Publish documentation for 2f53512e4d

This commit is contained in:
Gitea Actions
2026-09-26 22:42:08 +00:00
commit cb50f5a6a4
55 changed files with 33829 additions and 0 deletions
+69
View File
@@ -0,0 +1,69 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="shortcut icon" href="/thothii-docs//img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>ThothII Docs</title>
<link href="/thothii-docs//css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="/thothii-docs//css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="/thothii-docs//css/base.css" rel="stylesheet">
<link rel="stylesheet" href="/thothii-docs//css/highlight.css">
<link href="/thothii-docs/stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="/thothii-docs//js/jquery-3.2.1.min.js"></script>
<script src="/thothii-docs//js/bootstrap-3.3.7.min.js"></script>
<script src="/thothii-docs//js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '/thothii-docs/';
var is_top_frame = false;
var page_toc = null;
</script>
<script src="/thothii-docs//js/base.js"></script>
<script src="/thothii-docs/javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<h2 style="text-align: center">404</h2>
<h1 style="text-align: center">Page not found</h1>
<br>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+537
View File
@@ -0,0 +1,537 @@
body {
background-color: #f8f8f8;
}
/***********************************************************************
Top bar
***********************************************************************/
.navbar {
background-color: #546e7a;
box-shadow: 0 1.5px 3px rgba(0,0,0,.24), 0 3px 8px rgba(0,0,0,.05);
border: none;
border-radius: 0px;
margin-bottom: 0px;
height: 50px;
z-index: 2;
}
.wm-top-page {
overflow: hidden;
}
.wm-page-content {
max-width: 700px;
position: relative;
}
.wm-page-top-frame { display: none; }
.wm-top-page > .wm-page-top-frame { display: block; }
.wm-top-page > .wm-page-content { display: none; }
.wm-top-brand {
display: inline-block;
float: left;
overflow: visible;
width: 0px;
height: 50px;
color: #fff;
font-size: 18px;
white-space: nowrap;
text-decoration: none;
}
.wm-top-link, .wm-top-link:hover, .wm-top-link:active, .wm-top-link:visited, .wm-top-link:focus {
color: #fff;
text-decoration: none;
}
.wm-vcenter:before {
content: '';
display: inline-block;
height: 100%;
vertical-align: middle;
margin-left: -0.25em;
}
.wm-vcentered {
display: inline-block;
vertical-align: middle;
}
.wm-top-title {
display: inline-block;
line-height: 16px;
vertical-align: middle;
}
.wm-top-logo {
max-height: 100%;
}
.wm-top-version {
border: 1px solid #ddd;
border-radius: 3px;
padding: 0px 5px;
color: #ddd;
font-size: 8pt;
}
.wm-top-tool {
height: 50px;
white-space: nowrap;
}
.wm-top-tool-expanded {
position: absolute;
right: 0px;
padding: inherit;
width: 100%;
background-color: #546e7a;
}
.wm-top-search {
width: 20rem;
}
#wm-toc-button {
margin-right: 1rem;
margin-left: 0.5rem;
}
/***********************************************************************
Table of contents (side pane)
***********************************************************************/
.wm-toc-pane {
position: absolute;
top: 0px;
padding-top: 70px;
height: 100%;
min-width: 250px;
max-width: 350px;
z-index: 1;
background-color: #f2f2f2;
border-right: 1px solid #e0e0e0;
overflow: auto;
margin-left: 0px;
padding-left: 1rem;
padding-right: 1rem;
padding-bottom: 2rem;
transition: margin-left 0.3s;
}
.wm-content-pane {
position: absolute;
top: 0px;
padding-top: 50px;
height: 100%;
width: 100%;
z-index: 0;
padding-left: 250px;
transition: padding-left 0.3s;
/* required for iPhone to scroll the contained iframe */
-webkit-overflow-scrolling: touch;
}
.wm-toc-pane.wm-toc-dropdown {
position: absolute;
display: block;
top: 0;
left: 0;
margin-left: 0;
height: auto;
box-shadow: 2px 3px 4px 0 grey;
}
.wm-toc-repo {
margin-top: -15px;
margin-bottom: 5px;
padding-bottom: 5px;
border-bottom: 1px solid #e0e0e0;
}
.wm-toc-hidden > .wm-toc-pane {
margin-left: -250px;
}
.wm-toc-hidden > .wm-content-pane {
padding-left: 0px;
}
.wm-small-show {
display: none;
}
#wm-search-form {
width: 100%;
}
#wm-search-show {
display: none;
}
@media (max-width: 600px) {
.wm-small-hide {
display: none;
}
.wm-small-show {
display: block;
}
.wm-small-left {
float: left !important;
}
#wm-search-show {
display: block;
margin-left: 1rem;
}
.wm-top-tool-expanded #wm-search-show {
display: none;
}
.wm-top-search {
display: none;
}
.wm-top-tool-expanded .wm-top-search {
display: table;
width: 100%;
padding: 0px;
}
.wm-top-page {
overflow: visible;
}
.wm-top-container {
/* This prevents horizontal overflow, but cuts off search results on bigger
* screens, so included in small-screen section */
overflow-x: hidden;
}
.wm-toc-pane {
display: none;
}
.wm-content-pane {
padding-left: 0px;
overflow: visible;
}
}
.wm-toctree {
list-style-type: none;
line-height: 16px;
padding-left: 0px;
}
.wm-toctree a, .wm-toctree a:visited, .wm-toctree a:hover, .wm-toctree a:focus {
color: #546e7a;
text-decoration: none;
outline: none;
}
.wm-toc-text {
display: block;
padding: 4px;
cursor: pointer;
}
.wm-toc-lev1 > .wm-toc-text { padding-left: 14px; }
.wm-toc-lev2 > .wm-toc-text { padding-left: 28px; }
.wm-toc-lev3 > .wm-toc-text { padding-left: 42px; }
.wm-toc-lev4 > .wm-toc-text { padding-left: 56px; }
.wm-toc-lev5 > .wm-toc-text { padding-left: 70px; }
.wm-toc-lev6 > .wm-toc-text { padding-left: 84px; }
.wm-toc-lev1 + .wm-page-toc { margin-left: 14px; }
.wm-toc-lev2 + .wm-page-toc { margin-left: 28px; }
.wm-toc-lev3 + .wm-page-toc { margin-left: 42px; }
.wm-toc-lev4 + .wm-page-toc { margin-left: 56px; }
.wm-toc-lev5 + .wm-page-toc { margin-left: 70px; }
.wm-toc-lev6 + .wm-page-toc { margin-left: 84px; }
.wm-toc-li-nested {
padding: 0px;
margin: 0px;
}
.wm-toc-opener > .wm-toc-text::before {
content: "\25B6 \FE0E";
display: inline-block;
vertical-align: middle;
font-size: 8px;
width: 14px;
}
.wm-toc-opener.wm-toc-open > .wm-toc-text::before {
content: "\25BC \FE0E";
}
.wm-toc-li.wm-current, .wm-toc-li.wm-current:hover {
background-color: #546e7a;
color: white;
}
.wm-toc-li:hover {
background-color: #e0e0e0;
}
.wm-toc-li.wm-current a {
color: white;
}
.wm-toc-li-nested.wm-page-toc {
font-size: 1.2rem;
line-height: 1.2rem;
overflow: hidden;
border-left: 1px solid #546e7a;
}
.wm-page-toc-opener > .wm-toc-text::after {
content: "\25C4";
display: inline-block;
float: right;
vertical-align: middle;
font-size: 8px;
}
.wm-page-toc-opener.wm-page-toc-open > .wm-toc-text::after {
content: "\25BC";
}
.wm-page-toc-text {
padding: 2px 2px 2px 1rem;
display: block;
cursor: pointer;
}
.wm-article {
width: 1px;
min-width: 100%;
height: 100%;
border: none;
}
.btn:focus, .btn:active:focus, .btn.active:focus, .btn.focus, .btn:active.focus, .btn.active.focus {
outline: none;
}
.btn-default:focus, .btn-default.focus {
color: #333;
background-color: #fff;
border-color: #ccc;
}
.btn-default.greybtn {
color: #888;
}
.wm-article-nav-buttons {
margin: 1rem 0;
}
.wm-page-content img {
max-width: 100%;
display: inline-block;
padding: 4px;
line-height: 1.428571429;
background-color: #fff;
border: 1px solid #ddd;
border-radius: 4px;
margin: 20px auto 30px auto;
}
.wm-page-content a {
color: #2fa4e7;
}
.wm-article-nav {
display: inline-block;
max-width: 48%;
white-space: nowrap;
color: #546e7a;
text-align: right;
}
.wm-article-nav > .btn-link {
display: block;
padding-left: 0.5rem;
padding-right: 0.5rem;
overflow: hidden;
text-overflow: ellipsis;
}
.wm-article-nav > a, .wm-article-nav > a:visited, .wm-article-nav > a:hover, .wm-article-nav > a:focus {
color: #546e7a;
text-decoration: none;
outline: none;
}
/***********************************************************************
* Dropdown search results
***********************************************************************/
#mkdocs-search-results.dropdown-menu {
width: 40rem;
overflow-y: auto;
overflow-x: hidden;
white-space: normal;
max-height: calc(100vh - 60px);
max-width: 90vw;
}
#mkdocs-search-results {
font-family: "Helvetica Neue",Helvetica,Arial,sans-serif,FontAwesome;
}
.search-link {
font-size: 1.2rem;
}
.search-title {
font-weight: bold;
color: #337ab7;
padding-right: 1rem;
}
.search-text {
color: #666;
overflow: hidden;
text-overflow: ellipsis;
}
.search-text > b {
color: #000;
}
.wm-search-page {
list-style: none;
padding: 5px 0;
}
.wm-search-page > li {
padding: 1rem 0;
border-bottom: 1px solid #ccc;
}
.wm-search-page .search-link {
font-size: inherit;
}
.wm-search-page .search-link:hover, .wm-search-page .search-link:active {
text-decoration: none;
}
.wm-search-page .search-link:hover .search-title {
text-decoration: underline;
}
/***********************************************************************
* The rest is taken from base.css from mkdocs.
***********************************************************************/
.source-links {
float: right;
}
h1 {
color: #444;
font-weight: 400;
font-size: 42px;
}
h2, h3, h4, h5, h6 {
color: #444;
font-weight: 300;
}
hr {
border-top: 1px solid #aaa;
}
pre, .rst-content tt {
max-width: 100%;
background: #fff;
border: solid 1px #e1e4e5;
color: #333;
overflow-x: auto;
}
code.code-large, .rst-content tt.code-large {
font-size: 90%;
}
code {
padding: 2px 5px;
background: #fff;
border: solid 1px #e1e4e5;
color: #333;
white-space: pre-wrap;
word-wrap: break-word;
}
pre code {
background: transparent;
border: none;
white-space: pre;
word-wrap: normal;
font-family: monospace,serif;
font-size: 12px;
}
a code {
color: #2FA4E7;
}
a:hover code, a:focus code {
color: #157AB5;
}
footer {
margin-bottom: 10px;
text-align: center;
font-weight: 200;
font-size: smaller;
}
.modal-dialog {
margin-top: 60px;
}
.headerlink {
font-family: FontAwesome;
font-size: 14px;
display: none;
padding-left: .5em;
}
h1:hover .headerlink, h2:hover .headerlink, h3:hover .headerlink, h4:hover .headerlink, h5:hover .headerlink, h6:hover .headerlink{
display:inline-block;
}
.admonition {
padding: 15px;
margin-bottom: 20px;
border: 1px solid transparent;
border-radius: 4px;
text-align: left;
}
.admonition.note { /* csslint allow: adjoining-classes */
color: #3a87ad;
background-color: #d9edf7;
border-color: #bce8f1;
}
.admonition.warning { /* csslint allow: adjoining-classes */
color: #c09853;
background-color: #fcf8e3;
border-color: #fbeed5;
}
.admonition.danger { /* csslint allow: adjoining-classes */
color: #b94a48;
background-color: #f2dede;
border-color: #eed3d7;
}
.admonition-title {
font-weight: bold;
text-align: left;
}
+6757
View File
File diff suppressed because it is too large Load Diff
+6
View File
File diff suppressed because one or more lines are too long
File diff suppressed because it is too large Load Diff
File diff suppressed because one or more lines are too long
+124
View File
@@ -0,0 +1,124 @@
/*
This is the GitHub theme for highlight.js
github.com style (c) Vasily Polovnyov <vast@whiteants.net>
*/
.hljs {
display: block;
overflow-x: auto;
color: #333;
-webkit-text-size-adjust: none;
}
.hljs-comment,
.diff .hljs-header,
.hljs-javadoc {
color: #998;
font-style: italic;
}
.hljs-keyword,
.css .rule .hljs-keyword,
.hljs-winutils,
.nginx .hljs-title,
.hljs-subst,
.hljs-request,
.hljs-status {
color: #333;
font-weight: bold;
}
.hljs-number,
.hljs-hexcolor,
.ruby .hljs-constant {
color: #008080;
}
.hljs-string,
.hljs-tag .hljs-value,
.hljs-phpdoc,
.hljs-dartdoc,
.tex .hljs-formula {
color: #d14;
}
.hljs-title,
.hljs-id,
.scss .hljs-preprocessor {
color: #900;
font-weight: bold;
}
.hljs-list .hljs-keyword,
.hljs-subst {
font-weight: normal;
}
.hljs-class .hljs-title,
.hljs-type,
.vhdl .hljs-literal,
.tex .hljs-command {
color: #458;
font-weight: bold;
}
.hljs-tag,
.hljs-tag .hljs-title,
.hljs-rule .hljs-property,
.django .hljs-tag .hljs-keyword {
color: #000080;
font-weight: normal;
}
.hljs-attribute,
.hljs-variable,
.lisp .hljs-body,
.hljs-name {
color: #008080;
}
.hljs-regexp {
color: #009926;
}
.hljs-symbol,
.ruby .hljs-symbol .hljs-string,
.lisp .hljs-keyword,
.clojure .hljs-keyword,
.scheme .hljs-keyword,
.tex .hljs-special,
.hljs-prompt {
color: #990073;
}
.hljs-built_in {
color: #0086b3;
}
.hljs-preprocessor,
.hljs-pragma,
.hljs-pi,
.hljs-doctype,
.hljs-shebang,
.hljs-cdata {
color: #999;
font-weight: bold;
}
.hljs-deletion {
background: #fdd;
}
.hljs-addition {
background: #dfd;
}
.diff .hljs-change {
background: #0086b3;
}
.hljs-chunk {
color: #aaa;
}
+315
View File
@@ -0,0 +1,315 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8"/>
<meta content="IE=edge" http-equiv="X-UA-Compatible"/>
<meta content="width=device-width, initial-scale=1.0" name="viewport"/>
<link href="https://git.tylconsulting.it/thothii-docs/evidence/" rel="canonical"/>
<link href="../img/favicon.ico" rel="shortcut icon"/>
<meta content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" name="viewport"/>
<title>Evidence - ThothII Docs</title>
<link href="../css/bootstrap-3.3.7.min.css" rel="stylesheet"/>
<link href="../css/font-awesome-4.7.0.css" rel="stylesheet"/>
<link href="../css/base.css" rel="stylesheet"/>
<link href="../css/highlight.css" rel="stylesheet"/>
<link href="../stylesheets/extra.css" rel="stylesheet"/>
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../js/jquery-3.2.1.min.js"></script>
<script src="../js/bootstrap-3.3.7.min.js"></script>
<script src="../js/highlight.pack.js"></script>
<base target="_top"/>
<script>
var base_url = '..';
var is_top_frame = false;
var pageToc = [
{title: "Evidence: sources, preparation, and review", url: "#_top", children: [
{title: "Editable local Evidence", url: "#editable-local-evidence" },
{title: "Existing repository publication path", url: "#existing-repository-publication-path" },
{title: "Where the original source belongs", url: "#where-the-original-source-belongs" },
{title: "What an editable curated unit contains", url: "#what-an-editable-curated-unit-contains" },
{title: "Legacy v3 representation", url: "#legacy-v3-representation" },
{title: "Preparation: from source to active generation", url: "#preparation-from-source-to-active-generation" },
{title: "Author responsibilities", url: "#author-responsibilities" },
{title: "Reviewer responsibilities", url: "#reviewer-responsibilities" },
{title: "Available commands", url: "#available-commands" },
{title: "Formulas and session proposals", url: "#formulas-and-session-proposals" },
{title: "Contract references", url: "#contract-references" },
]},
];
</script>
<script src="../js/base.js"></script>
<script src="../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
<div class="wm-article-nav pull-right">
<a class="btn btn-xs btn-default pull-right" href="../usage/memory/">
Next
<i aria-hidden="true" class="fa fa-chevron-right"></i>
</a>
<a class="btn btn-xs btn-link" href="../usage/memory/">
Memory
</a>
</div>
<div class="wm-article-nav">
<a class="btn btn-xs btn-default pull-left" href="../operations/sensitivity-analysis/">
<i aria-hidden="true" class="fa fa-chevron-left"></i>
Previous</a><a class="btn btn-xs btn-link" href="../operations/sensitivity-analysis/">
Sensitive columns
</a>
</div>
</div>
<h1 id="evidence-sources-preparation-and-review">Evidence: sources, preparation, and review<a class="headerlink" href="#evidence-sources-preparation-and-review" title="Permanent link"></a></h1>
<p>This page describes the complete workspace Evidence lifecycle: where original material lives, how curated units are produced, when they become available at runtime, and what the author and reviewer are responsible for.</p>
<h2 id="editable-local-evidence">Editable local Evidence<a class="headerlink" href="#editable-local-evidence" title="Permanent link"></a></h2>
<p>E1 adds <a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/curated-evidence-v4.md">Curated Evidence v4 and a persistent local archive</a>.
The visible title and payload fields are authoritative Markdown. New manual units need no
external source; consolidation records their curator and distinguishes later corrections
from original documentary provenance. The core archive API creates immutable candidates
and advances its active pointer only after successful indexing.</p>
<p>E2 adds <strong>Administration → Evidence management</strong>, actual host file paths, complete
browsing and filtering, and the installed <code>tht workspace evidence consolidate
--workspace &lt;id&gt;</code> command. Edit files externally, consolidate to activate them, then
review and run Git manually. Runtime consumes only the active local snapshot.
The <a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/curated-evidence-v4.md#administration-and-installed-command">v4 contract</a>
describes host mounting, first conversion, failure recovery and Clear behavior.
The local PSD preview has 35 converted and indexed units. E3 adds explicit import/refresh
from local drafts and configured HTTP/S3 sources, durable current/proposed comparisons,
and keep/replace decisions with activation and retry. See
<a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/curated-evidence-v4.md#import-drafts-and-refresh-sources">Import drafts and refresh sources</a>.
