feat(auth): integrate authentication with installation lifecycle
This commit is contained in:
@@ -1,7 +1,6 @@
|
||||
services:
|
||||
core:
|
||||
environment:
|
||||
AUTH_MODE: none
|
||||
NODE_ENV: development
|
||||
THT_WORKSPACE_INSTALLATION_ID: local
|
||||
ports:
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
services:
|
||||
core:
|
||||
environment:
|
||||
AUTH_MODE: upstream
|
||||
THOTH_PUBLIC_EXPOSURE: "true"
|
||||
THT_DATA_ROOT: /data
|
||||
THT_WORKSPACE_INSTALLATION_ID: server
|
||||
@@ -11,6 +10,10 @@ services:
|
||||
- type: bind
|
||||
source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}
|
||||
target: /data
|
||||
- type: bind
|
||||
source: ${THT_AUTH_CONFIG_ROOT:?set THT_AUTH_CONFIG_ROOT}
|
||||
target: /run/thothii-auth
|
||||
read_only: true
|
||||
- type: bind
|
||||
source: ${THT_PI_STATE_ROOT:?set THT_PI_STATE_ROOT}
|
||||
target: /home/thoth/.pi
|
||||
@@ -30,6 +33,8 @@ services:
|
||||
source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT}
|
||||
target: /data/workspace-registry
|
||||
restart: unless-stopped
|
||||
# Deprecated migration adapter: only use this when no auth.yaml is mounted yet.
|
||||
# AUTH_MODE: upstream
|
||||
|
||||
frontend:
|
||||
ports:
|
||||
|
||||
@@ -3,7 +3,6 @@
|
||||
services:
|
||||
core:
|
||||
environment:
|
||||
AUTH_MODE: upstream
|
||||
THOTH_PUBLIC_EXPOSURE: "true"
|
||||
THT_SESSION_STORAGE: postgres
|
||||
THT_CONFIG: /app/harness/workspaces/server-sessions.yaml
|
||||
|
||||
Vendored
+1
@@ -6,6 +6,7 @@ THOTH_CORE_HTTP_PORT=8787
|
||||
MAX_PI_PROCESSES=4
|
||||
PI_AUTH_FILE=/absolute/path/to/pi-auth.json
|
||||
THT_SECRETS_FILE=/absolute/path/to/thothii.secrets
|
||||
THT_AUTH_CONFIG_ROOT=/absolute/path/to/thothii-auth
|
||||
|
||||
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git
|
||||
THT_WORKSPACE_GIT_BRANCH=main
|
||||
|
||||
Vendored
+1
@@ -5,6 +5,7 @@ THOTH_HTTP_PORT=8080
|
||||
MAX_PI_PROCESSES=4
|
||||
PI_AUTH_FILE=/absolute/path/to/pi-auth.json
|
||||
THT_SECRETS_FILE=/absolute/path/to/thothii.secrets
|
||||
THT_AUTH_CONFIG_ROOT=/absolute/path/to/thothii-auth
|
||||
|
||||
THT_DATA_ROOT=/srv/thothii/data
|
||||
THT_PI_STATE_ROOT=/srv/thothii/pi-state
|
||||
|
||||
@@ -9,6 +9,7 @@ THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=<abs>/deploy/psd/secrets/git-known-hosts
|
||||
# App
|
||||
THT_SECRETS_FILE=<abs>/deploy/psd/secrets/thothii.secrets
|
||||
PI_AUTH_FILE=<abs>/deploy/psd/secrets/pi-auth.json
|
||||
THT_AUTH_CONFIG_ROOT=<abs>/deploy/psd/auth
|
||||
# DWH and Evidence credentials are entered later in Workspace management and stored encrypted
|
||||
# by the backend. They do not depend on host filesystem paths.
|
||||
|
||||
@@ -19,7 +20,6 @@ PI_THINKING=medium
|
||||
|
||||
# App defaults
|
||||
THT_DWH_PRECHECK=true
|
||||
AUTH_MODE=none
|
||||
THOTH_PUBLIC_EXPOSURE=false
|
||||
MAX_PI_PROCESSES=4
|
||||
THOTH_HTTP_PORT=8080
|
||||
|
||||
@@ -8,5 +8,7 @@ workspaceRepository:
|
||||
remote: git@github.com:mptyl/tht-workspace-psd.git
|
||||
branch: main
|
||||
access: ssh
|
||||
authentication:
|
||||
configDirectory: "<abs>/projects/ThothII/deploy/psd/auth"
|
||||
overrides:
|
||||
- "<abs>/projects/ThothII/deploy/compose.git-ssh.yaml"
|
||||
|
||||
@@ -9,8 +9,10 @@ chmod 600 deploy/secrets/thothii.secrets
|
||||
```
|
||||
|
||||
The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). The supported
|
||||
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, and `THT_SSL_CA`. Values must be
|
||||
non-empty and contain no whitespace. Do not put secrets
|
||||
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, `THT_SSL_CA`,
|
||||
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. The two authentication keys are fixed
|
||||
empty entries for local authentication and must be populated only in a protected OIDC installation.
|
||||
Other configured values must be non-empty and contain no whitespace. Do not put secrets
|
||||
in the root `.env`, workspace YAML, URLs, logs, or rendered Compose output.
|
||||
|
||||
Do not add vector or embedding endpoint credentials to the bundle. Active operator manuals use
|
||||
|
||||
@@ -10,3 +10,7 @@
|
||||
|
||||
# Optional CA material/path understood by the configured adapter.
|
||||
# THT_CA=/run/secrets/ca-chain.pem
|
||||
|
||||
# OIDC/Authentik references. Keep these fixed keys empty until OIDC is configured.
|
||||
THT_OIDC_CLIENT_SECRET=
|
||||
THT_AUTHENTIK_API_TOKEN=
|
||||
|
||||
Reference in New Issue
Block a user