fix: retire active pgvector artifacts
This commit is contained in:
@@ -5,9 +5,10 @@ Git-backed workspace source of truth, installation-local connector bindings, and
|
||||
the [Pi management manual](pi-management.md) for provider configuration and image recovery.
|
||||
|
||||
This guide runs a single-user ThothII registry on Docker Desktop (macOS or Windows) or a local
|
||||
Linux Docker Engine. It is intentionally loopback-only. Git is shared; the checkout, connector
|
||||
bindings, credentials, and session data are local. Never put credentials in workspace YAML, Git,
|
||||
browser drafts, diagnostics, or `.env.example`.
|
||||
Linux Docker Engine. It is intentionally loopback-only. Git is shared; the checkout, DWH
|
||||
bindings, credentials, and session data are local, while internal Qdrant/Ollama ship in the
|
||||
Compose stack. Never put credentials in workspace YAML, Git, browser drafts, diagnostics, or
|
||||
`.env.example`.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
@@ -60,7 +61,7 @@ and branch are non-secret; every `*_FILE` is a local path whose content never en
|
||||
|
||||
| Location | Contains | Never contains |
|
||||
| --- | --- | --- |
|
||||
| Git workspace repository | schema v2 YAML, generated binding names, LLM policy, model/index identity | installation hostnames, keys, passwords, certificates, SSH keys |
|
||||
| Git workspace repository | schema v3 YAML, generated binding names, LLM policy, and semantic-index identity | installation hostnames, keys, passwords, certificates, SSH keys |
|
||||
| local `.env` | remote, branch, installation ID, `THT_WORKSPACE_BINDINGS_ENV_FILE`, and secret source paths | secret contents or `THT_WS_*` values |
|
||||
| workspace bindings env file | only `THT_WS_*` transport, endpoint, user, and `/run/secrets/...` path bindings | secret contents or unrelated application settings |
|
||||
| local secret directory | Git credentials/key, known hosts, CA, connector secret files | a copied registry checkout |
|
||||
@@ -168,13 +169,13 @@ curl --fail --silent http://127.0.0.1:8787/workspaces
|
||||
|
||||
The first status request clones, validates all descriptors, and atomically activates a snapshot.
|
||||
Use `POST /workspace-registry/pull` to fetch later revisions. Run workspace diagnostics only after
|
||||
required bindings are mounted. The optional writer probe uses a distinct writer file and removes
|
||||
its uniquely named temporary record; ordinary diagnostics are read-only.
|
||||
required DWH bindings are mounted. Schema-v3 diagnostics probe the internal Qdrant/Ollama
|
||||
services through backend config; ordinary diagnostics are read-only.
|
||||
|
||||
To migrate an existing legacy descriptor, create/clone an empty private remote, set the absolute
|
||||
`THT_SOURCE_ROOT`, transform with absolute paths, review the schema-v1 result, explicitly add
|
||||
vector database/schema and the complete schema-v2 contract, then commit/push. The transformer
|
||||
never imports `${ENV}` values or secrets.
|
||||
`THT_SOURCE_ROOT`, transform with absolute paths, review the schema-v1 result, explicitly produce
|
||||
the reviewed schema-v3 contract, then commit/push. The transformer never imports `${ENV}` values
|
||||
or secrets.
|
||||
|
||||
```sh
|
||||
THT_SOURCE_ROOT=/absolute/path/to/ThothII
|
||||
|
||||
@@ -32,7 +32,7 @@ targets with runtime ownership without copying secret or tracked file contents i
|
||||
state. Rerun it after a restore and before Compose or `thothctl` startup; it is idempotent and does
|
||||
not overwrite existing targets.
|
||||
|
||||
Permit outbound TCP only to approved Git/Gitea, DWH, vector, embedding, and bastion endpoints.
|
||||
Permit outbound TCP only to approved Git/Gitea, DWH, Qdrant, embedding, and bastion endpoints.
|
||||
Allow inbound traffic only from the reverse proxy/Docker network. Do not give the runtime service
|
||||
account Gitea administration, database-superuser rights, or a shell in the Git host.