Workflow gate corrections remain the subsequent shared increment, X1.</p>
<h2 id="existing-repository-publication-path">Existing repository publication path<a class="headerlink" href="#existing-repository-publication-path" title="Permanent link"></a></h2>
<p>The remainder describes the legacy, uninitialized repository source path. Initialized
v4 local archives use the lifecycle above; manual declarations need no source document.</p>
<p>The workspace repository is the versioned source. ThothII reads it, validates it, and publishes an atomic generation. It does not modify, commit, or push the author's repository.</p>
<p>Evidence becomes available to the workflow only when:</p>
<ol>
<li>the original material is in <code>source/</code>;</li>
<li>the derived unit is in <code>curated/</code>;</li>
<li>the manifest links the unit, source, and hash;</li>
<li>validation finds no errors or unresolved review items;</li>
<li>preprocessing builds and activates an indexed generation.</li>
</ol>
<p>A proposal generated during a session is not automatically published Evidence. The model may propose a formula or explanation, but a curator must import, review, and publish it in the repository before another session can retrieve it.</p>
<h2 id="where-the-original-source-belongs">Where the original source belongs<a class="headerlink" href="#where-the-original-source-belongs" title="Permanent link"></a></h2>
<p>For filesystem Evidence v2, the authoritative original source must be in the <code>source/</code> directory of the workspace repository. <code>curated/</code> contains the reviewed and indexed result, not the original material.</p>
<pre class="highlight"><code class="language-text">&lt;workspace-repository&gt;/
├── source/ # materiale originale, preservato
│ └── &lt;domain&gt;/&lt;file&gt;.md
├── curated/ # reviewed Evidence Units
│ └── &lt;domain&gt;/&lt;unit&gt;.md
├── manifest.yaml # preparation links, hashes, and metadata
└── example/ # examples and supporting material</code></pre>
<p>The workspace descriptor must declare <code>evidence.schema_version: 2</code> and use exactly this configuration for a filesystem source:</p>
<pre class="highlight"><code class="language-yaml">evidence:
schema_version: 2
source:
type: filesystem
uri: "&lt;workspace.id&gt;/evidence"
patterns:
- "curated/**/*.md"</code></pre>
<p>The legacy configuration may expose <code>source_root</code>, such as <code>${THT_DOCS_ROOT}</code> or <code>/data</code>. For the v2 structure, the runtime pattern must select only <code>curated/**/*.md</code>. Do not index <code>source/</code> directly, mix <code>source/</code> and <code>curated/</code>, use broader globs, or include non-Markdown files.</p>
<p>HTTP and S3 are separate adapters. They do not use the filesystem structure <code>source/</code> and <code>curated/</code>, but they must still provide stable provenance, without credentials in URIs, under the adapter-specific contract.</p>
<h2 id="what-an-editable-curated-unit-contains">What an editable curated unit contains<a class="headerlink" href="#what-an-editable-curated-unit-contains" title="Permanent link"></a></h2>
<p>New preparation produces unit schema v4. The first H1 contains its title; documented H2
sections contain the typed payload. A minimal manual unit is:</p>
<pre class="highlight"><code class="language-markdown">---
schema_version: 4
id: evidence:order-key
kind: domain
language: en
purposes: [sql_generation]
---
# Order key
## Rule
Join orders using the order number, financial year and company.</code></pre>
<p>Use <code>tht evidence migrate &lt;workspace-root&gt;</code> for deterministic legacy conversion. The
conversion preserves typed content and initializes an archive baseline; it does not
activate the local corpus. See the <a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/curated-evidence-v4.md">v4 contract</a> for
all eight kinds, provenance, file layout and the E1/E2 boundary.</p>
<h2 id="legacy-v3-representation">Legacy v3 representation<a class="headerlink" href="#legacy-v3-representation" title="Permanent link"></a></h2>
<p>Canonical Curated Evidence v3 hides canonical machine metadata in an HTML comment and renders the
whole review surface as real Markdown. GitHub therefore shows no frontmatter table. The body layout
is deterministic for each Evidence kind: prose uses sections and paragraphs, scopes and enum values
use wrapping lists, formulas use fenced SQL, supporting excerpts use blockquotes, and unresolved
review items use dedicated blocks. Long domain rules are split into readable paragraphs, labelled
subsections, and lists at existing semicolon boundaries. Their exact original text remains canonical
in an invisible marker, so the formatting cannot change their meaning or bytes.</p>
<p>Preprocessing parses the unit first and builds semantic chunks from the typed payload. The vector
store therefore receives the original rule text and not headings, list markers, or invisible
presentation metadata.</p>
<pre class="highlight"><code class="language-markdown">&lt;!-- tht:metadata:&lt;canonical metadata&gt; --&gt;
# Fascia pediatrica
&gt; **Dominio** · Italiano
&gt;
&gt; **Scopi:** Disambiguazione
## Ambito di applicazione
### Concetti
- fascia pediatrica
## Regola
La fascia pediatrica comprende i pazienti con età inferiore a 18 anni.
## Estratti di supporto
&gt; I pazienti sotto i 18 anni sono pediatrici.
&lt;details&gt;
&lt;summary&gt;Dettagli tecnici e provenienza&lt;/summary&gt;
- **ID:** `evidence:fascia-pediatrica`
- **File sorgente:** `source/domain/paziente.md`
&lt;/details&gt;</code></pre>
<p>The actual files contain invisible <code>tht:</code> comments for canonical metadata and typed-field
boundaries. Removing, duplicating, or desynchronizing them makes validation fail closed instead of
silently ignoring content. Unit schemas v1 and v2 remain readable for compatibility, but newly
prepared units use v4. Unit v3 remains readable as a conversion input.</p>
<p>Curated units must be atomic, readable by a second reviewer, and supported by the source.
Provenance references must lead back to the original file and the passage that supports the claim.
Do not put secrets, tokens, passwords, or credentials in metadata or URIs.</p>
<p>The modern canonical form also stores the Evidence kind, provenance, supporting excerpts, <code>source_file</code>, and <code>source_sha256</code>. The canonical contract rejects unknown fields, mutable metadata, and URIs containing credentials. Identifiers must remain stable even when a unit's kind changes.</p>
<h2 id="preparation-from-source-to-active-generation">Preparation: from source to active generation<a class="headerlink" href="#preparation-from-source-to-active-generation" title="Permanent link"></a></h2>
<div class="mermaid">flowchart TD
SRC["source/DOMAIN/*.md\noriginal material"] --&gt; PREP["tht evidence prepare\ncandidate preparation"]
PREP --&gt; CAND["curated/DOMAIN/*.md\nproposed or updated units"]
CAND --&gt; VAL["tht evidence validate\nstructure and link checks"]
VAL --&gt;|errors or review items| FIX["Author corrections\nand review"]
FIX --&gt; PREP
VAL --&gt;|publishable| COMMIT["Commit del repository\nauthoring clone"]
COMMIT --&gt; ING["tht workspace preprocess run\nnormalization and chunking"]
ING --&gt; BM25["BM25 index"]
ING --&gt; VEC["Embeddings and vector store"]
BM25 --&gt; GEN["Candidate generation"]
VEC --&gt; GEN
GEN --&gt; ACT["Replace active Evidence slice"]
ACT --&gt; RUNTIME["Evidence retrieval in the workflow"]
</div>
<p>Preparation can restructure changed sources, but it does not publish by itself. <code>prepare</code> produces a proposal and can identify the document involved in an error. <code>validate</code> does not write or publish. The curator publishes the revision. The complete workspace preprocessing command reads that exact revision and replaces the active Evidence slice. There is no application-level rollback; rerun complete preprocessing after correcting a failure.</p>
<p>Runtime retrieval is hybrid. The dense branch uses embeddings, the BM25 branch uses lexical search,
and deterministic fusion orders the results. Evidence fragments live in the workspace <code>reference</code>
collection together with Schema and relationships; runtime Memory and solved questions live in a
separate <code>memory</code> collection. The published unit keeps its provenance, which the model must cite when
it uses the Evidence.</p>
<h2 id="author-responsibilities">Author responsibilities<a class="headerlink" href="#author-responsibilities" title="Permanent link"></a></h2>
<p>The author prepares the material and makes every unit verifiable. The author must:</p>
<ul>
<li>put the original material in <code>source/</code> without changing its meaning during curation;</li>
<li>split the content into atomic units, with one rule or definition per unit when possible;</li>
<li>assign a stable identifier and a clear title;</li>
<li>provide provenance, tables, and related concepts when known;</li>
<li>keep the text in the workspace language;</li>
<li>separate facts, rules, examples, formulas, and limits;</li>
<li>include excerpts that support the unit without extending the conclusion beyond the source;</li>
<li>run <code>tht evidence prepare</code> and <code>tht evidence validate</code>;</li>
<li>resolve every error and review item before proposing a commit;</li>
<li>give the reviewer the necessary context, including source changes and the reason for any rename or retirement.</li>
</ul>
<p>The author must not:</p>
<ul>
<li>write directly to the active production corpus;</li>
<li>treat a model proposal as a verified fact;</li>
<li>delete an unsupported unit without recording its retirement or relink;</li>
<li>put credentials in metadata, files, or provenance URLs;</li>
<li>manually change manifests, hashes, or generations to make validation pass.</li>
</ul>
<h2 id="reviewer-responsibilities">Reviewer responsibilities<a class="headerlink" href="#reviewer-responsibilities" title="Permanent link"></a></h2>
<p>The reviewer does not approve text merely because it is clear. The reviewer checks the relationship between source, unit, and intended use. For each unit, the reviewer must check:</p>
<ol>
<li>the cited source exists in the reviewed revision;</li>
<li>the excerpt actually supports the claim;</li>
<li>the unit does not combine incompatible rules or independent concepts;</li>
<li>tables, columns, and concepts are identified correctly;</li>
<li>the identifier is stable and does not duplicate another unit;</li>
<li>the text distinguishes the definition, condition, exception, and example;</li>
<li>it contains no sensitive information or details absent from the source;</li>
<li>retrieval evaluation covers relevant queries and does not hide empty results.</li>
</ol>
<p>The reviewer can approve, request changes, reject, retire, or relink a unit to a new source. Retirement must be explicit. A relink must name the new file and leave a verifiable record of the decision. Approval does not publish immediately: the repository must pass validation and the generation must pass evaluation before activation.</p>
<h2 id="available-commands">Available commands<a class="headerlink" href="#available-commands" title="Permanent link"></a></h2>
<p>Authoring commands operate on the workspace repository and do not publish directly.</p>
<pre class="highlight"><code class="language-bash"># Prepare changed sources. Does not commit or publish.
tht evidence prepare &lt;workspace-root&gt;
# Reprocess all sources with the installed pipeline.
tht evidence prepare &lt;workspace-root&gt; --upgrade
# Rewrite legacy v1/v2 units as table-free v3 Markdown without model calls.
tht evidence migrate &lt;workspace-root&gt;
# Validate structure, manifest, links, and review items.
tht evidence validate &lt;workspace-root&gt;
# Return JSON for CI or automated tools.
tht evidence validate &lt;workspace-root&gt; --json
# Evaluate retrieval on a generation or the active generation.
tht evidence evaluate &lt;workspace-root&gt; --config &lt;workspace-config&gt;
tht evidence evaluate &lt;workspace-root&gt; --config &lt;workspace-config&gt; --generation &lt;id&gt; --json
# Resolve a unit without publishing: retire it or link it to a new source.
tht evidence resolve &lt;workspace-root&gt; evidence:&lt;id&gt; --retire
tht evidence resolve &lt;workspace-root&gt; evidence:&lt;id&gt; --source source/domain/nuovo.md
# Materialize Catalog-derived schema/LSH and the revision-pinned Evidence in one run.
tht --installation &lt;absolute&gt;/thothii-installation.yaml \
workspace preprocess run --workspace &lt;workspace-id&gt;</code></pre>
<p><code>evidence prepare</code>, <code>evidence migrate</code>, <code>evidence validate</code>, and <code>evidence resolve</code> are authoring
operations and require the repository path. Runtime publication is available only through the
complete host-side <code>workspace preprocess run</code>; there is no public Evidence-only preprocessing
command.</p>
<p>Exit codes are part of the operating contract: <code>evidence validate</code> returns <code>0</code> when the corpus is publishable, <code>1</code> for validation errors, and <code>3</code> when only review items or orphaned units remain. With <code>--json</code>, stdout must contain valid JSON only.</p>
<h2 id="formulas-and-session-proposals">Formulas and session proposals<a class="headerlink" href="#formulas-and-session-proposals" title="Permanent link"></a></h2>
<p>Formulas use a format distinct from document Evidence. A formula proposed during a session may be cited in the current proposal, but it does not enter the runtime corpus, receive a usable <code>evidence:</code> ID, or write to the repository. To become published, it must follow the same import, review, and preprocessing path as other units.</p>
<h2 id="contract-references">Contract references<a class="headerlink" href="#contract-references" title="Permanent link"></a></h2>
<ul>
