fix(deploy): close container final review
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
services:
|
||||
core:
|
||||
env_file:
|
||||
- path: ./deploy/.env
|
||||
required: false
|
||||
@@ -0,0 +1,33 @@
|
||||
services:
|
||||
core:
|
||||
environment:
|
||||
AUTH_MODE: upstream
|
||||
THOTH_PUBLIC_EXPOSURE: "true"
|
||||
THT_DB_NAME: ${THT_DB_NAME:?set THT_DB_NAME}
|
||||
THT_DWH_REST_URL: ${THT_DWH_REST_URL:?set THT_DWH_REST_URL}
|
||||
THT_VEC_REST_URL: ${THT_VEC_REST_URL:?set THT_VEC_REST_URL}
|
||||
THT_OLLAMA_URL: ${THT_OLLAMA_URL:?set THT_OLLAMA_URL}
|
||||
THT_DOCS_ROOT: ${THT_DOCS_ROOT:-/data/workspaces/example/evidence-source}
|
||||
THT_DWH_API_KEY_FILE: /run/secrets/dwh_api_key
|
||||
THT_VEC_API_KEY_FILE: /run/secrets/vector_reader_api_key
|
||||
THT_VEC_WRITE_API_KEY_FILE: /run/secrets/vector_writer_api_key
|
||||
THT_SSL_CA: /run/secrets/thoth_ca.pem
|
||||
secrets:
|
||||
- source: dwh_api_key
|
||||
target: dwh_api_key
|
||||
- source: vector_reader_api_key
|
||||
target: vector_reader_api_key
|
||||
- source: vector_writer_api_key
|
||||
target: vector_writer_api_key
|
||||
- source: thoth_ca
|
||||
target: thoth_ca.pem
|
||||
|
||||
secrets:
|
||||
dwh_api_key:
|
||||
file: ${THT_DWH_API_KEY_SECRET_FILE:?set THT_DWH_API_KEY_SECRET_FILE}
|
||||
vector_reader_api_key:
|
||||
file: ${THT_VEC_API_KEY_SECRET_FILE:?set THT_VEC_API_KEY_SECRET_FILE}
|
||||
vector_writer_api_key:
|
||||
file: ${THT_VEC_WRITE_API_KEY_SECRET_FILE:?set THT_VEC_WRITE_API_KEY_SECRET_FILE}
|
||||
thoth_ca:
|
||||
file: ${THT_CA_SECRET_FILE:?set THT_CA_SECRET_FILE}
|
||||
+2
-2
@@ -1,5 +1,5 @@
|
||||
# Copy this file to deploy/.env. Never commit deploy/.env or real credentials.
|
||||
# Compose passes these values to the core container at runtime; images contain no secrets.
|
||||
# LOCAL DEVELOPMENT ONLY. Copy to deploy/.env and use deploy/compose.local.yaml.
|
||||
# Never commit deploy/.env or real credentials. Production uses Compose secrets instead.
|
||||
|
||||
# Optional application defaults
|
||||
PI_PROVIDER=
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
# Host nginx example. The auth service MUST authenticate every request and return a stable
|
||||
# identity in X-Authenticated-User. ThothII itself remains on 127.0.0.1:8080.
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name thoth.example.test;
|
||||
|
||||
ssl_certificate /etc/nginx/tls/fullchain.pem;
|
||||
ssl_certificate_key /etc/nginx/tls/privkey.pem;
|
||||
|
||||
location = /_authenticate {
|
||||
internal;
|
||||
proxy_pass http://authentication-gateway/verify;
|
||||
proxy_pass_request_body off;
|
||||
proxy_set_header Content-Length "";
|
||||
proxy_set_header X-Original-URI $request_uri;
|
||||
}
|
||||
|
||||
location / {
|
||||
auth_request /_authenticate;
|
||||
auth_request_set $authenticated_user $upstream_http_x_authenticated_user;
|
||||
proxy_set_header X-Authenticated-User $authenticated_user;
|
||||
proxy_set_header X-Forwarded-Proto https;
|
||||
proxy_set_header Host $host;
|
||||
proxy_pass http://127.0.0.1:8080;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
# Runtime secrets and private CA
|
||||
|
||||
Do not put secret values in this directory or in Git. For production, create files outside the
|
||||
repository and point the `*_SECRET_FILE` variables documented in the root README at them.
|
||||
|
||||
Compose mounts each file read-only beneath `/run/secrets`. The core process runs as UID 10001;
|
||||
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
|
||||
mounted read-only with mode `0444`; verify with:
|
||||
|
||||
```sh
|
||||
docker compose -f compose.yaml -f deploy/compose.production.yaml \
|
||||
--profile external run --rm core sh -c 'id && test -r /run/secrets/thoth_ca.pem'
|
||||
```
|
||||
|
||||
The CA file should contain only the public PEM certificate chain. API-key files should contain
|
||||
one value with no surrounding quotes.
|
||||
Reference in New Issue
Block a user