refactor: remove legacy workspace runtime branches
This commit is contained in:
@@ -1,15 +1,12 @@
|
||||
import { constants, realpathSync, statSync, accessSync } from "node:fs";
|
||||
import { isAbsolute, relative } from "node:path";
|
||||
import { buildInstallationContract, type InstallationRole, type InstallationSuffix } from "./contracts.js";
|
||||
import { buildInstallationContract, type InstallationSuffix } from "./contracts.js";
|
||||
import {
|
||||
DWH_TRANSPORTS,
|
||||
VECTOR_TRANSPORTS,
|
||||
validateWorkspaceDescriptor,
|
||||
type DwhTransport,
|
||||
type VectorTransport,
|
||||
type WorkspaceDescriptor,
|
||||
} from "./schema.js";
|
||||
import type { DeprecatedV2Descriptor } from "./deprecated-v2-descriptor.js";
|
||||
|
||||
export interface ResolvedEvidenceBinding {
|
||||
values: Record<string, string>;
|
||||
@@ -18,42 +15,26 @@ export interface ResolvedEvidenceBinding {
|
||||
|
||||
export interface RuntimeBindings {
|
||||
dwh: ResolvedBinding;
|
||||
vector: ResolvedBinding;
|
||||
vectorWriter: ResolvedBinding;
|
||||
embedding: ResolvedBinding;
|
||||
evidence: ResolvedEvidenceBinding;
|
||||
}
|
||||
|
||||
export interface ResolvedBinding {
|
||||
transport: DwhTransport | VectorTransport;
|
||||
transport: DwhTransport;
|
||||
values: Record<string, string>;
|
||||
missing: string[];
|
||||
}
|
||||
|
||||
const REQUIRED_SUFFIXES: Record<"DWH" | "VECTOR", Record<string, readonly InstallationSuffix[]>> = {
|
||||
DWH: {
|
||||
postgres_direct: ["HOST", "PORT", "USER", "PASSWORD_FILE"],
|
||||
rest_api: ["BASE_URL", "API_KEY_FILE"],
|
||||
ssh_tunnel: [
|
||||
"USER", "PASSWORD_FILE", "SSH_HOST", "SSH_PORT", "SSH_USER",
|
||||
"SSH_PRIVATE_KEY_FILE", "SSH_KNOWN_HOSTS_FILE", "SSH_TARGET_HOST", "SSH_TARGET_PORT",
|
||||
],
|
||||
},
|
||||
VECTOR: {
|
||||
pgvector_direct: ["HOST", "PORT", "USER", "PASSWORD_FILE"],
|
||||
rest_api: ["BASE_URL", "API_KEY_FILE"],
|
||||
ssh_tunnel: [
|
||||
"USER", "PASSWORD_FILE", "SSH_HOST", "SSH_PORT", "SSH_USER",
|
||||
"SSH_PRIVATE_KEY_FILE", "SSH_KNOWN_HOSTS_FILE", "SSH_TARGET_HOST", "SSH_TARGET_PORT",
|
||||
],
|
||||
},
|
||||
const REQUIRED_SUFFIXES: Record<DwhTransport, readonly InstallationSuffix[]> = {
|
||||
postgres_direct: ["HOST", "PORT", "USER", "PASSWORD_FILE"],
|
||||
rest_api: ["BASE_URL", "API_KEY_FILE"],
|
||||
ssh_tunnel: [
|
||||
"USER", "PASSWORD_FILE", "SSH_HOST", "SSH_PORT", "SSH_USER",
|
||||
"SSH_PRIVATE_KEY_FILE", "SSH_KNOWN_HOSTS_FILE", "SSH_TARGET_HOST", "SSH_TARGET_PORT",
|
||||
],
|
||||
};
|
||||
|
||||
const EMBEDDING_REQUIRED_SUFFIXES: readonly InstallationSuffix[] = ["BASE_URL"];
|
||||
|
||||
function isTransport(value: string | undefined): value is DwhTransport | VectorTransport {
|
||||
return value !== undefined
|
||||
&& ([...DWH_TRANSPORTS, ...VECTOR_TRANSPORTS] as readonly string[]).includes(value);
|
||||
function isTransport(value: string | undefined): value is DwhTransport {
|
||||
return value !== undefined && (DWH_TRANSPORTS as readonly string[]).includes(value);
|
||||
}
|
||||
|
||||
function isInside(path: string, root: string): boolean {
|
||||
@@ -76,18 +57,23 @@ function safeSecretFilePath(path: string, secretRoots: readonly string[]): strin
|
||||
}
|
||||
}
|
||||
|
||||
function requireSupportedDescriptor(workspace: unknown): void {
|
||||
if (typeof workspace !== "object" || workspace === null) {
|
||||
throw new Error("Workspace bindings support only workspace schema version 3");
|
||||
}
|
||||
const metadata = Reflect.get(workspace, "workspace");
|
||||
if (typeof metadata !== "object" || metadata === null
|
||||
|| Reflect.get(metadata, "schema_version") !== 3) {
|
||||
throw new Error("Workspace bindings support only workspace schema version 3");
|
||||
}
|
||||
}
|
||||
|
||||
function requiredSuffixes(
|
||||
workspace: WorkspaceDescriptor,