<li><a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/workspace-evidence-v3.md">Workspace Evidence v3 contract</a></li>
<li><a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/workspace-preprocessing-cli.md">Preprocessing CLI contract</a></li>
</ul>
<br/>
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
<div class="wm-article-nav pull-right">
<a class="btn btn-xs btn-default pull-right" href="../usage/memory/">
Next
<i aria-hidden="true" class="fa fa-chevron-right"></i>
</a>
<a class="btn btn-xs btn-link" href="../usage/memory/">
Memory
</a>
</div>
<div class="wm-article-nav">
<a class="btn btn-xs btn-default pull-left" href="../operations/sensitivity-analysis/">
<i aria-hidden="true" class="fa fa-chevron-left"></i>
Previous</a><a class="btn btn-xs btn-link" href="../operations/sensitivity-analysis/">
Sensitive columns
</a>
</div>
</div>
<br/>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
<script type="module">import mermaid from "https://unpkg.com/mermaid@10.4.0/dist/mermaid.esm.min.mjs";
mermaid.initialize({});</script></body>
</html>
Binary file not shown.
File diff suppressed because it is too large Load Diff

After

Width:  |  Height:  |  Size: 434 KiB

Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+288
View File
@@ -0,0 +1,288 @@
<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd" >
<svg xmlns="http://www.w3.org/2000/svg">
<metadata></metadata>
<defs>
<font id="glyphicons_halflingsregular" horiz-adv-x="1200" >
<font-face units-per-em="1200" ascent="960" descent="-240" />
<missing-glyph horiz-adv-x="500" />
<glyph horiz-adv-x="0" />
<glyph horiz-adv-x="400" />
<glyph unicode=" " />
<glyph unicode="*" d="M600 1100q15 0 34 -1.5t30 -3.5l11 -1q10 -2 17.5 -10.5t7.5 -18.5v-224l158 158q7 7 18 8t19 -6l106 -106q7 -8 6 -19t-8 -18l-158 -158h224q10 0 18.5 -7.5t10.5 -17.5q6 -41 6 -75q0 -15 -1.5 -34t-3.5 -30l-1 -11q-2 -10 -10.5 -17.5t-18.5 -7.5h-224l158 -158 q7 -7 8 -18t-6 -19l-106 -106q-8 -7 -19 -6t-18 8l-158 158v-224q0 -10 -7.5 -18.5t-17.5 -10.5q-41 -6 -75 -6q-15 0 -34 1.5t-30 3.5l-11 1q-10 2 -17.5 10.5t-7.5 18.5v224l-158 -158q-7 -7 -18 -8t-19 6l-106 106q-7 8 -6 19t8 18l158 158h-224q-10 0 -18.5 7.5 t-10.5 17.5q-6 41 -6 75q0 15 1.5 34t3.5 30l1 11q2 10 10.5 17.5t18.5 7.5h224l-158 158q-7 7 -8 18t6 19l106 106q8 7 19 6t18 -8l158 -158v224q0 10 7.5 18.5t17.5 10.5q41 6 75 6z" />
<glyph unicode="+" d="M450 1100h200q21 0 35.5 -14.5t14.5 -35.5v-350h350q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-350v-350q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v350h-350q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5 h350v350q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xa0;" />
<glyph unicode="&#xa5;" d="M825 1100h250q10 0 12.5 -5t-5.5 -13l-364 -364q-6 -6 -11 -18h268q10 0 13 -6t-3 -14l-120 -160q-6 -8 -18 -14t-22 -6h-125v-100h275q10 0 13 -6t-3 -14l-120 -160q-6 -8 -18 -14t-22 -6h-125v-174q0 -11 -7.5 -18.5t-18.5 -7.5h-148q-11 0 -18.5 7.5t-7.5 18.5v174 h-275q-10 0 -13 6t3 14l120 160q6 8 18 14t22 6h125v100h-275q-10 0 -13 6t3 14l120 160q6 8 18 14t22 6h118q-5 12 -11 18l-364 364q-8 8 -5.5 13t12.5 5h250q25 0 43 -18l164 -164q8 -8 18 -8t18 8l164 164q18 18 43 18z" />
<glyph unicode="&#x2000;" horiz-adv-x="650" />
<glyph unicode="&#x2001;" horiz-adv-x="1300" />
<glyph unicode="&#x2002;" horiz-adv-x="650" />
<glyph unicode="&#x2003;" horiz-adv-x="1300" />
<glyph unicode="&#x2004;" horiz-adv-x="433" />
<glyph unicode="&#x2005;" horiz-adv-x="325" />
<glyph unicode="&#x2006;" horiz-adv-x="216" />
<glyph unicode="&#x2007;" horiz-adv-x="216" />
<glyph unicode="&#x2008;" horiz-adv-x="162" />
<glyph unicode="&#x2009;" horiz-adv-x="260" />
<glyph unicode="&#x200a;" horiz-adv-x="72" />
<glyph unicode="&#x202f;" horiz-adv-x="260" />
<glyph unicode="&#x205f;" horiz-adv-x="325" />
<glyph unicode="&#x20ac;" d="M744 1198q242 0 354 -189q60 -104 66 -209h-181q0 45 -17.5 82.5t-43.5 61.5t-58 40.5t-60.5 24t-51.5 7.5q-19 0 -40.5 -5.5t-49.5 -20.5t-53 -38t-49 -62.5t-39 -89.5h379l-100 -100h-300q-6 -50 -6 -100h406l-100 -100h-300q9 -74 33 -132t52.5 -91t61.5 -54.5t59 -29 t47 -7.5q22 0 50.5 7.5t60.5 24.5t58 41t43.5 61t17.5 80h174q-30 -171 -128 -278q-107 -117 -274 -117q-206 0 -324 158q-36 48 -69 133t-45 204h-217l100 100h112q1 47 6 100h-218l100 100h134q20 87 51 153.5t62 103.5q117 141 297 141z" />
<glyph unicode="&#x20bd;" d="M428 1200h350q67 0 120 -13t86 -31t57 -49.5t35 -56.5t17 -64.5t6.5 -60.5t0.5 -57v-16.5v-16.5q0 -36 -0.5 -57t-6.5 -61t-17 -65t-35 -57t-57 -50.5t-86 -31.5t-120 -13h-178l-2 -100h288q10 0 13 -6t-3 -14l-120 -160q-6 -8 -18 -14t-22 -6h-138v-175q0 -11 -5.5 -18 t-15.5 -7h-149q-10 0 -17.5 7.5t-7.5 17.5v175h-267q-10 0 -13 6t3 14l120 160q6 8 18 14t22 6h117v100h-267q-10 0 -13 6t3 14l120 160q6 8 18 14t22 6h117v475q0 10 7.5 17.5t17.5 7.5zM600 1000v-300h203q64 0 86.5 33t22.5 119q0 84 -22.5 116t-86.5 32h-203z" />
<glyph unicode="&#x2212;" d="M250 700h800q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-800q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#x231b;" d="M1000 1200v-150q0 -21 -14.5 -35.5t-35.5 -14.5h-50v-100q0 -91 -49.5 -165.5t-130.5 -109.5q81 -35 130.5 -109.5t49.5 -165.5v-150h50q21 0 35.5 -14.5t14.5 -35.5v-150h-800v150q0 21 14.5 35.5t35.5 14.5h50v150q0 91 49.5 165.5t130.5 109.5q-81 35 -130.5 109.5 t-49.5 165.5v100h-50q-21 0 -35.5 14.5t-14.5 35.5v150h800zM400 1000v-100q0 -60 32.5 -109.5t87.5 -73.5q28 -12 44 -37t16 -55t-16 -55t-44 -37q-55 -24 -87.5 -73.5t-32.5 -109.5v-150h400v150q0 60 -32.5 109.5t-87.5 73.5q-28 12 -44 37t-16 55t16 55t44 37 q55 24 87.5 73.5t32.5 109.5v100h-400z" />
<glyph unicode="&#x25fc;" horiz-adv-x="500" d="M0 0z" />
<glyph unicode="&#x2601;" d="M503 1089q110 0 200.5 -59.5t134.5 -156.5q44 14 90 14q120 0 205 -86.5t85 -206.5q0 -121 -85 -207.5t-205 -86.5h-750q-79 0 -135.5 57t-56.5 137q0 69 42.5 122.5t108.5 67.5q-2 12 -2 37q0 153 108 260.5t260 107.5z" />
<glyph unicode="&#x26fa;" d="M774 1193.5q16 -9.5 20.5 -27t-5.5 -33.5l-136 -187l467 -746h30q20 0 35 -18.5t15 -39.5v-42h-1200v42q0 21 15 39.5t35 18.5h30l468 746l-135 183q-10 16 -5.5 34t20.5 28t34 5.5t28 -20.5l111 -148l112 150q9 16 27 20.5t34 -5zM600 200h377l-182 112l-195 534v-646z " />
<glyph unicode="&#x2709;" d="M25 1100h1150q10 0 12.5 -5t-5.5 -13l-564 -567q-8 -8 -18 -8t-18 8l-564 567q-8 8 -5.5 13t12.5 5zM18 882l264 -264q8 -8 8 -18t-8 -18l-264 -264q-8 -8 -13 -5.5t-5 12.5v550q0 10 5 12.5t13 -5.5zM918 618l264 264q8 8 13 5.5t5 -12.5v-550q0 -10 -5 -12.5t-13 5.5 l-264 264q-8 8 -8 18t8 18zM818 482l364 -364q8 -8 5.5 -13t-12.5 -5h-1150q-10 0 -12.5 5t5.5 13l364 364q8 8 18 8t18 -8l164 -164q8 -8 18 -8t18 8l164 164q8 8 18 8t18 -8z" />
<glyph unicode="&#x270f;" d="M1011 1210q19 0 33 -13l153 -153q13 -14 13 -33t-13 -33l-99 -92l-214 214l95 96q13 14 32 14zM1013 800l-615 -614l-214 214l614 614zM317 96l-333 -112l110 335z" />
<glyph unicode="&#xe001;" d="M700 650v-550h250q21 0 35.5 -14.5t14.5 -35.5v-50h-800v50q0 21 14.5 35.5t35.5 14.5h250v550l-500 550h1200z" />
<glyph unicode="&#xe002;" d="M368 1017l645 163q39 15 63 0t24 -49v-831q0 -55 -41.5 -95.5t-111.5 -63.5q-79 -25 -147 -4.5t-86 75t25.5 111.5t122.5 82q72 24 138 8v521l-600 -155v-606q0 -42 -44 -90t-109 -69q-79 -26 -147 -5.5t-86 75.5t25.5 111.5t122.5 82.5q72 24 138 7v639q0 38 14.5 59 t53.5 34z" />
<glyph unicode="&#xe003;" d="M500 1191q100 0 191 -39t156.5 -104.5t104.5 -156.5t39 -191l-1 -2l1 -5q0 -141 -78 -262l275 -274q23 -26 22.5 -44.5t-22.5 -42.5l-59 -58q-26 -20 -46.5 -20t-39.5 20l-275 274q-119 -77 -261 -77l-5 1l-2 -1q-100 0 -191 39t-156.5 104.5t-104.5 156.5t-39 191 t39 191t104.5 156.5t156.5 104.5t191 39zM500 1022q-88 0 -162 -43t-117 -117t-43 -162t43 -162t117 -117t162 -43t162 43t117 117t43 162t-43 162t-117 117t-162 43z" />
<glyph unicode="&#xe005;" d="M649 949q48 68 109.5 104t121.5 38.5t118.5 -20t102.5 -64t71 -100.5t27 -123q0 -57 -33.5 -117.5t-94 -124.5t-126.5 -127.5t-150 -152.5t-146 -174q-62 85 -145.5 174t-150 152.5t-126.5 127.5t-93.5 124.5t-33.5 117.5q0 64 28 123t73 100.5t104 64t119 20 t120.5 -38.5t104.5 -104z" />
<glyph unicode="&#xe006;" d="M407 800l131 353q7 19 17.5 19t17.5 -19l129 -353h421q21 0 24 -8.5t-14 -20.5l-342 -249l130 -401q7 -20 -0.5 -25.5t-24.5 6.5l-343 246l-342 -247q-17 -12 -24.5 -6.5t-0.5 25.5l130 400l-347 251q-17 12 -14 20.5t23 8.5h429z" />
<glyph unicode="&#xe007;" d="M407 800l131 353q7 19 17.5 19t17.5 -19l129 -353h421q21 0 24 -8.5t-14 -20.5l-342 -249l130 -401q7 -20 -0.5 -25.5t-24.5 6.5l-343 246l-342 -247q-17 -12 -24.5 -6.5t-0.5 25.5l130 400l-347 251q-17 12 -14 20.5t23 8.5h429zM477 700h-240l197 -142l-74 -226 l193 139l195 -140l-74 229l192 140h-234l-78 211z" />
<glyph unicode="&#xe008;" d="M600 1200q124 0 212 -88t88 -212v-250q0 -46 -31 -98t-69 -52v-75q0 -10 6 -21.5t15 -17.5l358 -230q9 -5 15 -16.5t6 -21.5v-93q0 -10 -7.5 -17.5t-17.5 -7.5h-1150q-10 0 -17.5 7.5t-7.5 17.5v93q0 10 6 21.5t15 16.5l358 230q9 6 15 17.5t6 21.5v75q-38 0 -69 52 t-31 98v250q0 124 88 212t212 88z" />
<glyph unicode="&#xe009;" d="M25 1100h1150q10 0 17.5 -7.5t7.5 -17.5v-1050q0 -10 -7.5 -17.5t-17.5 -7.5h-1150q-10 0 -17.5 7.5t-7.5 17.5v1050q0 10 7.5 17.5t17.5 7.5zM100 1000v-100h100v100h-100zM875 1000h-550q-10 0 -17.5 -7.5t-7.5 -17.5v-350q0 -10 7.5 -17.5t17.5 -7.5h550 q10 0 17.5 7.5t7.5 17.5v350q0 10 -7.5 17.5t-17.5 7.5zM1000 1000v-100h100v100h-100zM100 800v-100h100v100h-100zM1000 800v-100h100v100h-100zM100 600v-100h100v100h-100zM1000 600v-100h100v100h-100zM875 500h-550q-10 0 -17.5 -7.5t-7.5 -17.5v-350q0 -10 7.5 -17.5 t17.5 -7.5h550q10 0 17.5 7.5t7.5 17.5v350q0 10 -7.5 17.5t-17.5 7.5zM100 400v-100h100v100h-100zM1000 400v-100h100v100h-100zM100 200v-100h100v100h-100zM1000 200v-100h100v100h-100z" />
<glyph unicode="&#xe010;" d="M50 1100h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5zM650 1100h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v400 q0 21 14.5 35.5t35.5 14.5zM50 500h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5zM650 500h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-400 q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe011;" d="M50 1100h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM450 1100h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200 q0 21 14.5 35.5t35.5 14.5zM850 1100h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM50 700h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200 q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM450 700h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM850 700h200q21 0 35.5 -14.5t14.5 -35.5v-200 q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM50 300h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM450 300h200 q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM850 300h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5 t35.5 14.5z" />
<glyph unicode="&#xe012;" d="M50 1100h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM450 1100h700q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-700q-21 0 -35.5 14.5t-14.5 35.5v200 q0 21 14.5 35.5t35.5 14.5zM50 700h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM450 700h700q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-700 q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM50 300h200q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5zM450 300h700q21 0 35.5 -14.5t14.5 -35.5v-200 q0 -21 -14.5 -35.5t-35.5 -14.5h-700q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe013;" d="M465 477l571 571q8 8 18 8t17 -8l177 -177q8 -7 8 -17t-8 -18l-783 -784q-7 -8 -17.5 -8t-17.5 8l-384 384q-8 8 -8 18t8 17l177 177q7 8 17 8t18 -8l171 -171q7 -7 18 -7t18 7z" />
<glyph unicode="&#xe014;" d="M904 1083l178 -179q8 -8 8 -18.5t-8 -17.5l-267 -268l267 -268q8 -7 8 -17.5t-8 -18.5l-178 -178q-8 -8 -18.5 -8t-17.5 8l-268 267l-268 -267q-7 -8 -17.5 -8t-18.5 8l-178 178q-8 8 -8 18.5t8 17.5l267 268l-267 268q-8 7 -8 17.5t8 18.5l178 178q8 8 18.5 8t17.5 -8 l268 -267l268 268q7 7 17.5 7t18.5 -7z" />
<glyph unicode="&#xe015;" d="M507 1177q98 0 187.5 -38.5t154.5 -103.5t103.5 -154.5t38.5 -187.5q0 -141 -78 -262l300 -299q8 -8 8 -18.5t-8 -18.5l-109 -108q-7 -8 -17.5 -8t-18.5 8l-300 299q-119 -77 -261 -77q-98 0 -188 38.5t-154.5 103t-103 154.5t-38.5 188t38.5 187.5t103 154.5 t154.5 103.5t188 38.5zM506.5 1023q-89.5 0 -165.5 -44t-120 -120.5t-44 -166t44 -165.5t120 -120t165.5 -44t166 44t120.5 120t44 165.5t-44 166t-120.5 120.5t-166 44zM425 900h150q10 0 17.5 -7.5t7.5 -17.5v-75h75q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5 t-17.5 -7.5h-75v-75q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v75h-75q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5h75v75q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe016;" d="M507 1177q98 0 187.5 -38.5t154.5 -103.5t103.5 -154.5t38.5 -187.5q0 -141 -78 -262l300 -299q8 -8 8 -18.5t-8 -18.5l-109 -108q-7 -8 -17.5 -8t-18.5 8l-300 299q-119 -77 -261 -77q-98 0 -188 38.5t-154.5 103t-103 154.5t-38.5 188t38.5 187.5t103 154.5 t154.5 103.5t188 38.5zM506.5 1023q-89.5 0 -165.5 -44t-120 -120.5t-44 -166t44 -165.5t120 -120t165.5 -44t166 44t120.5 120t44 165.5t-44 166t-120.5 120.5t-166 44zM325 800h350q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-350q-10 0 -17.5 7.5 t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe017;" d="M550 1200h100q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5zM800 975v166q167 -62 272 -209.5t105 -331.5q0 -117 -45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5 t-184.5 123t-123 184.5t-45.5 224q0 184 105 331.5t272 209.5v-166q-103 -55 -165 -155t-62 -220q0 -116 57 -214.5t155.5 -155.5t214.5 -57t214.5 57t155.5 155.5t57 214.5q0 120 -62 220t-165 155z" />
<glyph unicode="&#xe018;" d="M1025 1200h150q10 0 17.5 -7.5t7.5 -17.5v-1150q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v1150q0 10 7.5 17.5t17.5 7.5zM725 800h150q10 0 17.5 -7.5t7.5 -17.5v-750q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v750 q0 10 7.5 17.5t17.5 7.5zM425 500h150q10 0 17.5 -7.5t7.5 -17.5v-450q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v450q0 10 7.5 17.5t17.5 7.5zM125 300h150q10 0 17.5 -7.5t7.5 -17.5v-250q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5 v250q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe019;" d="M600 1174q33 0 74 -5l38 -152l5 -1q49 -14 94 -39l5 -2l134 80q61 -48 104 -105l-80 -134l3 -5q25 -44 39 -93l1 -6l152 -38q5 -43 5 -73q0 -34 -5 -74l-152 -38l-1 -6q-15 -49 -39 -93l-3 -5l80 -134q-48 -61 -104 -105l-134 81l-5 -3q-44 -25 -94 -39l-5 -2l-38 -151 q-43 -5 -74 -5q-33 0 -74 5l-38 151l-5 2q-49 14 -94 39l-5 3l-134 -81q-60 48 -104 105l80 134l-3 5q-25 45 -38 93l-2 6l-151 38q-6 42 -6 74q0 33 6 73l151 38l2 6q13 48 38 93l3 5l-80 134q47 61 105 105l133 -80l5 2q45 25 94 39l5 1l38 152q43 5 74 5zM600 815 q-89 0 -152 -63t-63 -151.5t63 -151.5t152 -63t152 63t63 151.5t-63 151.5t-152 63z" />
