feat(compose): use one secret bundle for local services
This commit is contained in:
@@ -3,10 +3,16 @@ set -eu
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
export THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE=${THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE:-/tmp/vector-bootstrap}
|
||||
export THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE=${THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE:-/tmp/vector-migrator}
|
||||
export THT_VECTOR_READER_PASSWORD_SECRET_FILE=${THT_VECTOR_READER_PASSWORD_SECRET_FILE:-/tmp/vector-reader}
|
||||
export THT_VECTOR_WRITER_PASSWORD_SECRET_FILE=${THT_VECTOR_WRITER_PASSWORD_SECRET_FILE:-/tmp/vector-writer}
|
||||
tmp_bundle=$(mktemp)
|
||||
trap 'rm -f "$tmp_bundle"' EXIT HUP INT TERM
|
||||
cat >"$tmp_bundle" <<'EOF'
|
||||
THT_VECTOR_BOOTSTRAP_PASSWORD=test-bootstrap
|
||||
THT_VECTOR_MIGRATOR_PASSWORD=test-migrator
|
||||
THT_VECTOR_READER_PASSWORD=test-reader
|
||||
THT_VECTOR_WRITER_PASSWORD=test-writer
|
||||
EOF
|
||||
chmod 0600 "$tmp_bundle"
|
||||
export THT_SECRETS_FILE="$tmp_bundle"
|
||||
|
||||
local_files="-f compose.yaml -f deploy/compose.local-vector.yaml -f deploy/compose.preprocess.yaml -f deploy/compose.preprocess-local-vector.yaml"
|
||||
local_json=$(docker compose $local_files --profile local-vector --profile preprocess config --format json)
|
||||
@@ -16,6 +22,16 @@ import json, sys
|
||||
|
||||
config = json.load(sys.stdin)
|
||||
services = config["services"]
|
||||
assert "thothii_secrets" in config.get("secrets", {}), config.get("secrets")
|
||||
assert "vector_bootstrap_password" not in config.get("secrets", {})
|
||||
assert "vector_migrator_password" not in config.get("secrets", {})
|
||||
assert "vector_reader_password" not in config.get("secrets", {})
|
||||
assert "vector_writer_password" not in config.get("secrets", {})
|
||||
for name, service in services.items():
|
||||
if name.startswith("vector-") or name.startswith("preprocess-") or name == "core":
|
||||
assert any(item.get("target") == "thothii.secrets" for item in service.get("secrets", []) if isinstance(item, dict)), (name, service.get("secrets"))
|
||||
assert "vector_reader_password" not in str(service)
|
||||
assert "vector_writer_password" not in str(service)
|
||||
for name in ("preprocess-evidence", "preprocess-dwh"):
|
||||
dependency = services[name].get("depends_on", {}).get("vector-migrate")
|
||||
assert dependency is not None, f"{name} does not depend on vector-migrate"
|
||||
@@ -37,7 +53,32 @@ assert "vector-reconcile" not in services
|
||||
for name in ("preprocess-evidence", "preprocess-dwh"):
|
||||
service = services[name]
|
||||
assert "depends_on" not in service
|
||||
assert not service.get("secrets"), service.get("secrets")
|
||||
assert all(item.get("target") == "thothii.secrets" for item in service.get("secrets", []) if isinstance(item, dict)), service.get("secrets")
|
||||
assert "vector_reader_password" not in str(service)
|
||||
assert "vector_writer_password" not in str(service)
|
||||
'
|
||||
|
||||
python3 - <<'PY'
|
||||
import os
|
||||
from pathlib import Path
|
||||
|
||||
os.environ.update({
|
||||
"THT_DB_NAME": "thoth",
|
||||
"THT_DWH_REST_URL": "http://dwh.invalid",
|
||||
"THT_DWH_API_KEY": "dwh",
|
||||
"THT_VECTOR_DATABASE": "thoth",
|
||||
"THT_VECTOR_READER_USER": "reader",
|
||||
"THT_VECTOR_WRITER_USER": "writer",
|
||||
"THT_VECTOR_READER_PASSWORD_FILE": "/tmp/generated-reader",
|
||||
"THT_VECTOR_WRITER_PASSWORD_FILE": "/tmp/generated-writer",
|
||||
"THT_DOCS_ROOT": "/data/source",
|
||||
"THT_OLLAMA_URL": "http://ollama.invalid",
|
||||
})
|
||||
text = Path("deploy/workspaces/local-vector.yaml").read_text()
|
||||
assert "password_file: ${THT_VECTOR_READER_PASSWORD_FILE}" in text
|
||||
assert "password_file: ${THT_VECTOR_WRITER_PASSWORD_FILE}" in text
|
||||
assert "${THT_SECRETS_FILE}" not in text
|
||||
print("local-vector workspace resolution contract: ok")
|
||||
PY
|
||||
|
||||
echo "preprocess compose config: ok"
|
||||
|
||||
Reference in New Issue
Block a user