docs: describe read-only workspace runtime configuration
This commit is contained in:
+11
-10
@@ -211,15 +211,17 @@ The named human operator can now edit both placeholder files without `sudo`; use
|
||||
preserves the group, or create replacements under `umask 0007` in the setgid operator directory.
|
||||
Replace every placeholder with an absolute path. Use exactly one Git transport override. For
|
||||
HTTPS, replace `deploy/compose.git-ssh.yaml` with `deploy/compose.git-https.yaml`. Keep the required
|
||||
session-server overlay and generated connector-secret override. Optional host-gateway or pinned
|
||||
session-server overlay. Optional host-gateway or pinned
|
||||
image overrides go after them.
|
||||
|
||||
Create each credential as an independent regular file in `/srv/thothii/secrets`, owned by
|
||||
Create each installation credential (Pi/application, Git, and session storage) as an independent
|
||||
regular file in `/srv/thothii/secrets`, owned by
|
||||
UID 10001, group `thothii-ops`, and mode `0640`. Owner access lets the UID 10001 container read a
|
||||
file mounted under `/run/secrets`; group access lets the reviewed human run `thothctl`. The
|
||||
operator environment records only absolute `*_FILE` or
|
||||
`*_SOURCE` paths. Compose mounts application and connector targets read-only under `/run/secrets`;
|
||||
the frontend receives none. Do not print file contents while testing permissions.
|
||||
operator environment records only absolute `*_FILE` or `*_SOURCE` paths for those installation
|
||||
credentials. DWH and Evidence values are entered later through Workspace management and persist
|
||||
as ciphertext under `/data/workspace-secrets`; the frontend receives no secret values. Do not
|
||||
print file contents while testing permissions.
|
||||
|
||||
```sh
|
||||
sudo find /srv/thothii/secrets -type f -exec chown 10001:thothii-ops {} +
|
||||
@@ -227,11 +229,10 @@ sudo find /srv/thothii/secrets -type f -exec chmod 0640 {} +
|
||||
sudo find /srv/thothii/secrets -type f \( ! -user thothii -o ! -group thothii-ops -o ! -perm 0640 \) -print
|
||||
```
|
||||
|
||||
Add `THT_WORKSPACE_BINDINGS_ENV_FILE=/srv/thothii/operator/workspace-bindings.env` and the matching
|
||||
connector `*_SOURCE` paths to `server.env`. Generate
|
||||
`/srv/thothii/operator/connector-secrets.server.yaml` as described in
|
||||
[server workspace-registry installation](server-workspace-registry.md). Secret values must never
|
||||
be pasted into `server.env`, the installation YAML, a URL, or a shell argument.
|
||||
Configure the remote repository and exactly one read-only Git transport as described in
|
||||
[server workspace repository installation](server-workspace-registry.md). After startup, complete
|
||||
the selected workspace's DWH and Evidence credentials through Workspace management. Secret values
|
||||
must never be pasted into `server.env`, the installation YAML, a URL, or a shell argument.
|
||||
|
||||
## Build locally or select pinned images
|
||||
|
||||
|
||||
Reference in New Issue
Block a user