<glyph unicode="&#xe020;" d="M500 1300h300q41 0 70.5 -29.5t29.5 -70.5v-100h275q10 0 17.5 -7.5t7.5 -17.5v-75h-1100v75q0 10 7.5 17.5t17.5 7.5h275v100q0 41 29.5 70.5t70.5 29.5zM500 1200v-100h300v100h-300zM1100 900v-800q0 -41 -29.5 -70.5t-70.5 -29.5h-700q-41 0 -70.5 29.5t-29.5 70.5 v800h900zM300 800v-700h100v700h-100zM500 800v-700h100v700h-100zM700 800v-700h100v700h-100zM900 800v-700h100v700h-100z" />
<glyph unicode="&#xe021;" d="M18 618l620 608q8 7 18.5 7t17.5 -7l608 -608q8 -8 5.5 -13t-12.5 -5h-175v-575q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v375h-300v-375q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v575h-175q-10 0 -12.5 5t5.5 13z" />
<glyph unicode="&#xe022;" d="M600 1200v-400q0 -41 29.5 -70.5t70.5 -29.5h300v-650q0 -21 -14.5 -35.5t-35.5 -14.5h-800q-21 0 -35.5 14.5t-14.5 35.5v1100q0 21 14.5 35.5t35.5 14.5h450zM1000 800h-250q-21 0 -35.5 14.5t-14.5 35.5v250z" />
<glyph unicode="&#xe023;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM600 1027q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5t57 -214.5 t155.5 -155.5t214.5 -57t214.5 57t155.5 155.5t57 214.5t-57 214.5t-155.5 155.5t-214.5 57zM525 900h50q10 0 17.5 -7.5t7.5 -17.5v-275h175q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v350q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe024;" d="M1300 0h-538l-41 400h-242l-41 -400h-538l431 1200h209l-21 -300h162l-20 300h208zM515 800l-27 -300h224l-27 300h-170z" />
<glyph unicode="&#xe025;" d="M550 1200h200q21 0 35.5 -14.5t14.5 -35.5v-450h191q20 0 25.5 -11.5t-7.5 -27.5l-327 -400q-13 -16 -32 -16t-32 16l-327 400q-13 16 -7.5 27.5t25.5 11.5h191v450q0 21 14.5 35.5t35.5 14.5zM1125 400h50q10 0 17.5 -7.5t7.5 -17.5v-350q0 -10 -7.5 -17.5t-17.5 -7.5 h-1050q-10 0 -17.5 7.5t-7.5 17.5v350q0 10 7.5 17.5t17.5 7.5h50q10 0 17.5 -7.5t7.5 -17.5v-175h900v175q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe026;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM600 1027q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5t57 -214.5 t155.5 -155.5t214.5 -57t214.5 57t155.5 155.5t57 214.5t-57 214.5t-155.5 155.5t-214.5 57zM525 900h150q10 0 17.5 -7.5t7.5 -17.5v-275h137q21 0 26 -11.5t-8 -27.5l-223 -275q-13 -16 -32 -16t-32 16l-223 275q-13 16 -8 27.5t26 11.5h137v275q0 10 7.5 17.5t17.5 7.5z " />
<glyph unicode="&#xe027;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM600 1027q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5t57 -214.5 t155.5 -155.5t214.5 -57t214.5 57t155.5 155.5t57 214.5t-57 214.5t-155.5 155.5t-214.5 57zM632 914l223 -275q13 -16 8 -27.5t-26 -11.5h-137v-275q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v275h-137q-21 0 -26 11.5t8 27.5l223 275q13 16 32 16 t32 -16z" />
<glyph unicode="&#xe028;" d="M225 1200h750q10 0 19.5 -7t12.5 -17l186 -652q7 -24 7 -49v-425q0 -12 -4 -27t-9 -17q-12 -6 -37 -6h-1100q-12 0 -27 4t-17 8q-6 13 -6 38l1 425q0 25 7 49l185 652q3 10 12.5 17t19.5 7zM878 1000h-556q-10 0 -19 -7t-11 -18l-87 -450q-2 -11 4 -18t16 -7h150 q10 0 19.5 -7t11.5 -17l38 -152q2 -10 11.5 -17t19.5 -7h250q10 0 19.5 7t11.5 17l38 152q2 10 11.5 17t19.5 7h150q10 0 16 7t4 18l-87 450q-2 11 -11 18t-19 7z" />
<glyph unicode="&#xe029;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM600 1027q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5t57 -214.5 t155.5 -155.5t214.5 -57t214.5 57t155.5 155.5t57 214.5t-57 214.5t-155.5 155.5t-214.5 57zM540 820l253 -190q17 -12 17 -30t-17 -30l-253 -190q-16 -12 -28 -6.5t-12 26.5v400q0 21 12 26.5t28 -6.5z" />
<glyph unicode="&#xe030;" d="M947 1060l135 135q7 7 12.5 5t5.5 -13v-362q0 -10 -7.5 -17.5t-17.5 -7.5h-362q-11 0 -13 5.5t5 12.5l133 133q-109 76 -238 76q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5t57 -214.5t155.5 -155.5t214.5 -57t214.5 57t155.5 155.5t57 214.5h150q0 -117 -45.5 -224 t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5q192 0 347 -117z" />
<glyph unicode="&#xe031;" d="M947 1060l135 135q7 7 12.5 5t5.5 -13v-361q0 -11 -7.5 -18.5t-18.5 -7.5h-361q-11 0 -13 5.5t5 12.5l134 134q-110 75 -239 75q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5h-150q0 117 45.5 224t123 184.5t184.5 123t224 45.5q192 0 347 -117zM1027 600h150 q0 -117 -45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5q-192 0 -348 118l-134 -134q-7 -8 -12.5 -5.5t-5.5 12.5v360q0 11 7.5 18.5t18.5 7.5h360q10 0 12.5 -5.5t-5.5 -12.5l-133 -133q110 -76 240 -76q116 0 214.5 57t155.5 155.5t57 214.5z" />
<glyph unicode="&#xe032;" d="M125 1200h1050q10 0 17.5 -7.5t7.5 -17.5v-1150q0 -10 -7.5 -17.5t-17.5 -7.5h-1050q-10 0 -17.5 7.5t-7.5 17.5v1150q0 10 7.5 17.5t17.5 7.5zM1075 1000h-850q-10 0 -17.5 -7.5t-7.5 -17.5v-850q0 -10 7.5 -17.5t17.5 -7.5h850q10 0 17.5 7.5t7.5 17.5v850 q0 10 -7.5 17.5t-17.5 7.5zM325 900h50q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-50q-10 0 -17.5 7.5t-7.5 17.5v50q0 10 7.5 17.5t17.5 7.5zM525 900h450q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-450q-10 0 -17.5 7.5t-7.5 17.5v50 q0 10 7.5 17.5t17.5 7.5zM325 700h50q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-50q-10 0 -17.5 7.5t-7.5 17.5v50q0 10 7.5 17.5t17.5 7.5zM525 700h450q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-450q-10 0 -17.5 7.5t-7.5 17.5v50 q0 10 7.5 17.5t17.5 7.5zM325 500h50q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-50q-10 0 -17.5 7.5t-7.5 17.5v50q0 10 7.5 17.5t17.5 7.5zM525 500h450q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-450q-10 0 -17.5 7.5t-7.5 17.5v50 q0 10 7.5 17.5t17.5 7.5zM325 300h50q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-50q-10 0 -17.5 7.5t-7.5 17.5v50q0 10 7.5 17.5t17.5 7.5zM525 300h450q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-450q-10 0 -17.5 7.5t-7.5 17.5v50 q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe033;" d="M900 800v200q0 83 -58.5 141.5t-141.5 58.5h-300q-82 0 -141 -59t-59 -141v-200h-100q-41 0 -70.5 -29.5t-29.5 -70.5v-600q0 -41 29.5 -70.5t70.5 -29.5h900q41 0 70.5 29.5t29.5 70.5v600q0 41 -29.5 70.5t-70.5 29.5h-100zM400 800v150q0 21 15 35.5t35 14.5h200 q20 0 35 -14.5t15 -35.5v-150h-300z" />
<glyph unicode="&#xe034;" d="M125 1100h50q10 0 17.5 -7.5t7.5 -17.5v-1075h-100v1075q0 10 7.5 17.5t17.5 7.5zM1075 1052q4 0 9 -2q16 -6 16 -23v-421q0 -6 -3 -12q-33 -59 -66.5 -99t-65.5 -58t-56.5 -24.5t-52.5 -6.5q-26 0 -57.5 6.5t-52.5 13.5t-60 21q-41 15 -63 22.5t-57.5 15t-65.5 7.5 q-85 0 -160 -57q-7 -5 -15 -5q-6 0 -11 3q-14 7 -14 22v438q22 55 82 98.5t119 46.5q23 2 43 0.5t43 -7t32.5 -8.5t38 -13t32.5 -11q41 -14 63.5 -21t57 -14t63.5 -7q103 0 183 87q7 8 18 8z" />
<glyph unicode="&#xe035;" d="M600 1175q116 0 227 -49.5t192.5 -131t131 -192.5t49.5 -227v-300q0 -10 -7.5 -17.5t-17.5 -7.5h-50q-10 0 -17.5 7.5t-7.5 17.5v300q0 127 -70.5 231.5t-184.5 161.5t-245 57t-245 -57t-184.5 -161.5t-70.5 -231.5v-300q0 -10 -7.5 -17.5t-17.5 -7.5h-50 q-10 0 -17.5 7.5t-7.5 17.5v300q0 116 49.5 227t131 192.5t192.5 131t227 49.5zM220 500h160q8 0 14 -6t6 -14v-460q0 -8 -6 -14t-14 -6h-160q-8 0 -14 6t-6 14v460q0 8 6 14t14 6zM820 500h160q8 0 14 -6t6 -14v-460q0 -8 -6 -14t-14 -6h-160q-8 0 -14 6t-6 14v460 q0 8 6 14t14 6z" />
<glyph unicode="&#xe036;" d="M321 814l258 172q9 6 15 2.5t6 -13.5v-750q0 -10 -6 -13.5t-15 2.5l-258 172q-21 14 -46 14h-250q-10 0 -17.5 7.5t-7.5 17.5v350q0 10 7.5 17.5t17.5 7.5h250q25 0 46 14zM900 668l120 120q7 7 17 7t17 -7l34 -34q7 -7 7 -17t-7 -17l-120 -120l120 -120q7 -7 7 -17 t-7 -17l-34 -34q-7 -7 -17 -7t-17 7l-120 119l-120 -119q-7 -7 -17 -7t-17 7l-34 34q-7 7 -7 17t7 17l119 120l-119 120q-7 7 -7 17t7 17l34 34q7 8 17 8t17 -8z" />
<glyph unicode="&#xe037;" d="M321 814l258 172q9 6 15 2.5t6 -13.5v-750q0 -10 -6 -13.5t-15 2.5l-258 172q-21 14 -46 14h-250q-10 0 -17.5 7.5t-7.5 17.5v350q0 10 7.5 17.5t17.5 7.5h250q25 0 46 14zM766 900h4q10 -1 16 -10q96 -129 96 -290q0 -154 -90 -281q-6 -9 -17 -10l-3 -1q-9 0 -16 6 l-29 23q-7 7 -8.5 16.5t4.5 17.5q72 103 72 229q0 132 -78 238q-6 8 -4.5 18t9.5 17l29 22q7 5 15 5z" />
<glyph unicode="&#xe038;" d="M967 1004h3q11 -1 17 -10q135 -179 135 -396q0 -105 -34 -206.5t-98 -185.5q-7 -9 -17 -10h-3q-9 0 -16 6l-42 34q-8 6 -9 16t5 18q111 150 111 328q0 90 -29.5 176t-84.5 157q-6 9 -5 19t10 16l42 33q7 5 15 5zM321 814l258 172q9 6 15 2.5t6 -13.5v-750q0 -10 -6 -13.5 t-15 2.5l-258 172q-21 14 -46 14h-250q-10 0 -17.5 7.5t-7.5 17.5v350q0 10 7.5 17.5t17.5 7.5h250q25 0 46 14zM766 900h4q10 -1 16 -10q96 -129 96 -290q0 -154 -90 -281q-6 -9 -17 -10l-3 -1q-9 0 -16 6l-29 23q-7 7 -8.5 16.5t4.5 17.5q72 103 72 229q0 132 -78 238 q-6 8 -4.5 18.5t9.5 16.5l29 22q7 5 15 5z" />
<glyph unicode="&#xe039;" d="M500 900h100v-100h-100v-100h-400v-100h-100v600h500v-300zM1200 700h-200v-100h200v-200h-300v300h-200v300h-100v200h600v-500zM100 1100v-300h300v300h-300zM800 1100v-300h300v300h-300zM300 900h-100v100h100v-100zM1000 900h-100v100h100v-100zM300 500h200v-500 h-500v500h200v100h100v-100zM800 300h200v-100h-100v-100h-200v100h-100v100h100v200h-200v100h300v-300zM100 400v-300h300v300h-300zM300 200h-100v100h100v-100zM1200 200h-100v100h100v-100zM700 0h-100v100h100v-100zM1200 0h-300v100h300v-100z" />
<glyph unicode="&#xe040;" d="M100 200h-100v1000h100v-1000zM300 200h-100v1000h100v-1000zM700 200h-200v1000h200v-1000zM900 200h-100v1000h100v-1000zM1200 200h-200v1000h200v-1000zM400 0h-300v100h300v-100zM600 0h-100v91h100v-91zM800 0h-100v91h100v-91zM1100 0h-200v91h200v-91z" />
<glyph unicode="&#xe041;" d="M500 1200l682 -682q8 -8 8 -18t-8 -18l-464 -464q-8 -8 -18 -8t-18 8l-682 682l1 475q0 10 7.5 17.5t17.5 7.5h474zM319.5 1024.5q-29.5 29.5 -71 29.5t-71 -29.5t-29.5 -71.5t29.5 -71.5t71 -29.5t71 29.5t29.5 71.5t-29.5 71.5z" />
<glyph unicode="&#xe042;" d="M500 1200l682 -682q8 -8 8 -18t-8 -18l-464 -464q-8 -8 -18 -8t-18 8l-682 682l1 475q0 10 7.5 17.5t17.5 7.5h474zM800 1200l682 -682q8 -8 8 -18t-8 -18l-464 -464q-8 -8 -18 -8t-18 8l-56 56l424 426l-700 700h150zM319.5 1024.5q-29.5 29.5 -71 29.5t-71 -29.5 t-29.5 -71.5t29.5 -71.5t71 -29.5t71 29.5t29.5 71.5t-29.5 71.5z" />
<glyph unicode="&#xe043;" d="M300 1200h825q75 0 75 -75v-900q0 -25 -18 -43l-64 -64q-8 -8 -13 -5.5t-5 12.5v950q0 10 -7.5 17.5t-17.5 7.5h-700q-25 0 -43 -18l-64 -64q-8 -8 -5.5 -13t12.5 -5h700q10 0 17.5 -7.5t7.5 -17.5v-950q0 -10 -7.5 -17.5t-17.5 -7.5h-850q-10 0 -17.5 7.5t-7.5 17.5v975 q0 25 18 43l139 139q18 18 43 18z" />
<glyph unicode="&#xe044;" d="M250 1200h800q21 0 35.5 -14.5t14.5 -35.5v-1150l-450 444l-450 -445v1151q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe045;" d="M822 1200h-444q-11 0 -19 -7.5t-9 -17.5l-78 -301q-7 -24 7 -45l57 -108q6 -9 17.5 -15t21.5 -6h450q10 0 21.5 6t17.5 15l62 108q14 21 7 45l-83 301q-1 10 -9 17.5t-19 7.5zM1175 800h-150q-10 0 -21 -6.5t-15 -15.5l-78 -156q-4 -9 -15 -15.5t-21 -6.5h-550 q-10 0 -21 6.5t-15 15.5l-78 156q-4 9 -15 15.5t-21 6.5h-150q-10 0 -17.5 -7.5t-7.5 -17.5v-650q0 -10 7.5 -17.5t17.5 -7.5h150q10 0 17.5 7.5t7.5 17.5v150q0 10 7.5 17.5t17.5 7.5h750q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 7.5 -17.5t17.5 -7.5h150q10 0 17.5 7.5 t7.5 17.5v650q0 10 -7.5 17.5t-17.5 7.5zM850 200h-500q-10 0 -19.5 -7t-11.5 -17l-38 -152q-2 -10 3.5 -17t15.5 -7h600q10 0 15.5 7t3.5 17l-38 152q-2 10 -11.5 17t-19.5 7z" />
<glyph unicode="&#xe046;" d="M500 1100h200q56 0 102.5 -20.5t72.5 -50t44 -59t25 -50.5l6 -20h150q41 0 70.5 -29.5t29.5 -70.5v-600q0 -41 -29.5 -70.5t-70.5 -29.5h-1000q-41 0 -70.5 29.5t-29.5 70.5v600q0 41 29.5 70.5t70.5 29.5h150q2 8 6.5 21.5t24 48t45 61t72 48t102.5 21.5zM900 800v-100 h100v100h-100zM600 730q-95 0 -162.5 -67.5t-67.5 -162.5t67.5 -162.5t162.5 -67.5t162.5 67.5t67.5 162.5t-67.5 162.5t-162.5 67.5zM600 603q43 0 73 -30t30 -73t-30 -73t-73 -30t-73 30t-30 73t30 73t73 30z" />
<glyph unicode="&#xe047;" d="M681 1199l385 -998q20 -50 60 -92q18 -19 36.5 -29.5t27.5 -11.5l10 -2v-66h-417v66q53 0 75 43.5t5 88.5l-82 222h-391q-58 -145 -92 -234q-11 -34 -6.5 -57t25.5 -37t46 -20t55 -6v-66h-365v66q56 24 84 52q12 12 25 30.5t20 31.5l7 13l399 1006h93zM416 521h340 l-162 457z" />
<glyph unicode="&#xe048;" d="M753 641q5 -1 14.5 -4.5t36 -15.5t50.5 -26.5t53.5 -40t50.5 -54.5t35.5 -70t14.5 -87q0 -67 -27.5 -125.5t-71.5 -97.5t-98.5 -66.5t-108.5 -40.5t-102 -13h-500v89q41 7 70.5 32.5t29.5 65.5v827q0 24 -0.5 34t-3.5 24t-8.5 19.5t-17 13.5t-28 12.5t-42.5 11.5v71 l471 -1q57 0 115.5 -20.5t108 -57t80.5 -94t31 -124.5q0 -51 -15.5 -96.5t-38 -74.5t-45 -50.5t-38.5 -30.5zM400 700h139q78 0 130.5 48.5t52.5 122.5q0 41 -8.5 70.5t-29.5 55.5t-62.5 39.5t-103.5 13.5h-118v-350zM400 200h216q80 0 121 50.5t41 130.5q0 90 -62.5 154.5 t-156.5 64.5h-159v-400z" />
<glyph unicode="&#xe049;" d="M877 1200l2 -57q-83 -19 -116 -45.5t-40 -66.5l-132 -839q-9 -49 13 -69t96 -26v-97h-500v97q186 16 200 98l173 832q3 17 3 30t-1.5 22.5t-9 17.5t-13.5 12.5t-21.5 10t-26 8.5t-33.5 10q-13 3 -19 5v57h425z" />
<glyph unicode="&#xe050;" d="M1300 900h-50q0 21 -4 37t-9.5 26.5t-18 17.5t-22 11t-28.5 5.5t-31 2t-37 0.5h-200v-850q0 -22 25 -34.5t50 -13.5l25 -2v-100h-400v100q4 0 11 0.5t24 3t30 7t24 15t11 24.5v850h-200q-25 0 -37 -0.5t-31 -2t-28.5 -5.5t-22 -11t-18 -17.5t-9.5 -26.5t-4 -37h-50v300 h1000v-300zM175 1000h-75v-800h75l-125 -167l-125 167h75v800h-75l125 167z" />
<glyph unicode="&#xe051;" d="M1100 900h-50q0 21 -4 37t-9.5 26.5t-18 17.5t-22 11t-28.5 5.5t-31 2t-37 0.5h-200v-650q0 -22 25 -34.5t50 -13.5l25 -2v-100h-400v100q4 0 11 0.5t24 3t30 7t24 15t11 24.5v650h-200q-25 0 -37 -0.5t-31 -2t-28.5 -5.5t-22 -11t-18 -17.5t-9.5 -26.5t-4 -37h-50v300 h1000v-300zM1167 50l-167 -125v75h-800v-75l-167 125l167 125v-75h800v75z" />
