feat(auth): integrate authentication with installation lifecycle
This commit is contained in:
@@ -24,7 +24,7 @@ if (services.join(",") !== "core,embedding,embedding-model-init,frontend,qdrant"
|
||||
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
|
||||
throw new Error("default Compose contains application-specific coupling");
|
||||
}
|
||||
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions", "qdrant-data", "embedding-models"]) {
|
||||
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions", "auth-state", "qdrant-data", "embedding-models"]) {
|
||||
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
|
||||
}
|
||||
const core = config.services.core;
|
||||
@@ -35,9 +35,12 @@ const modelInit = config.services["embedding-model-init"];
|
||||
if (!frontend.ports?.some((port) => port.host_ip === "127.0.0.1")) {
|
||||
throw new Error("local frontend must publish a loopback port");
|
||||
}
|
||||
for (const service of [qdrant, embedding, modelInit]) {
|
||||
for (const service of [embedding, modelInit]) {
|
||||
if ((service.ports || []).length !== 0) throw new Error("private semantic services must not publish host ports");
|
||||
}
|
||||
if (!qdrant.ports?.some((port) => port.host_ip === "127.0.0.1" && Number(port.target) === 6333)) {
|
||||
throw new Error("local Qdrant dashboard must publish only its loopback port");
|
||||
}
|
||||
if ((qdrant.expose || []).join(",") !== "6333") throw new Error("qdrant must expose only 6333");
|
||||
if ((embedding.expose || []).join(",") !== "11434") throw new Error("embedding must expose only 11434");
|
||||
if (!qdrant.healthcheck) throw new Error("qdrant must define a healthcheck");
|
||||
@@ -53,8 +56,9 @@ if (modelInit.image !== "ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279
|
||||
}
|
||||
const env = core.environment || {};
|
||||
for (const [key, value] of Object.entries({
|
||||
AUTH_MODE: "none",
|
||||
THT_WORKSPACE_INSTALLATION_ID: "local",
|
||||
THT_AUTH_CONFIG_FILE: "/run/thothii-auth/auth.yaml",
|
||||
THT_AUTH_STATE_ROOT: "/data/auth",
|
||||
THT_INTERNAL_QDRANT_URL: "http://qdrant:6333",
|
||||
THT_INTERNAL_EMBEDDING_URL: "http://embedding:11434",
|
||||
THT_INTERNAL_EMBEDDING_MODEL: "qwen3-embedding:0.6b",
|
||||
@@ -62,6 +66,18 @@ for (const [key, value] of Object.entries({
|
||||
})) {
|
||||
if (env[key] !== value) throw new Error(`unexpected core ${key}: ${env[key]}`);
|
||||
}
|
||||
const authConfigMounts = (core.volumes || []).filter((mount) => mount.target === "/run/thothii-auth");
|
||||
if (authConfigMounts.length !== 1 || authConfigMounts[0].type !== "bind" || !authConfigMounts[0].read_only) {
|
||||
throw new Error("core must receive exactly one read-only authentication configuration bind");
|
||||
}
|
||||
const authStateMounts = (core.volumes || []).filter((mount) => mount.target === "/data/auth");
|
||||
if (authStateMounts.length !== 1 || authStateMounts[0].type !== "volume" || authStateMounts[0].source !== "auth-state") {
|
||||
throw new Error("core must receive exactly one auth-state volume");
|
||||
}
|
||||
const maintenanceMounts = config.services["workspace-maintenance"]?.volumes || [];
|
||||
if (maintenanceMounts.some((mount) => mount.target === "/run/thothii-auth" || mount.target === "/data/auth")) {
|
||||
throw new Error("workspace-maintenance must not receive authentication configuration or state");
|
||||
}
|
||||
for (const forbidden of ["THT_VEC_REST_URL", "THT_VEC_WRITE_REST_URL", "THT_OLLAMA_URL"]) {
|
||||
if (Object.hasOwn(env, forbidden) && env[forbidden] !== "") {
|
||||
throw new Error(`core must not require external semantic binding ${forbidden}`);
|
||||
|
||||
Reference in New Issue
Block a user