diff --git a/PROJECT_STATE.md b/PROJECT_STATE.md index 7047e193..0952344b 100644 --- a/PROJECT_STATE.md +++ b/PROJECT_STATE.md @@ -16,8 +16,13 @@ and invariants are in [AGENTS.md](AGENTS.md); prior snapshots remain in Git. bindings. Ticket #45 adds host `installation preflight` and `installation plan` with release/image checks, canonical external diagnostics and private input seals; see [the preflight reference](docs/install/installation-preflight.md). - The remainder of the installation tickets, - Docker Hub publication and example databases remain pending. + Ticket #46 adds the maintainer release producer and the first public + [Linux amd64 prerelease](https://git.tylconsulting.it/mptyl/ThothII/releases/tag/installation-v0.1.0-install-preview.1), + with Docker Hub core/frontend images and a downloadable native operator bundle. + See [publication instructions](docs/install/publishing-images.md) and + [verification evidence](docs/reports/2026-09-28-installation-prerelease.md). + Non-interactive execution (#47 onward), real-host acceptance and example + databases remain pending; the prerelease does not certify a complete installer. - React supports full/embedded rendering independently of local/OIDC/upstream auth, with EN/IT UI and immutable session interaction language. See @@ -98,7 +103,7 @@ A later deployment does not prove every earlier acceptance item passed. ## Documentation maintenance -MkDocs publishes only 20 product/operator pages and five approved assets. +MkDocs publishes only 22 product/operator pages and five approved assets. Architecture, contracts, ADRs, plans, research, tests and release evidence are excluded from HTML and search. The repository itself is public: editorial exclusion is not confidentiality. diff --git a/docs/install/publishing-images.md b/docs/install/publishing-images.md index e93cf6ed..d0d2bed7 100644 --- a/docs/install/publishing-images.md +++ b/docs/install/publishing-images.md @@ -11,6 +11,12 @@ Prerequisiti del manutentore: Git, Node 24/npm, Go indicato in `tools/tht/go.mod Docker con Buildx e capacità di eseguire Linux amd64, `tar`. Bun viene installato dal lock npm e serve soltanto per compilare il pacchetto. Il commit da pubblicare deve essere già disponibile sul repository Gitea pubblico. +Eseguire il produttore su Linux, WSL2 o macOS; la shell Windows nativa non è supportata. + +La prima [prerelease Linux amd64](https://git.tylconsulting.it/mptyl/ThothII/releases/tag/installation-v0.1.0-install-preview.1) +è disponibile: `0.1.0-install-preview.1`, con immagini pubbliche +[core](https://hub.docker.com/r/tylconsulting/thothii-core) e +[frontend](https://hub.docker.com/r/tylconsulting/thothii-frontend). 1. Eseguire `docker login` sul computer di pubblicazione con un account autorizzato a creare repository pubblici e pubblicare immagini nel namespace scelto. @@ -66,6 +72,10 @@ Bun for producer builds only. Push the selected source commit to the public Gite repository before publication. Use Docker's credential store for `docker login` and Git's credential helper for Gitea release/attachment permissions. Never pass tokens as command arguments or include them in a checkout or archive. +Run the producer on Linux, WSL2 or macOS, not a native Windows shell. + +The first [Linux amd64 prerelease](https://git.tylconsulting.it/mptyl/ThothII/releases/tag/installation-v0.1.0-install-preview.1) +is available as `0.1.0-install-preview.1`, with public Docker Hub core/frontend images. From `backend`, run `npm ci`, then the command above with an explicit revision, version, namespace, platforms and a new private output directory. A temporary Git diff --git a/docs/reports/2026-09-28-installation-prerelease.md b/docs/reports/2026-09-28-installation-prerelease.md new file mode 100644 index 00000000..f136adf9 --- /dev/null +++ b/docs/reports/2026-09-28-installation-prerelease.md @@ -0,0 +1,74 @@ +# First installation prerelease — ticket #46 + +Date: 2026-09-28. Source: `ec0421e9fd47176f4883a4e9b4054d5c2a3ad2b8`. +Branch: `codex/guided-standalone-install`. Platform: **linux/amd64**. + +## Public artifacts + +- [Gitea prerelease and