<glyph unicode="&#xe052;" d="M50 1100h600q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-600q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 800h1000q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1000q-21 0 -35.5 14.5t-14.5 35.5v100 q0 21 14.5 35.5t35.5 14.5zM50 500h800q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-800q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 200h1100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1100 q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe053;" d="M250 1100h700q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-700q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 800h1100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1100q-21 0 -35.5 14.5t-14.5 35.5v100 q0 21 14.5 35.5t35.5 14.5zM250 500h700q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-700q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 200h1100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1100 q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe054;" d="M500 950v100q0 21 14.5 35.5t35.5 14.5h600q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-600q-21 0 -35.5 14.5t-14.5 35.5zM100 650v100q0 21 14.5 35.5t35.5 14.5h1000q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1000 q-21 0 -35.5 14.5t-14.5 35.5zM300 350v100q0 21 14.5 35.5t35.5 14.5h800q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-800q-21 0 -35.5 14.5t-14.5 35.5zM0 50v100q0 21 14.5 35.5t35.5 14.5h1100q21 0 35.5 -14.5t14.5 -35.5v-100 q0 -21 -14.5 -35.5t-35.5 -14.5h-1100q-21 0 -35.5 14.5t-14.5 35.5z" />
<glyph unicode="&#xe055;" d="M50 1100h1100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1100q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 800h1100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1100q-21 0 -35.5 14.5t-14.5 35.5v100 q0 21 14.5 35.5t35.5 14.5zM50 500h1100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1100q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 200h1100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1100 q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe056;" d="M50 1100h100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM350 1100h800q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-800q-21 0 -35.5 14.5t-14.5 35.5v100 q0 21 14.5 35.5t35.5 14.5zM50 800h100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM350 800h800q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-800 q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 500h100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM350 500h800q21 0 35.5 -14.5t14.5 -35.5v-100 q0 -21 -14.5 -35.5t-35.5 -14.5h-800q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 200h100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM350 200h800 q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-800q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe057;" d="M400 0h-100v1100h100v-1100zM550 1100h100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM550 800h500q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-500 q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM267 550l-167 -125v75h-200v100h200v75zM550 500h300q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-300q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM550 200h600 q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-600q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe058;" d="M50 1100h100q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM900 0h-100v1100h100v-1100zM50 800h500q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-500 q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM1100 600h200v-100h-200v-75l-167 125l167 125v-75zM50 500h300q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-300q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5zM50 200h600 q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-600q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe059;" d="M75 1000h750q31 0 53 -22t22 -53v-650q0 -31 -22 -53t-53 -22h-750q-31 0 -53 22t-22 53v650q0 31 22 53t53 22zM1200 300l-300 300l300 300v-600z" />
<glyph unicode="&#xe060;" d="M44 1100h1112q18 0 31 -13t13 -31v-1012q0 -18 -13 -31t-31 -13h-1112q-18 0 -31 13t-13 31v1012q0 18 13 31t31 13zM100 1000v-737l247 182l298 -131l-74 156l293 318l236 -288v500h-1000zM342 884q56 0 95 -39t39 -94.5t-39 -95t-95 -39.5t-95 39.5t-39 95t39 94.5 t95 39z" />
<glyph unicode="&#xe062;" d="M648 1169q117 0 216 -60t156.5 -161t57.5 -218q0 -115 -70 -258q-69 -109 -158 -225.5t-143 -179.5l-54 -62q-9 8 -25.5 24.5t-63.5 67.5t-91 103t-98.5 128t-95.5 148q-60 132 -60 249q0 88 34 169.5t91.5 142t137 96.5t166.5 36zM652.5 974q-91.5 0 -156.5 -65 t-65 -157t65 -156.5t156.5 -64.5t156.5 64.5t65 156.5t-65 157t-156.5 65z" />
<glyph unicode="&#xe063;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM600 173v854q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5t57 -214.5 t155.5 -155.5t214.5 -57z" />
<glyph unicode="&#xe064;" d="M554 1295q21 -72 57.5 -143.5t76 -130t83 -118t82.5 -117t70 -116t49.5 -126t18.5 -136.5q0 -71 -25.5 -135t-68.5 -111t-99 -82t-118.5 -54t-125.5 -23q-84 5 -161.5 34t-139.5 78.5t-99 125t-37 164.5q0 69 18 136.5t49.5 126.5t69.5 116.5t81.5 117.5t83.5 119 t76.5 131t58.5 143zM344 710q-23 -33 -43.5 -70.5t-40.5 -102.5t-17 -123q1 -37 14.5 -69.5t30 -52t41 -37t38.5 -24.5t33 -15q21 -7 32 -1t13 22l6 34q2 10 -2.5 22t-13.5 19q-5 4 -14 12t-29.5 40.5t-32.5 73.5q-26 89 6 271q2 11 -6 11q-8 1 -15 -10z" />
<glyph unicode="&#xe065;" d="M1000 1013l108 115q2 1 5 2t13 2t20.5 -1t25 -9.5t28.5 -21.5q22 -22 27 -43t0 -32l-6 -10l-108 -115zM350 1100h400q50 0 105 -13l-187 -187h-368q-41 0 -70.5 -29.5t-29.5 -70.5v-500q0 -41 29.5 -70.5t70.5 -29.5h500q41 0 70.5 29.5t29.5 70.5v182l200 200v-332 q0 -165 -93.5 -257.5t-256.5 -92.5h-400q-165 0 -257.5 92.5t-92.5 257.5v400q0 165 92.5 257.5t257.5 92.5zM1009 803l-362 -362l-161 -50l55 170l355 355z" />
<glyph unicode="&#xe066;" d="M350 1100h361q-164 -146 -216 -200h-195q-41 0 -70.5 -29.5t-29.5 -70.5v-500q0 -41 29.5 -70.5t70.5 -29.5h500q41 0 70.5 29.5t29.5 70.5l200 153v-103q0 -165 -92.5 -257.5t-257.5 -92.5h-400q-165 0 -257.5 92.5t-92.5 257.5v400q0 165 92.5 257.5t257.5 92.5z M824 1073l339 -301q8 -7 8 -17.5t-8 -17.5l-340 -306q-7 -6 -12.5 -4t-6.5 11v203q-26 1 -54.5 0t-78.5 -7.5t-92 -17.5t-86 -35t-70 -57q10 59 33 108t51.5 81.5t65 58.5t68.5 40.5t67 24.5t56 13.5t40 4.5v210q1 10 6.5 12.5t13.5 -4.5z" />
<glyph unicode="&#xe067;" d="M350 1100h350q60 0 127 -23l-178 -177h-349q-41 0 -70.5 -29.5t-29.5 -70.5v-500q0 -41 29.5 -70.5t70.5 -29.5h500q41 0 70.5 29.5t29.5 70.5v69l200 200v-219q0 -165 -92.5 -257.5t-257.5 -92.5h-400q-165 0 -257.5 92.5t-92.5 257.5v400q0 165 92.5 257.5t257.5 92.5z M643 639l395 395q7 7 17.5 7t17.5 -7l101 -101q7 -7 7 -17.5t-7 -17.5l-531 -532q-7 -7 -17.5 -7t-17.5 7l-248 248q-7 7 -7 17.5t7 17.5l101 101q7 7 17.5 7t17.5 -7l111 -111q8 -7 18 -7t18 7z" />
<glyph unicode="&#xe068;" d="M318 918l264 264q8 8 18 8t18 -8l260 -264q7 -8 4.5 -13t-12.5 -5h-170v-200h200v173q0 10 5 12t13 -5l264 -260q8 -7 8 -17.5t-8 -17.5l-264 -265q-8 -7 -13 -5t-5 12v173h-200v-200h170q10 0 12.5 -5t-4.5 -13l-260 -264q-8 -8 -18 -8t-18 8l-264 264q-8 8 -5.5 13 t12.5 5h175v200h-200v-173q0 -10 -5 -12t-13 5l-264 265q-8 7 -8 17.5t8 17.5l264 260q8 7 13 5t5 -12v-173h200v200h-175q-10 0 -12.5 5t5.5 13z" />
<glyph unicode="&#xe069;" d="M250 1100h100q21 0 35.5 -14.5t14.5 -35.5v-438l464 453q15 14 25.5 10t10.5 -25v-1000q0 -21 -10.5 -25t-25.5 10l-464 453v-438q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v1000q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe070;" d="M50 1100h100q21 0 35.5 -14.5t14.5 -35.5v-438l464 453q15 14 25.5 10t10.5 -25v-438l464 453q15 14 25.5 10t10.5 -25v-1000q0 -21 -10.5 -25t-25.5 10l-464 453v-438q0 -21 -10.5 -25t-25.5 10l-464 453v-438q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5 t-14.5 35.5v1000q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe071;" d="M1200 1050v-1000q0 -21 -10.5 -25t-25.5 10l-464 453v-438q0 -21 -10.5 -25t-25.5 10l-492 480q-15 14 -15 35t15 35l492 480q15 14 25.5 10t10.5 -25v-438l464 453q15 14 25.5 10t10.5 -25z" />
<glyph unicode="&#xe072;" d="M243 1074l814 -498q18 -11 18 -26t-18 -26l-814 -498q-18 -11 -30.5 -4t-12.5 28v1000q0 21 12.5 28t30.5 -4z" />
<glyph unicode="&#xe073;" d="M250 1000h200q21 0 35.5 -14.5t14.5 -35.5v-800q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v800q0 21 14.5 35.5t35.5 14.5zM650 1000h200q21 0 35.5 -14.5t14.5 -35.5v-800q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v800 q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe074;" d="M1100 950v-800q0 -21 -14.5 -35.5t-35.5 -14.5h-800q-21 0 -35.5 14.5t-14.5 35.5v800q0 21 14.5 35.5t35.5 14.5h800q21 0 35.5 -14.5t14.5 -35.5z" />
<glyph unicode="&#xe075;" d="M500 612v438q0 21 10.5 25t25.5 -10l492 -480q15 -14 15 -35t-15 -35l-492 -480q-15 -14 -25.5 -10t-10.5 25v438l-464 -453q-15 -14 -25.5 -10t-10.5 25v1000q0 21 10.5 25t25.5 -10z" />
<glyph unicode="&#xe076;" d="M1048 1102l100 1q20 0 35 -14.5t15 -35.5l5 -1000q0 -21 -14.5 -35.5t-35.5 -14.5l-100 -1q-21 0 -35.5 14.5t-14.5 35.5l-2 437l-463 -454q-14 -15 -24.5 -10.5t-10.5 25.5l-2 437l-462 -455q-15 -14 -25.5 -9.5t-10.5 24.5l-5 1000q0 21 10.5 25.5t25.5 -10.5l466 -450 l-2 438q0 20 10.5 24.5t25.5 -9.5l466 -451l-2 438q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe077;" d="M850 1100h100q21 0 35.5 -14.5t14.5 -35.5v-1000q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v438l-464 -453q-15 -14 -25.5 -10t-10.5 25v1000q0 21 10.5 25t25.5 -10l464 -453v438q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe078;" d="M686 1081l501 -540q15 -15 10.5 -26t-26.5 -11h-1042q-22 0 -26.5 11t10.5 26l501 540q15 15 36 15t36 -15zM150 400h1000q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1000q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe079;" d="M885 900l-352 -353l352 -353l-197 -198l-552 552l552 550z" />
<glyph unicode="&#xe080;" d="M1064 547l-551 -551l-198 198l353 353l-353 353l198 198z" />
<glyph unicode="&#xe081;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM650 900h-100q-21 0 -35.5 -14.5t-14.5 -35.5v-150h-150 q-21 0 -35.5 -14.5t-14.5 -35.5v-100q0 -21 14.5 -35.5t35.5 -14.5h150v-150q0 -21 14.5 -35.5t35.5 -14.5h100q21 0 35.5 14.5t14.5 35.5v150h150q21 0 35.5 14.5t14.5 35.5v100q0 21 -14.5 35.5t-35.5 14.5h-150v150q0 21 -14.5 35.5t-35.5 14.5z" />
<glyph unicode="&#xe082;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM850 700h-500q-21 0 -35.5 -14.5t-14.5 -35.5v-100q0 -21 14.5 -35.5 t35.5 -14.5h500q21 0 35.5 14.5t14.5 35.5v100q0 21 -14.5 35.5t-35.5 14.5z" />
<glyph unicode="&#xe083;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM741.5 913q-12.5 0 -21.5 -9l-120 -120l-120 120q-9 9 -21.5 9 t-21.5 -9l-141 -141q-9 -9 -9 -21.5t9 -21.5l120 -120l-120 -120q-9 -9 -9 -21.5t9 -21.5l141 -141q9 -9 21.5 -9t21.5 9l120 120l120 -120q9 -9 21.5 -9t21.5 9l141 141q9 9 9 21.5t-9 21.5l-120 120l120 120q9 9 9 21.5t-9 21.5l-141 141q-9 9 -21.5 9z" />
<glyph unicode="&#xe084;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM546 623l-84 85q-7 7 -17.5 7t-18.5 -7l-139 -139q-7 -8 -7 -18t7 -18 l242 -241q7 -8 17.5 -8t17.5 8l375 375q7 7 7 17.5t-7 18.5l-139 139q-7 7 -17.5 7t-17.5 -7z" />
<glyph unicode="&#xe085;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM588 941q-29 0 -59 -5.5t-63 -20.5t-58 -38.5t-41.5 -63t-16.5 -89.5 q0 -25 20 -25h131q30 -5 35 11q6 20 20.5 28t45.5 8q20 0 31.5 -10.5t11.5 -28.5q0 -23 -7 -34t-26 -18q-1 0 -13.5 -4t-19.5 -7.5t-20 -10.5t-22 -17t-18.5 -24t-15.5 -35t-8 -46q-1 -8 5.5 -16.5t20.5 -8.5h173q7 0 22 8t35 28t37.5 48t29.5 74t12 100q0 47 -17 83 t-42.5 57t-59.5 34.5t-64 18t-59 4.5zM675 400h-150q-10 0 -17.5 -7.5t-7.5 -17.5v-150q0 -10 7.5 -17.5t17.5 -7.5h150q10 0 17.5 7.5t7.5 17.5v150q0 10 -7.5 17.5t-17.5 7.5z" />
<glyph unicode="&#xe086;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM675 1000h-150q-10 0 -17.5 -7.5t-7.5 -17.5v-150q0 -10 7.5 -17.5 t17.5 -7.5h150q10 0 17.5 7.5t7.5 17.5v150q0 10 -7.5 17.5t-17.5 7.5zM675 700h-250q-10 0 -17.5 -7.5t-7.5 -17.5v-50q0 -10 7.5 -17.5t17.5 -7.5h75v-200h-75q-10 0 -17.5 -7.5t-7.5 -17.5v-50q0 -10 7.5 -17.5t17.5 -7.5h350q10 0 17.5 7.5t7.5 17.5v50q0 10 -7.5 17.5 t-17.5 7.5h-75v275q0 10 -7.5 17.5t-17.5 7.5z" />
<glyph unicode="&#xe087;" d="M525 1200h150q10 0 17.5 -7.5t7.5 -17.5v-194q103 -27 178.5 -102.5t102.5 -178.5h194q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-194q-27 -103 -102.5 -178.5t-178.5 -102.5v-194q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v194 q-103 27 -178.5 102.5t-102.5 178.5h-194q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5h194q27 103 102.5 178.5t178.5 102.5v194q0 10 7.5 17.5t17.5 7.5zM700 893v-168q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v168q-68 -23 -119 -74 t-74 -119h168q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-168q23 -68 74 -119t119 -74v168q0 10 7.5 17.5t17.5 7.5h150q10 0 17.5 -7.5t7.5 -17.5v-168q68 23 119 74t74 119h-168q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5h168 q-23 68 -74 119t-119 74z" />
<glyph unicode="&#xe088;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM600 1027q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5t57 -214.5 t155.5 -155.5t214.5 -57t214.5 57t155.5 155.5t57 214.5t-57 214.5t-155.5 155.5t-214.5 57zM759 823l64 -64q7 -7 7 -17.5t-7 -17.5l-124 -124l124 -124q7 -7 7 -17.5t-7 -17.5l-64 -64q-7 -7 -17.5 -7t-17.5 7l-124 124l-124 -124q-7 -7 -17.5 -7t-17.5 7l-64 64 q-7 7 -7 17.5t7 17.5l124 124l-124 124q-7 7 -7 17.5t7 17.5l64 64q7 7 17.5 7t17.5 -7l124 -124l124 124q7 7 17.5 7t17.5 -7z" />
<glyph unicode="&#xe089;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM600 1027q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5t57 -214.5 t155.5 -155.5t214.5 -57t214.5 57t155.5 155.5t57 214.5t-57 214.5t-155.5 155.5t-214.5 57zM782 788l106 -106q7 -7 7 -17.5t-7 -17.5l-320 -321q-8 -7 -18 -7t-18 7l-202 203q-8 7 -8 17.5t8 17.5l106 106q7 8 17.5 8t17.5 -8l79 -79l197 197q7 7 17.5 7t17.5 -7z" />
<glyph unicode="&#xe090;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM600 1027q-116 0 -214.5 -57t-155.5 -155.5t-57 -214.5q0 -120 65 -225 l587 587q-105 65 -225 65zM965 819l-584 -584q104 -62 219 -62q116 0 214.5 57t155.5 155.5t57 214.5q0 115 -62 219z" />
<glyph unicode="&#xe091;" d="M39 582l522 427q16 13 27.5 8t11.5 -26v-291h550q21 0 35.5 -14.5t14.5 -35.5v-200q0 -21 -14.5 -35.5t-35.5 -14.5h-550v-291q0 -21 -11.5 -26t-27.5 8l-522 427q-16 13 -16 32t16 32z" />
<glyph unicode="&#xe092;" d="M639 1009l522 -427q16 -13 16 -32t-16 -32l-522 -427q-16 -13 -27.5 -8t-11.5 26v291h-550q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5h550v291q0 21 11.5 26t27.5 -8z" />
<glyph unicode="&#xe093;" d="M682 1161l427 -522q13 -16 8 -27.5t-26 -11.5h-291v-550q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v550h-291q-21 0 -26 11.5t8 27.5l427 522q13 16 32 16t32 -16z" />
