feat: render private semantic service endpoints
This commit is contained in:
@@ -58,6 +58,12 @@ export function buildApp(config: AppConfig, deps?: BuildAppDeps): FastifyInstanc
|
||||
secretRoots: config.workspaceRegistry.secretRoots,
|
||||
secretsFile: config.secretsFile,
|
||||
secretFiles: config.secretFiles,
|
||||
semanticRuntime: {
|
||||
internalQdrantUrl: config.internalQdrantUrl,
|
||||
internalEmbeddingUrl: config.internalEmbeddingUrl,
|
||||
internalEmbeddingModel: config.internalEmbeddingModel,
|
||||
internalEmbeddingDimensions: config.internalEmbeddingDimensions,
|
||||
},
|
||||
});
|
||||
const mgr = deps?.mgr ?? new PiProcessManager(config, deps?.spawnFn ? { spawnFn: deps.spawnFn } : undefined);
|
||||
const hub = deps?.hub ?? new SseHub();
|
||||
|
||||
@@ -30,6 +30,10 @@ export interface AppConfig {
|
||||
legacyWorkspaceMode: boolean;
|
||||
workspaceDiagnosticTimeoutMs: number;
|
||||
workspaceRegistry: WorkspaceRegistryConfig;
|
||||
internalQdrantUrl: string;
|
||||
internalEmbeddingUrl: string;
|
||||
internalEmbeddingModel: string;
|
||||
internalEmbeddingDimensions: number;
|
||||
}
|
||||
|
||||
export const MAX_WORKSPACE_DIAGNOSTIC_TIMEOUT_MS = 10_000;
|
||||
@@ -101,6 +105,47 @@ function piManagementTimeout(value: string | undefined): number {
|
||||
return timeout;
|
||||
}
|
||||
|
||||
function loopbackHost(host: string): boolean {
|
||||
return host === "::1"
|
||||
|| host === "127.0.0.1"
|
||||
|| /^127(?:\.\d{1,3}){3}$/.test(host);
|
||||
}
|
||||
|
||||
function internalServiceUrl(
|
||||
value: string | undefined,
|
||||
fallback: string,
|
||||
label: string,
|
||||
allowedHosts: readonly string[],
|
||||
): string {
|
||||
const raw = value ?? fallback;
|
||||
let parsed: URL;
|
||||
try {
|
||||
parsed = new URL(raw);
|
||||
} catch {
|
||||
throw new Error(`${label} configuration is invalid`);
|
||||
}
|
||||
if (
|
||||
(parsed.protocol !== "http:" && parsed.protocol !== "https:")
|
||||
|| parsed.username.length > 0
|
||||
|| parsed.password.length > 0
|
||||
|| parsed.pathname !== "/"
|
||||
|| parsed.search.length > 0
|
||||
|| parsed.hash.length > 0
|
||||
|| (!allowedHosts.includes(parsed.hostname) && !loopbackHost(parsed.hostname))
|
||||
) {
|
||||
throw new Error(`${label} configuration is invalid`);
|
||||
}
|
||||
return parsed.toString().replace(/\/$/, "");
|
||||
}
|
||||
|
||||
function positiveDimension(value: string | undefined, fallback: number): number {
|
||||
const parsed = Number(value ?? fallback);
|
||||
if (!Number.isSafeInteger(parsed) || parsed <= 0) {
|
||||
throw new Error("internal embedding dimensions configuration is invalid");
|
||||
}
|
||||
return parsed;
|
||||
}
|
||||
|
||||
export function loadConfig(env: Record<string, string | undefined>): AppConfig {
|
||||
const authMode = env.AUTH_MODE ?? "none";
|
||||
if (!(["none", "mock", "upstream"] as const).includes(authMode as AppConfig["authMode"])) {
|
||||
@@ -208,6 +253,18 @@ export function loadConfig(env: Record<string, string | undefined>): AppConfig {
|
||||
maxImportEntries: positiveImportLimit(env.THT_WORKSPACE_MAX_IMPORT_ENTRIES, 32),
|
||||
};
|
||||
const settingsFile = env.SETTINGS_FILE ?? "data/settings.json";
|
||||
const internalQdrantUrl = internalServiceUrl(
|
||||
env.THT_INTERNAL_QDRANT_URL,
|
||||
"http://qdrant:6333",
|
||||
"internal Qdrant URL",
|
||||
["qdrant", "localhost"],
|
||||
);
|
||||
const internalEmbeddingUrl = internalServiceUrl(
|
||||
env.THT_INTERNAL_EMBEDDING_URL,
|
||||
"http://embedding:11434",
|
||||
"internal embedding URL",
|
||||
["embedding", "localhost"],
|
||||
);
|
||||
return {
|
||||
host: env.HOST ?? "127.0.0.1",
|
||||
port: Number(env.PORT ?? 8787),
|
||||
@@ -231,5 +288,9 @@ export function loadConfig(env: Record<string, string | undefined>): AppConfig {
|
||||
legacyWorkspaceMode: legacyWorkspaceMode === "local",
|
||||
workspaceDiagnosticTimeoutMs: diagnosticTimeout(env.THT_WORKSPACE_DIAGNOSTIC_TIMEOUT_MS),
