docs: describe read-only workspace runtime configuration

This commit is contained in:
2026-08-14 18:01:02 +02:00
parent 422f1d47b4
commit ab33e0ed0a
26 changed files with 511 additions and 911 deletions
+8 -9
View File
@@ -53,7 +53,7 @@ The frontend depends on the core health check and proxies `/health` and `/api/*`
application health endpoint intentionally checks process readiness only; external dependency
diagnostics are exposed by `tht doctor` and do not prevent the UI from starting.
## Git-backed workspace registry
## Git-backed workspace repository
Workspace descriptors are shared through a validated Git repository while endpoint bindings and
secret files remain installation-local. Use the [local Mac/PC installation manual](docs/install/local-workspace-registry.md)
@@ -68,20 +68,19 @@ The curator-owned repository layout is:
thoth-workspaces.yaml
<id>/workspace.yaml
<id>/evidence/**
workspace-docs/<id>/{contract.env.example,README.md}
```
`thoth-workspaces.yaml` uses the `schema_version` value `1` and the ordered `workspaces` list of
`{id, name, description?}` entries. It is authoritative for workspace ID, name, description, and
display order. The API may create `<id>/workspace.yaml` only when the catalog slot already exists
and the descriptor is absent. A pulled catalog-only slot reports `configuration_required`. After
bootstrap, existing descriptors remain curator-owned and change only through curator Git commit,
push, and installation pull. The API never writes `thoth-workspaces.yaml` or `<id>/evidence/**`;
its generated docs live only at `workspace-docs/<id>/{contract.env.example,README.md}`.
display order. Every catalog entry must have a matching descriptor in the same commit; otherwise
the complete candidate is rejected. Descriptors remain curator-owned and change only through a
Git commit and push from a separate authoring clone, followed by an installation pull. ThothII
never writes any workspace repository content.
The operator workflow is: curate catalog/descriptor/Evidence changes in Git, commit and push,
**Pull latest registry** from each ThothII installation, run **Validate workspace** and **Test on
this installation**, then select the workspace locally before creating sessions. Each new session
**Update workspace repository** from each ThothII installation, select the workspace, complete its
write-only runtime-secret fields, run **Validate workspace source** and **Test workspace
connections**, then select the workspace locally before creating sessions. Each new session
pins the Git revision it used; a later pull cannot change a Resume. Snapshot cleanup retains every
revision referenced by an open, closed, or failed unarchived session. It reconciles from the
single local installation list or from a server administrator's complete session list, never from