<glyph unicode="&#xe094;" d="M550 1200h200q21 0 35.5 -14.5t14.5 -35.5v-550h291q21 0 26 -11.5t-8 -27.5l-427 -522q-13 -16 -32 -16t-32 16l-427 522q-13 16 -8 27.5t26 11.5h291v550q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe095;" d="M639 1109l522 -427q16 -13 16 -32t-16 -32l-522 -427q-16 -13 -27.5 -8t-11.5 26v291q-94 -2 -182 -20t-170.5 -52t-147 -92.5t-100.5 -135.5q5 105 27 193.5t67.5 167t113 135t167 91.5t225.5 42v262q0 21 11.5 26t27.5 -8z" />
<glyph unicode="&#xe096;" d="M850 1200h300q21 0 35.5 -14.5t14.5 -35.5v-300q0 -21 -10.5 -25t-24.5 10l-94 94l-249 -249q-8 -7 -18 -7t-18 7l-106 106q-7 8 -7 18t7 18l249 249l-94 94q-14 14 -10 24.5t25 10.5zM350 0h-300q-21 0 -35.5 14.5t-14.5 35.5v300q0 21 10.5 25t24.5 -10l94 -94l249 249 q8 7 18 7t18 -7l106 -106q7 -8 7 -18t-7 -18l-249 -249l94 -94q14 -14 10 -24.5t-25 -10.5z" />
<glyph unicode="&#xe097;" d="M1014 1120l106 -106q7 -8 7 -18t-7 -18l-249 -249l94 -94q14 -14 10 -24.5t-25 -10.5h-300q-21 0 -35.5 14.5t-14.5 35.5v300q0 21 10.5 25t24.5 -10l94 -94l249 249q8 7 18 7t18 -7zM250 600h300q21 0 35.5 -14.5t14.5 -35.5v-300q0 -21 -10.5 -25t-24.5 10l-94 94 l-249 -249q-8 -7 -18 -7t-18 7l-106 106q-7 8 -7 18t7 18l249 249l-94 94q-14 14 -10 24.5t25 10.5z" />
<glyph unicode="&#xe101;" d="M600 1177q117 0 224 -45.5t184.5 -123t123 -184.5t45.5 -224t-45.5 -224t-123 -184.5t-184.5 -123t-224 -45.5t-224 45.5t-184.5 123t-123 184.5t-45.5 224t45.5 224t123 184.5t184.5 123t224 45.5zM704 900h-208q-20 0 -32 -14.5t-8 -34.5l58 -302q4 -20 21.5 -34.5 t37.5 -14.5h54q20 0 37.5 14.5t21.5 34.5l58 302q4 20 -8 34.5t-32 14.5zM675 400h-150q-10 0 -17.5 -7.5t-7.5 -17.5v-150q0 -10 7.5 -17.5t17.5 -7.5h150q10 0 17.5 7.5t7.5 17.5v150q0 10 -7.5 17.5t-17.5 7.5z" />
<glyph unicode="&#xe102;" d="M260 1200q9 0 19 -2t15 -4l5 -2q22 -10 44 -23l196 -118q21 -13 36 -24q29 -21 37 -12q11 13 49 35l196 118q22 13 45 23q17 7 38 7q23 0 47 -16.5t37 -33.5l13 -16q14 -21 18 -45l25 -123l8 -44q1 -9 8.5 -14.5t17.5 -5.5h61q10 0 17.5 -7.5t7.5 -17.5v-50 q0 -10 -7.5 -17.5t-17.5 -7.5h-50q-10 0 -17.5 -7.5t-7.5 -17.5v-175h-400v300h-200v-300h-400v175q0 10 -7.5 17.5t-17.5 7.5h-50q-10 0 -17.5 7.5t-7.5 17.5v50q0 10 7.5 17.5t17.5 7.5h61q11 0 18 3t7 8q0 4 9 52l25 128q5 25 19 45q2 3 5 7t13.5 15t21.5 19.5t26.5 15.5 t29.5 7zM915 1079l-166 -162q-7 -7 -5 -12t12 -5h219q10 0 15 7t2 17l-51 149q-3 10 -11 12t-15 -6zM463 917l-177 157q-8 7 -16 5t-11 -12l-51 -143q-3 -10 2 -17t15 -7h231q11 0 12.5 5t-5.5 12zM500 0h-375q-10 0 -17.5 7.5t-7.5 17.5v375h400v-400zM1100 400v-375 q0 -10 -7.5 -17.5t-17.5 -7.5h-375v400h400z" />
<glyph unicode="&#xe103;" d="M1165 1190q8 3 21 -6.5t13 -17.5q-2 -178 -24.5 -323.5t-55.5 -245.5t-87 -174.5t-102.5 -118.5t-118 -68.5t-118.5 -33t-120 -4.5t-105 9.5t-90 16.5q-61 12 -78 11q-4 1 -12.5 0t-34 -14.5t-52.5 -40.5l-153 -153q-26 -24 -37 -14.5t-11 43.5q0 64 42 102q8 8 50.5 45 t66.5 58q19 17 35 47t13 61q-9 55 -10 102.5t7 111t37 130t78 129.5q39 51 80 88t89.5 63.5t94.5 45t113.5 36t129 31t157.5 37t182 47.5zM1116 1098q-8 9 -22.5 -3t-45.5 -50q-38 -47 -119 -103.5t-142 -89.5l-62 -33q-56 -30 -102 -57t-104 -68t-102.5 -80.5t-85.5 -91 t-64 -104.5q-24 -56 -31 -86t2 -32t31.5 17.5t55.5 59.5q25 30 94 75.5t125.5 77.5t147.5 81q70 37 118.5 69t102 79.5t99 111t86.5 148.5q22 50 24 60t-6 19z" />
<glyph unicode="&#xe104;" d="M653 1231q-39 -67 -54.5 -131t-10.5 -114.5t24.5 -96.5t47.5 -80t63.5 -62.5t68.5 -46.5t65 -30q-4 7 -17.5 35t-18.5 39.5t-17 39.5t-17 43t-13 42t-9.5 44.5t-2 42t4 43t13.5 39t23 38.5q96 -42 165 -107.5t105 -138t52 -156t13 -159t-19 -149.5q-13 -55 -44 -106.5 t-68 -87t-78.5 -64.5t-72.5 -45t-53 -22q-72 -22 -127 -11q-31 6 -13 19q6 3 17 7q13 5 32.5 21t41 44t38.5 63.5t21.5 81.5t-6.5 94.5t-50 107t-104 115.5q10 -104 -0.5 -189t-37 -140.5t-65 -93t-84 -52t-93.5 -11t-95 24.5q-80 36 -131.5 114t-53.5 171q-2 23 0 49.5 t4.5 52.5t13.5 56t27.5 60t46 64.5t69.5 68.5q-8 -53 -5 -102.5t17.5 -90t34 -68.5t44.5 -39t49 -2q31 13 38.5 36t-4.5 55t-29 64.5t-36 75t-26 75.5q-15 85 2 161.5t53.5 128.5t85.5 92.5t93.5 61t81.5 25.5z" />
<glyph unicode="&#xe105;" d="M600 1094q82 0 160.5 -22.5t140 -59t116.5 -82.5t94.5 -95t68 -95t42.5 -82.5t14 -57.5t-14 -57.5t-43 -82.5t-68.5 -95t-94.5 -95t-116.5 -82.5t-140 -59t-159.5 -22.5t-159.5 22.5t-140 59t-116.5 82.5t-94.5 95t-68.5 95t-43 82.5t-14 57.5t14 57.5t42.5 82.5t68 95 t94.5 95t116.5 82.5t140 59t160.5 22.5zM888 829q-15 15 -18 12t5 -22q25 -57 25 -119q0 -124 -88 -212t-212 -88t-212 88t-88 212q0 59 23 114q8 19 4.5 22t-17.5 -12q-70 -69 -160 -184q-13 -16 -15 -40.5t9 -42.5q22 -36 47 -71t70 -82t92.5 -81t113 -58.5t133.5 -24.5 t133.5 24t113 58.5t92.5 81.5t70 81.5t47 70.5q11 18 9 42.5t-14 41.5q-90 117 -163 189zM448 727l-35 -36q-15 -15 -19.5 -38.5t4.5 -41.5q37 -68 93 -116q16 -13 38.5 -11t36.5 17l35 34q14 15 12.5 33.5t-16.5 33.5q-44 44 -89 117q-11 18 -28 20t-32 -12z" />
<glyph unicode="&#xe106;" d="M592 0h-148l31 120q-91 20 -175.5 68.5t-143.5 106.5t-103.5 119t-66.5 110t-22 76q0 21 14 57.5t42.5 82.5t68 95t94.5 95t116.5 82.5t140 59t160.5 22.5q61 0 126 -15l32 121h148zM944 770l47 181q108 -85 176.5 -192t68.5 -159q0 -26 -19.5 -71t-59.5 -102t-93 -112 t-129 -104.5t-158 -75.5l46 173q77 49 136 117t97 131q11 18 9 42.5t-14 41.5q-54 70 -107 130zM310 824q-70 -69 -160 -184q-13 -16 -15 -40.5t9 -42.5q18 -30 39 -60t57 -70.5t74 -73t90 -61t105 -41.5l41 154q-107 18 -178.5 101.5t-71.5 193.5q0 59 23 114q8 19 4.5 22 t-17.5 -12zM448 727l-35 -36q-15 -15 -19.5 -38.5t4.5 -41.5q37 -68 93 -116q16 -13 38.5 -11t36.5 17l12 11l22 86l-3 4q-44 44 -89 117q-11 18 -28 20t-32 -12z" />
<glyph unicode="&#xe107;" d="M-90 100l642 1066q20 31 48 28.5t48 -35.5l642 -1056q21 -32 7.5 -67.5t-50.5 -35.5h-1294q-37 0 -50.5 34t7.5 66zM155 200h345v75q0 10 7.5 17.5t17.5 7.5h150q10 0 17.5 -7.5t7.5 -17.5v-75h345l-445 723zM496 700h208q20 0 32 -14.5t8 -34.5l-58 -252 q-4 -20 -21.5 -34.5t-37.5 -14.5h-54q-20 0 -37.5 14.5t-21.5 34.5l-58 252q-4 20 8 34.5t32 14.5z" />
<glyph unicode="&#xe108;" d="M650 1200q62 0 106 -44t44 -106v-339l363 -325q15 -14 26 -38.5t11 -44.5v-41q0 -20 -12 -26.5t-29 5.5l-359 249v-263q100 -93 100 -113v-64q0 -21 -13 -29t-32 1l-205 128l-205 -128q-19 -9 -32 -1t-13 29v64q0 20 100 113v263l-359 -249q-17 -12 -29 -5.5t-12 26.5v41 q0 20 11 44.5t26 38.5l363 325v339q0 62 44 106t106 44z" />
<glyph unicode="&#xe109;" d="M850 1200h100q21 0 35.5 -14.5t14.5 -35.5v-50h50q21 0 35.5 -14.5t14.5 -35.5v-150h-1100v150q0 21 14.5 35.5t35.5 14.5h50v50q0 21 14.5 35.5t35.5 14.5h100q21 0 35.5 -14.5t14.5 -35.5v-50h500v50q0 21 14.5 35.5t35.5 14.5zM1100 800v-750q0 -21 -14.5 -35.5 t-35.5 -14.5h-1000q-21 0 -35.5 14.5t-14.5 35.5v750h1100zM100 600v-100h100v100h-100zM300 600v-100h100v100h-100zM500 600v-100h100v100h-100zM700 600v-100h100v100h-100zM900 600v-100h100v100h-100zM100 400v-100h100v100h-100zM300 400v-100h100v100h-100zM500 400 v-100h100v100h-100zM700 400v-100h100v100h-100zM900 400v-100h100v100h-100zM100 200v-100h100v100h-100zM300 200v-100h100v100h-100zM500 200v-100h100v100h-100zM700 200v-100h100v100h-100zM900 200v-100h100v100h-100z" />
<glyph unicode="&#xe110;" d="M1135 1165l249 -230q15 -14 15 -35t-15 -35l-249 -230q-14 -14 -24.5 -10t-10.5 25v150h-159l-600 -600h-291q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5h209l600 600h241v150q0 21 10.5 25t24.5 -10zM522 819l-141 -141l-122 122h-209q-21 0 -35.5 14.5 t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5h291zM1135 565l249 -230q15 -14 15 -35t-15 -35l-249 -230q-14 -14 -24.5 -10t-10.5 25v150h-241l-181 181l141 141l122 -122h159v150q0 21 10.5 25t24.5 -10z" />
<glyph unicode="&#xe111;" d="M100 1100h1000q41 0 70.5 -29.5t29.5 -70.5v-600q0 -41 -29.5 -70.5t-70.5 -29.5h-596l-304 -300v300h-100q-41 0 -70.5 29.5t-29.5 70.5v600q0 41 29.5 70.5t70.5 29.5z" />
<glyph unicode="&#xe112;" d="M150 1200h200q21 0 35.5 -14.5t14.5 -35.5v-250h-300v250q0 21 14.5 35.5t35.5 14.5zM850 1200h200q21 0 35.5 -14.5t14.5 -35.5v-250h-300v250q0 21 14.5 35.5t35.5 14.5zM1100 800v-300q0 -41 -3 -77.5t-15 -89.5t-32 -96t-58 -89t-89 -77t-129 -51t-174 -20t-174 20 t-129 51t-89 77t-58 89t-32 96t-15 89.5t-3 77.5v300h300v-250v-27v-42.5t1.5 -41t5 -38t10 -35t16.5 -30t25.5 -24.5t35 -19t46.5 -12t60 -4t60 4.5t46.5 12.5t35 19.5t25 25.5t17 30.5t10 35t5 38t2 40.5t-0.5 42v25v250h300z" />
<glyph unicode="&#xe113;" d="M1100 411l-198 -199l-353 353l-353 -353l-197 199l551 551z" />
<glyph unicode="&#xe114;" d="M1101 789l-550 -551l-551 551l198 199l353 -353l353 353z" />
<glyph unicode="&#xe115;" d="M404 1000h746q21 0 35.5 -14.5t14.5 -35.5v-551h150q21 0 25 -10.5t-10 -24.5l-230 -249q-14 -15 -35 -15t-35 15l-230 249q-14 14 -10 24.5t25 10.5h150v401h-381zM135 984l230 -249q14 -14 10 -24.5t-25 -10.5h-150v-400h385l215 -200h-750q-21 0 -35.5 14.5 t-14.5 35.5v550h-150q-21 0 -25 10.5t10 24.5l230 249q14 15 35 15t35 -15z" />
<glyph unicode="&#xe116;" d="M56 1200h94q17 0 31 -11t18 -27l38 -162h896q24 0 39 -18.5t10 -42.5l-100 -475q-5 -21 -27 -42.5t-55 -21.5h-633l48 -200h535q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-50v-50q0 -21 -14.5 -35.5t-35.5 -14.5t-35.5 14.5t-14.5 35.5v50h-300v-50 q0 -21 -14.5 -35.5t-35.5 -14.5t-35.5 14.5t-14.5 35.5v50h-31q-18 0 -32.5 10t-20.5 19l-5 10l-201 961h-54q-20 0 -35 14.5t-15 35.5t15 35.5t35 14.5z" />
<glyph unicode="&#xe117;" d="M1200 1000v-100h-1200v100h200q0 41 29.5 70.5t70.5 29.5h300q41 0 70.5 -29.5t29.5 -70.5h500zM0 800h1200v-800h-1200v800z" />
<glyph unicode="&#xe118;" d="M200 800l-200 -400v600h200q0 41 29.5 70.5t70.5 29.5h300q42 0 71 -29.5t29 -70.5h500v-200h-1000zM1500 700l-300 -700h-1200l300 700h1200z" />
<glyph unicode="&#xe119;" d="M635 1184l230 -249q14 -14 10 -24.5t-25 -10.5h-150v-601h150q21 0 25 -10.5t-10 -24.5l-230 -249q-14 -15 -35 -15t-35 15l-230 249q-14 14 -10 24.5t25 10.5h150v601h-150q-21 0 -25 10.5t10 24.5l230 249q14 15 35 15t35 -15z" />
<glyph unicode="&#xe120;" d="M936 864l249 -229q14 -15 14 -35.5t-14 -35.5l-249 -229q-15 -15 -25.5 -10.5t-10.5 24.5v151h-600v-151q0 -20 -10.5 -24.5t-25.5 10.5l-249 229q-14 15 -14 35.5t14 35.5l249 229q15 15 25.5 10.5t10.5 -25.5v-149h600v149q0 21 10.5 25.5t25.5 -10.5z" />
<glyph unicode="&#xe121;" d="M1169 400l-172 732q-5 23 -23 45.5t-38 22.5h-672q-20 0 -38 -20t-23 -41l-172 -739h1138zM1100 300h-1000q-41 0 -70.5 -29.5t-29.5 -70.5v-100q0 -41 29.5 -70.5t70.5 -29.5h1000q41 0 70.5 29.5t29.5 70.5v100q0 41 -29.5 70.5t-70.5 29.5zM800 100v100h100v-100h-100 zM1000 100v100h100v-100h-100z" />
<glyph unicode="&#xe122;" d="M1150 1100q21 0 35.5 -14.5t14.5 -35.5v-850q0 -21 -14.5 -35.5t-35.5 -14.5t-35.5 14.5t-14.5 35.5v850q0 21 14.5 35.5t35.5 14.5zM1000 200l-675 200h-38l47 -276q3 -16 -5.5 -20t-29.5 -4h-7h-84q-20 0 -34.5 14t-18.5 35q-55 337 -55 351v250v6q0 16 1 23.5t6.5 14 t17.5 6.5h200l675 250v-850zM0 750v-250q-4 0 -11 0.5t-24 6t-30 15t-24 30t-11 48.5v50q0 26 10.5 46t25 30t29 16t25.5 7z" />
<glyph unicode="&#xe123;" d="M553 1200h94q20 0 29 -10.5t3 -29.5l-18 -37q83 -19 144 -82.5t76 -140.5l63 -327l118 -173h17q19 0 33 -14.5t14 -35t-13 -40.5t-31 -27q-8 -4 -23 -9.5t-65 -19.5t-103 -25t-132.5 -20t-158.5 -9q-57 0 -115 5t-104 12t-88.5 15.5t-73.5 17.5t-54.5 16t-35.5 12l-11 4 q-18 8 -31 28t-13 40.5t14 35t33 14.5h17l118 173l63 327q15 77 76 140t144 83l-18 32q-6 19 3.5 32t28.5 13zM498 110q50 -6 102 -6q53 0 102 6q-12 -49 -39.5 -79.5t-62.5 -30.5t-63 30.5t-39 79.5z" />
<glyph unicode="&#xe124;" d="M800 946l224 78l-78 -224l234 -45l-180 -155l180 -155l-234 -45l78 -224l-224 78l-45 -234l-155 180l-155 -180l-45 234l-224 -78l78 224l-234 45l180 155l-180 155l234 45l-78 224l224 -78l45 234l155 -180l155 180z" />
<glyph unicode="&#xe125;" d="M650 1200h50q40 0 70 -40.5t30 -84.5v-150l-28 -125h328q40 0 70 -40.5t30 -84.5v-100q0 -45 -29 -74l-238 -344q-16 -24 -38 -40.5t-45 -16.5h-250q-7 0 -42 25t-66 50l-31 25h-61q-45 0 -72.5 18t-27.5 57v400q0 36 20 63l145 196l96 198q13 28 37.5 48t51.5 20z M650 1100l-100 -212l-150 -213v-375h100l136 -100h214l250 375v125h-450l50 225v175h-50zM50 800h100q21 0 35.5 -14.5t14.5 -35.5v-500q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v500q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe126;" d="M600 1100h250q23 0 45 -16.5t38 -40.5l238 -344q29 -29 29 -74v-100q0 -44 -30 -84.5t-70 -40.5h-328q28 -118 28 -125v-150q0 -44 -30 -84.5t-70 -40.5h-50q-27 0 -51.5 20t-37.5 48l-96 198l-145 196q-20 27 -20 63v400q0 39 27.5 57t72.5 18h61q124 100 139 100z M50 1000h100q21 0 35.5 -14.5t14.5 -35.5v-500q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v500q0 21 14.5 35.5t35.5 14.5zM636 1000l-136 -100h-100v-375l150 -213l100 -212h50v175l-50 225h450v125l-250 375h-214z" />
<glyph unicode="&#xe127;" d="M356 873l363 230q31 16 53 -6l110 -112q13 -13 13.5 -32t-11.5 -34l-84 -121h302q84 0 138 -38t54 -110t-55 -111t-139 -39h-106l-131 -339q-6 -21 -19.5 -41t-28.5 -20h-342q-7 0 -90 81t-83 94v525q0 17 14 35.5t28 28.5zM400 792v-503l100 -89h293l131 339 q6 21 19.5 41t28.5 20h203q21 0 30.5 25t0.5 50t-31 25h-456h-7h-6h-5.5t-6 0.5t-5 1.5t-5 2t-4 2.5t-4 4t-2.5 4.5q-12 25 5 47l146 183l-86 83zM50 800h100q21 0 35.5 -14.5t14.5 -35.5v-500q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v500 q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe128;" d="M475 1103l366 -230q2 -1 6 -3.5t14 -10.5t18 -16.5t14.5 -20t6.5 -22.5v-525q0 -13 -86 -94t-93 -81h-342q-15 0 -28.5 20t-19.5 41l-131 339h-106q-85 0 -139.5 39t-54.5 111t54 110t138 38h302l-85 121q-11 15 -10.5 34t13.5 32l110 112q22 22 53 6zM370 945l146 -183 q17 -22 5 -47q-2 -2 -3.5 -4.5t-4 -4t-4 -2.5t-5 -2t-5 -1.5t-6 -0.5h-6h-6.5h-6h-475v-100h221q15 0 29 -20t20 -41l130 -339h294l106 89v503l-342 236zM1050 800h100q21 0 35.5 -14.5t14.5 -35.5v-500q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5 v500q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe129;" d="M550 1294q72 0 111 -55t39 -139v-106l339 -131q21 -6 41 -19.5t20 -28.5v-342q0 -7 -81 -90t-94 -83h-525q-17 0 -35.5 14t-28.5 28l-9 14l-230 363q-16 31 6 53l112 110q13 13 32 13.5t34 -11.5l121 -84v302q0 84 38 138t110 54zM600 972v203q0 21 -25 30.5t-50 0.5 t-25 -31v-456v-7v-6v-5.5t-0.5 -6t-1.5 -5t-2 -5t-2.5 -4t-4 -4t-4.5 -2.5q-25 -12 -47 5l-183 146l-83 -86l236 -339h503l89 100v293l-339 131q-21 6 -41 19.5t-20 28.5zM450 200h500q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-500 q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe130;" d="M350 1100h500q21 0 35.5 14.5t14.5 35.5v100q0 21 -14.5 35.5t-35.5 14.5h-500q-21 0 -35.5 -14.5t-14.5 -35.5v-100q0 -21 14.5 -35.5t35.5 -14.5zM600 306v-106q0 -84 -39 -139t-111 -55t-110 54t-38 138v302l-121 -84q-15 -12 -34 -11.5t-32 13.5l-112 110 q-22 22 -6 53l230 363q1 2 3.5 6t10.5 13.5t16.5 17t20 13.5t22.5 6h525q13 0 94 -83t81 -90v-342q0 -15 -20 -28.5t-41 -19.5zM308 900l-236 -339l83 -86l183 146q22 17 47 5q2 -1 4.5 -2.5t4 -4t2.5 -4t2 -5t1.5 -5t0.5 -6v-5.5v-6v-7v-456q0 -22 25 -31t50 0.5t25 30.5 v203q0 15 20 28.5t41 19.5l339 131v293l-89 100h-503z" />
