feat: render private semantic service endpoints

This commit is contained in:
2026-08-08 17:17:02 +02:00
parent f7b9f3276b
commit bc8afe0205
10 changed files with 372 additions and 19 deletions
+6
View File
@@ -58,6 +58,12 @@ export function buildApp(config: AppConfig, deps?: BuildAppDeps): FastifyInstanc
secretRoots: config.workspaceRegistry.secretRoots,
secretsFile: config.secretsFile,
secretFiles: config.secretFiles,
semanticRuntime: {
internalQdrantUrl: config.internalQdrantUrl,
internalEmbeddingUrl: config.internalEmbeddingUrl,
internalEmbeddingModel: config.internalEmbeddingModel,
internalEmbeddingDimensions: config.internalEmbeddingDimensions,
},
});
const mgr = deps?.mgr ?? new PiProcessManager(config, deps?.spawnFn ? { spawnFn: deps.spawnFn } : undefined);
const hub = deps?.hub ?? new SseHub();
+61
View File
@@ -30,6 +30,10 @@ export interface AppConfig {
legacyWorkspaceMode: boolean;
workspaceDiagnosticTimeoutMs: number;
workspaceRegistry: WorkspaceRegistryConfig;
internalQdrantUrl: string;
internalEmbeddingUrl: string;
internalEmbeddingModel: string;
internalEmbeddingDimensions: number;
}
export const MAX_WORKSPACE_DIAGNOSTIC_TIMEOUT_MS = 10_000;
@@ -101,6 +105,47 @@ function piManagementTimeout(value: string | undefined): number {
return timeout;
}
function loopbackHost(host: string): boolean {
return host === "::1"
|| host === "127.0.0.1"
|| /^127(?:\.\d{1,3}){3}$/.test(host);
}
function internalServiceUrl(
value: string | undefined,
fallback: string,
label: string,
allowedHosts: readonly string[],
): string {
const raw = value ?? fallback;
let parsed: URL;
try {
parsed = new URL(raw);
} catch {
throw new Error(`${label} configuration is invalid`);
}
if (
(parsed.protocol !== "http:" && parsed.protocol !== "https:")
|| parsed.username.length > 0
|| parsed.password.length > 0
|| parsed.pathname !== "/"
|| parsed.search.length > 0
|| parsed.hash.length > 0
|| (!allowedHosts.includes(parsed.hostname) && !loopbackHost(parsed.hostname))
) {
throw new Error(`${label} configuration is invalid`);
}
return parsed.toString().replace(/\/$/, "");
}
function positiveDimension(value: string | undefined, fallback: number): number {
const parsed = Number(value ?? fallback);
if (!Number.isSafeInteger(parsed) || parsed <= 0) {
throw new Error("internal embedding dimensions configuration is invalid");
}
return parsed;
}
export function loadConfig(env: Record<string, string | undefined>): AppConfig {
const authMode = env.AUTH_MODE ?? "none";
if (!(["none", "mock", "upstream"] as const).includes(authMode as AppConfig["authMode"])) {
@@ -208,6 +253,18 @@ export function loadConfig(env: Record<string, string | undefined>): AppConfig {
maxImportEntries: positiveImportLimit(env.THT_WORKSPACE_MAX_IMPORT_ENTRIES, 32),
};
const settingsFile = env.SETTINGS_FILE ?? "data/settings.json";
const internalQdrantUrl = internalServiceUrl(
env.THT_INTERNAL_QDRANT_URL,
"http://qdrant:6333",
"internal Qdrant URL",
["qdrant", "localhost"],
);
const internalEmbeddingUrl = internalServiceUrl(
env.THT_INTERNAL_EMBEDDING_URL,
"http://embedding:11434",
"internal embedding URL",
["embedding", "localhost"],
);
return {
host: env.HOST ?? "127.0.0.1",
port: Number(env.PORT ?? 8787),
@@ -231,5 +288,9 @@ export function loadConfig(env: Record<string, string | undefined>): AppConfig {
legacyWorkspaceMode: legacyWorkspaceMode === "local",