|
||||
role: Exclude<InstallationRole, "EVIDENCE">,
|
||||
transport: DwhTransport | VectorTransport,
|
||||
transport: DwhTransport,
|
||||
): readonly InstallationSuffix[] {
|
||||
if (role === "EMBEDDING") return EMBEDDING_REQUIRED_SUFFIXES;
|
||||
if (role === "VECTOR_WRITER") return ["API_KEY_FILE"];
|
||||
const required = REQUIRED_SUFFIXES[role][transport] ?? [];
|
||||
const diagnostic = role === "DWH"
|
||||
? workspace.diagnostics?.dwh_rest
|
||||
: (workspace as unknown as DeprecatedV2Descriptor).diagnostics?.vector_rest?.metadata;
|
||||
return transport === "rest_api" && diagnostic?.auth === "none"
|
||||
const required = REQUIRED_SUFFIXES[transport];
|
||||
return transport === "rest_api" && workspace.diagnostics?.dwh_rest?.auth === "none"
|
||||
? required.filter((suffix) => suffix !== "API_KEY_FILE")
|
||||
: required;
|
||||
}
|
||||
@@ -98,37 +84,29 @@ function requiredSuffixes(
|
||||
*/
|
||||
export function resolveBinding(
|
||||
workspace: WorkspaceDescriptor,
|
||||
role: Exclude<InstallationRole, "EVIDENCE">,
|
||||
role: "DWH",
|
||||
env: NodeJS.ProcessEnv,
|
||||
secretRoots: readonly string[],
|
||||
): ResolvedBinding {
|
||||
requireSupportedDescriptor(workspace);
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
if (descriptor.workspace.schema_version === 3 && role !== "DWH") {
|
||||
return { transport: "rest_api", values: {}, missing: [] };
|
||||
}
|
||||
|
||||
const contract = buildInstallationContract(descriptor);
|
||||
const legacy = descriptor as unknown as DeprecatedV2Descriptor;
|
||||
const variables = contract.variables.filter((variable) => variable.role === role);
|
||||
const transportVariable = variables.find((variable) => variable.suffix === "TRANSPORT");
|
||||
const supported = role === "DWH"
|
||||
? descriptor.dwh.supported_transports
|
||||
: role === "VECTOR"
|
||||
? legacy.semantic_index.vector_store.supported_transports
|
||||
: ["rest_api"] as const;
|
||||
const supported = descriptor.dwh.supported_transports;
|
||||
const selectedValue = transportVariable ? env[transportVariable.name] : undefined;
|
||||
const selectedTransport = isTransport(selectedValue) ? selectedValue : supported[0];
|
||||
const missing: string[] = [];
|
||||
|
||||
if (transportVariable && (!isTransport(selectedValue) || !supported.includes(selectedTransport as never))) {
|
||||
if (transportVariable && (!isTransport(selectedValue) || !supported.includes(selectedTransport))) {
|
||||
missing.push(transportVariable.name);
|
||||
}
|
||||
|
||||
const required = new Set(requiredSuffixes(descriptor, role, selectedTransport));
|
||||
const required = new Set(requiredSuffixes(descriptor, selectedTransport));
|
||||
const values: Record<string, string> = {};
|
||||
for (const variable of variables) {
|
||||
if (variable.suffix === "TRANSPORT") continue;
|
||||
if (variable.transports && !variable.transports.includes(selectedTransport as never)) continue;
|
||||
if (variable.transports && !variable.transports.includes(selectedTransport)) continue;
|
||||
|
||||
const value = env[variable.name];
|
||||
const present = value !== undefined && value.trim() !== "";
|
||||
@@ -149,12 +127,13 @@ export function resolveEvidenceBinding(
|
||||
env: NodeJS.ProcessEnv,
|
||||
secretRoots: readonly string[],
|
||||
): ResolvedEvidenceBinding {
|
||||
requireSupportedDescriptor(workspace);
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
const variables = buildInstallationContract(descriptor).variables
|
||||
.filter((variable) => variable.role === "EVIDENCE");
|
||||
if (variables.length === 0) return { values: {}, missing: [] };
|
||||
|
||||
const source = "evidence" in descriptor ? descriptor.evidence?.source : undefined;
|
||||
const source = descriptor.evidence?.source;
|
||||
const required = new Set<InstallationSuffix>(