<glyph unicode="&#xe131;" d="M600 1178q118 0 225 -45.5t184.5 -123t123 -184.5t45.5 -225t-45.5 -225t-123 -184.5t-184.5 -123t-225 -45.5t-225 45.5t-184.5 123t-123 184.5t-45.5 225t45.5 225t123 184.5t184.5 123t225 45.5zM914 632l-275 223q-16 13 -27.5 8t-11.5 -26v-137h-275 q-10 0 -17.5 -7.5t-7.5 -17.5v-150q0 -10 7.5 -17.5t17.5 -7.5h275v-137q0 -21 11.5 -26t27.5 8l275 223q16 13 16 32t-16 32z" />
<glyph unicode="&#xe132;" d="M600 1178q118 0 225 -45.5t184.5 -123t123 -184.5t45.5 -225t-45.5 -225t-123 -184.5t-184.5 -123t-225 -45.5t-225 45.5t-184.5 123t-123 184.5t-45.5 225t45.5 225t123 184.5t184.5 123t225 45.5zM561 855l-275 -223q-16 -13 -16 -32t16 -32l275 -223q16 -13 27.5 -8 t11.5 26v137h275q10 0 17.5 7.5t7.5 17.5v150q0 10 -7.5 17.5t-17.5 7.5h-275v137q0 21 -11.5 26t-27.5 -8z" />
<glyph unicode="&#xe133;" d="M600 1178q118 0 225 -45.5t184.5 -123t123 -184.5t45.5 -225t-45.5 -225t-123 -184.5t-184.5 -123t-225 -45.5t-225 45.5t-184.5 123t-123 184.5t-45.5 225t45.5 225t123 184.5t184.5 123t225 45.5zM855 639l-223 275q-13 16 -32 16t-32 -16l-223 -275q-13 -16 -8 -27.5 t26 -11.5h137v-275q0 -10 7.5 -17.5t17.5 -7.5h150q10 0 17.5 7.5t7.5 17.5v275h137q21 0 26 11.5t-8 27.5z" />
<glyph unicode="&#xe134;" d="M600 1178q118 0 225 -45.5t184.5 -123t123 -184.5t45.5 -225t-45.5 -225t-123 -184.5t-184.5 -123t-225 -45.5t-225 45.5t-184.5 123t-123 184.5t-45.5 225t45.5 225t123 184.5t184.5 123t225 45.5zM675 900h-150q-10 0 -17.5 -7.5t-7.5 -17.5v-275h-137q-21 0 -26 -11.5 t8 -27.5l223 -275q13 -16 32 -16t32 16l223 275q13 16 8 27.5t-26 11.5h-137v275q0 10 -7.5 17.5t-17.5 7.5z" />
<glyph unicode="&#xe135;" d="M600 1176q116 0 222.5 -46t184 -123.5t123.5 -184t46 -222.5t-46 -222.5t-123.5 -184t-184 -123.5t-222.5 -46t-222.5 46t-184 123.5t-123.5 184t-46 222.5t46 222.5t123.5 184t184 123.5t222.5 46zM627 1101q-15 -12 -36.5 -20.5t-35.5 -12t-43 -8t-39 -6.5 q-15 -3 -45.5 0t-45.5 -2q-20 -7 -51.5 -26.5t-34.5 -34.5q-3 -11 6.5 -22.5t8.5 -18.5q-3 -34 -27.5 -91t-29.5 -79q-9 -34 5 -93t8 -87q0 -9 17 -44.5t16 -59.5q12 0 23 -5t23.5 -15t19.5 -14q16 -8 33 -15t40.5 -15t34.5 -12q21 -9 52.5 -32t60 -38t57.5 -11 q7 -15 -3 -34t-22.5 -40t-9.5 -38q13 -21 23 -34.5t27.5 -27.5t36.5 -18q0 -7 -3.5 -16t-3.5 -14t5 -17q104 -2 221 112q30 29 46.5 47t34.5 49t21 63q-13 8 -37 8.5t-36 7.5q-15 7 -49.5 15t-51.5 19q-18 0 -41 -0.5t-43 -1.5t-42 -6.5t-38 -16.5q-51 -35 -66 -12 q-4 1 -3.5 25.5t0.5 25.5q-6 13 -26.5 17.5t-24.5 6.5q1 15 -0.5 30.5t-7 28t-18.5 11.5t-31 -21q-23 -25 -42 4q-19 28 -8 58q6 16 22 22q6 -1 26 -1.5t33.5 -4t19.5 -13.5q7 -12 18 -24t21.5 -20.5t20 -15t15.5 -10.5l5 -3q2 12 7.5 30.5t8 34.5t-0.5 32q-3 18 3.5 29 t18 22.5t15.5 24.5q6 14 10.5 35t8 31t15.5 22.5t34 22.5q-6 18 10 36q8 0 24 -1.5t24.5 -1.5t20 4.5t20.5 15.5q-10 23 -31 42.5t-37.5 29.5t-49 27t-43.5 23q0 1 2 8t3 11.5t1.5 10.5t-1 9.5t-4.5 4.5q31 -13 58.5 -14.5t38.5 2.5l12 5q5 28 -9.5 46t-36.5 24t-50 15 t-41 20q-18 -4 -37 0zM613 994q0 -17 8 -42t17 -45t9 -23q-8 1 -39.5 5.5t-52.5 10t-37 16.5q3 11 16 29.5t16 25.5q10 -10 19 -10t14 6t13.5 14.5t16.5 12.5z" />
<glyph unicode="&#xe136;" d="M756 1157q164 92 306 -9l-259 -138l145 -232l251 126q6 -89 -34 -156.5t-117 -110.5q-60 -34 -127 -39.5t-126 16.5l-596 -596q-15 -16 -36.5 -16t-36.5 16l-111 110q-15 15 -15 36.5t15 37.5l600 599q-34 101 5.5 201.5t135.5 154.5z" />
<glyph unicode="&#xe137;" horiz-adv-x="1220" d="M100 1196h1000q41 0 70.5 -29.5t29.5 -70.5v-100q0 -41 -29.5 -70.5t-70.5 -29.5h-1000q-41 0 -70.5 29.5t-29.5 70.5v100q0 41 29.5 70.5t70.5 29.5zM1100 1096h-200v-100h200v100zM100 796h1000q41 0 70.5 -29.5t29.5 -70.5v-100q0 -41 -29.5 -70.5t-70.5 -29.5h-1000 q-41 0 -70.5 29.5t-29.5 70.5v100q0 41 29.5 70.5t70.5 29.5zM1100 696h-500v-100h500v100zM100 396h1000q41 0 70.5 -29.5t29.5 -70.5v-100q0 -41 -29.5 -70.5t-70.5 -29.5h-1000q-41 0 -70.5 29.5t-29.5 70.5v100q0 41 29.5 70.5t70.5 29.5zM1100 296h-300v-100h300v100z " />
<glyph unicode="&#xe138;" d="M150 1200h900q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-900q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5zM700 500v-300l-200 -200v500l-350 500h900z" />
<glyph unicode="&#xe139;" d="M500 1200h200q41 0 70.5 -29.5t29.5 -70.5v-100h300q41 0 70.5 -29.5t29.5 -70.5v-400h-500v100h-200v-100h-500v400q0 41 29.5 70.5t70.5 29.5h300v100q0 41 29.5 70.5t70.5 29.5zM500 1100v-100h200v100h-200zM1200 400v-200q0 -41 -29.5 -70.5t-70.5 -29.5h-1000 q-41 0 -70.5 29.5t-29.5 70.5v200h1200z" />
<glyph unicode="&#xe140;" d="M50 1200h300q21 0 25 -10.5t-10 -24.5l-94 -94l199 -199q7 -8 7 -18t-7 -18l-106 -106q-8 -7 -18 -7t-18 7l-199 199l-94 -94q-14 -14 -24.5 -10t-10.5 25v300q0 21 14.5 35.5t35.5 14.5zM850 1200h300q21 0 35.5 -14.5t14.5 -35.5v-300q0 -21 -10.5 -25t-24.5 10l-94 94 l-199 -199q-8 -7 -18 -7t-18 7l-106 106q-7 8 -7 18t7 18l199 199l-94 94q-14 14 -10 24.5t25 10.5zM364 470l106 -106q7 -8 7 -18t-7 -18l-199 -199l94 -94q14 -14 10 -24.5t-25 -10.5h-300q-21 0 -35.5 14.5t-14.5 35.5v300q0 21 10.5 25t24.5 -10l94 -94l199 199 q8 7 18 7t18 -7zM1071 271l94 94q14 14 24.5 10t10.5 -25v-300q0 -21 -14.5 -35.5t-35.5 -14.5h-300q-21 0 -25 10.5t10 24.5l94 94l-199 199q-7 8 -7 18t7 18l106 106q8 7 18 7t18 -7z" />
<glyph unicode="&#xe141;" d="M596 1192q121 0 231.5 -47.5t190 -127t127 -190t47.5 -231.5t-47.5 -231.5t-127 -190.5t-190 -127t-231.5 -47t-231.5 47t-190.5 127t-127 190.5t-47 231.5t47 231.5t127 190t190.5 127t231.5 47.5zM596 1010q-112 0 -207.5 -55.5t-151 -151t-55.5 -207.5t55.5 -207.5 t151 -151t207.5 -55.5t207.5 55.5t151 151t55.5 207.5t-55.5 207.5t-151 151t-207.5 55.5zM454.5 905q22.5 0 38.5 -16t16 -38.5t-16 -39t-38.5 -16.5t-38.5 16.5t-16 39t16 38.5t38.5 16zM754.5 905q22.5 0 38.5 -16t16 -38.5t-16 -39t-38 -16.5q-14 0 -29 10l-55 -145 q17 -23 17 -51q0 -36 -25.5 -61.5t-61.5 -25.5t-61.5 25.5t-25.5 61.5q0 32 20.5 56.5t51.5 29.5l122 126l1 1q-9 14 -9 28q0 23 16 39t38.5 16zM345.5 709q22.5 0 38.5 -16t16 -38.5t-16 -38.5t-38.5 -16t-38.5 16t-16 38.5t16 38.5t38.5 16zM854.5 709q22.5 0 38.5 -16 t16 -38.5t-16 -38.5t-38.5 -16t-38.5 16t-16 38.5t16 38.5t38.5 16z" />
<glyph unicode="&#xe142;" d="M546 173l469 470q91 91 99 192q7 98 -52 175.5t-154 94.5q-22 4 -47 4q-34 0 -66.5 -10t-56.5 -23t-55.5 -38t-48 -41.5t-48.5 -47.5q-376 -375 -391 -390q-30 -27 -45 -41.5t-37.5 -41t-32 -46.5t-16 -47.5t-1.5 -56.5q9 -62 53.5 -95t99.5 -33q74 0 125 51l548 548 q36 36 20 75q-7 16 -21.5 26t-32.5 10q-26 0 -50 -23q-13 -12 -39 -38l-341 -338q-15 -15 -35.5 -15.5t-34.5 13.5t-14 34.5t14 34.5q327 333 361 367q35 35 67.5 51.5t78.5 16.5q14 0 29 -1q44 -8 74.5 -35.5t43.5 -68.5q14 -47 2 -96.5t-47 -84.5q-12 -11 -32 -32 t-79.5 -81t-114.5 -115t-124.5 -123.5t-123 -119.5t-96.5 -89t-57 -45q-56 -27 -120 -27q-70 0 -129 32t-93 89q-48 78 -35 173t81 163l511 511q71 72 111 96q91 55 198 55q80 0 152 -33q78 -36 129.5 -103t66.5 -154q17 -93 -11 -183.5t-94 -156.5l-482 -476 q-15 -15 -36 -16t-37 14t-17.5 34t14.5 35z" />
<glyph unicode="&#xe143;" d="M649 949q48 68 109.5 104t121.5 38.5t118.5 -20t102.5 -64t71 -100.5t27 -123q0 -57 -33.5 -117.5t-94 -124.5t-126.5 -127.5t-150 -152.5t-146 -174q-62 85 -145.5 174t-150 152.5t-126.5 127.5t-93.5 124.5t-33.5 117.5q0 64 28 123t73 100.5t104 64t119 20 t120.5 -38.5t104.5 -104zM896 972q-33 0 -64.5 -19t-56.5 -46t-47.5 -53.5t-43.5 -45.5t-37.5 -19t-36 19t-40 45.5t-43 53.5t-54 46t-65.5 19q-67 0 -122.5 -55.5t-55.5 -132.5q0 -23 13.5 -51t46 -65t57.5 -63t76 -75l22 -22q15 -14 44 -44t50.5 -51t46 -44t41 -35t23 -12 t23.5 12t42.5 36t46 44t52.5 52t44 43q4 4 12 13q43 41 63.5 62t52 55t46 55t26 46t11.5 44q0 79 -53 133.5t-120 54.5z" />
<glyph unicode="&#xe144;" d="M776.5 1214q93.5 0 159.5 -66l141 -141q66 -66 66 -160q0 -42 -28 -95.5t-62 -87.5l-29 -29q-31 53 -77 99l-18 18l95 95l-247 248l-389 -389l212 -212l-105 -106l-19 18l-141 141q-66 66 -66 159t66 159l283 283q65 66 158.5 66zM600 706l105 105q10 -8 19 -17l141 -141 q66 -66 66 -159t-66 -159l-283 -283q-66 -66 -159 -66t-159 66l-141 141q-66 66 -66 159.5t66 159.5l55 55q29 -55 75 -102l18 -17l-95 -95l247 -248l389 389z" />
<glyph unicode="&#xe145;" d="M603 1200q85 0 162 -15t127 -38t79 -48t29 -46v-953q0 -41 -29.5 -70.5t-70.5 -29.5h-600q-41 0 -70.5 29.5t-29.5 70.5v953q0 21 30 46.5t81 48t129 37.5t163 15zM300 1000v-700h600v700h-600zM600 254q-43 0 -73.5 -30.5t-30.5 -73.5t30.5 -73.5t73.5 -30.5t73.5 30.5 t30.5 73.5t-30.5 73.5t-73.5 30.5z" />
<glyph unicode="&#xe146;" d="M902 1185l283 -282q15 -15 15 -36t-14.5 -35.5t-35.5 -14.5t-35 15l-36 35l-279 -267v-300l-212 210l-308 -307l-280 -203l203 280l307 308l-210 212h300l267 279l-35 36q-15 14 -15 35t14.5 35.5t35.5 14.5t35 -15z" />
<glyph unicode="&#xe148;" d="M700 1248v-78q38 -5 72.5 -14.5t75.5 -31.5t71 -53.5t52 -84t24 -118.5h-159q-4 36 -10.5 59t-21 45t-40 35.5t-64.5 20.5v-307l64 -13q34 -7 64 -16.5t70 -32t67.5 -52.5t47.5 -80t20 -112q0 -139 -89 -224t-244 -97v-77h-100v79q-150 16 -237 103q-40 40 -52.5 93.5 t-15.5 139.5h139q5 -77 48.5 -126t117.5 -65v335l-27 8q-46 14 -79 26.5t-72 36t-63 52t-40 72.5t-16 98q0 70 25 126t67.5 92t94.5 57t110 27v77h100zM600 754v274q-29 -4 -50 -11t-42 -21.5t-31.5 -41.5t-10.5 -65q0 -29 7 -50.5t16.5 -34t28.5 -22.5t31.5 -14t37.5 -10 q9 -3 13 -4zM700 547v-310q22 2 42.5 6.5t45 15.5t41.5 27t29 42t12 59.5t-12.5 59.5t-38 44.5t-53 31t-66.5 24.5z" />
<glyph unicode="&#xe149;" d="M561 1197q84 0 160.5 -40t123.5 -109.5t47 -147.5h-153q0 40 -19.5 71.5t-49.5 48.5t-59.5 26t-55.5 9q-37 0 -79 -14.5t-62 -35.5q-41 -44 -41 -101q0 -26 13.5 -63t26.5 -61t37 -66q6 -9 9 -14h241v-100h-197q8 -50 -2.5 -115t-31.5 -95q-45 -62 -99 -112 q34 10 83 17.5t71 7.5q32 1 102 -16t104 -17q83 0 136 30l50 -147q-31 -19 -58 -30.5t-55 -15.5t-42 -4.5t-46 -0.5q-23 0 -76 17t-111 32.5t-96 11.5q-39 -3 -82 -16t-67 -25l-23 -11l-55 145q4 3 16 11t15.5 10.5t13 9t15.5 12t14.5 14t17.5 18.5q48 55 54 126.5 t-30 142.5h-221v100h166q-23 47 -44 104q-7 20 -12 41.5t-6 55.5t6 66.5t29.5 70.5t58.5 71q97 88 263 88z" />
<glyph unicode="&#xe150;" d="M400 300h150q21 0 25 -11t-10 -25l-230 -250q-14 -15 -35 -15t-35 15l-230 250q-14 14 -10 25t25 11h150v900h200v-900zM935 1184l230 -249q14 -14 10 -24.5t-25 -10.5h-150v-900h-200v900h-150q-21 0 -25 10.5t10 24.5l230 249q14 15 35 15t35 -15z" />
<glyph unicode="&#xe151;" d="M1000 700h-100v100h-100v-100h-100v500h300v-500zM400 300h150q21 0 25 -11t-10 -25l-230 -250q-14 -15 -35 -15t-35 15l-230 250q-14 14 -10 25t25 11h150v900h200v-900zM801 1100v-200h100v200h-100zM1000 350l-200 -250h200v-100h-300v150l200 250h-200v100h300v-150z " />
<glyph unicode="&#xe152;" d="M400 300h150q21 0 25 -11t-10 -25l-230 -250q-14 -15 -35 -15t-35 15l-230 250q-14 14 -10 25t25 11h150v900h200v-900zM1000 1050l-200 -250h200v-100h-300v150l200 250h-200v100h300v-150zM1000 0h-100v100h-100v-100h-100v500h300v-500zM801 400v-200h100v200h-100z " />
<glyph unicode="&#xe153;" d="M400 300h150q21 0 25 -11t-10 -25l-230 -250q-14 -15 -35 -15t-35 15l-230 250q-14 14 -10 25t25 11h150v900h200v-900zM1000 700h-100v400h-100v100h200v-500zM1100 0h-100v100h-200v400h300v-500zM901 400v-200h100v200h-100z" />
<glyph unicode="&#xe154;" d="M400 300h150q21 0 25 -11t-10 -25l-230 -250q-14 -15 -35 -15t-35 15l-230 250q-14 14 -10 25t25 11h150v900h200v-900zM1100 700h-100v100h-200v400h300v-500zM901 1100v-200h100v200h-100zM1000 0h-100v400h-100v100h200v-500z" />
<glyph unicode="&#xe155;" d="M400 300h150q21 0 25 -11t-10 -25l-230 -250q-14 -15 -35 -15t-35 15l-230 250q-14 14 -10 25t25 11h150v900h200v-900zM900 1000h-200v200h200v-200zM1000 700h-300v200h300v-200zM1100 400h-400v200h400v-200zM1200 100h-500v200h500v-200z" />
<glyph unicode="&#xe156;" d="M400 300h150q21 0 25 -11t-10 -25l-230 -250q-14 -15 -35 -15t-35 15l-230 250q-14 14 -10 25t25 11h150v900h200v-900zM1200 1000h-500v200h500v-200zM1100 700h-400v200h400v-200zM1000 400h-300v200h300v-200zM900 100h-200v200h200v-200z" />
<glyph unicode="&#xe157;" d="M350 1100h400q162 0 256 -93.5t94 -256.5v-400q0 -165 -93.5 -257.5t-256.5 -92.5h-400q-165 0 -257.5 92.5t-92.5 257.5v400q0 165 92.5 257.5t257.5 92.5zM800 900h-500q-41 0 -70.5 -29.5t-29.5 -70.5v-500q0 -41 29.5 -70.5t70.5 -29.5h500q41 0 70.5 29.5t29.5 70.5 v500q0 41 -29.5 70.5t-70.5 29.5z" />
<glyph unicode="&#xe158;" d="M350 1100h400q165 0 257.5 -92.5t92.5 -257.5v-400q0 -165 -92.5 -257.5t-257.5 -92.5h-400q-163 0 -256.5 92.5t-93.5 257.5v400q0 163 94 256.5t256 93.5zM800 900h-500q-41 0 -70.5 -29.5t-29.5 -70.5v-500q0 -41 29.5 -70.5t70.5 -29.5h500q41 0 70.5 29.5t29.5 70.5 v500q0 41 -29.5 70.5t-70.5 29.5zM440 770l253 -190q17 -12 17 -30t-17 -30l-253 -190q-16 -12 -28 -6.5t-12 26.5v400q0 21 12 26.5t28 -6.5z" />
<glyph unicode="&#xe159;" d="M350 1100h400q163 0 256.5 -94t93.5 -256v-400q0 -165 -92.5 -257.5t-257.5 -92.5h-400q-165 0 -257.5 92.5t-92.5 257.5v400q0 163 92.5 256.5t257.5 93.5zM800 900h-500q-41 0 -70.5 -29.5t-29.5 -70.5v-500q0 -41 29.5 -70.5t70.5 -29.5h500q41 0 70.5 29.5t29.5 70.5 v500q0 41 -29.5 70.5t-70.5 29.5zM350 700h400q21 0 26.5 -12t-6.5 -28l-190 -253q-12 -17 -30 -17t-30 17l-190 253q-12 16 -6.5 28t26.5 12z" />
<glyph unicode="&#xe160;" d="M350 1100h400q165 0 257.5 -92.5t92.5 -257.5v-400q0 -163 -92.5 -256.5t-257.5 -93.5h-400q-163 0 -256.5 94t-93.5 256v400q0 165 92.5 257.5t257.5 92.5zM800 900h-500q-41 0 -70.5 -29.5t-29.5 -70.5v-500q0 -41 29.5 -70.5t70.5 -29.5h500q41 0 70.5 29.5t29.5 70.5 v500q0 41 -29.5 70.5t-70.5 29.5zM580 693l190 -253q12 -16 6.5 -28t-26.5 -12h-400q-21 0 -26.5 12t6.5 28l190 253q12 17 30 17t30 -17z" />
<glyph unicode="&#xe161;" d="M550 1100h400q165 0 257.5 -92.5t92.5 -257.5v-400q0 -165 -92.5 -257.5t-257.5 -92.5h-400q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5h450q41 0 70.5 29.5t29.5 70.5v500q0 41 -29.5 70.5t-70.5 29.5h-450q-21 0 -35.5 14.5t-14.5 35.5v100 q0 21 14.5 35.5t35.5 14.5zM338 867l324 -284q16 -14 16 -33t-16 -33l-324 -284q-16 -14 -27 -9t-11 26v150h-250q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5h250v150q0 21 11 26t27 -9z" />
