docs: describe read-only workspace runtime configuration

This commit is contained in:
2026-08-14 18:01:02 +02:00
parent 422f1d47b4
commit ab33e0ed0a
26 changed files with 511 additions and 911 deletions
+5 -9
View File
@@ -1,11 +1,9 @@
# Copy these non-secret registry settings into the installation environment.
# Copy these non-secret workspace repository settings into the installation environment.
# Select at most one Git transport override. Every host path below must be absolute and normalized.
# Their contents are never committed, emitted by the API, or stored in the registry.
# Their contents are never committed, emitted by the API, or stored in the repository checkout.
THT_WORKSPACE_REGISTRY_ROOT=/data/workspace-registry
THT_WORKSPACE_GIT_BRANCH=main
THT_WORKSPACE_INSTALLATION_ID=local
THT_WORKSPACE_GIT_AUTHOR_NAME=Thoth Workspace Registry
THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@localhost
# Set the remote for this installation; use its own SSH/HTTPS address, never an application endpoint.
# THT_WORKSPACE_GIT_REMOTE=ssh://git@your-git-host/your-org/thoth-workspaces.git
@@ -14,10 +12,8 @@ THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@localhost
# THT_WORKSPACE_GIT_SSH_KEY_FILE=/absolute/path/to/git-ssh-key
# THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=/absolute/path/to/git-known-hosts
# Generate an untracked connector override from arbitrary THT_WS_*_FILE bindings and their
# matching host-only THT_WS_*_SOURCE paths. The generator records paths and variable names only;
# it never writes secret values into the generated Compose file.
# scripts/generate-connector-secrets-override.sh --bindings-env /absolute/path/workspace-bindings.env \
# --operator-env /absolute/path/operator.env --output deploy/compose.connector-secrets.local.yaml
# Workspace connector credentials are entered after installation in Workspace management.
# ThothII encrypts them in its workspace-secrets volume and never returns their values to the GUI.
# Git credentials remain installation-only and are selected with one transport override below.
# Run Compose through scripts/compose-with-preflight.sh so relative, non-normalized, and mixed
# SSH/HTTPS selections are rejected before Docker receives the invocation.