secret_dir/bootstrap"
|
||||
export THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE="$secret_dir/migrator"
|
||||
export THT_VECTOR_READER_PASSWORD_SECRET_FILE="$secret_dir/reader"
|
||||
export THT_VECTOR_WRITER_PASSWORD_SECRET_FILE="$secret_dir/writer"
|
||||
export THT_VECTOR_READER_PASSWORD="smoke-reader-${smoke_project}"
|
||||
export THT_VECTOR_WRITER_PASSWORD="smoke-writer-${smoke_project}"
|
||||
export THT_VECTOR_BOOTSTRAP_USER=thoth_bootstrap_smoke
|
||||
export THOTH_SMOKE_OWNER="$smoke_owner"
|
||||
|
||||
@@ -132,7 +130,7 @@ def credential(role: str) -> DatabaseConfig:
|
||||
database=database,
|
||||
schema="vectors",
|
||||
user=f"thoth_vector_{role}",
|
||||
password=os.environ[f"THT_VECTOR_{role.upper()}_PASSWORD"],
|
||||
password=open(os.environ[f"THT_VECTOR_{role.upper()}_PASSWORD_FILE"]).read(),
|
||||
)
|
||||
|
||||
store = PgVectorStore(credential("reader"), credential("writer"), expected_dimension=768)
|
||||
@@ -168,6 +166,14 @@ printf '%s\n' "$services" | grep -qx vector-reconcile
|
||||
printf '%s\n' "$services" | grep -qx vector-migrate
|
||||
|
||||
compose up --build --wait vector-reconcile vector-migrate core
|
||||
core_id=$(compose ps -q core)
|
||||
inspect_env=$(docker inspect --format '{{json .Config.Env}}' "$core_id")
|
||||
if printf '%s' "$inspect_env" | grep -q "smoke-\(reader\|writer\)-${smoke_project}"; then
|
||||
echo "docker inspect exposed a direct vector password" >&2
|
||||
exit 1
|
||||
fi
|
||||
printf '%s' "$inspect_env" | grep -q 'THT_VECTOR_READER_PASSWORD_FILE=/run/secrets/vector_reader_password'
|
||||
printf '%s' "$inspect_env" | grep -q 'THT_VECTOR_WRITER_PASSWORD_FILE=/run/secrets/vector_writer_password'
|
||||
migration_status=$(compose run --rm --no-deps vector-migrate)
|
||||
printf '%s\n' "$migration_status" | grep -q '"pending": \[\]'
|
||||
migrator_flags=$(compose run --rm --no-deps --entrypoint sh vector-reconcile -ec '
|
||||
@@ -178,13 +184,11 @@ migrator_flags=$(compose run --rm --no-deps --entrypoint sh vector-reconcile -ec
|
||||
test "$migrator_flags" = t
|
||||
probe_vector write
|
||||
|
||||
old_reader_password=$THT_VECTOR_READER_PASSWORD
|
||||
old_reader_password=$(cat "$secret_dir/reader")
|
||||
for secret in migrator reader writer; do
|
||||
password="rotated-${secret}-${smoke_project}"
|
||||
printf '%s' "$password" >"$secret_dir/$secret"
|
||||
done
|
||||
export THT_VECTOR_READER_PASSWORD="rotated-reader-${smoke_project}"
|
||||
export THT_VECTOR_WRITER_PASSWORD="rotated-writer-${smoke_project}"
|
||||
|
||||
compose run --rm vector-reconcile
|
||||
rotation_status=$(compose run --rm --no-deps vector-migrate)
|
||||
@@ -205,6 +209,8 @@ printf '%s' "wrong-bootstrap-${smoke_project}" >"$secret_dir/bootstrap-wrong"
|
||||
printf '%s' "next-bootstrap-'quoted-${smoke_project}" >"$secret_dir/bootstrap-next"
|
||||
cp "$secret_dir/bootstrap" "$secret_dir/bootstrap-before-negative"
|
||||
printf 'invalid bootstrap password\n' >"$secret_dir/bootstrap-whitespace"
|
||||
chmod 0600 "$secret_dir/bootstrap-wrong" "$secret_dir/bootstrap-next" \
|
||||
"$secret_dir/bootstrap-before-negative" "$secret_dir/bootstrap-whitespace"
|
||||
if COMPOSE_PROJECT_NAME="$smoke_project" \
|
||||
./scripts/vector-rotate-bootstrap-password.sh \
|
||||
"$secret_dir/bootstrap" "$secret_dir/bootstrap-whitespace" \
|
||||
@@ -344,8 +350,10 @@ if [ "$mode" = "--backup-restore" ]; then
|
||||
--entrypoint /opt/thoth/reconcile-roles.sh "$image" >/dev/null
|
||||
|
||||
docker run --rm -i --network "$network" \
|
||||
-e THT_VECTOR_READER_PASSWORD="$THT_VECTOR_READER_PASSWORD" \
|
||||
-e THT_VECTOR_WRITER_PASSWORD="$THT_VECTOR_WRITER_PASSWORD" \
|
||||
--mount "type=bind,source=$secret_dir/reader,target=/run/secrets/vector_reader_password,readonly" \
|
||||
--mount "type=bind,source=$secret_dir/writer,target=/run/secrets/vector_writer_password,readonly" \
|
||||
-e THT_VECTOR_READER_PASSWORD_FILE=/run/secrets/vector_reader_password \
|
||||
-e THT_VECTOR_WRITER_PASSWORD_FILE=/run/secrets/vector_writer_password \
|
||||
--entrypoint /opt/venv/bin/python thothii-core:local - "$marker" <<'PY'
|
||||
import hashlib
|
||||
import os
|
||||
@@ -359,7 +367,8 @@ from tht.vectorstore.records import VectorRecord
|
||||
def config(role):
|
||||
return DatabaseConfig(
|
||||
host="vector-db-restore", port=5432, database="thoth", schema="vectors",
|
||||
user=f"thoth_vector_{role}", password=os.environ[f"THT_VECTOR_{role.upper()}_PASSWORD"],
|
||||
user=f"thoth_vector_{role}",
|
||||
password=open(os.environ[f"THT_VECTOR_{role.upper()}_PASSWORD_FILE"]).read(),
|
||||
)
|
||||
|
||||
store = PgVectorStore(config("reader"), config("writer"), expected_dimension=768)
|
||||
|
||||
Reference in New Issue
Block a user