feat: profile-gated workspace-maintenance service and connector override generator (P2)

This commit is contained in:
2026-08-11 18:40:11 +02:00
parent 17f2e48463
commit c5f65d0f15
9 changed files with 156 additions and 19 deletions
+1
View File
@@ -1,5 +1,6 @@
# Select this override only for an HTTPS Git remote. The separate CA mount keeps TLS validation
# explicit; neither host-only source file nor its contents belongs in the base Compose contract.
# Active-snapshot workspace-maintenance operations intentionally receive no Git credential mounts.
x-thoth-git-transport: https
services:
+1
View File
@@ -1,5 +1,6 @@
# Select this override only for an SSH Git remote. The host-only source files must be absolute,
# normalized paths; strict host-key checking is mandatory for registry pull and publish.
# Active-snapshot workspace-maintenance operations intentionally receive no Git credential mounts.
x-thoth-git-transport: ssh
services:
+5
View File
@@ -11,3 +11,8 @@ services:
ports:
- "127.0.0.1:${THOTH_HTTP_PORT:-8080}:8080"
restart: "no"
workspace-maintenance:
environment:
THT_WORKSPACE_INSTALLATION_ID: local
restart: "no"
+2
View File
@@ -1,3 +1,5 @@
# Retired for operator use: this profile remains only as a non-public engine-fixture path.
# It exercises the legacy preprocessing fixtures and must not become a second operator interface.
services:
preprocess-evidence:
image: thothii-core:local
+15
View File
@@ -35,3 +35,18 @@ services:
ports:
- "${THOTH_SERVER_BIND:-127.0.0.1}:${THOTH_HTTP_PORT:-8080}:8080"
restart: unless-stopped
workspace-maintenance:
environment:
THT_DATA_ROOT: /data
THT_WORKSPACE_INSTALLATION_ID: server
volumes: !override
- type: bind
source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}/sessions
target: /data/sessions
- type: bind
source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT}
target: /data/workspace-registry
read_only: true
restart: "no"