docs: keep installation configuration inside ThothII

This commit is contained in:
2026-07-12 10:21:53 +02:00
parent e81a250b47
commit 7f8346ff58
4 changed files with 111 additions and 54 deletions
+10 -6
View File
@@ -1,7 +1,9 @@
# Runtime secrets and private CA
Do not put secret values in this directory or in Git. For production, create files outside the
repository and point the `*_SECRET_FILE` variables documented in the root README at them.
Secret values in this directory are ignored by Git and remain local to the cloned `ThothII`
directory. This self-contained layout is the default installation documented in
`docs/installazione-docker-4-contesti.md`; an enterprise deployment may point the same
`*_SECRET_FILE` variables at an external secret-manager materialization instead.
Compose mounts each file read-only beneath `/run/secrets`. The core process runs as UID 10001;
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
@@ -21,8 +23,10 @@ one value with no surrounding quotes.
reads it afresh for each Pi child and maps it to the selected provider's native environment name;
the generic path/value is not placed in settings, health output, argv, or logs. Supported hosted
providers include Anthropic, OpenAI, Google/Gemini, DeepSeek, Z.AI, Groq, Mistral, OpenRouter,
xAI, Cerebras, and Cohere. Local Ollama/LM Studio providers require no file. Unknown hosted
providers fail closed until an explicit mapping is added.
xAI, and Cerebras. Local Ollama/LM Studio providers require no file. Compound providers such as
Bedrock, Azure OpenAI Responses, and Cloudflare Workers AI/Gateway fail closed because they
require multiple credential/configuration values. Unknown hosted providers fail closed until an
explicit mapping is added.
## Rotating the initialized local-vector bootstrap password
@@ -32,8 +36,8 @@ project:
```sh
./scripts/vector-rotate-bootstrap-password.sh \
/absolute/path/to/current-bootstrap-secret \
/absolute/path/to/staged-new-bootstrap-secret
deploy/secrets/vector_bootstrap_password \
deploy/secrets/vector_bootstrap_password.next
```
The command authenticates using the current file, changes only the authenticated bootstrap role,