|
||||
source?.type === "http"
|
||||
? ["SIGNED_URLS_FILE"]
|
||||
@@ -176,29 +155,22 @@ export function resolveEvidenceBinding(
|
||||
return { values, missing };
|
||||
}
|
||||
|
||||
/** Resolve all runtime roles together so optional writer credentials cannot be smuggled into reader bindings. */
|
||||
/** Resolve the complete schema-v3 runtime binding set. */
|
||||
export function resolveRuntimeBindings(
|
||||
workspace: WorkspaceDescriptor,
|
||||
env: NodeJS.ProcessEnv,
|
||||
secretRoots: readonly string[],
|
||||
): RuntimeBindings {
|
||||
requireSupportedDescriptor(workspace);
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
|
||||
return {
|
||||
dwh: resolveBinding(descriptor, "DWH", env, secretRoots),
|
||||
vector: resolveBinding(descriptor, "VECTOR", env, secretRoots),
|
||||
vectorWriter: resolveBinding(descriptor, "VECTOR_WRITER", env, secretRoots),
|
||||
embedding: resolveBinding(descriptor, "EMBEDDING", env, secretRoots),
|
||||
evidence: resolveEvidenceBinding(descriptor, env, secretRoots),
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* SSH bindings are currently probe-only: diagnostics owns a short-lived tunnel, while the
|
||||
* session runtime has no tunnel owner. Keep activation fail-closed until that lifecycle exists.
|
||||
*/
|
||||
/** SSH bindings remain diagnostic-only until the session runtime owns a long-lived tunnel. */
|
||||
export function supportsSessionRuntime(bindings: RuntimeBindings): boolean {
|
||||
return bindings.dwh.transport !== "ssh_tunnel"
|
||||
&& bindings.vector.transport !== "ssh_tunnel"
|
||||
&& bindings.evidence.missing.length === 0;
|
||||
return bindings.dwh.transport !== "ssh_tunnel" && bindings.evidence.missing.length === 0;
|
||||
}
|
||||
|
||||
@@ -1,8 +1,7 @@
|
||||
import { validateWorkspaceDescriptor } from "./schema.js";
|
||||
import type { DwhTransport, VectorTransport, WorkspaceDescriptor } from "./schema.js";
|
||||
import type { DeprecatedV2Descriptor } from "./deprecated-v2-descriptor.js";
|
||||
import type { DwhTransport, WorkspaceDescriptor } from "./schema.js";
|
||||
|
||||
export type InstallationRole = "DWH" | "VECTOR" | "VECTOR_WRITER" | "EMBEDDING" | "EVIDENCE";
|
||||
export type InstallationRole = "DWH" | "EVIDENCE";
|
||||
export type InstallationSuffix =
|
||||
| "TRANSPORT"
|
||||
| "HOST"
|
||||
@@ -24,7 +23,7 @@ export type InstallationSuffix =
|
||||
| "SECRET_KEY_FILE"
|
||||
| "SESSION_TOKEN_FILE";
|
||||
|
||||
type ConnectorTransport = DwhTransport | VectorTransport;
|
||||
type ConnectorTransport = DwhTransport;
|
||||
|
||||
export interface InstallationVariable {
|
||||
name: string;
|
||||
@@ -67,12 +66,6 @@ const SSH_SUFFIXES: readonly InstallationSuffix[] = [
|
||||
"SSH_TARGET_PORT",
|
||||
];
|
||||
|
||||
const EMBEDDING_SUFFIXES: readonly InstallationSuffix[] = [
|
||||
"BASE_URL",
|
||||
"API_KEY_FILE",
|
||||
"TLS_CA_FILE",
|
||||
];
|
||||
|
||||
function namespaceFor(workspace: WorkspaceDescriptor): string {
|
||||
return workspace.workspace.id.replaceAll("-", "_").toUpperCase();
|
||||
}
|
||||
@@ -94,11 +87,10 @@ function createVariable(
|
||||
|
||||
function connectorVariables(
|
||||
namespace: string,
|
||||
role: "DWH" | "VECTOR",
|
||||
transports: readonly ConnectorTransport[],
|
||||
transports: readonly DwhTransport[],
|
||||
): InstallationVariable[] {
|
||||
const suffixTransports = new Map<InstallationSuffix, ConnectorTransport[]>();
|
||||
const add = (suffixes: readonly InstallationSuffix[], transport: ConnectorTransport) => {
|
||||
const suffixTransports = new Map<InstallationSuffix, DwhTransport[]>();
|
||||
const add = (suffixes: readonly InstallationSuffix[], transport: DwhTransport) => {
|
||||
for (const suffix of suffixes) {
|
||||
const applicable = suffixTransports.get(suffix) ?? [];
|
||||