|
||||
|
||||
@@ -40,7 +40,7 @@ account Gitea administration, database-superuser rights, or a shell in the Git h
|
||||
|
||||
Create a private Gitea (or compatible Git) repository such as `platform/thoth-workspaces`. Protect
|
||||
`main` according to the release policy and grant the ThothII publisher only the intended repository
|
||||
scope. Commit canonical schema-v2 descriptors and generated `.md`/`.env.example` artifacts only;
|
||||
scope. Commit canonical schema-v3 descriptors and generated `.md`/`.env.example` artifacts only;
|
||||
do not commit installation bindings or secret material.
|
||||
|
||||
For SSH, create a least-privilege deploy key, record Gitea's host key in managed known-hosts, and
|
||||
@@ -49,7 +49,7 @@ machine credential in the secret manager and mount the Gitea/private CA separate
|
||||
Gitea admin credential in the application.
|
||||
|
||||
Bootstrap an empty remote from a temporary review clone: migrate legacy descriptors, review their
|
||||
schema-v2 identity and generated artifacts, commit, and push `main`. The running server is not an
|
||||
schema-v3 identity and generated artifacts, commit, and push `main`. The running server is not an
|
||||
authoring environment for migration.
|
||||
|
||||
## Git credentials, CA, SSH key, and known-hosts mounts
|
||||
@@ -78,8 +78,8 @@ rendered Compose output.
|
||||
|
||||
## Shared Git values, local bindings, and secret files
|
||||
|
||||
Git describes workspace schema, immutable ID, DWH/vector identity, semantic-index dimensions and
|
||||
distance, embedding contract, and LLM policy. The installation supplies remote/branch/installation
|
||||
Git describes workspace schema, immutable ID, DWH identity, semantic-index dimensions and
|
||||
distance, internal embedding contract, and LLM policy. The installation supplies remote/branch/installation
|
||||
ID and one absolute `THT_WORKSPACE_BINDINGS_ENV_FILE` containing only `THT_WS_*` transport,
|
||||
endpoint, user, and `/run/secrets/...` path bindings. The base Compose loads that file only into
|
||||
`core`. Secret contents are only in host files, never the values stored in Git or browser-local
|
||||
@@ -95,8 +95,9 @@ The runtime registry layout is persistent and must be backed up together:
|
||||
```
|
||||
|
||||
Variable names derive from the immutable ID: `north-star-research` becomes `NORTH_STAR_RESEARCH`, producing
|
||||
`THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE`. A declared vector writer uses the distinct
|
||||
`THT_WS_NORTH_STAR_RESEARCH_VECTOR_WRITER_API_KEY_FILE`; a reader file is never a writer substitute.
|
||||
`THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE`. Keep the bindings file limited to DWH transport,
|
||||
endpoint, user, and secret-path values; internal semantic services are supplied by Compose and do
|
||||
not require workspace-local vector or embedding bindings.
|
||||
Copy [the bindings env example](examples/workspace-bindings.env.example) to the protected operator
|
||||
directory. Every path-valued `*_FILE` entry needs an absolute host-only `*_SOURCE` path. Generate
|
||||
the untracked connector override from those files during bootstrap; do not copy or maintain a
|
||||
@@ -216,8 +217,8 @@ For upgrades, record active status/head, finish active work, use the documented
|
||||
proxy traffic.
|
||||
|
||||
For legacy descriptor migration, use a temporary review clone and the legacy transformer with absolute paths.
|
||||
Its schema-v1 output is `migration_required`; explicitly supply vector database/schema, collection
|
||||
identity, diagnostics, and the reviewed v2 contract before commit. Never import `${ENV}` values or
|
||||
Its schema-v1 output is `migration_required`; explicitly supply collection identity, diagnostics,
|
||||
and the reviewed v3 contract before commit. Never import `${ENV}` values or
|
||||
copy secret files.
|
||||
|
||||
After valid bootstrap, Git outage retains the active snapshot with `degraded: true`. Repair
|
||||
|
||||
Reference in New Issue
Block a user