fix: initialize workspace secret volume for runtime

This commit is contained in:
2026-08-14 18:13:52 +02:00
parent bd42aa5934
commit 9414a4b4dd
3 changed files with 5 additions and 1 deletions
+1
View File
@@ -1,6 +1,7 @@
# File operatore reali (contengono o referenziano segreti): non tracciare.
operator.env
workspace-bindings.env
workspace-bindings.yaml
thothii-installation.yaml
connector-secrets.yaml
secrets/*
+1 -1
View File
@@ -54,7 +54,7 @@ RUN ln -s /usr/local/lib/node_modules/npm/bin/npm-cli.js /usr/local/bin/npm \
RUN useradd --create-home --uid 10001 --shell /bin/bash thoth
# Docker copies these owned directories into newly-created named volumes, allowing the non-root
# runtime user to create application settings, sessions, registry snapshots, state, and locks.
RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry \
RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry /data/workspace-secrets \
&& chown -R thoth:thoth /home/thoth/.pi /data
COPY harness/ /app/harness/
+3
View File
@@ -1762,6 +1762,9 @@ if not any("workspace-secrets:/data/workspace-secrets" in str(value) for value i
if not any(mount.get("source") == "workspace-secrets" and mount.get("target") == "/data/workspace-secrets"
for mount in maintenance["volumes"] if isinstance(mount, dict)):
raise SystemExit("workspace-maintenance cannot use the encrypted workspace vault")
dockerfile = (root / "docker/core.Dockerfile").read_text()
if "/data/workspace-secrets" not in dockerfile:
raise SystemExit("core image does not pre-create the workspace secret volume target")
checked = [
root / "docs/install/local-workspace-registry.md",