applicable.push(transport);
|
||||
@@ -107,7 +99,7 @@ function connectorVariables(
|
||||
};
|
||||
|
||||
for (const transport of transports) {
|
||||
if (transport === "postgres_direct" || transport === "pgvector_direct") {
|
||||
if (transport === "postgres_direct") {
|
||||
add(DIRECT_SUFFIXES, transport);
|
||||
} else if (transport === "rest_api") {
|
||||
add(REST_SUFFIXES, transport);
|
||||
@@ -117,9 +109,9 @@ function connectorVariables(
|
||||
}
|
||||
|
||||
return [
|
||||
createVariable(namespace, role, "TRANSPORT", transports),
|
||||
createVariable(namespace, "DWH", "TRANSPORT", transports),
|
||||
...[...suffixTransports.entries()].map(([suffix, applicable]) => (
|
||||
createVariable(namespace, role, suffix, applicable)
|
||||
createVariable(namespace, "DWH", suffix, applicable)
|
||||
)),
|
||||
];
|
||||
}
|
||||
@@ -143,30 +135,27 @@ function evidenceVariables(
|
||||
return [];
|
||||
}
|
||||
|
||||
function requireSupportedDescriptor(workspace: unknown): void {
|
||||
if (typeof workspace !== "object" || workspace === null) {
|
||||
throw new Error("Installation contract supports only workspace schema version 3");
|
||||
}
|
||||
const metadata = Reflect.get(workspace, "workspace");
|
||||
if (typeof metadata !== "object" || metadata === null
|
||||
|| Reflect.get(metadata, "schema_version") !== 3) {
|
||||
throw new Error("Installation contract supports only workspace schema version 3");
|
||||
}
|
||||
}
|
||||
|
||||
export function buildInstallationContract(workspace: WorkspaceDescriptor): InstallationContract {
|
||||
requireSupportedDescriptor(workspace);
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
const namespace = namespaceFor(descriptor);
|
||||
const schemaVersion = Number(descriptor.workspace.schema_version);
|
||||
const legacy = descriptor as unknown as DeprecatedV2Descriptor;
|
||||
|
||||
return {
|
||||
workspaceId: descriptor.workspace.id,
|
||||
namespace,
|
||||
variables: [
|
||||
...connectorVariables(namespace, "DWH", descriptor.dwh.supported_transports),
|
||||
...(schemaVersion === 2
|
||||
? connectorVariables(
|
||||
namespace,
|
||||
"VECTOR",
|
||||
legacy.semantic_index.vector_store.supported_transports,
|
||||
)
|
||||
: []),
|
||||
...(schemaVersion === 2 && legacy.semantic_index.vector_writer
|
||||
? [createVariable(namespace, "VECTOR_WRITER", "API_KEY_FILE")]
|
||||
: []),
|
||||
...(schemaVersion === 2
|
||||
? EMBEDDING_SUFFIXES.map((suffix) => createVariable(namespace, "EMBEDDING", suffix))
|
||||
: []),
|
||||
...connectorVariables(namespace, descriptor.dwh.supported_transports),
|
||||
...evidenceVariables(namespace, descriptor),
|
||||
],
|
||||
};
|
||||
@@ -276,10 +265,10 @@ export function renderWorkspaceDocs(workspace: WorkspaceDescriptor): { envExampl
|
||||
"",
|
||||
"Use the following UI fields as installation bindings. Secret fields always contain file paths, never secret values.",
|
||||
"",
|
||||
...(["DWH", "VECTOR", "VECTOR_WRITER", "EMBEDDING", "EVIDENCE"] as const)
|
||||
...(["DWH", "EVIDENCE"] as const)
|
||||
.filter((role) => variablesByRole.has(role))
|
||||
.flatMap((role) => [
|
||||
`## ${role === "DWH" ? "Data warehouse" : role === "VECTOR" ? "Vector store" : role === "VECTOR_WRITER" ? "Vector writer" : role === "EMBEDDING" ? "Embedding service" : "Evidence"}`,
|
||||
`## ${role === "DWH" ? "Data warehouse" : "Evidence"}`,
|
||||
"",
|
||||
...(variablesByRole.get(role) ?? []).map((variable) => (
|
||||
`- \`${variable.name}\`${variable.transports ? ` (for: ${variable.transports.join(", ")})` : ""}`
|
||||
|
||||
@@ -1,52 +0,0 @@
|
||||
import type {
|
||||
CanonicalDiagnostics,
|
||||
DwhTransport,
|
||||
VectorTransport,
|
||||
} from "./schema.js";
|
||||
|
||||
/**
|
||||
* Temporary compile-time shape for legacy runtime branches that will be removed separately.
