fix: initialize workspace secret volume for runtime
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
# File operatore reali (contengono o referenziano segreti): non tracciare.
|
||||
operator.env
|
||||
workspace-bindings.env
|
||||
workspace-bindings.yaml
|
||||
thothii-installation.yaml
|
||||
connector-secrets.yaml
|
||||
secrets/*
|
||||
|
||||
@@ -54,7 +54,7 @@ RUN ln -s /usr/local/lib/node_modules/npm/bin/npm-cli.js /usr/local/bin/npm \
|
||||
RUN useradd --create-home --uid 10001 --shell /bin/bash thoth
|
||||
# Docker copies these owned directories into newly-created named volumes, allowing the non-root
|
||||
# runtime user to create application settings, sessions, registry snapshots, state, and locks.
|
||||
RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry \
|
||||
RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry /data/workspace-secrets \
|
||||
&& chown -R thoth:thoth /home/thoth/.pi /data
|
||||
|
||||
COPY harness/ /app/harness/
|
||||
|
||||
@@ -1762,6 +1762,9 @@ if not any("workspace-secrets:/data/workspace-secrets" in str(value) for value i
|
||||
if not any(mount.get("source") == "workspace-secrets" and mount.get("target") == "/data/workspace-secrets"
|
||||
for mount in maintenance["volumes"] if isinstance(mount, dict)):
|
||||
raise SystemExit("workspace-maintenance cannot use the encrypted workspace vault")
|
||||
dockerfile = (root / "docker/core.Dockerfile").read_text()
|
||||
if "/data/workspace-secrets" not in dockerfile:
|
||||
raise SystemExit("core image does not pre-create the workspace secret volume target")
|
||||
|
||||
checked = [
|
||||
root / "docs/install/local-workspace-registry.md",
|
||||
|
||||
Reference in New Issue
Block a user