docs(deploy): document user-owned session cutover
This commit is contained in:
@@ -43,3 +43,19 @@ password into `THT_VECTOR_BOOTSTRAP_PASSWORD` in the bundle before restarting
|
||||
Hosted Pi providers must use a single provider key. Compound providers (Bedrock, Azure OpenAI
|
||||
Responses, Cloudflare Workers AI/Gateway) fail closed until a provider-specific credential
|
||||
adapter is implemented.
|
||||
|
||||
## User-owned session database secrets
|
||||
|
||||
The server-session overlay deliberately does **not** add session database credentials to the
|
||||
shared bundle. Materialize three distinct Docker secrets from protected host or secret-manager
|
||||
files: `session_runtime_password`, `session_migrator_password`, and `session_ca.pem`. Their host
|
||||
source paths are respectively `THT_SESSION_RUNTIME_PASSWORD_SOURCE`,
|
||||
`THT_SESSION_MIGRATOR_PASSWORD_SOURCE`, and `THT_SESSION_CA_SOURCE`; all must be absolute paths
|
||||
outside the repository. The runtime password is mounted only into `core`; the migrator password
|
||||
is mounted only into the one-shot `session-migrate` service. Do not reuse either login for the
|
||||
other role.
|
||||
|
||||
`session_ca.pem` is a PEM file rather than a bundle value because the bundle rejects whitespace.
|
||||
The server workspace receives only its mount path through `THT_SESSION_DB_SSLROOTCERT`; it uses
|
||||
`THT_SESSION_DB_SSLMODE=verify-ca` or, normally, `verify-full`. TLS disable/prefer/require modes
|
||||
are unsupported for session storage.
|
||||
|
||||
Reference in New Issue
Block a user