|
||||
* It is deliberately not part of the accepted workspace descriptor schema.
|
||||
*/
|
||||
export interface DeprecatedV2Descriptor {
|
||||
workspace: {
|
||||
schema_version: 2;
|
||||
id: string;
|
||||
name: string;
|
||||
description?: string;
|
||||
language: "en" | "it";
|
||||
};
|
||||
dwh: {
|
||||
engine: "postgres";
|
||||
database: string;
|
||||
schema: string;
|
||||
port?: number;
|
||||
timeout_ms?: number;
|
||||
supported_transports: DwhTransport[];
|
||||
};
|
||||
semantic_index: {
|
||||
vector_store: {
|
||||
engine: "pgvector";
|
||||
database: string;
|
||||
schema: string;
|
||||
collection: string;
|
||||
dimensions: number;
|
||||
distance: "cosine" | "l2" | "inner_product";
|
||||
port?: number;
|
||||
timeout_ms?: number;
|
||||
supported_transports: VectorTransport[];
|
||||
};
|
||||
vector_writer?: Record<string, never>;
|
||||
embedding: {
|
||||
provider: "ollama_compatible" | "openai_compatible";
|
||||
model: string;
|
||||
dimensions: number;
|
||||
timeout_ms?: number;
|
||||
};
|
||||
};
|
||||
llm_policy: {
|
||||
default?: `${string}/${string}`;
|
||||
allowed: `${string}/${string}`[];
|
||||
};
|
||||
diagnostics?: CanonicalDiagnostics;
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -1,8 +1,37 @@
|
||||
import { validateOperationalWorkspace, type WorkspaceV3 } from "./schema.js";
|
||||
import type { DeprecatedV2Descriptor } from "./deprecated-v2-descriptor.js";
|
||||
import {
|
||||
validateOperationalWorkspace,
|
||||
type CanonicalDiagnostics,
|
||||
type DwhTransport,
|
||||
type WorkspaceV3,
|
||||
} from "./schema.js";
|
||||
|
||||
/** Legacy input exists only at the migration boundary and is never an accepted runtime descriptor. */
|
||||
interface WorkspaceV2MigrationInput {
|
||||
workspace: {
|
||||
schema_version: 2;
|
||||
id: string;
|
||||
name: string;
|
||||
description?: string;
|
||||
language: "en" | "it";
|
||||
};
|
||||
dwh: {
|
||||
engine: "postgres";
|
||||
database: string;
|
||||
schema: string;
|
||||
port?: number;
|
||||
timeout_ms?: number;
|
||||
supported_transports: DwhTransport[];
|
||||
};
|
||||
semantic_index: unknown;
|
||||
llm_policy: {
|
||||
default?: `${string}/${string}`;
|
||||
allowed: `${string}/${string}`[];
|
||||
};
|
||||
diagnostics?: CanonicalDiagnostics;
|
||||
}
|
||||
|
||||
export function migrateWorkspaceV2ToV3(
|
||||
legacy: DeprecatedV2Descriptor,
|
||||
legacy: WorkspaceV2MigrationInput,
|
||||
collection: string,
|
||||
): WorkspaceV3 {
|
||||
return validateOperationalWorkspace({
|
||||
|
||||
@@ -1,12 +1,7 @@
|
||||
import { basename, join } from "node:path";
|
||||
import { stringify } from "yaml";
|
||||
import { buildInstallationContract } from "./contracts.js";
|
||||
import {
|
||||
validateWorkspaceDescriptor,
|
||||
type WorkspaceDescriptor,
|
||||
type WorkspaceV3,
|
||||
} from "./schema.js";
|
||||
import type { DeprecatedV2Descriptor } from "./deprecated-v2-descriptor.js";
|
||||
import { validateWorkspaceDescriptor, type WorkspaceDescriptor } from "./schema.js";
|
||||
import type { ResolvedBinding, ResolvedEvidenceBinding, RuntimeBindings } from "./bindings.js";
|
||||
export type { RuntimeBindings } from "./bindings.js";
|
||||
|
||||
@@ -45,10 +40,6 @@ const DEFAULT_SEMANTIC_RUNTIME: SemanticRuntimeConfig = {
|
||||
internalEmbeddingDimensions: 1024,
|
||||
};
|
||||
|
||||
function seconds(timeoutMs: number | undefined): number | undefined {
|
||||
return timeoutMs === undefined ? undefined : Math.max(1, Math.ceil(timeoutMs / 1_000));
|
||||
}
|
||||
|
||||
function bindingValue(binding: ResolvedBinding, name: string): string | undefined {
|
||||
return binding.values[name];
|
||||
}
|
||||
@@ -59,7 +50,7 @@ function requireBinding(binding: ResolvedBinding, name: string): string {
|
||||
return value;
|
||||
}
|
