fix: harden DWH auth operator guidance
This commit is contained in:
@@ -2,16 +2,18 @@
|
||||
|
||||
Authentication acceptance is documented in the [manual authentication matrix](../testing/authentication-manual-acceptance.md).
|
||||
Use generic OIDC with Authentik as the certified group catalog, map only the exact TOT Users and
|
||||
TOT Admin groups, then run Workspace Validate, `tht auth check`, `tht auth check --interactive`,
|
||||
and Workspace Test in that order. Browser callback E2E, native Windows execution, approved PSD
|
||||
TOT Admin groups, then run **Validate workspace source**, `tht auth check`, `tht auth check --interactive`,
|
||||
and **Test workspace connections** in that order. Browser callback E2E, native Windows execution, approved PSD
|
||||
manual identities, external L2, and the two parked restore-lock preconditions remain pending the
|
||||
Task 15/release gates.
|
||||
|
||||
Guida operativa per collegare ThothII al DWH di PSD con il nuovo sistema (registry Git + descriptor
|
||||
v3 + `tht`).
|
||||
|
||||
## Stato attuale (2026-08-13)
|
||||
## Stato storico Mac/local (2026-08-13)
|
||||
|
||||
> Questo stato è storico per Mac/local; il server PSD Project A usa binding separato `postgres_direct` read-only.
|
||||
>
|
||||
> Per la rotazione della credenziale DWH, fare riferimento al [runbook PSD](../operations/psd-dwh-auth-rollout.md): non autorizza modifiche finché i due gate non sono approvati. Il ThothII PSD server resta `postgres_direct`; il Mac e i client remoti usano `rest_api` con una chiave per installazione. `postgres_direct` e `ssh_tunnel` non usano chiavi `dwh-auth`.
|
||||
|
||||
- **Repository PSD pubblicato:** `https://github.com/mptyl/tht-workspace-psd` (privato), branch
|
||||
@@ -22,7 +24,7 @@ v3 + `tht`).
|
||||
- **Config operatore pronta** (file reali gitignored in `deploy/psd/`): `operator.env`,
|
||||
`thothii-installation.yaml` e i secret d'installazione in `secrets/` (pi-auth, secret bundle,
|
||||
chiave SSH, known_hosts). L'API key DWH va completata nella gestione Workspace ed è conservata
|
||||
nel vault cifrato del backend. Nessuna CA: il DWH REST usa HTTPS pubblico.
|
||||
nel vault cifrato del backend. Il certificato REST è self-issued/private: ogni Mac/local senza trust equivalente deve usare `TLS_CA_FILE` e verificare il fingerprint fuori banda, come in `docs/install/dwh-auth-tls.md`.
|
||||
- **Stack avviato** (progetto `thothii-70417a3e30ea`, via `tht start`): `qdrant`, `embedding`
|
||||
(con `qwen3-embedding:0.6b`), `core`, `frontend` sani. Il registry ha **clonato e attivato**
|
||||
`psd-clinical` (stato `ready`).
|
||||
|
||||
Reference in New Issue
Block a user