|
||||
workspaceRegistry,
|
||||
internalQdrantUrl,
|
||||
internalEmbeddingUrl,
|
||||
internalEmbeddingModel: env.THT_INTERNAL_EMBEDDING_MODEL ?? "qwen3-embedding:0.6b",
|
||||
internalEmbeddingDimensions: positiveDimension(env.THT_INTERNAL_EMBEDDING_DIMENSIONS, 1024),
|
||||
};
|
||||
}
|
||||
|
||||
@@ -9,7 +9,12 @@ import { parseAllDocuments } from "yaml";
|
||||
import { clearPrincipalEnvironment, principalEnvironment, type PrincipalContext } from "../auth/principal.js";
|
||||
import { secretValue, type SecretBundleConfig } from "../config/secret-bundle.js";
|
||||
import { resolveRuntimeBindings } from "../workspaces/bindings.js";
|
||||
import { renderRuntimeConfig, type RuntimeInstallationOverlay, type RuntimePaths } from "../workspaces/runtime-renderer.js";
|
||||
import {
|
||||
renderRuntimeConfig,
|
||||
type RuntimeInstallationOverlay,
|
||||
type RuntimePaths,
|
||||
type SemanticRuntimeConfig,
|
||||
} from "../workspaces/runtime-renderer.js";
|
||||
import { parseWorkspaceYaml } from "../workspaces/schema.js";
|
||||
|
||||
export interface ThtConfig extends SecretBundleConfig {
|
||||
@@ -19,6 +24,7 @@ export interface ThtConfig extends SecretBundleConfig {
|
||||
dataRoot?: string;
|
||||
runtimeSnapshotRoot?: string;
|
||||
secretRoots?: readonly string[];
|
||||
semanticRuntime: SemanticRuntimeConfig;
|
||||
}
|
||||
|
||||
export interface RuntimeConfigLease {
|
||||
@@ -190,6 +196,7 @@ export class ThtRunner {
|
||||
this.runtimePaths(canonical.workspaceId),
|
||||
canonical,
|
||||
this.installationOverlay(),
|
||||
this.cfg.semanticRuntime,
|
||||
);
|
||||
const path = this.createRuntimeSnapshot(config);
|
||||
let released = false;
|
||||
|
||||
@@ -97,7 +97,7 @@ export function resolveBinding(
|
||||
): ResolvedBinding {
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
if (descriptor.workspace.schema_version === 3 && role !== "DWH") {
|
||||
throw new Error("Schema version 3 semantic bindings are not supported by the legacy installation contract");
|
||||
return { transport: "rest_api", values: {}, missing: [] };
|
||||
}
|
||||
|
||||
const contract = buildInstallationContract(descriptor);
|
||||
@@ -143,9 +143,6 @@ export function resolveRuntimeBindings(
|
||||
secretRoots: readonly string[],
|
||||
): RuntimeBindings {
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
if (descriptor.workspace.schema_version === 3) {
|
||||
throw new Error("Schema version 3 semantic runtime bindings are not supported before the internal Qdrant/Ollama runtime lands");
|
||||
}
|
||||
|
||||
return {
|
||||
dwh: resolveBinding(descriptor, "DWH", env, secretRoots),
|
||||
|
||||
@@ -20,6 +20,20 @@ export interface RuntimeInstallationOverlay {
|
||||
profile?: unknown;
|
||||
}
|
||||
|
||||
export interface SemanticRuntimeConfig {
|
||||
internalQdrantUrl: string;
|
||||
internalEmbeddingUrl: string;
|
||||
internalEmbeddingModel: string;
|
||||
internalEmbeddingDimensions: number;
|
||||
}
|
||||
|
||||
const DEFAULT_SEMANTIC_RUNTIME: SemanticRuntimeConfig = {
|
||||
internalQdrantUrl: "http://qdrant:6333",
|
||||
internalEmbeddingUrl: "http://embedding:11434",
|
||||
internalEmbeddingModel: "qwen3-embedding:0.6b",
|
||||
internalEmbeddingDimensions: 1024,
|
||||
};
|
||||
|
||||
function seconds(timeoutMs: number | undefined): number | undefined {
|
||||
return timeoutMs === undefined ? undefined : Math.max(1, Math.ceil(timeoutMs / 1_000));
|
||||
}
|
||||
@@ -85,13 +99,77 @@ export function renderRuntimeConfig(
|
||||
paths: RuntimePaths,
|
||||
identity?: RuntimeIdentity,
|
||||
installation: RuntimeInstallationOverlay = {},
|
||||
semanticRuntime: SemanticRuntimeConfig = DEFAULT_SEMANTIC_RUNTIME,
|
||||
): string {
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
const contract = buildInstallationContract(descriptor);
|
||||
const name = (role: "DWH" | "VECTOR" | "EMBEDDING", suffix: string) => {
|
||||