||||
|
||||
function legacyDirectConnection(
|
||||
function directConnection(
|
||||
binding: ResolvedBinding,
|
||||
names: { host: string; port: string; user: string; passwordFile: string; tlsCaFile: string },
|
||||
identity: { database: string; schema: string },
|
||||
@@ -77,7 +68,7 @@ function legacyDirectConnection(
|
||||
return connection;
|
||||
}
|
||||
|
||||
function legacyRestEndpoint(
|
||||
function restEndpoint(
|
||||
binding: ResolvedBinding,
|
||||
names: { baseUrl: string; apiKeyFile: string; tlsCaFile: string },
|
||||
requiresCredential: boolean,
|
||||
@@ -115,7 +106,7 @@ function requireEvidenceBinding(binding: ResolvedEvidenceBinding, name: string):
|
||||
}
|
||||
|
||||
function renderEvidence(
|
||||
workspace: WorkspaceV3,
|
||||
workspace: WorkspaceDescriptor,
|
||||
binding: ResolvedEvidenceBinding,
|
||||
context: RuntimeRenderContext,
|
||||
bindingName: (suffix: string) => string,
|
||||
@@ -188,6 +179,7 @@ function renderEvidence(
|
||||
};
|
||||
}
|
||||
|
||||
|
||||
function placeholderConnection(identity: { database: string; schema: string }): Record<string, unknown> {
|
||||
return {
|
||||
host: "localhost",
|
||||
@@ -200,7 +192,18 @@ function placeholderConnection(identity: { database: string; schema: string }):
|
||||
};
|
||||
}
|
||||
|
||||
/** Render the compatibility fields consumed by the current Python harness. */
|
||||
function requireSupportedDescriptor(workspace: unknown): void {
|
||||
if (typeof workspace !== "object" || workspace === null) {
|
||||
throw new Error("Runtime renderer supports only workspace schema version 3");
|
||||
}
|
||||
const metadata = Reflect.get(workspace, "workspace");
|
||||
if (typeof metadata !== "object" || metadata === null
|
||||
|| Reflect.get(metadata, "schema_version") !== 3) {
|
||||
throw new Error("Runtime renderer supports only workspace schema version 3");
|
||||
}
|
||||
}
|
||||
|
||||
/** Render the schema-v3 compatibility fields consumed by the current Python harness. */
|
||||
export function renderRuntimeConfig(
|
||||
workspace: WorkspaceDescriptor,
|
||||
bindings: RuntimeBindings,
|
||||
@@ -209,119 +212,36 @@ export function renderRuntimeConfig(
|
||||
installation: RuntimeInstallationOverlay = {},
|
||||
semanticRuntime: SemanticRuntimeConfig = DEFAULT_SEMANTIC_RUNTIME,
|
||||
): string {
|
||||
requireSupportedDescriptor(workspace);
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
const contract = buildInstallationContract(descriptor);
|
||||
const name = (role: "DWH" | "VECTOR" | "EMBEDDING" | "EVIDENCE", suffix: string) => {
|
||||
const name = (role: "DWH" | "EVIDENCE", suffix: string) => {
|
||||
const variable = contract.variables.find((entry) => entry.role === role && entry.suffix === suffix);
|
||||
if (!variable) throw new Error(`workspace contract is missing ${role}_${suffix}`);
|
||||
return variable.name;
|
||||
};
|
||||
if (Number(descriptor.workspace.schema_version) !== 2) {
|
||||
if (Number(descriptor.workspace.schema_version) === 1) {
|
||||
throw new Error("Workspace descriptor requires explicit migration to schema version 2");
|
||||
}
|
||||
const canonicalV3 = descriptor as WorkspaceV3;
|
||||
const renderedEvidence = canonicalV3.evidence === undefined
|
||||
? undefined
|
||||
: renderEvidence(
|
||||
canonicalV3,
|
||||
bindings.evidence,
|
||||
requireRuntimeRenderContext(identity),
|
||||
(suffix) => name("EVIDENCE", suffix),
|
||||
);
|
||||
if (bindings.dwh.missing.length > 0) {
|
||||
throw new Error("runtime configuration requires complete bindings");
|
||||
}
|
||||
|
||||
const dwhRest = bindings.dwh.transport === "rest_api";
|
||||
const dwhIdentity = { database: descriptor.dwh.database, schema: descriptor.dwh.schema };
|
||||
const database = bindings.dwh.transport === "postgres_direct"
|
||||
