fix: initialize workspace secret volume for runtime
This commit is contained in:
@@ -1,6 +1,7 @@
|
|||||||
# File operatore reali (contengono o referenziano segreti): non tracciare.
|
# File operatore reali (contengono o referenziano segreti): non tracciare.
|
||||||
operator.env
|
operator.env
|
||||||
workspace-bindings.env
|
workspace-bindings.env
|
||||||
|
workspace-bindings.yaml
|
||||||
thothii-installation.yaml
|
thothii-installation.yaml
|
||||||
connector-secrets.yaml
|
connector-secrets.yaml
|
||||||
secrets/*
|
secrets/*
|
||||||
|
|||||||
@@ -54,7 +54,7 @@ RUN ln -s /usr/local/lib/node_modules/npm/bin/npm-cli.js /usr/local/bin/npm \
|
|||||||
RUN useradd --create-home --uid 10001 --shell /bin/bash thoth
|
RUN useradd --create-home --uid 10001 --shell /bin/bash thoth
|
||||||
# Docker copies these owned directories into newly-created named volumes, allowing the non-root
|
# Docker copies these owned directories into newly-created named volumes, allowing the non-root
|
||||||
# runtime user to create application settings, sessions, registry snapshots, state, and locks.
|
# runtime user to create application settings, sessions, registry snapshots, state, and locks.
|
||||||
RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry \
|
RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry /data/workspace-secrets \
|
||||||
&& chown -R thoth:thoth /home/thoth/.pi /data
|
&& chown -R thoth:thoth /home/thoth/.pi /data
|
||||||
|
|
||||||
COPY harness/ /app/harness/
|
COPY harness/ /app/harness/
|
||||||
|
|||||||
@@ -1762,6 +1762,9 @@ if not any("workspace-secrets:/data/workspace-secrets" in str(value) for value i
|
|||||||
if not any(mount.get("source") == "workspace-secrets" and mount.get("target") == "/data/workspace-secrets"
|
if not any(mount.get("source") == "workspace-secrets" and mount.get("target") == "/data/workspace-secrets"
|
||||||
for mount in maintenance["volumes"] if isinstance(mount, dict)):
|
for mount in maintenance["volumes"] if isinstance(mount, dict)):
|
||||||
raise SystemExit("workspace-maintenance cannot use the encrypted workspace vault")
|
raise SystemExit("workspace-maintenance cannot use the encrypted workspace vault")
|
||||||
|
dockerfile = (root / "docker/core.Dockerfile").read_text()
|
||||||
|
if "/data/workspace-secrets" not in dockerfile:
|
||||||
|
raise SystemExit("core image does not pre-create the workspace secret volume target")
|
||||||
|
|
||||||
checked = [
|
checked = [
|
||||||
root / "docs/install/local-workspace-registry.md",
|
root / "docs/install/local-workspace-registry.md",
|
||||||
|
|||||||
Reference in New Issue
Block a user