feat: unify installation model catalog

This commit is contained in:
Codex
2026-09-02 18:45:33 +02:00
parent ae053961a3
commit 7b7927bfe5
169 changed files with 3696 additions and 4572 deletions
-8
View File
@@ -21,14 +21,6 @@ services:
source: ${PI_AUTH_FILE:?set PI_AUTH_FILE}
target: /home/thoth/.pi/agent/auth.json
read_only: true
- type: bind
source: ./deploy/pi/models.json
target: /home/thoth/.pi/agent/models.json
read_only: true
- type: bind
source: ./deploy/pi/settings.json
target: /home/thoth/.pi/agent/settings.json
read_only: true
- type: bind
source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT}
target: /data/workspace-registry
-46
View File
@@ -1,46 +0,0 @@
{
"providers": {
"zai": {
"baseUrl": "https://api.z.ai/api/coding/paas/v4",
"api": "openai-completions",
"apiKey": "$ZAI_API_KEY",
"models": [
{
"id": "glm-5.3",
"name": "GLM-5.3",
"reasoning": true,
"contextWindow": 200000,
"maxTokens": 131072
}
]
},
"local-qwen": {
"name": "Local Qwen",
"baseUrl": "https://ml-aritmolab.policlinicosandonato.it/v1",
"api": "openai-completions",
"apiKey": "local",
"models": [
{
"id": "qwen3.6-35b-a3b",
"name": "Qwen3.6 35B A3B",
"reasoning": false,
"input": ["text"],
"cost": {
"input": 0,
"output": 0,
"cacheRead": 0,
"cacheWrite": 0
},
"contextWindow": 131072,
"maxTokens": 16384,
"compat": {
"supportsDeveloperRole": false,
"supportsReasoningEffort": false,
"supportsStore": false,
"maxTokensField": "max_tokens"
}
}
]
}
}
}
-9
View File
@@ -1,9 +0,0 @@
{
"defaultProjectTrust": "always",
"enabledModels": [
"zai/glm-5.3",
"deepseek/deepseek-v4-flash",
"deepseek/deepseek-v4-pro",
"local-qwen/qwen3.6-35b-a3b"
]
}
+1 -3
View File
@@ -14,9 +14,7 @@ THT_AUTH_CONFIG_ROOT=<abs>/deploy/psd/auth
# DWH and Evidence credentials are entered later in Workspace management and stored encrypted
# by the backend. They do not depend on host filesystem paths.
# Pi (LLM)
PI_PROVIDER=zai
PI_MODEL=glm-5.3
# Pi runtime preference; provider/model defaults live only in installation modelCatalog.
PI_THINKING=medium
# App defaults
+64 -35
View File
@@ -1,6 +1,6 @@
# Esempio soltanto: `tht setup` genera deploy/<installation-id>/thothii-installation.yaml.
# Sostituisci i path assoluti se usi questo riferimento per una configurazione avanzata.
# Seleziona UN solo override Git (https o ssh).
# Example only: `tht setup` generates deploy/<installation-id>/thothii-installation.yaml.
# Replace every absolute path before using this as an advanced reference.
schemaVersion: 2
profile: local
projectDirectory: "<abs>/projects/ThothII"
envFile: "<abs>/projects/ThothII/deploy/psd/operator.env"
@@ -8,38 +8,67 @@ workspaceRepository:
remote: git@github.com:mptyl/tht-workspace-psd.git
branch: main
access: ssh
metadataGeneration:
default: glm-53
models:
- id: deepseek-v4-pro
label: DeepSeek V4 Pro
litellm:
provider: deepseek
model: deepseek-v4-pro
apiKeyEnv: DEEPSEEK_API_KEY
- id: deepseek-v4-flash
label: DeepSeek V4 Flash
litellm:
provider: deepseek
model: deepseek-v4-flash
apiKeyEnv: DEEPSEEK_API_KEY
- id: glm-53
label: GLM 5.3
litellm:
provider: openai
model: glm-5.3
endpoint:
baseUrl: https://api.z.ai/api/coding/paas/v4
apiKeyEnv: ZAI_API_KEY
- id: qwen-36
label: AritmoLab Qwen 3.6 35B A3B
litellm:
provider: openai
model: qwen3.6-35b-a3b
disableThinking: true
endpoint:
baseUrl: https://ml-aritmolab.policlinicosandonato.it/v1
# Qwen omette apiKeyEnv: l'endpoint VPN non autentica le richieste.
modelCatalog:
defaults:
session: zai/glm-5.3
metadataGeneration: zai/glm-5.3
embedding:
id: ollama/qwen3-embedding:0.6b
dimensions: 1024
providers:
deepseek:
authentication:
mode: pi_auth
session:
mode: pi_builtin
models:
deepseek-v4-pro:
session: {}
deepseek-v4-flash:
session: {}
zai:
endpoint:
baseUrl: https://api.z.ai/api/coding/paas/v4
authentication:
mode: secret_env
apiKeyEnv: ZAI_API_KEY
session:
mode: openai_compatible
metadataGeneration:
litellmProvider: openai
models:
glm-5.3:
label: GLM 5.3
session:
reasoning: true
contextWindow: 200000
maxTokens: 131072
metadataGeneration: {}
local-qwen:
endpoint:
baseUrl: https://ml-aritmolab.policlinicosandonato.it/v1
authentication:
mode: none
session:
mode: openai_compatible
metadataGeneration:
litellmProvider: openai
models:
qwen3.6-35b-a3b:
label: AritmoLab Qwen 3.6 35B A3B
session:
reasoning: false
input: [text]
cost: {input: 0, output: 0, cacheRead: 0, cacheWrite: 0}
contextWindow: 131072
maxTokens: 16384
compatibility:
supportsDeveloperRole: false
supportsReasoningEffort: false
supportsStore: false
maxTokensField: max_tokens
metadataGeneration:
disableThinking: true
authentication:
configDirectory: "<abs>/projects/ThothII/deploy/psd/auth"
overrides:
+8 -7
View File
@@ -10,8 +10,9 @@ chmod 600 deploy/secrets/thothii.secrets
The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). The supported
installation keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, `THT_SSL_CA`,
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. Metadata-generation models may reference
exactly one of `THT_METADATA_API_KEY`, `ANTHROPIC_API_KEY`, `AZURE_API_KEY`, `GEMINI_API_KEY`,
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. Installation Model Catalog providers may
reference exactly one of `THT_MODEL_API_KEY`, `THT_METADATA_API_KEY`, `ANTHROPIC_API_KEY`,
`AZURE_API_KEY`, `GEMINI_API_KEY`,
`DEEPSEEK_API_KEY`, `OPENAI_API_KEY`, `OPENROUTER_API_KEY`, or `ZAI_API_KEY` through their
descriptor `apiKeyEnv`. An entry for an explicitly configured endpoint that accepts unauthenticated
requests may omit `apiKeyEnv`; hosted/default endpoints must always reference a key.
@@ -23,10 +24,10 @@ installation. Other configured values must be non-empty and contain no
whitespace. Do not put secrets in the root `.env`, installation YAML, workspace YAML, URLs, logs,
or rendered Compose output.
`THT_MODEL_API_KEY` remains the generic Pi child credential. Metadata generation is a separate
backend-owned runtime and reads only the key named by its own `metadataGeneration.models[].apiKeyEnv`
(when present);
it does not read Pi settings, `PI_AUTH_FILE`, or workspace `llm_policy`.
Session and metadata-generation runtimes read only the provider key named by
`modelCatalog.providers.<provider>.authentication.apiKeyEnv`. They share the declaration and
credential reference, not their execution lifecycle. Pi-owned authentication remains available only
to session-only built-in providers through `authentication.mode: pi_auth`.
Do not add vector or embedding endpoint credentials to the bundle. Active operator manuals use
internal Qdrant and Ollama services, so vector/embedding runtime endpoint secrets are not part of
@@ -56,7 +57,7 @@ and only then deleting the old files. The old variables remain a compatibility p
upgrades, but the documented and tested default is an absolute `THT_SECRETS_FILE` path to the
protected bundle.
Hosted Pi providers must use a single model key through `THT_MODEL_API_KEY`. Compound providers
Hosted providers must use one explicitly named catalog key. Compound providers
(Bedrock, Azure OpenAI Responses, Cloudflare Workers AI/Gateway) fail closed until a
provider-specific credential adapter is implemented.
+5 -6
View File
@@ -2,14 +2,13 @@
# Values are read as literal strings (no shell expansion or command substitution).
# Leave unused keys out of the file.
# Hosted model provider (single-key providers only).
# THT_MODEL_API_KEY=replace-me
# Description Generation only. The selected name must match apiKeyEnv in metadataGeneration.
# Allowed names: THT_METADATA_API_KEY, ANTHROPIC_API_KEY, AZURE_API_KEY, GEMINI_API_KEY,
# Hosted catalog provider (single-key providers only). The selected name must match
# modelCatalog.providers.<provider>.authentication.apiKeyEnv.
# Allowed names include THT_MODEL_API_KEY, THT_METADATA_API_KEY, ANTHROPIC_API_KEY,
# AZURE_API_KEY, GEMINI_API_KEY,
# DEEPSEEK_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, or ZAI_API_KEY.
# OPENAI_API_KEY=replace-me
# A model with an explicit unauthenticated endpoint omits apiKeyEnv and needs no bundle entry.
# A provider with an explicit keyless endpoint uses authentication.mode: none.
# External DWH adapter.
# THT_DWH_API_KEY=replace-me
+2 -18
View File
@@ -1,8 +1,8 @@
workspace:
schema_version: 3
schema_version: 4
id: example
name: Example workspace
description: Generic example WorkspaceV3 descriptor.
description: Generic example WorkspaceV4 descriptor.
language: en
dwh:
@@ -13,17 +13,6 @@ dwh:
- postgres_direct
- rest_api
semantic_index:
vector_store:
engine: qdrant
collection: example
dimensions: 1024
distance: cosine
embedding:
provider: ollama_internal
model: qwen3-embedding:0.6b
dimensions: 1024
evidence:
source:
type: filesystem
@@ -35,11 +24,6 @@ evidence:
max_chunk_chars: 4000
retain_published_generations: 3
llm_policy:
default: zai/glm-5.2
allowed:
- zai/glm-5.2
diagnostics:
dwh_rest:
method: GET
+2 -18
View File
@@ -1,8 +1,8 @@
workspace:
schema_version: 3
schema_version: 4
id: example-workspace
name: Example Workspace
description: Example WorkspaceV3 descriptor.
description: Example WorkspaceV4 descriptor.
language: en
dwh:
@@ -13,17 +13,6 @@ dwh:
- postgres_direct
- rest_api
semantic_index:
vector_store:
engine: qdrant
collection: example-workspace
dimensions: 1024
distance: cosine
embedding:
provider: ollama_internal
model: qwen3-embedding:0.6b
dimensions: 1024
evidence:
source:
type: filesystem
@@ -35,11 +24,6 @@ evidence:
max_chunk_chars: 4000
retain_published_generations: 3
llm_policy:
default: zai/glm-5.2
allowed:
- zai/glm-5.2
diagnostics:
dwh_rest:
method: GET