docs: record verified Docker Hub installation prerelease

This commit is contained in:
Codex
2026-09-28 17:54:05 +02:00
parent ec0421e9fd
commit 931ac2fad4
3 changed files with 92 additions and 3 deletions
+8 -3
View File
@@ -16,8 +16,13 @@ and invariants are in [AGENTS.md](AGENTS.md); prior snapshots remain in Git.
bindings. Ticket #45 adds host `installation preflight` and `installation plan` bindings. Ticket #45 adds host `installation preflight` and `installation plan`
with release/image checks, canonical external diagnostics and private input seals; with release/image checks, canonical external diagnostics and private input seals;
see [the preflight reference](docs/install/installation-preflight.md). see [the preflight reference](docs/install/installation-preflight.md).
The remainder of the installation tickets, Ticket #46 adds the maintainer release producer and the first public
Docker Hub publication and example databases remain pending. [Linux amd64 prerelease](https://git.tylconsulting.it/mptyl/ThothII/releases/tag/installation-v0.1.0-install-preview.1),
with Docker Hub core/frontend images and a downloadable native operator bundle.
See [publication instructions](docs/install/publishing-images.md) and
[verification evidence](docs/reports/2026-09-28-installation-prerelease.md).
Non-interactive execution (#47 onward), real-host acceptance and example
databases remain pending; the prerelease does not certify a complete installer.
- React supports full/embedded rendering independently of local/OIDC/upstream auth, - React supports full/embedded rendering independently of local/OIDC/upstream auth,
with EN/IT UI and immutable session interaction language. See with EN/IT UI and immutable session interaction language. See
@@ -98,7 +103,7 @@ A later deployment does not prove every earlier acceptance item passed.
## Documentation maintenance ## Documentation maintenance
MkDocs publishes only 20 product/operator pages and five approved assets. MkDocs publishes only 22 product/operator pages and five approved assets.
Architecture, contracts, ADRs, plans, research, tests and release evidence are Architecture, contracts, ADRs, plans, research, tests and release evidence are
excluded from HTML and search. The repository itself is public: editorial exclusion excluded from HTML and search. The repository itself is public: editorial exclusion
is not confidentiality. is not confidentiality.
+10
View File
@@ -11,6 +11,12 @@ Prerequisiti del manutentore: Git, Node 24/npm, Go indicato in `tools/tht/go.mod
Docker con Buildx e capacità di eseguire Linux amd64, `tar`. Bun viene installato Docker con Buildx e capacità di eseguire Linux amd64, `tar`. Bun viene installato
dal lock npm e serve soltanto per compilare il pacchetto. Il commit da pubblicare dal lock npm e serve soltanto per compilare il pacchetto. Il commit da pubblicare
deve essere già disponibile sul repository Gitea pubblico. deve essere già disponibile sul repository Gitea pubblico.
Eseguire il produttore su Linux, WSL2 o macOS; la shell Windows nativa non è supportata.
La prima [prerelease Linux amd64](https://git.tylconsulting.it/mptyl/ThothII/releases/tag/installation-v0.1.0-install-preview.1)
è disponibile: `0.1.0-install-preview.1`, con immagini pubbliche
[core](https://hub.docker.com/r/tylconsulting/thothii-core) e
[frontend](https://hub.docker.com/r/tylconsulting/thothii-frontend).
1. Eseguire `docker login` sul computer di pubblicazione con un account autorizzato 1. Eseguire `docker login` sul computer di pubblicazione con un account autorizzato
a creare repository pubblici e pubblicare immagini nel namespace scelto. a creare repository pubblici e pubblicare immagini nel namespace scelto.
@@ -66,6 +72,10 @@ Bun for producer builds only. Push the selected source commit to the public Gite
repository before publication. Use Docker's credential store for `docker login` repository before publication. Use Docker's credential store for `docker login`
and Git's credential helper for Gitea release/attachment permissions. Never pass and Git's credential helper for Gitea release/attachment permissions. Never pass
tokens as command arguments or include them in a checkout or archive. tokens as command arguments or include them in a checkout or archive.
Run the producer on Linux, WSL2 or macOS, not a native Windows shell.
The first [Linux amd64 prerelease](https://git.tylconsulting.it/mptyl/ThothII/releases/tag/installation-v0.1.0-install-preview.1)
is available as `0.1.0-install-preview.1`, with public Docker Hub core/frontend images.
