docs: describe read-only workspace runtime configuration
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
# Select this override only for an SSH Git remote. The host-only source files must be absolute,
|
||||
# normalized paths; strict host-key checking is mandatory for registry pull and publish.
|
||||
# normalized paths; strict host-key checking is mandatory for read-only repository fetch and pull.
|
||||
# Active-snapshot workspace-maintenance operations intentionally receive no Git credential mounts.
|
||||
x-thoth-git-transport: ssh
|
||||
|
||||
|
||||
@@ -49,4 +49,7 @@ services:
|
||||
source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT}
|
||||
target: /data/workspace-registry
|
||||
read_only: true
|
||||
- type: bind
|
||||
source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}/workspace-secrets
|
||||
target: /data/workspace-secrets
|
||||
restart: "no"
|
||||
|
||||
Vendored
-2
@@ -8,8 +8,6 @@ THT_SECRETS_FILE=/absolute/path/to/thothii.secrets
|
||||
|
||||
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git
|
||||
THT_WORKSPACE_GIT_BRANCH=main
|
||||
THT_WORKSPACE_GIT_AUTHOR_NAME="Thoth Workspace Registry"
|
||||
THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@example.invalid
|
||||
|
||||
THT_DB_NAME=warehouse
|
||||
THT_DWH_REST_URL=https://dwh.example.invalid
|
||||
|
||||
Vendored
-2
@@ -13,8 +13,6 @@ THT_BACKUP_ROOT=/srv/thothii-backups
|
||||
THT_SERVER_WORKSPACE_CONFIG=/absolute/path/to/server-sessions.yaml
|
||||
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git
|
||||
THT_WORKSPACE_GIT_BRANCH=main
|
||||
THT_WORKSPACE_GIT_AUTHOR_NAME="Thoth Workspace Registry"
|
||||
THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@example.invalid
|
||||
|
||||
THT_DB_NAME=warehouse
|
||||
THT_DWH_REST_URL=https://dwh.example.invalid
|
||||
|
||||
@@ -2,18 +2,14 @@
|
||||
THT_WORKSPACE_GIT_REMOTE=git@github.com:mptyl/tht-workspace-psd.git
|
||||
THT_WORKSPACE_GIT_BRANCH=main
|
||||
THT_WORKSPACE_INSTALLATION_ID=psd-local
|
||||
THT_WORKSPACE_GIT_AUTHOR_NAME="Thoth PSD"
|
||||
THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-psd@example.invalid
|
||||
THT_WORKSPACE_GIT_SSH_KEY_FILE=<abs>/deploy/psd/secrets/git-ssh-key
|
||||
THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=<abs>/deploy/psd/secrets/git-known-hosts
|
||||
|
||||
# App
|
||||
THT_SECRETS_FILE=<abs>/deploy/psd/secrets/thothii.secrets
|
||||
PI_AUTH_FILE=<abs>/deploy/psd/secrets/pi-auth.json
|
||||
THT_WORKSPACE_BINDINGS_ENV_FILE=<abs>/deploy/psd/workspace-bindings.env
|
||||
|
||||
# Connector secret sources (host-only paths)
|
||||
THT_WS_PSD_CLINICAL_DWH_API_KEY_SOURCE=<abs>/deploy/psd/secrets/psd-clinical-dwh-api-key
|
||||
# DWH and Evidence credentials are entered later in Workspace management and stored encrypted
|
||||
# by the backend. They do not depend on host filesystem paths.
|
||||
|
||||
# Pi (LLM)
|
||||
PI_PROVIDER=zai
|
||||
|
||||
@@ -9,4 +9,3 @@ workspaceRepository:
|
||||
access: ssh
|
||||
overrides:
|
||||
- "<abs>/projects/ThothII/deploy/compose.git-ssh.yaml"
|
||||
- "<abs>/projects/ThothII/deploy/psd/connector-secrets.yaml"
|
||||
|
||||
@@ -1,11 +1,9 @@
|
||||
# Copy these non-secret registry settings into the installation environment.
|
||||
# Copy these non-secret workspace repository settings into the installation environment.
|
||||
# Select at most one Git transport override. Every host path below must be absolute and normalized.
|
||||
# Their contents are never committed, emitted by the API, or stored in the registry.
|
||||
# Their contents are never committed, emitted by the API, or stored in the repository checkout.
|
||||
THT_WORKSPACE_REGISTRY_ROOT=/data/workspace-registry
|
||||
THT_WORKSPACE_GIT_BRANCH=main
|
||||
THT_WORKSPACE_INSTALLATION_ID=local
|
||||
THT_WORKSPACE_GIT_AUTHOR_NAME=Thoth Workspace Registry
|
||||
THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@localhost
|
||||
|
||||
# Set the remote for this installation; use its own SSH/HTTPS address, never an application endpoint.
|
||||
# THT_WORKSPACE_GIT_REMOTE=ssh://git@your-git-host/your-org/thoth-workspaces.git
|
||||
@@ -14,10 +12,8 @@ THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@localhost
|
||||
# THT_WORKSPACE_GIT_SSH_KEY_FILE=/absolute/path/to/git-ssh-key
|
||||
# THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=/absolute/path/to/git-known-hosts
|
||||
|
||||
# Generate an untracked connector override from arbitrary THT_WS_*_FILE bindings and their
|
||||
# matching host-only THT_WS_*_SOURCE paths. The generator records paths and variable names only;
|
||||
# it never writes secret values into the generated Compose file.
|
||||
# scripts/generate-connector-secrets-override.sh --bindings-env /absolute/path/workspace-bindings.env \
|
||||
# --operator-env /absolute/path/operator.env --output deploy/compose.connector-secrets.local.yaml
|
||||
# Workspace connector credentials are entered after installation in Workspace management.
|
||||
# ThothII encrypts them in its workspace-secrets volume and never returns their values to the GUI.
|
||||
# Git credentials remain installation-only and are selected with one transport override below.
|
||||
# Run Compose through scripts/compose-with-preflight.sh so relative, non-normalized, and mixed
|
||||
# SSH/HTTPS selections are rejected before Docker receives the invocation.
|
||||
|
||||
Reference in New Issue
Block a user