From 9414a4b4dddcb62efe5522f30a67087abb5eefd1 Mon Sep 17 00:00:00 2001 From: mptyl Date: Fri, 14 Aug 2026 18:13:52 +0200 Subject: [PATCH] fix: initialize workspace secret volume for runtime --- deploy/psd/.gitignore | 1 + docker/core.Dockerfile | 2 +- scripts/verify-workspace-install-docs.sh | 3 +++ 3 files changed, 5 insertions(+), 1 deletion(-) diff --git a/deploy/psd/.gitignore b/deploy/psd/.gitignore index ba5e56e0..1a939266 100644 --- a/deploy/psd/.gitignore +++ b/deploy/psd/.gitignore @@ -1,6 +1,7 @@ # File operatore reali (contengono o referenziano segreti): non tracciare. operator.env workspace-bindings.env +workspace-bindings.yaml thothii-installation.yaml connector-secrets.yaml secrets/* diff --git a/docker/core.Dockerfile b/docker/core.Dockerfile index c6cfb521..8402f640 100644 --- a/docker/core.Dockerfile +++ b/docker/core.Dockerfile @@ -54,7 +54,7 @@ RUN ln -s /usr/local/lib/node_modules/npm/bin/npm-cli.js /usr/local/bin/npm \ RUN useradd --create-home --uid 10001 --shell /bin/bash thoth # Docker copies these owned directories into newly-created named volumes, allowing the non-root # runtime user to create application settings, sessions, registry snapshots, state, and locks. -RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry \ +RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry /data/workspace-secrets \ && chown -R thoth:thoth /home/thoth/.pi /data COPY harness/ /app/harness/ diff --git a/scripts/verify-workspace-install-docs.sh b/scripts/verify-workspace-install-docs.sh index 34935cef..72d0674a 100755 --- a/scripts/verify-workspace-install-docs.sh +++ b/scripts/verify-workspace-install-docs.sh @@ -1762,6 +1762,9 @@ if not any("workspace-secrets:/data/workspace-secrets" in str(value) for value i if not any(mount.get("source") == "workspace-secrets" and mount.get("target") == "/data/workspace-secrets" for mount in maintenance["volumes"] if isinstance(mount, dict)): raise SystemExit("workspace-maintenance cannot use the encrypted workspace vault") +dockerfile = (root / "docker/core.Dockerfile").read_text() +if "/data/workspace-secrets" not in dockerfile: + raise SystemExit("core image does not pre-create the workspace secret volume target") checked = [ root / "docs/install/local-workspace-registry.md",