workspaceDiagnosticTimeoutMs: diagnosticTimeout(env.THT_WORKSPACE_DIAGNOSTIC_TIMEOUT_MS),
workspaceRegistry,
internalQdrantUrl,
internalEmbeddingUrl,
internalEmbeddingModel: env.THT_INTERNAL_EMBEDDING_MODEL ?? "qwen3-embedding:0.6b",
internalEmbeddingDimensions: positiveDimension(env.THT_INTERNAL_EMBEDDING_DIMENSIONS, 1024),
};
}
+8 -1
View File
@@ -9,7 +9,12 @@ import { parseAllDocuments } from "yaml";
import { clearPrincipalEnvironment, principalEnvironment, type PrincipalContext } from "../auth/principal.js";
import { secretValue, type SecretBundleConfig } from "../config/secret-bundle.js";
import { resolveRuntimeBindings } from "../workspaces/bindings.js";
import { renderRuntimeConfig, type RuntimeInstallationOverlay, type RuntimePaths } from "../workspaces/runtime-renderer.js";
import {
renderRuntimeConfig,
type RuntimeInstallationOverlay,
type RuntimePaths,
type SemanticRuntimeConfig,
} from "../workspaces/runtime-renderer.js";
import { parseWorkspaceYaml } from "../workspaces/schema.js";
export interface ThtConfig extends SecretBundleConfig {
@@ -19,6 +24,7 @@ export interface ThtConfig extends SecretBundleConfig {
dataRoot?: string;
runtimeSnapshotRoot?: string;
secretRoots?: readonly string[];
semanticRuntime: SemanticRuntimeConfig;
}
export interface RuntimeConfigLease {
@@ -190,6 +196,7 @@ export class ThtRunner {
this.runtimePaths(canonical.workspaceId),
canonical,
this.installationOverlay(),
this.cfg.semanticRuntime,
);
const path = this.createRuntimeSnapshot(config);
let released = false;
+1 -4
View File
@@ -97,7 +97,7 @@ export function resolveBinding(
): ResolvedBinding {
const descriptor = validateWorkspaceDescriptor(workspace);
if (descriptor.workspace.schema_version === 3 && role !== "DWH") {
throw new Error("Schema version 3 semantic bindings are not supported by the legacy installation contract");
return { transport: "rest_api", values: {}, missing: [] };
}
const contract = buildInstallationContract(descriptor);
@@ -143,9 +143,6 @@ export function resolveRuntimeBindings(
secretRoots: readonly string[],
): RuntimeBindings {
const descriptor = validateWorkspaceDescriptor(workspace);
if (descriptor.workspace.schema_version === 3) {
throw new Error("Schema version 3 semantic runtime bindings are not supported before the internal Qdrant/Ollama runtime lands");
}
return {
dwh: resolveBinding(descriptor, "DWH", env, secretRoots),
+79 -7
View File
@@ -20,6 +20,20 @@ export interface RuntimeInstallationOverlay {
profile?: unknown;
}
export interface SemanticRuntimeConfig {
internalQdrantUrl: string;
internalEmbeddingUrl: string;
internalEmbeddingModel: string;
internalEmbeddingDimensions: number;
}
const DEFAULT_SEMANTIC_RUNTIME: SemanticRuntimeConfig = {
internalQdrantUrl: "http://qdrant:6333",
internalEmbeddingUrl: "http://embedding:11434",
internalEmbeddingModel: "qwen3-embedding:0.6b",
internalEmbeddingDimensions: 1024,
};
function seconds(timeoutMs: number | undefined): number | undefined {
return timeoutMs === undefined ? undefined : Math.max(1, Math.ceil(timeoutMs / 1_000));
}
@@ -85,13 +99,77 @@ export function renderRuntimeConfig(
paths: RuntimePaths,
identity?: RuntimeIdentity,
installation: RuntimeInstallationOverlay = {},
semanticRuntime: SemanticRuntimeConfig = DEFAULT_SEMANTIC_RUNTIME,
): string {
const descriptor = validateWorkspaceDescriptor(workspace);
const contract = buildInstallationContract(descriptor);
