docs: describe read-only workspace runtime configuration

This commit is contained in:
2026-08-14 18:01:02 +02:00
parent 422f1d47b4
commit ab33e0ed0a
26 changed files with 511 additions and 911 deletions
+10 -12
View File
@@ -109,19 +109,19 @@ Copy-Item docs/install/examples/thothii-installation.local.yaml `
```
Edit `deploy/env/local.env`. At minimum set the workspace Git remote, `PI_AUTH_FILE`,
`THT_SECRETS_FILE`, external service endpoints, and the absolute
`THT_WORKSPACE_BINDINGS_ENV_FILE`. Create each secret as a separate regular file under the
protected operator directory and set mode `0600`. On Windows use a user-only ACL instead.
`THT_SECRETS_FILE`, and external service endpoints. Create the Pi/application and Git transport
files under the protected operator directory and set mode `0600`. On Windows use a user-only ACL
instead. DWH and Evidence credentials are entered later through Workspace management and stored
in the backend's encrypted `workspace-secrets` volume.
Do not paste credentials into this guide's commands, `.env`, workspace YAML, Git, URLs, image build
arguments, or the installation descriptor. Secret contents are mounted read-only under
`/run/secrets` (Pi's auth store has its own protected read-only mount) and must never be committed,
embedded, rendered, or logged.
Follow [the local workspace-registry guide](local-workspace-registry.md) to create the bindings
file, choose exactly one Git SSH/HTTPS override, and generate the connector-secret override. A
fresh install requires a valid private workspace repository; the Git-backed registry remains the
source of truth.
Follow [the local workspace repository guide](local-workspace-registry.md) to choose exactly one
read-only Git SSH/HTTPS override. A fresh install requires a valid private workspace repository;
the remote Git repository remains the source of truth.
Copy the installation example to an operator-controlled file named exactly
`thothii-installation.yaml`, then replace all placeholders with absolute paths:
@@ -132,8 +132,7 @@ cp docs/install/examples/thothii-installation.local.yaml \
```
For HTTPS, replace the SSH override in that file with `deploy/compose.git-https.yaml`. Add only
reviewed local overrides, including the generated connector-secret file. Paths may contain spaces
when correctly represented as YAML strings.
reviewed local overrides. Paths may contain spaces when correctly represented as YAML strings.
Native Windows uses the same four fields. Use single-quoted absolute Windows paths so backslashes
remain literal YAML characters:
@@ -144,14 +143,13 @@ projectDirectory: 'C:\Users\operator\src\ThothII'
envFile: 'C:\Users\operator\src\ThothII\deploy\env\local.env'
overrides:
- 'C:\Users\operator\src\ThothII\deploy\compose.git-ssh.yaml'
- 'C:\Users\operator\thothii-operator\connector-secrets.local.yaml'
```
## Address external services
An address is interpreted inside `core`. Therefore container 127.0.0.1 means the container itself,
not the Docker host. Keep every DWH, vector, embedding, and LLM address configurable in the local
environment/workspace bindings.
not the Docker host. Keep external DWH and LLM addresses configurable in the installation; Qdrant
and embedding are internal services in the standard stack.
- **Docker Desktop (macOS and Windows):** use `host.docker.internal`, for example
`http://host.docker.internal:11434`.