fix(docker): run real questions through trusted Pi gate

This commit is contained in:
2026-07-12 19:20:10 +02:00
parent c446d40e1f
commit 7628eaa579
16 changed files with 266 additions and 14 deletions
@@ -0,0 +1,70 @@
# Local and Server Docker Deployment Implementation Plan
> **For Codex:** execute this plan in the current isolated worktree; keep runtime credentials out of Git.
**Goal:** Configure and verify a Docker Desktop deployment using GLM 5.2 and the existing PSD workspace, while retaining a portable server deployment contract.
**Architecture:** The base Compose file builds two applications and consumes only generic environment values and a Docker secret bundle. A tracked GLM Pi registry is mounted read-only in the core container. A Git-ignored local override supplies Mac-specific PSD workspace and CA mounts; server operators supply equivalent server runtime values separately.
**Tech Stack:** Docker Compose v2, Node 22, Python 3.12, Pi RPC, Fastify, nginx.
---
### Task 1: Add the non-secret GLM Pi registry
**Files:**
- Create: `deploy/pi/models.json`
- Modify: `docker/core.Dockerfile`
- Modify: `compose.yaml`
- Test: Compose configuration and Pi model discovery
1. Define the `zai/glm-5.2` OpenAI-compatible model registry without a credential.
2. Create the Pi user configuration directory in the core image and mount the registry read-only.
3. Verify that `get_available_models` returns `zai/glm-5.2` when the bundle supplies the model key.
### Task 2: Add generic PSD-compatible runtime templates
**Files:**
- Create: `deploy/workspaces/psd.yaml.example`
- Create: `deploy/compose.psd-local.yaml.example`
- Modify: `deploy/env.example`
- Modify: `README.md`
1. Define a relative `/data/workspaces/psd` workspace configuration with external REST DWH/vector adapters.
2. Document required non-secret environment values and the local/server boundary.
3. Keep host paths and credential values out of all tracked files.
### Task 3: Materialize local runtime configuration securely
**Files (ignored):**
- Create: `.env`
- Create: `deploy/secrets/thothii.secrets`
- Create: `deploy/compose.psd-local.yaml`
- Create: `deploy/workspaces/psd.yaml`
1. Transfer only required values from the existing local configuration without writing them to logs.
2. Set `PI_PROVIDER=zai`, `PI_MODEL=glm-5.2`, and the Docker Desktop host gateway for Ollama.
3. Bind-mount the PSD workspace and private CA read-only where appropriate; sessions remain writable.
4. Enforce restricted modes on the secret bundle.
### Task 4: Build and verify the Docker deployment
**Commands:**
- `docker compose config --quiet`
- `docker compose build`
- `docker compose up -d`
- health/API/model/session smoke checks
1. Validate rendered Compose configuration without exposing secrets.
2. Build the core and frontend images.
3. Verify secret mount, core and frontend health, and model listing.
4. Start a PSD session using GLM 5.2 and verify Pi emits a workflow event or gate.
5. Capture sanitized diagnostics and stop only disposable test resources; leave the validated local stack running unless it fails.
### Task 5: Record the deployment result
**Files:**
- Modify: `README.md` or deployment documentation
1. Record the exact local startup command and server-equivalent configuration steps.
2. State verified endpoints, model, and session-start result without secret values.