? { ...legacyDirectConnection(bindings.dwh, {
|
||||
host: name("DWH", "HOST"),
|
||||
port: name("DWH", "PORT"),
|
||||
user: name("DWH", "USER"),
|
||||
passwordFile: name("DWH", "PASSWORD_FILE"),
|
||||
tlsCaFile: name("DWH", "TLS_CA_FILE"),
|
||||
}, dwhIdentity), transport: "direct" }
|
||||
: placeholderConnection(dwhIdentity);
|
||||
const renderedV3: Record<string, unknown> = {
|
||||
...(identity ? {
|
||||
runtime_identity: {
|
||||
workspace_id: identity.workspaceId,
|
||||
workspace_revision: identity.workspaceRevision,
|
||||
source_identity: `workspace://${identity.workspaceId}`,
|
||||
},
|
||||
} : {}),
|
||||
...(installation.session_storage === undefined
|
||||
? {} : { session_storage: installation.session_storage }),
|
||||
...(installation.profile === undefined ? {} : { profile: installation.profile }),
|
||||
language: descriptor.workspace.language,
|
||||
database,
|
||||
resources: {
|
||||
vector: {
|
||||
engine: "qdrant",
|
||||
base_url: semanticRuntime.internalQdrantUrl,
|
||||
collection: descriptor.semantic_index.vector_store.collection,
|
||||
},
|
||||
embeddings: {
|
||||
provider: "ollama_internal",
|
||||
base_url: semanticRuntime.internalEmbeddingUrl,
|
||||
model: semanticRuntime.internalEmbeddingModel,
|
||||
dimensions: semanticRuntime.internalEmbeddingDimensions,
|
||||
},
|
||||
},
|
||||
roots: paths,
|
||||
paths,
|
||||
...(renderedEvidence ?? {}),
|
||||
};
|
||||
if (bindings.dwh.transport === "postgres_direct") {
|
||||
renderedV3.dwh = { type: "postgres_direct", connection: database };
|
||||
} else if (dwhRest) {
|
||||
renderedV3.rest = legacyRestEndpoint(bindings.dwh, {
|
||||
baseUrl: name("DWH", "BASE_URL"),
|
||||
apiKeyFile: name("DWH", "API_KEY_FILE"),
|
||||
tlsCaFile: name("DWH", "TLS_CA_FILE"),
|
||||
}, descriptor.diagnostics?.dwh_rest?.auth !== "none");
|
||||
renderedV3.database = placeholderConnection(dwhIdentity);
|
||||
renderedV3.dwh = { type: "thoth_rest", database: dwhIdentity, endpoint: renderedV3.rest };
|
||||
} else {
|
||||
throw new Error("ssh_tunnel runtime configuration requires a diagnostic tunnel");
|
||||
}
|
||||
return stringify(renderedV3, { lineWidth: 0, sortMapEntries: false });
|
||||
}
|
||||
|
||||
const canonical = descriptor as unknown as DeprecatedV2Descriptor;
|
||||
if ([...bindings.dwh.missing, ...bindings.vector.missing, ...bindings.embedding.missing].length > 0) {
|
||||
const renderedEvidence = descriptor.evidence === undefined
|
||||
? undefined
|
||||
: renderEvidence(
|
||||
descriptor,
|
||||
bindings.evidence,
|
||||
requireRuntimeRenderContext(identity),
|
||||
(suffix) => name("EVIDENCE", suffix),
|
||||
);
|
||||
if (bindings.dwh.missing.length > 0) {
|
||||
throw new Error("runtime configuration requires complete bindings");
|
||||
}
|
||||
|
||||
const dwhIdentity = { database: canonical.dwh.database, schema: canonical.dwh.schema };
|
||||
const vectorIdentity = {
|
||||
database: canonical.semantic_index.vector_store.database ?? canonical.dwh.database,
|
||||
schema: canonical.semantic_index.vector_store.schema ?? canonical.dwh.schema,
|
||||
};
|
||||
const dwhDirect = bindings.dwh.transport === "postgres_direct";
|
||||
const vectorDirect = bindings.vector.transport === "pgvector_direct";
|
||||
const database = dwhDirect
|
||||
? { ...legacyDirectConnection(bindings.dwh, {
|
||||
host: name("DWH", "HOST"), port: name("DWH", "PORT"), user: name("DWH", "USER"),
|
||||
passwordFile: name("DWH", "PASSWORD_FILE"), tlsCaFile: name("DWH", "TLS_CA_FILE"),
|
||||
const dwhIdentity = { database: descriptor.dwh.database, schema: descriptor.dwh.schema };
|
||||
const database = bindings.dwh.transport === "postgres_direct"
|
||||
? { ...directConnection(bindings.dwh, {
|
||||
host: name("DWH", "HOST"),
|
||||
port: name("DWH", "PORT"),
|
||||
user: name("DWH", "USER"),