const variable = contract.variables.find((entry) => entry.role === role && entry.suffix === suffix);
|
||||
if (!variable) throw new Error(`workspace contract is missing ${role}_${suffix}`);
|
||||
return variable.name;
|
||||
};
|
||||
if (descriptor.workspace.schema_version !== 2) {
|
||||
if (descriptor.workspace.schema_version === 1) {
|
||||
throw new Error("Workspace descriptor requires explicit migration to schema version 2");
|
||||
}
|
||||
throw new Error("Schema version 3 runtime rendering is unsupported until the internal semantic runtime is implemented");
|
||||
if (bindings.dwh.missing.length > 0) {
|
||||
throw new Error("runtime configuration requires complete bindings");
|
||||
}
|
||||
|
||||
const dwhRest = bindings.dwh.transport === "rest_api";
|
||||
const dwhIdentity = { database: descriptor.dwh.database, schema: descriptor.dwh.schema };
|
||||
const database = bindings.dwh.transport === "postgres_direct"
|
||||
? { ...legacyDirectConnection(bindings.dwh, {
|
||||
host: name("DWH", "HOST"),
|
||||
port: name("DWH", "PORT"),
|
||||
user: name("DWH", "USER"),
|
||||
passwordFile: name("DWH", "PASSWORD_FILE"),
|
||||
tlsCaFile: name("DWH", "TLS_CA_FILE"),
|
||||
}, dwhIdentity), transport: "direct" }
|
||||
: placeholderConnection(dwhIdentity);
|
||||
const renderedV3: Record<string, unknown> = {
|
||||
...(identity ? {
|
||||
runtime_identity: {
|
||||
workspace_id: identity.workspaceId,
|
||||
workspace_revision: identity.workspaceRevision,
|
||||
source_identity: `workspace://${identity.workspaceId}`,
|
||||
},
|
||||
} : {}),
|
||||
...(installation.session_storage === undefined
|
||||
? {} : { session_storage: installation.session_storage }),
|
||||
...(installation.profile === undefined ? {} : { profile: installation.profile }),
|
||||
language: descriptor.workspace.language,
|
||||
database,
|
||||
embeddings: {
|
||||
provider: "ollama_internal",
|
||||
base_url: semanticRuntime.internalEmbeddingUrl,
|
||||
model: semanticRuntime.internalEmbeddingModel,
|
||||
dimensions: semanticRuntime.internalEmbeddingDimensions,
|
||||
},
|
||||
resources: {
|
||||
vector: {
|
||||
engine: "qdrant",
|
||||
base_url: semanticRuntime.internalQdrantUrl,
|
||||
collection: descriptor.semantic_index.vector_store.collection,
|
||||
},
|
||||
},
|
||||
roots: paths,
|
||||
paths,
|
||||
};
|
||||
if (bindings.dwh.transport === "postgres_direct") {
|
||||
renderedV3.dwh = { type: "postgres_direct", connection: database };
|
||||
} else if (dwhRest) {
|
||||
renderedV3.rest = legacyRestEndpoint(bindings.dwh, {
|
||||
baseUrl: name("DWH", "BASE_URL"),
|
||||
apiKeyFile: name("DWH", "API_KEY_FILE"),
|
||||
tlsCaFile: name("DWH", "TLS_CA_FILE"),
|
||||
}, descriptor.diagnostics?.dwh_rest?.auth !== "none");
|
||||
renderedV3.database = placeholderConnection(dwhIdentity);
|
||||
renderedV3.dwh = { type: "thoth_rest", database: dwhIdentity, endpoint: renderedV3.rest };
|
||||
} else {
|
||||
throw new Error("ssh_tunnel runtime configuration requires a diagnostic tunnel");
|
||||
}
|
||||
return stringify(renderedV3, { lineWidth: 0, sortMapEntries: false });
|
||||
}
|
||||
|
||||
const canonical = descriptor as WorkspaceV2;
|
||||
@@ -99,12 +177,6 @@ export function renderRuntimeConfig(
|
||||
throw new Error("runtime configuration requires complete bindings");
|
||||
}
|
||||
|
||||
const contract = buildInstallationContract(canonical);
|
||||
const name = (role: "DWH" | "VECTOR" | "EMBEDDING", suffix: string) => {
|
||||
const variable = contract.variables.find((entry) => entry.role === role && entry.suffix === suffix);
|
||||
if (!variable) throw new Error(`workspace contract is missing ${role}_${suffix}`);
|
||||
return variable.name;
|
||||
};
|
||||
const dwhIdentity = { database: canonical.dwh.database, schema: canonical.dwh.schema };
|
||||
const vectorIdentity = {
|
||||
database: canonical.semantic_index.vector_store.database ?? canonical.dwh.database,
|
||||
|
||||
Reference in New Issue
Block a user