const name = (role: "DWH" | "VECTOR" | "EMBEDDING", suffix: string) => {
const variable = contract.variables.find((entry) => entry.role === role && entry.suffix === suffix);
if (!variable) throw new Error(`workspace contract is missing ${role}_${suffix}`);
return variable.name;
};
if (descriptor.workspace.schema_version !== 2) {
if (descriptor.workspace.schema_version === 1) {
throw new Error("Workspace descriptor requires explicit migration to schema version 2");
}
throw new Error("Schema version 3 runtime rendering is unsupported until the internal semantic runtime is implemented");
if (bindings.dwh.missing.length > 0) {
throw new Error("runtime configuration requires complete bindings");
}
const dwhRest = bindings.dwh.transport === "rest_api";
const dwhIdentity = { database: descriptor.dwh.database, schema: descriptor.dwh.schema };
const database = bindings.dwh.transport === "postgres_direct"
? { ...legacyDirectConnection(bindings.dwh, {
host: name("DWH", "HOST"),
port: name("DWH", "PORT"),
user: name("DWH", "USER"),
passwordFile: name("DWH", "PASSWORD_FILE"),
tlsCaFile: name("DWH", "TLS_CA_FILE"),
}, dwhIdentity), transport: "direct" }
: placeholderConnection(dwhIdentity);
const renderedV3: Record<string, unknown> = {
...(identity ? {
runtime_identity: {
workspace_id: identity.workspaceId,
workspace_revision: identity.workspaceRevision,
source_identity: `workspace://${identity.workspaceId}`,
},
} : {}),
...(installation.session_storage === undefined
? {} : { session_storage: installation.session_storage }),
...(installation.profile === undefined ? {} : { profile: installation.profile }),
language: descriptor.workspace.language,
database,
embeddings: {
provider: "ollama_internal",
base_url: semanticRuntime.internalEmbeddingUrl,
model: semanticRuntime.internalEmbeddingModel,
dimensions: semanticRuntime.internalEmbeddingDimensions,
},
resources: {
vector: {
engine: "qdrant",
base_url: semanticRuntime.internalQdrantUrl,
collection: descriptor.semantic_index.vector_store.collection,
},
},
roots: paths,
paths,
};
if (bindings.dwh.transport === "postgres_direct") {
renderedV3.dwh = { type: "postgres_direct", connection: database };
} else if (dwhRest) {
renderedV3.rest = legacyRestEndpoint(bindings.dwh, {
baseUrl: name("DWH", "BASE_URL"),
apiKeyFile: name("DWH", "API_KEY_FILE"),
tlsCaFile: name("DWH", "TLS_CA_FILE"),
}, descriptor.diagnostics?.dwh_rest?.auth !== "none");
renderedV3.database = placeholderConnection(dwhIdentity);
renderedV3.dwh = { type: "thoth_rest", database: dwhIdentity, endpoint: renderedV3.rest };
} else {
throw new Error("ssh_tunnel runtime configuration requires a diagnostic tunnel");
}
return stringify(renderedV3, { lineWidth: 0, sortMapEntries: false });
}
const canonical = descriptor as WorkspaceV2;
@@ -99,12 +177,6 @@ export function renderRuntimeConfig(
throw new Error("runtime configuration requires complete bindings");
}
const contract = buildInstallationContract(canonical);
const name = (role: "DWH" | "VECTOR" | "EMBEDDING", suffix: string) => {
const variable = contract.variables.find((entry) => entry.role === role && entry.suffix === suffix);
if (!variable) throw new Error(`workspace contract is missing ${role}_${suffix}`);
return variable.name;
};
const dwhIdentity = { database: canonical.dwh.database, schema: canonical.dwh.schema };
const vectorIdentity = {
database: canonical.semantic_index.vector_store.database ?? canonical.dwh.database,