docs: keep installation configuration inside ThothII
This commit is contained in:
+12
-7
@@ -1,11 +1,12 @@
|
||||
# LOCAL DEVELOPMENT ONLY. Copy to deploy/.env and use deploy/compose.local.yaml.
|
||||
# Never commit deploy/.env or real credentials. Production uses Compose secrets instead.
|
||||
# LOCAL/PRODUCTION CONFIGURATION TEMPLATE. Copy to deploy/.env.
|
||||
# Never commit deploy/.env or the files under deploy/secrets/.
|
||||
|
||||
# Optional application defaults
|
||||
PI_PROVIDER=
|
||||
PI_MODEL=
|
||||
PI_THINKING=
|
||||
THT_MODEL_API_KEY_FILE=/absolute/path/to/model_api_key
|
||||
# Container-only path is assigned by deploy/compose.production.yaml.
|
||||
THT_MODEL_API_KEY_SECRET_FILE=deploy/secrets/model-api-key
|
||||
MAX_PI_PROCESSES=4
|
||||
AUTH_MODE=none
|
||||
|
||||
@@ -13,11 +14,15 @@ AUTH_MODE=none
|
||||
THT_DB_NAME=
|
||||
THT_DWH_REST_URL=
|
||||
THT_DWH_API_KEY=
|
||||
THT_DWH_API_KEY_SECRET_FILE=deploy/secrets/dwh-api-key
|
||||
|
||||
# External vector service. Use a distinct write key where the service supports one.
|
||||
THT_VEC_REST_URL=
|
||||
THT_VEC_API_KEY=
|
||||
THT_VEC_WRITE_API_KEY=
|
||||
THT_VEC_API_KEY_SECRET_FILE=deploy/secrets/vector-reader-api-key
|
||||
THT_VEC_WRITE_API_KEY_SECRET_FILE=deploy/secrets/vector-writer-api-key
|
||||
THT_CA_SECRET_FILE=deploy/secrets/ca-chain.pem
|
||||
|
||||
# Optional local-vector profile. Keep these secret files outside Git and readable by Docker.
|
||||
THT_VECTOR_DATABASE=thoth
|
||||
@@ -25,12 +30,12 @@ THT_VECTOR_BOOTSTRAP_USER=postgres
|
||||
THT_VECTOR_MIGRATOR_USER=thoth_vector_migrator
|
||||
THT_VECTOR_READER_USER=thoth_vector_reader
|
||||
THT_VECTOR_WRITER_USER=thoth_vector_writer
|
||||
THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE=/absolute/path/to/vector_bootstrap_password
|
||||
THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE=deploy/secrets/vector_bootstrap_password
|
||||
# Changing the file alone does not rotate an initialized DB; use
|
||||
# scripts/vector-rotate-bootstrap-password.sh OLD_SECRET_FILE NEW_SECRET_FILE.
|
||||
THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE=/absolute/path/to/vector_migrator_password
|
||||
THT_VECTOR_READER_PASSWORD_SECRET_FILE=/absolute/path/to/vector_reader_password
|
||||
THT_VECTOR_WRITER_PASSWORD_SECRET_FILE=/absolute/path/to/vector_writer_password
|
||||
THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE=deploy/secrets/vector_migrator_password
|
||||
THT_VECTOR_READER_PASSWORD_SECRET_FILE=deploy/secrets/vector_reader_password
|
||||
THT_VECTOR_WRITER_PASSWORD_SECRET_FILE=deploy/secrets/vector_writer_password
|
||||
|
||||
# External embeddings service
|
||||
THT_OLLAMA_URL=
|
||||
|
||||
@@ -1,7 +1,9 @@
|
||||
# Runtime secrets and private CA
|
||||
|
||||
Do not put secret values in this directory or in Git. For production, create files outside the
|
||||
repository and point the `*_SECRET_FILE` variables documented in the root README at them.
|
||||
Secret values in this directory are ignored by Git and remain local to the cloned `ThothII`
|
||||
directory. This self-contained layout is the default installation documented in
|
||||
`docs/installazione-docker-4-contesti.md`; an enterprise deployment may point the same
|
||||
`*_SECRET_FILE` variables at an external secret-manager materialization instead.
|
||||
|
||||
Compose mounts each file read-only beneath `/run/secrets`. The core process runs as UID 10001;
|
||||
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
|
||||
@@ -21,8 +23,10 @@ one value with no surrounding quotes.
|
||||
reads it afresh for each Pi child and maps it to the selected provider's native environment name;
|
||||
the generic path/value is not placed in settings, health output, argv, or logs. Supported hosted
|
||||
providers include Anthropic, OpenAI, Google/Gemini, DeepSeek, Z.AI, Groq, Mistral, OpenRouter,
|
||||
xAI, Cerebras, and Cohere. Local Ollama/LM Studio providers require no file. Unknown hosted
|
||||
providers fail closed until an explicit mapping is added.
|
||||
xAI, and Cerebras. Local Ollama/LM Studio providers require no file. Compound providers such as
|
||||
Bedrock, Azure OpenAI Responses, and Cloudflare Workers AI/Gateway fail closed because they
|
||||
require multiple credential/configuration values. Unknown hosted providers fail closed until an
|
||||
explicit mapping is added.
|
||||
|
||||
## Rotating the initialized local-vector bootstrap password
|
||||
|
||||
@@ -32,8 +36,8 @@ project:
|
||||
|
||||
```sh
|
||||
./scripts/vector-rotate-bootstrap-password.sh \
|
||||
/absolute/path/to/current-bootstrap-secret \
|
||||
/absolute/path/to/staged-new-bootstrap-secret
|
||||
deploy/secrets/vector_bootstrap_password \
|
||||
deploy/secrets/vector_bootstrap_password.next
|
||||
```
|
||||
|
||||
The command authenticates using the current file, changes only the authenticated bootstrap role,
|
||||
|
||||
Reference in New Issue
Block a user