fix: harden model catalog projections

This commit is contained in:
Codex
2026-09-02 19:25:01 +02:00
parent ce4c31a6fb
commit a6a5bf2036
38 changed files with 573 additions and 83 deletions
+9 -7
View File
@@ -100,7 +100,7 @@ generated/
├── pi/
│ ├── models.json
│ └── settings.json
└── compose.model-catalog.yaml
└── compose.models.yaml
```
The normalized catalog is consumed by the backend. The Pi files and Compose override are boundary
@@ -117,17 +117,19 @@ tht --installation "$INSTALLATION" start
tht --installation "$INSTALLATION" doctor
```
After editing `modelCatalog` or provider credentials, reload the current Pi image. Restart validates
the YAML and regenerates projections before recreating `core`:
After editing `modelCatalog` or provider credentials, apply the complete runtime projection with
the normal installation lifecycle, then run the Pi checks:
```bash
tht --installation "$INSTALLATION" pi restart --yes --drain
tht --installation "$INSTALLATION" start
tht --installation "$INSTALLATION" pi doctor
tht --installation "$INSTALLATION" pi test
```
`tht pi update` changes the Pi version; it is not the configuration command. There is no
`tht pi configure` and no separate apply command.
`tht pi restart`, `tht pi update`, and `tht pi rollback` refuse to run while generated model
projections differ from `modelCatalog`: those commands recreate only `core`, so they must never
partially apply an embedding change. `tht pi update` changes the Pi version; it is not the
configuration command. There is no `tht pi configure` and no separate apply command.
## Migrating a legacy installation
@@ -136,7 +138,7 @@ files, but never modifies them. Supply the facts that cannot be inferred safely
candidate:
```bash
tht --installation /absolute/path/legacy-installation.yaml installation migrate \
tht --installation /absolute/path/legacy/thothii-installation.yaml installation migrate \
--output /absolute/path/thothii-installation.v2.yaml \
--session-default zai/glm-5.3 \
--embedding-id ollama/qwen3-embedding:0.6b \
@@ -166,6 +166,8 @@ Generation is deterministic and published only after every candidate artifact va
generation aborts start before Compose is invoked. `tht doctor` recomputes expected bytes and reports
differences; no digest manifest or separate apply command exists. When projection bytes change,
`tht start` recreates the affected services so they cannot continue with an older bind mount.
Pi-only restart, update, and rollback operations reject projection drift and direct the operator to
`tht start`, because applying only the core-facing files could leave embedding services stale.
Generated projections are not backed up. Restore validates the canonical installation descriptor,
regenerates every projection, and only then starts services. Base Compose files and `operator.env`