fix: retire active pgvector artifacts
This commit is contained in:
@@ -141,7 +141,7 @@ an independent 32-minute outer timeout and does not retry a failed command.
|
||||
Current release status (2026-08-05): clean-root render/setup and the production runtime-binding
|
||||
resolver contracts are green. The server fixture supplies all four private trusted claims,
|
||||
including exact non-admin value `0`, and a focused test proves nginx normalization produces the
|
||||
accepted non-admin backend principal. Canonical schema-v2 registry descriptors now pass through
|
||||
accepted non-admin backend principal. Canonical schema-v3 registry descriptors now pass through
|
||||
one backend-owned, secret-safe runtime handoff for inventory and session execution; canonical
|
||||
identity and durable session/artifact/index roots are retained. The fresh update-only smoke passed
|
||||
bad-candidate mutation, automatic `rolled_back` compensation, exact prior-image restoration,
|
||||
@@ -181,7 +181,7 @@ docker compose --env-file deploy/env/local.env \
|
||||
-f deploy/compose.preprocess.yaml --profile preprocess run --rm preprocess-evidence
|
||||
```
|
||||
|
||||
Replace the final service with `preprocess-dwh` when required. The overlay makes each job wait for the vector
|
||||
Replace the final service with `preprocess-dwh` when required. The overlay makes each job wait for the internal Qdrant
|
||||
service health checks and embedding model initialization; no separate semantic-service startup is
|
||||
required.
|
||||
|
||||
@@ -194,37 +194,36 @@ egress policy. Store access key, secret key, and session token as secret referen
|
||||
deployment configuration—never in Compose environment values or source URIs. Discovery and reads
|
||||
are bounded by configured page, object, and byte limits.
|
||||
|
||||
Create a versioned PostgreSQL custom-format backup (the filename is operator-controlled, so use
|
||||
an immutable timestamp or release identifier):
|
||||
Create a versioned Qdrant volume backup for one exact Compose project (the filename is
|
||||
operator-controlled, so use an immutable timestamp or release identifier):
|
||||
|
||||
```sh
|
||||
./scripts/vector-backup.sh \
|
||||
--host 127.0.0.1 --port 5432 --database thoth --user thoth_backup \
|
||||
--password-file /secure/thoth/vector-backup-password \
|
||||
--output /secure/backups/thoth-vectors-2026-07-12.dump
|
||||
--project-name thothii \
|
||||
--output /secure/backups/thoth-qdrant-2026-08-08.tar
|
||||
```
|
||||
|
||||
The dump contains the three allowlisted `vectors` tables, their data and ACLs, plus the
|
||||
`public.tht_vector_migrations` ledger. Login roles and passwords are deliberately not copied:
|
||||
provision/reconcile the approved role names on the target first, and install the `vector`
|
||||
extension in its `vectors` schema. The target must otherwise contain no vector tables or ledger.
|
||||
The script resolves exactly one Docker volume with the labels
|
||||
`com.docker.compose.project=<project>` and `com.docker.compose.volume=qdrant-data`, stops the
|
||||
`qdrant` service if it is running, archives that volume's persistent contents, then restores the
|
||||
prior service state. It never performs global Docker cleanup and refuses to overwrite an existing
|
||||
archive path.
|
||||
|
||||
Restore always names both the currently active source and a target on a physically distinct
|
||||
PostgreSQL cluster. The script compares PostgreSQL system identity, so host aliases or a different
|
||||
database in the active cluster cannot bypass the guard. It refuses a non-empty target unless
|
||||
`--force-nonempty` is explicit, and the clean restore is one transaction:
|
||||
Restore targets that same exact project-scoped `qdrant-data` volume. Because restore replaces the
|
||||
persistent Qdrant data in place, it requires an explicit confirmation that exactly repeats the
|
||||
Compose project name:
|
||||
|
||||
```sh
|
||||
./scripts/vector-restore.sh \
|
||||
--active-host vector-db --active-database thoth --active-user thoth_backup \
|
||||
--active-password-file /secure/thoth/vector-active-password \
|
||||
--target-host vector-db-restore --target-database thoth --target-user thoth_restore \
|
||||
--target-password-file /secure/thoth/vector-restore-password \
|
||||
--input /secure/backups/thoth-vectors-2026-07-12.dump
|
||||
--project-name thothii \
|
||||
--input /secure/backups/thoth-qdrant-2026-08-08.tar \
|
||||
--confirm-project thothii
|
||||
```
|
||||
|
||||
After restore, run `tht vector migrate --status --json`, adapter health, and a known retrieval
|
||||
query against the target before changing any migration/export endpoint.
|
||||
The restore script stops `qdrant`, validates the exact labeled target, stages the current volume
|
||||
contents for rollback, extracts the requested archive into the volume, and then returns the
|
||||
service to its prior running state. After restore, run the backend health checks and a known
|
||||
retrieval query before reopening write traffic.
|
||||
|
||||
## Production trust boundary and secrets
|
||||
|
||||
|
||||
Reference in New Issue
Block a user