docs: describe read-only workspace runtime configuration
This commit is contained in:
+10
-12
@@ -109,19 +109,19 @@ Copy-Item docs/install/examples/thothii-installation.local.yaml `
|
||||
```
|
||||
|
||||
Edit `deploy/env/local.env`. At minimum set the workspace Git remote, `PI_AUTH_FILE`,
|
||||
`THT_SECRETS_FILE`, external service endpoints, and the absolute
|
||||
`THT_WORKSPACE_BINDINGS_ENV_FILE`. Create each secret as a separate regular file under the
|
||||
protected operator directory and set mode `0600`. On Windows use a user-only ACL instead.
|
||||
`THT_SECRETS_FILE`, and external service endpoints. Create the Pi/application and Git transport
|
||||
files under the protected operator directory and set mode `0600`. On Windows use a user-only ACL
|
||||
instead. DWH and Evidence credentials are entered later through Workspace management and stored
|
||||
in the backend's encrypted `workspace-secrets` volume.
|
||||
|
||||
Do not paste credentials into this guide's commands, `.env`, workspace YAML, Git, URLs, image build
|
||||
arguments, or the installation descriptor. Secret contents are mounted read-only under
|
||||
`/run/secrets` (Pi's auth store has its own protected read-only mount) and must never be committed,
|
||||
embedded, rendered, or logged.
|
||||
|
||||
Follow [the local workspace-registry guide](local-workspace-registry.md) to create the bindings
|
||||
file, choose exactly one Git SSH/HTTPS override, and generate the connector-secret override. A
|
||||
fresh install requires a valid private workspace repository; the Git-backed registry remains the
|
||||
source of truth.
|
||||
Follow [the local workspace repository guide](local-workspace-registry.md) to choose exactly one
|
||||
read-only Git SSH/HTTPS override. A fresh install requires a valid private workspace repository;
|
||||
the remote Git repository remains the source of truth.
|
||||
|
||||
Copy the installation example to an operator-controlled file named exactly
|
||||
`thothii-installation.yaml`, then replace all placeholders with absolute paths:
|
||||
@@ -132,8 +132,7 @@ cp docs/install/examples/thothii-installation.local.yaml \
|
||||
```
|
||||
|
||||
For HTTPS, replace the SSH override in that file with `deploy/compose.git-https.yaml`. Add only
|
||||
reviewed local overrides, including the generated connector-secret file. Paths may contain spaces
|
||||
when correctly represented as YAML strings.
|
||||
reviewed local overrides. Paths may contain spaces when correctly represented as YAML strings.
|
||||
|
||||
Native Windows uses the same four fields. Use single-quoted absolute Windows paths so backslashes
|
||||
remain literal YAML characters:
|
||||
@@ -144,14 +143,13 @@ projectDirectory: 'C:\Users\operator\src\ThothII'
|
||||
envFile: 'C:\Users\operator\src\ThothII\deploy\env\local.env'
|
||||
overrides:
|
||||
- 'C:\Users\operator\src\ThothII\deploy\compose.git-ssh.yaml'
|
||||
- 'C:\Users\operator\thothii-operator\connector-secrets.local.yaml'
|
||||
```
|
||||
|
||||
## Address external services
|
||||
|
||||
An address is interpreted inside `core`. Therefore container 127.0.0.1 means the container itself,
|
||||
not the Docker host. Keep every DWH, vector, embedding, and LLM address configurable in the local
|
||||
environment/workspace bindings.
|
||||
not the Docker host. Keep external DWH and LLM addresses configurable in the installation; Qdrant
|
||||
and embedding are internal services in the standard stack.
|
||||
|
||||
- **Docker Desktop (macOS and Windows):** use `host.docker.internal`, for example
|
||||
`http://host.docker.internal:11434`.
|
||||
|
||||
Reference in New Issue
Block a user