|
||||
passwordFile: name("DWH", "PASSWORD_FILE"),
|
||||
tlsCaFile: name("DWH", "TLS_CA_FILE"),
|
||||
}, dwhIdentity), transport: "direct" }
|
||||
: placeholderConnection(dwhIdentity);
|
||||
const vectorDb = vectorDirect
|
||||
? legacyDirectConnection(bindings.vector, {
|
||||
host: name("VECTOR", "HOST"), port: name("VECTOR", "PORT"), user: name("VECTOR", "USER"),
|
||||
passwordFile: name("VECTOR", "PASSWORD_FILE"), tlsCaFile: name("VECTOR", "TLS_CA_FILE"),
|
||||
}, vectorIdentity)
|
||||
: placeholderConnection(vectorIdentity);
|
||||
const embedding: Record<string, unknown> = {
|
||||
base_url: requireBinding(bindings.embedding, name("EMBEDDING", "BASE_URL")),
|
||||
model: canonical.semantic_index.embedding.model,
|
||||
dim: canonical.semantic_index.embedding.dimensions,
|
||||
};
|
||||
const embeddingTimeout = seconds(canonical.semantic_index.embedding.timeout_ms);
|
||||
if (embeddingTimeout !== undefined) embedding.timeout = embeddingTimeout;
|
||||
|
||||
const rendered: Record<string, unknown> = {
|
||||
...(identity ? {
|
||||
runtime_identity: {
|
||||
@@ -333,37 +253,38 @@ export function renderRuntimeConfig(
|
||||
...(installation.session_storage === undefined
|
||||
? {} : { session_storage: installation.session_storage }),
|
||||
...(installation.profile === undefined ? {} : { profile: installation.profile }),
|
||||
language: canonical.workspace.language,
|
||||
language: descriptor.workspace.language,
|
||||
database,
|
||||
vector_db: vectorDb,
|
||||
embeddings: embedding,
|
||||
resources: {
|
||||
vector: {
|
||||
engine: "qdrant",
|
||||
base_url: semanticRuntime.internalQdrantUrl,
|
||||
collection: descriptor.semantic_index.vector_store.collection,
|
||||
},
|
||||
embeddings: {
|
||||
provider: "ollama_internal",
|
||||
base_url: semanticRuntime.internalEmbeddingUrl,
|
||||
model: semanticRuntime.internalEmbeddingModel,
|
||||
dimensions: semanticRuntime.internalEmbeddingDimensions,
|
||||
},
|
||||
},
|
||||
roots: paths,
|
||||
paths,
|
||||
...(renderedEvidence ?? {}),
|
||||
};
|
||||
if (dwhDirect) {
|
||||
if (bindings.dwh.transport === "postgres_direct") {
|
||||
rendered.dwh = { type: "postgres_direct", connection: database };
|
||||
} else if (bindings.dwh.transport === "rest_api") {
|
||||
const rest = legacyRestEndpoint(bindings.dwh, {
|
||||
baseUrl: name("DWH", "BASE_URL"), apiKeyFile: name("DWH", "API_KEY_FILE"),
|
||||
const rest = restEndpoint(bindings.dwh, {
|
||||
baseUrl: name("DWH", "BASE_URL"),
|
||||
apiKeyFile: name("DWH", "API_KEY_FILE"),
|
||||
tlsCaFile: name("DWH", "TLS_CA_FILE"),
|
||||
}, canonical.diagnostics?.dwh_rest?.auth !== "none");
|
||||
}, descriptor.diagnostics?.dwh_rest?.auth !== "none");
|
||||
rendered.rest = rest;
|
||||
rendered.database = placeholderConnection(dwhIdentity);
|
||||
rendered.dwh = { type: "thoth_rest", database: dwhIdentity, endpoint: rest };
|
||||
} else {
|
||||
throw new Error("ssh_tunnel runtime configuration requires a diagnostic tunnel");
|
||||
}
|
||||
if (vectorDirect) {
|
||||
rendered.vectors = { type: "pgvector_direct", connection: vectorDb };
|
||||
} else if (bindings.vector.transport === "rest_api") {
|
||||
const vectorRest = legacyRestEndpoint(bindings.vector, {
|
||||
baseUrl: name("VECTOR", "BASE_URL"), apiKeyFile: name("VECTOR", "API_KEY_FILE"),
|
||||
tlsCaFile: name("VECTOR", "TLS_CA_FILE"),
|
||||
}, canonical.diagnostics?.vector_rest?.metadata.auth !== "none");
|
||||
rendered.vector_rest = vectorRest;
|
||||
rendered.vectors = { type: "thoth_vector_http", reader: vectorRest };
|
||||
} else {
|
||||
throw new Error("ssh_tunnel runtime configuration requires a diagnostic tunnel");
|
||||
}
|
||||
|
||||
return stringify(rendered, { lineWidth: 0, sortMapEntries: false });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user