feat: implement metadata catalog database management

This commit is contained in:
Codex
2026-08-27 22:43:54 +02:00
parent 705af3aeb2
commit 79c4c925b5
86 changed files with 12566 additions and 135 deletions
+13 -12
View File
@@ -25,14 +25,14 @@ const fs = require("fs");
const [configPath, profile] = process.argv.slice(2);
const config = JSON.parse(fs.readFileSync(configPath, "utf8"));
const services = Object.keys(config.services).sort();
if (services.join(",") !== "core,embedding,embedding-model-init,frontend,qdrant") {
throw new Error("mandatory stack must include core, frontend, qdrant, embedding, and embedding-model-init");
if (services.join(",") !== "catalog-db,core,embedding,embedding-model-init,frontend,qdrant") {
throw new Error("mandatory stack must include catalog-db, core, frontend, qdrant, embedding, and embedding-model-init");
}
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
throw new Error("forbidden application coupling");
}
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
for (const volume of ["qdrant-data", "embedding-models"]) {
for (const volume of ["catalog-data", "qdrant-data", "embedding-models"]) {
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
}
if (profile === "local") {
@@ -114,8 +114,8 @@ const bundleSecrets = runtimeSecrets.filter(
if (bundleSecrets.length !== 1) {
throw new Error("core must receive exactly one canonical runtime secret bundle");
}
if (profile === "local" && runtimeSecrets.length !== 1) {
throw new Error("local core must receive only the canonical runtime secret bundle");
if (profile === "local" && runtimeSecrets.length !== 2) {
throw new Error("local core must receive only its runtime bundle and catalog password");
}
if (profile === "server") {
const targets = new Set(runtimeSecrets.map((secret) => secret.target));
@@ -171,14 +171,14 @@ const fs = require("fs");
const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8"));
const services = Object.keys(config.services).sort();
if (services.join(",") !== "core,embedding,embedding-model-init,frontend,qdrant") {
throw new Error("mandatory stack must include core, frontend, qdrant, embedding, and embedding-model-init");
if (services.join(",") !== "catalog-db,core,embedding,embedding-model-init,frontend,qdrant") {
throw new Error("mandatory stack must include catalog-db, core, frontend, qdrant, embedding, and embedding-model-init");
}
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
throw new Error("forbidden application coupling");
}
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions", "qdrant-data", "embedding-models"]) {
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions", "catalog-data", "qdrant-data", "embedding-models"]) {
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
}
if (!Object.hasOwn(config.services.core.environment || {}, "THT_LLM_URL")) {
@@ -222,10 +222,11 @@ if (config.services.core.environment?.THT_SECRETS_FILE !== "/run/secrets/thothii
throw new Error("core must read the canonical runtime secret bundle from /run/secrets");
}
const runtimeSecrets = config.services.core.secrets || [];
if (runtimeSecrets.length !== 1
|| runtimeSecrets[0].source !== "thothii_secrets"
|| runtimeSecrets[0].target !== "thothii.secrets") {
throw new Error("core must receive exactly the canonical runtime secret bundle");
const hasTarget = (name) => runtimeSecrets.some((secret) => secret.target === name || secret.target?.endsWith(`/${name}`));
if (runtimeSecrets.length !== 2
|| !hasTarget("thothii.secrets")
|| !hasTarget("catalog_runtime_password")) {
throw new Error("core must receive only the canonical runtime bundle and catalog password");
}
if ((config.services.frontend.secrets || []).length !== 0) {
throw new Error("frontend must not receive runtime secrets");