downloads](https://git.tylconsulting.it/mptyl/ThothII/releases/tag/installation-v0.1.0-install-preview.1) +- [Docker Hub core](https://hub.docker.com/r/tylconsulting/thothii-core) +- [Docker Hub frontend](https://hub.docker.com/r/tylconsulting/thothii-frontend) +- Image version: `0.1.0-install-preview.1`. +- Git tag: `installation-v0.1.0-install-preview.1`. + +The release was created as a draft, then made public only after image pulls, +smoke tests and uploaded attachment checks passed. Docker and Git credential +stores supplied publisher authentication; no token is present in this report, +the source worktree or the release bundle. + +Archive: `thothii-0.1.0-install-preview.1-linux-amd64.tar.gz` (40,926,764 bytes). +SHA-256: `4c130276a265c3c66249abb39e3c1cf02b8603efc00a06985d91385bd8112fff`. +`SHA256SUMS.txt` is the second release attachment. + +The archive contains native `tht` and its sibling workspace/document validator, +the release manifest, Compose files, initialization scripts/SQL and IT/EN guides. +There is no application checkout, user workspace, environment credential file, +example database or embedded compiler dependency on the consumer host. + +## Immutable image references + +All references use `docker.io/` and SHA-256 platform manifests: + +| Role | Repository | Digest | +| --- | --- | --- | +| Core, Catalog migration, workspace maintenance | `tylconsulting/thothii-core` | `7ac0b3362c93837c02d9f8d3153d3ab3441cc43594ee7786dafc845a69d5c956` | +| Frontend | `tylconsulting/thothii-frontend` | `2f2b5426a96687702c1f2574c547ea1d1c339419dae05382e83f3706eec6a582` | +| Catalog | `library/postgres` | `45cd22f8d32e189d245403954882f88e7a8714301fda80dab6da90f1265b25a3` | +| Qdrant | `qdrant/qdrant` | `da65a06bc75e42702f80c992b99c5144b0fbd675ae7a96d2991de0bf957b7071` | +| Embedding and model initialization | `ollama/ollama` | `67366844c1f0ed498888b8ee804f629d47ff22a4b559d76154154249bff0dd44` | + +## Verification + +- Backend: 111 test files passed; 1,422 tests passed, 41 skipped. Typecheck passed. +- Producer: seven tests passed, covering real-source packaging, interrupted + preparation, immutable published retries, registry digest/platform verification, + redirect credential isolation, conflicting Git tags and subprocess timeouts. +- Strict MkDocs build passed with 22 allowed public pages. +- Both images built from the detached source commit and pushed successfully. +- All five image roles pulled by digest using an empty Docker client configuration. +- Network-isolated core checks: embedded Pi version, workflow CLI, migration and + workspace-maintenance assets. Frontend configuration smoke passed. +- Packaged Compose rendered without a source checkout or installation credentials. +- Gitea attachment bytes matched local checksums before and after publication; + the public download checks used no authentication. Git tag matched source SHA. +- Re-running the identical publication command after completion succeeded through + the existing-release path, verifying images and public attachments without + rebuilding, uploading replacement files or republishing the release. +- In a network-isolated Linux amd64 PostgreSQL container, the downloaded-format + bundle reported the correct release/commit and successfully performed + `workspace prepare`, `workspace validate` and `installation prepare`. Those + commands used the two bundled executables mounted read-only; no application + checkout, Node, Bun or Python was mounted into the consumer container. + +## Remaining acceptance + +This is an image and tooling prerelease. It includes document preparation, +validation, preflight and planning delivered by #43–45. It does not yet implement +the full non-interactive execution, binding import, workspace readiness or recovery +increments. Example databases remain deferred independently. + +The publisher ran on macOS with Linux amd64 container execution. This is not the +manual Windows/WSL2 installation gate. That gate follows integration of the +remaining installer tickets and requires a newly published integrated release, +real DWH/model endpoints, one human-reviewed question and persistence checks. +Omarchy and macOS acceptance follow Windows in separate steps.