feat(auth): integrate authentication with installation lifecycle

This commit is contained in:
2026-08-17 20:21:42 +02:00
parent 0a2c667231
commit 9558eaa508
30 changed files with 756 additions and 120 deletions
-1
View File
@@ -1,7 +1,6 @@
services:
core:
environment:
AUTH_MODE: none
NODE_ENV: development
THT_WORKSPACE_INSTALLATION_ID: local
ports:
+6 -1
View File
@@ -1,7 +1,6 @@
services:
core:
environment:
AUTH_MODE: upstream
THOTH_PUBLIC_EXPOSURE: "true"
THT_DATA_ROOT: /data
THT_WORKSPACE_INSTALLATION_ID: server
@@ -11,6 +10,10 @@ services:
- type: bind
source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}
target: /data
- type: bind
source: ${THT_AUTH_CONFIG_ROOT:?set THT_AUTH_CONFIG_ROOT}
target: /run/thothii-auth
read_only: true
- type: bind
source: ${THT_PI_STATE_ROOT:?set THT_PI_STATE_ROOT}
target: /home/thoth/.pi
@@ -30,6 +33,8 @@ services:
source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT}
target: /data/workspace-registry
restart: unless-stopped
# Deprecated migration adapter: only use this when no auth.yaml is mounted yet.
# AUTH_MODE: upstream
frontend:
ports:
@@ -3,7 +3,6 @@
services:
core:
environment:
AUTH_MODE: upstream
THOTH_PUBLIC_EXPOSURE: "true"
THT_SESSION_STORAGE: postgres
THT_CONFIG: /app/harness/workspaces/server-sessions.yaml
+1
View File
@@ -6,6 +6,7 @@ THOTH_CORE_HTTP_PORT=8787
MAX_PI_PROCESSES=4
PI_AUTH_FILE=/absolute/path/to/pi-auth.json
THT_SECRETS_FILE=/absolute/path/to/thothii.secrets
THT_AUTH_CONFIG_ROOT=/absolute/path/to/thothii-auth
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git
THT_WORKSPACE_GIT_BRANCH=main
+1
View File
@@ -5,6 +5,7 @@ THOTH_HTTP_PORT=8080
MAX_PI_PROCESSES=4
PI_AUTH_FILE=/absolute/path/to/pi-auth.json
THT_SECRETS_FILE=/absolute/path/to/thothii.secrets
THT_AUTH_CONFIG_ROOT=/absolute/path/to/thothii-auth
THT_DATA_ROOT=/srv/thothii/data
THT_PI_STATE_ROOT=/srv/thothii/pi-state
+1 -1
View File
@@ -9,6 +9,7 @@ THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=<abs>/deploy/psd/secrets/git-known-hosts
# App
THT_SECRETS_FILE=<abs>/deploy/psd/secrets/thothii.secrets
PI_AUTH_FILE=<abs>/deploy/psd/secrets/pi-auth.json
THT_AUTH_CONFIG_ROOT=<abs>/deploy/psd/auth
# DWH and Evidence credentials are entered later in Workspace management and stored encrypted
# by the backend. They do not depend on host filesystem paths.
@@ -19,7 +20,6 @@ PI_THINKING=medium
# App defaults
THT_DWH_PRECHECK=true
AUTH_MODE=none
THOTH_PUBLIC_EXPOSURE=false
MAX_PI_PROCESSES=4
THOTH_HTTP_PORT=8080
@@ -8,5 +8,7 @@ workspaceRepository:
remote: git@github.com:mptyl/tht-workspace-psd.git
branch: main
access: ssh
authentication:
configDirectory: "<abs>/projects/ThothII/deploy/psd/auth"
overrides:
- "<abs>/projects/ThothII/deploy/compose.git-ssh.yaml"
+4 -2
View File
@@ -9,8 +9,10 @@ chmod 600 deploy/secrets/thothii.secrets
```
The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). The supported
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, and `THT_SSL_CA`. Values must be
non-empty and contain no whitespace. Do not put secrets
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, `THT_SSL_CA`,
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. The two authentication keys are fixed
empty entries for local authentication and must be populated only in a protected OIDC installation.
Other configured values must be non-empty and contain no whitespace. Do not put secrets
in the root `.env`, workspace YAML, URLs, logs, or rendered Compose output.
Do not add vector or embedding endpoint credentials to the bundle. Active operator manuals use
+4
View File
@@ -10,3 +10,7 @@
# Optional CA material/path understood by the configured adapter.
# THT_CA=/run/secrets/ca-chain.pem
# OIDC/Authentik references. Keep these fixed keys empty until OIDC is configured.
THT_OIDC_CLIENT_SECRET=
THT_AUTHENTIK_API_TOKEN=