From `backend`, run `npm ci`, then the command above with an explicit revision, From `backend`, run `npm ci`, then the command above with an explicit revision,
version, namespace, platforms and a new private output directory. A temporary Git version, namespace, platforms and a new private output directory. A temporary Git
@@ -0,0 +1,74 @@
# First installation prerelease — ticket #46
Date: 2026-09-28. Source: `ec0421e9fd47176f4883a4e9b4054d5c2a3ad2b8`.
Branch: `codex/guided-standalone-install`. Platform: **linux/amd64**.
## Public artifacts
- [Gitea prerelease and downloads](https://git.tylconsulting.it/mptyl/ThothII/releases/tag/installation-v0.1.0-install-preview.1)
- [Docker Hub core](https://hub.docker.com/r/tylconsulting/thothii-core)
- [Docker Hub frontend](https://hub.docker.com/r/tylconsulting/thothii-frontend)
- Image version: `0.1.0-install-preview.1`.
- Git tag: `installation-v0.1.0-install-preview.1`.
The release was created as a draft, then made public only after image pulls,
smoke tests and uploaded attachment checks passed. Docker and Git credential
stores supplied publisher authentication; no token is present in this report,
the source worktree or the release bundle.
Archive: `thothii-0.1.0-install-preview.1-linux-amd64.tar.gz` (40,926,764 bytes).
SHA-256: `4c130276a265c3c66249abb39e3c1cf02b8603efc00a06985d91385bd8112fff`.
`SHA256SUMS.txt` is the second release attachment.
The archive contains native `tht` and its sibling workspace/document validator,
the release manifest, Compose files, initialization scripts/SQL and IT/EN guides.
There is no application checkout, user workspace, environment credential file,
example database or embedded compiler dependency on the consumer host.
## Immutable image references
All references use `docker.io/` and SHA-256 platform manifests:
| Role | Repository | Digest |
| --- | --- | --- |
| Core, Catalog migration, workspace maintenance | `tylconsulting/thothii-core` | `7ac0b3362c93837c02d9f8d3153d3ab3441cc43594ee7786dafc845a69d5c956` |
| Frontend | `tylconsulting/thothii-frontend` | `2f2b5426a96687702c1f2574c547ea1d1c339419dae05382e83f3706eec6a582` |
| Catalog | `library/postgres` | `45cd22f8d32e189d245403954882f88e7a8714301fda80dab6da90f1265b25a3` |
| Qdrant | `qdrant/qdrant` | `da65a06bc75e42702f80c992b99c5144b0fbd675ae7a96d2991de0bf957b7071` |
| Embedding and model initialization | `ollama/ollama` | `67366844c1f0ed498888b8ee804f629d47ff22a4b559d76154154249bff0dd44` |
## Verification
- Backend: 111 test files passed; 1,422 tests passed, 41 skipped. Typecheck passed.
- Producer: seven tests passed, covering real-source packaging, interrupted
preparation, immutable published retries, registry digest/platform verification,
redirect credential isolation, conflicting Git tags and subprocess timeouts.
- Strict MkDocs build passed with 22 allowed public pages.
- Both images built from the detached source commit and pushed successfully.
- All five image roles pulled by digest using an empty Docker client configuration.
- Network-isolated core checks: embedded Pi version, workflow CLI, migration and
workspace-maintenance assets. Frontend configuration smoke passed.
- Packaged Compose rendered without a source checkout or installation credentials.
- Gitea attachment bytes matched local checksums before and after publication;
the public download checks used no authentication. Git tag matched source SHA.
- Re-running the identical publication command after completion succeeded through
the existing-release path, verifying images and public attachments without
rebuilding, uploading replacement files or republishing the release.
- In a network-isolated Linux amd64 PostgreSQL container, the downloaded-format
bundle reported the correct release/commit and successfully performed
`workspace prepare`, `workspace validate` and `installation prepare`. Those
commands used the two bundled executables mounted read-only; no application
checkout, Node, Bun or Python was mounted into the consumer container.
## Remaining acceptance
This is an image and tooling prerelease. It includes document preparation,
validation, preflight and planning delivered by #43–45. It does not yet implement
the full non-interactive execution, binding import, workspace readiness or recovery
increments. Example databases remain deferred independently.
The publisher ran on macOS with Linux amd64 container execution. This is not the
manual Windows/WSL2 installation gate. That gate follows integration of the
remaining installer tickets and requires a newly published integrated release,
real DWH/model endpoints, one human-reviewed question and persistence checks.
Omarchy and macOS acceptance follow Windows in separate steps.