<glyph unicode="&#xe162;" d="M793 1182l9 -9q8 -10 5 -27q-3 -11 -79 -225.5t-78 -221.5l300 1q24 0 32.5 -17.5t-5.5 -35.5q-1 0 -133.5 -155t-267 -312.5t-138.5 -162.5q-12 -15 -26 -15h-9l-9 8q-9 11 -4 32q2 9 42 123.5t79 224.5l39 110h-302q-23 0 -31 19q-10 21 6 41q75 86 209.5 237.5 t228 257t98.5 111.5q9 16 25 16h9z" />
<glyph unicode="&#xe163;" d="M350 1100h400q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-450q-41 0 -70.5 -29.5t-29.5 -70.5v-500q0 -41 29.5 -70.5t70.5 -29.5h450q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-165 0 -257.5 92.5t-92.5 257.5v400 q0 165 92.5 257.5t257.5 92.5zM938 867l324 -284q16 -14 16 -33t-16 -33l-324 -284q-16 -14 -27 -9t-11 26v150h-250q-21 0 -35.5 14.5t-14.5 35.5v200q0 21 14.5 35.5t35.5 14.5h250v150q0 21 11 26t27 -9z" />
<glyph unicode="&#xe164;" d="M750 1200h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -10.5 -25t-24.5 10l-109 109l-312 -312q-15 -15 -35.5 -15t-35.5 15l-141 141q-15 15 -15 35.5t15 35.5l312 312l-109 109q-14 14 -10 24.5t25 10.5zM456 900h-156q-41 0 -70.5 -29.5t-29.5 -70.5v-500 q0 -41 29.5 -70.5t70.5 -29.5h500q41 0 70.5 29.5t29.5 70.5v148l200 200v-298q0 -165 -93.5 -257.5t-256.5 -92.5h-400q-165 0 -257.5 92.5t-92.5 257.5v400q0 165 92.5 257.5t257.5 92.5h300z" />
<glyph unicode="&#xe165;" d="M600 1186q119 0 227.5 -46.5t187 -125t125 -187t46.5 -227.5t-46.5 -227.5t-125 -187t-187 -125t-227.5 -46.5t-227.5 46.5t-187 125t-125 187t-46.5 227.5t46.5 227.5t125 187t187 125t227.5 46.5zM600 1022q-115 0 -212 -56.5t-153.5 -153.5t-56.5 -212t56.5 -212 t153.5 -153.5t212 -56.5t212 56.5t153.5 153.5t56.5 212t-56.5 212t-153.5 153.5t-212 56.5zM600 794q80 0 137 -57t57 -137t-57 -137t-137 -57t-137 57t-57 137t57 137t137 57z" />
<glyph unicode="&#xe166;" d="M450 1200h200q21 0 35.5 -14.5t14.5 -35.5v-350h245q20 0 25 -11t-9 -26l-383 -426q-14 -15 -33.5 -15t-32.5 15l-379 426q-13 15 -8.5 26t25.5 11h250v350q0 21 14.5 35.5t35.5 14.5zM50 300h1000q21 0 35.5 -14.5t14.5 -35.5v-250h-1100v250q0 21 14.5 35.5t35.5 14.5z M900 200v-50h100v50h-100z" />
<glyph unicode="&#xe167;" d="M583 1182l378 -435q14 -15 9 -31t-26 -16h-244v-250q0 -20 -17 -35t-39 -15h-200q-20 0 -32 14.5t-12 35.5v250h-250q-20 0 -25.5 16.5t8.5 31.5l383 431q14 16 33.5 17t33.5 -14zM50 300h1000q21 0 35.5 -14.5t14.5 -35.5v-250h-1100v250q0 21 14.5 35.5t35.5 14.5z M900 200v-50h100v50h-100z" />
<glyph unicode="&#xe168;" d="M396 723l369 369q7 7 17.5 7t17.5 -7l139 -139q7 -8 7 -18.5t-7 -17.5l-525 -525q-7 -8 -17.5 -8t-17.5 8l-292 291q-7 8 -7 18t7 18l139 139q8 7 18.5 7t17.5 -7zM50 300h1000q21 0 35.5 -14.5t14.5 -35.5v-250h-1100v250q0 21 14.5 35.5t35.5 14.5zM900 200v-50h100v50 h-100z" />
<glyph unicode="&#xe169;" d="M135 1023l142 142q14 14 35 14t35 -14l77 -77l-212 -212l-77 76q-14 15 -14 36t14 35zM655 855l210 210q14 14 24.5 10t10.5 -25l-2 -599q-1 -20 -15.5 -35t-35.5 -15l-597 -1q-21 0 -25 10.5t10 24.5l208 208l-154 155l212 212zM50 300h1000q21 0 35.5 -14.5t14.5 -35.5 v-250h-1100v250q0 21 14.5 35.5t35.5 14.5zM900 200v-50h100v50h-100z" />
<glyph unicode="&#xe170;" d="M350 1200l599 -2q20 -1 35 -15.5t15 -35.5l1 -597q0 -21 -10.5 -25t-24.5 10l-208 208l-155 -154l-212 212l155 154l-210 210q-14 14 -10 24.5t25 10.5zM524 512l-76 -77q-15 -14 -36 -14t-35 14l-142 142q-14 14 -14 35t14 35l77 77zM50 300h1000q21 0 35.5 -14.5 t14.5 -35.5v-250h-1100v250q0 21 14.5 35.5t35.5 14.5zM900 200v-50h100v50h-100z" />
<glyph unicode="&#xe171;" d="M1200 103l-483 276l-314 -399v423h-399l1196 796v-1096zM483 424v-230l683 953z" />
<glyph unicode="&#xe172;" d="M1100 1000v-850q0 -21 -14.5 -35.5t-35.5 -14.5h-150v400h-700v-400h-150q-21 0 -35.5 14.5t-14.5 35.5v1000q0 20 14.5 35t35.5 15h250v-300h500v300h100zM700 1000h-100v200h100v-200z" />
<glyph unicode="&#xe173;" d="M1100 1000l-2 -149l-299 -299l-95 95q-9 9 -21.5 9t-21.5 -9l-149 -147h-312v-400h-150q-21 0 -35.5 14.5t-14.5 35.5v1000q0 20 14.5 35t35.5 15h250v-300h500v300h100zM700 1000h-100v200h100v-200zM1132 638l106 -106q7 -7 7 -17.5t-7 -17.5l-420 -421q-8 -7 -18 -7 t-18 7l-202 203q-8 7 -8 17.5t8 17.5l106 106q7 8 17.5 8t17.5 -8l79 -79l297 297q7 7 17.5 7t17.5 -7z" />
<glyph unicode="&#xe174;" d="M1100 1000v-269l-103 -103l-134 134q-15 15 -33.5 16.5t-34.5 -12.5l-266 -266h-329v-400h-150q-21 0 -35.5 14.5t-14.5 35.5v1000q0 20 14.5 35t35.5 15h250v-300h500v300h100zM700 1000h-100v200h100v-200zM1202 572l70 -70q15 -15 15 -35.5t-15 -35.5l-131 -131 l131 -131q15 -15 15 -35.5t-15 -35.5l-70 -70q-15 -15 -35.5 -15t-35.5 15l-131 131l-131 -131q-15 -15 -35.5 -15t-35.5 15l-70 70q-15 15 -15 35.5t15 35.5l131 131l-131 131q-15 15 -15 35.5t15 35.5l70 70q15 15 35.5 15t35.5 -15l131 -131l131 131q15 15 35.5 15 t35.5 -15z" />
<glyph unicode="&#xe175;" d="M1100 1000v-300h-350q-21 0 -35.5 -14.5t-14.5 -35.5v-150h-500v-400h-150q-21 0 -35.5 14.5t-14.5 35.5v1000q0 20 14.5 35t35.5 15h250v-300h500v300h100zM700 1000h-100v200h100v-200zM850 600h100q21 0 35.5 -14.5t14.5 -35.5v-250h150q21 0 25 -10.5t-10 -24.5 l-230 -230q-14 -14 -35 -14t-35 14l-230 230q-14 14 -10 24.5t25 10.5h150v250q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe176;" d="M1100 1000v-400l-165 165q-14 15 -35 15t-35 -15l-263 -265h-402v-400h-150q-21 0 -35.5 14.5t-14.5 35.5v1000q0 20 14.5 35t35.5 15h250v-300h500v300h100zM700 1000h-100v200h100v-200zM935 565l230 -229q14 -15 10 -25.5t-25 -10.5h-150v-250q0 -20 -14.5 -35 t-35.5 -15h-100q-21 0 -35.5 15t-14.5 35v250h-150q-21 0 -25 10.5t10 25.5l230 229q14 15 35 15t35 -15z" />
<glyph unicode="&#xe177;" d="M50 1100h1100q21 0 35.5 -14.5t14.5 -35.5v-150h-1200v150q0 21 14.5 35.5t35.5 14.5zM1200 800v-550q0 -21 -14.5 -35.5t-35.5 -14.5h-1100q-21 0 -35.5 14.5t-14.5 35.5v550h1200zM100 500v-200h400v200h-400z" />
<glyph unicode="&#xe178;" d="M935 1165l248 -230q14 -14 14 -35t-14 -35l-248 -230q-14 -14 -24.5 -10t-10.5 25v150h-400v200h400v150q0 21 10.5 25t24.5 -10zM200 800h-50q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5h50v-200zM400 800h-100v200h100v-200zM18 435l247 230 q14 14 24.5 10t10.5 -25v-150h400v-200h-400v-150q0 -21 -10.5 -25t-24.5 10l-247 230q-15 14 -15 35t15 35zM900 300h-100v200h100v-200zM1000 500h51q20 0 34.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-34.5 -14.5h-51v200z" />
<glyph unicode="&#xe179;" d="M862 1073l276 116q25 18 43.5 8t18.5 -41v-1106q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v397q-4 1 -11 5t-24 17.5t-30 29t-24 42t-11 56.5v359q0 31 18.5 65t43.5 52zM550 1200q22 0 34.5 -12.5t14.5 -24.5l1 -13v-450q0 -28 -10.5 -59.5 t-25 -56t-29 -45t-25.5 -31.5l-10 -11v-447q0 -21 -14.5 -35.5t-35.5 -14.5h-200q-21 0 -35.5 14.5t-14.5 35.5v447q-4 4 -11 11.5t-24 30.5t-30 46t-24 55t-11 60v450q0 2 0.5 5.5t4 12t8.5 15t14.5 12t22.5 5.5q20 0 32.5 -12.5t14.5 -24.5l3 -13v-350h100v350v5.5t2.5 12 t7 15t15 12t25.5 5.5q23 0 35.5 -12.5t13.5 -24.5l1 -13v-350h100v350q0 2 0.5 5.5t3 12t7 15t15 12t24.5 5.5z" />
<glyph unicode="&#xe180;" d="M1200 1100v-56q-4 0 -11 -0.5t-24 -3t-30 -7.5t-24 -15t-11 -24v-888q0 -22 25 -34.5t50 -13.5l25 -2v-56h-400v56q75 0 87.5 6.5t12.5 43.5v394h-500v-394q0 -37 12.5 -43.5t87.5 -6.5v-56h-400v56q4 0 11 0.5t24 3t30 7.5t24 15t11 24v888q0 22 -25 34.5t-50 13.5 l-25 2v56h400v-56q-75 0 -87.5 -6.5t-12.5 -43.5v-394h500v394q0 37 -12.5 43.5t-87.5 6.5v56h400z" />
<glyph unicode="&#xe181;" d="M675 1000h375q21 0 35.5 -14.5t14.5 -35.5v-150h-105l-295 -98v98l-200 200h-400l100 100h375zM100 900h300q41 0 70.5 -29.5t29.5 -70.5v-500q0 -41 -29.5 -70.5t-70.5 -29.5h-300q-41 0 -70.5 29.5t-29.5 70.5v500q0 41 29.5 70.5t70.5 29.5zM100 800v-200h300v200 h-300zM1100 535l-400 -133v163l400 133v-163zM100 500v-200h300v200h-300zM1100 398v-248q0 -21 -14.5 -35.5t-35.5 -14.5h-375l-100 -100h-375l-100 100h400l200 200h105z" />
<glyph unicode="&#xe182;" d="M17 1007l162 162q17 17 40 14t37 -22l139 -194q14 -20 11 -44.5t-20 -41.5l-119 -118q102 -142 228 -268t267 -227l119 118q17 17 42.5 19t44.5 -12l192 -136q19 -14 22.5 -37.5t-13.5 -40.5l-163 -162q-3 -1 -9.5 -1t-29.5 2t-47.5 6t-62.5 14.5t-77.5 26.5t-90 42.5 t-101.5 60t-111 83t-119 108.5q-74 74 -133.5 150.5t-94.5 138.5t-60 119.5t-34.5 100t-15 74.5t-4.5 48z" />
<glyph unicode="&#xe183;" d="M600 1100q92 0 175 -10.5t141.5 -27t108.5 -36.5t81.5 -40t53.5 -37t31 -27l9 -10v-200q0 -21 -14.5 -33t-34.5 -9l-202 34q-20 3 -34.5 20t-14.5 38v146q-141 24 -300 24t-300 -24v-146q0 -21 -14.5 -38t-34.5 -20l-202 -34q-20 -3 -34.5 9t-14.5 33v200q3 4 9.5 10.5 t31 26t54 37.5t80.5 39.5t109 37.5t141 26.5t175 10.5zM600 795q56 0 97 -9.5t60 -23.5t30 -28t12 -24l1 -10v-50l365 -303q14 -15 24.5 -40t10.5 -45v-212q0 -21 -14.5 -35.5t-35.5 -14.5h-1100q-21 0 -35.5 14.5t-14.5 35.5v212q0 20 10.5 45t24.5 40l365 303v50 q0 4 1 10.5t12 23t30 29t60 22.5t97 10z" />
<glyph unicode="&#xe184;" d="M1100 700l-200 -200h-600l-200 200v500h200v-200h200v200h200v-200h200v200h200v-500zM250 400h700q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-12l137 -100h-950l137 100h-12q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5zM50 100h1100q21 0 35.5 -14.5 t14.5 -35.5v-50h-1200v50q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe185;" d="M700 1100h-100q-41 0 -70.5 -29.5t-29.5 -70.5v-1000h300v1000q0 41 -29.5 70.5t-70.5 29.5zM1100 800h-100q-41 0 -70.5 -29.5t-29.5 -70.5v-700h300v700q0 41 -29.5 70.5t-70.5 29.5zM400 0h-300v400q0 41 29.5 70.5t70.5 29.5h100q41 0 70.5 -29.5t29.5 -70.5v-400z " />
<glyph unicode="&#xe186;" d="M200 1100h700q124 0 212 -88t88 -212v-500q0 -124 -88 -212t-212 -88h-700q-124 0 -212 88t-88 212v500q0 124 88 212t212 88zM100 900v-700h900v700h-900zM500 700h-200v-100h200v-300h-300v100h200v100h-200v300h300v-100zM900 700v-300l-100 -100h-200v500h200z M700 700v-300h100v300h-100z" />
<glyph unicode="&#xe187;" d="M200 1100h700q124 0 212 -88t88 -212v-500q0 -124 -88 -212t-212 -88h-700q-124 0 -212 88t-88 212v500q0 124 88 212t212 88zM100 900v-700h900v700h-900zM500 300h-100v200h-100v-200h-100v500h100v-200h100v200h100v-500zM900 700v-300l-100 -100h-200v500h200z M700 700v-300h100v300h-100z" />
<glyph unicode="&#xe188;" d="M200 1100h700q124 0 212 -88t88 -212v-500q0 -124 -88 -212t-212 -88h-700q-124 0 -212 88t-88 212v500q0 124 88 212t212 88zM100 900v-700h900v700h-900zM500 700h-200v-300h200v-100h-300v500h300v-100zM900 700h-200v-300h200v-100h-300v500h300v-100z" />
<glyph unicode="&#xe189;" d="M200 1100h700q124 0 212 -88t88 -212v-500q0 -124 -88 -212t-212 -88h-700q-124 0 -212 88t-88 212v500q0 124 88 212t212 88zM100 900v-700h900v700h-900zM500 400l-300 150l300 150v-300zM900 550l-300 -150v300z" />
<glyph unicode="&#xe190;" d="M200 1100h700q124 0 212 -88t88 -212v-500q0 -124 -88 -212t-212 -88h-700q-124 0 -212 88t-88 212v500q0 124 88 212t212 88zM100 900v-700h900v700h-900zM900 300h-700v500h700v-500zM800 700h-130q-38 0 -66.5 -43t-28.5 -108t27 -107t68 -42h130v300zM300 700v-300 h130q41 0 68 42t27 107t-28.5 108t-66.5 43h-130z" />
<glyph unicode="&#xe191;" d="M200 1100h700q124 0 212 -88t88 -212v-500q0 -124 -88 -212t-212 -88h-700q-124 0 -212 88t-88 212v500q0 124 88 212t212 88zM100 900v-700h900v700h-900zM500 700h-200v-100h200v-300h-300v100h200v100h-200v300h300v-100zM900 300h-100v400h-100v100h200v-500z M700 300h-100v100h100v-100z" />
<glyph unicode="&#xe192;" d="M200 1100h700q124 0 212 -88t88 -212v-500q0 -124 -88 -212t-212 -88h-700q-124 0 -212 88t-88 212v500q0 124 88 212t212 88zM100 900v-700h900v700h-900zM300 700h200v-400h-300v500h100v-100zM900 300h-100v400h-100v100h200v-500zM300 600v-200h100v200h-100z M700 300h-100v100h100v-100z" />
<glyph unicode="&#xe193;" d="M200 1100h700q124 0 212 -88t88 -212v-500q0 -124 -88 -212t-212 -88h-700q-124 0 -212 88t-88 212v500q0 124 88 212t212 88zM100 900v-700h900v700h-900zM500 500l-199 -200h-100v50l199 200v150h-200v100h300v-300zM900 300h-100v400h-100v100h200v-500zM701 300h-100 v100h100v-100z" />
<glyph unicode="&#xe194;" d="M600 1191q120 0 229.5 -47t188.5 -126t126 -188.5t47 -229.5t-47 -229.5t-126 -188.5t-188.5 -126t-229.5 -47t-229.5 47t-188.5 126t-126 188.5t-47 229.5t47 229.5t126 188.5t188.5 126t229.5 47zM600 1021q-114 0 -211 -56.5t-153.5 -153.5t-56.5 -211t56.5 -211 t153.5 -153.5t211 -56.5t211 56.5t153.5 153.5t56.5 211t-56.5 211t-153.5 153.5t-211 56.5zM800 700h-300v-200h300v-100h-300l-100 100v200l100 100h300v-100z" />
<glyph unicode="&#xe195;" d="M600 1191q120 0 229.5 -47t188.5 -126t126 -188.5t47 -229.5t-47 -229.5t-126 -188.5t-188.5 -126t-229.5 -47t-229.5 47t-188.5 126t-126 188.5t-47 229.5t47 229.5t126 188.5t188.5 126t229.5 47zM600 1021q-114 0 -211 -56.5t-153.5 -153.5t-56.5 -211t56.5 -211 t153.5 -153.5t211 -56.5t211 56.5t153.5 153.5t56.5 211t-56.5 211t-153.5 153.5t-211 56.5zM800 700v-100l-50 -50l100 -100v-50h-100l-100 100h-150v-100h-100v400h300zM500 700v-100h200v100h-200z" />
<glyph unicode="&#xe197;" d="M503 1089q110 0 200.5 -59.5t134.5 -156.5q44 14 90 14q120 0 205 -86.5t85 -207t-85 -207t-205 -86.5h-128v250q0 21 -14.5 35.5t-35.5 14.5h-300q-21 0 -35.5 -14.5t-14.5 -35.5v-250h-222q-80 0 -136 57.5t-56 136.5q0 69 43 122.5t108 67.5q-2 19 -2 37q0 100 49 185 t134 134t185 49zM525 500h150q10 0 17.5 -7.5t7.5 -17.5v-275h137q21 0 26 -11.5t-8 -27.5l-223 -244q-13 -16 -32 -16t-32 16l-223 244q-13 16 -8 27.5t26 11.5h137v275q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe198;" d="M502 1089q110 0 201 -59.5t135 -156.5q43 15 89 15q121 0 206 -86.5t86 -206.5q0 -99 -60 -181t-150 -110l-378 360q-13 16 -31.5 16t-31.5 -16l-381 -365h-9q-79 0 -135.5 57.5t-56.5 136.5q0 69 43 122.5t108 67.5q-2 19 -2 38q0 100 49 184.5t133.5 134t184.5 49.5z M632 467l223 -228q13 -16 8 -27.5t-26 -11.5h-137v-275q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v275h-137q-21 0 -26 11.5t8 27.5q199 204 223 228q19 19 31.5 19t32.5 -19z" />
<glyph unicode="&#xe199;" d="M700 100v100h400l-270 300h170l-270 300h170l-300 333l-300 -333h170l-270 -300h170l-270 -300h400v-100h-50q-21 0 -35.5 -14.5t-14.5 -35.5v-50h400v50q0 21 -14.5 35.5t-35.5 14.5h-50z" />
<glyph unicode="&#xe200;" d="M600 1179q94 0 167.5 -56.5t99.5 -145.5q89 -6 150.5 -71.5t61.5 -155.5q0 -61 -29.5 -112.5t-79.5 -82.5q9 -29 9 -55q0 -74 -52.5 -126.5t-126.5 -52.5q-55 0 -100 30v-251q21 0 35.5 -14.5t14.5 -35.5v-50h-300v50q0 21 14.5 35.5t35.5 14.5v251q-45 -30 -100 -30 q-74 0 -126.5 52.5t-52.5 126.5q0 18 4 38q-47 21 -75.5 65t-28.5 97q0 74 52.5 126.5t126.5 52.5q5 0 23 -2q0 2 -1 10t-1 13q0 116 81.5 197.5t197.5 81.5z" />
<glyph unicode="&#xe201;" d="M1010 1010q111 -111 150.5 -260.5t0 -299t-150.5 -260.5q-83 -83 -191.5 -126.5t-218.5 -43.5t-218.5 43.5t-191.5 126.5q-111 111 -150.5 260.5t0 299t150.5 260.5q83 83 191.5 126.5t218.5 43.5t218.5 -43.5t191.5 -126.5zM476 1065q-4 0 -8 -1q-121 -34 -209.5 -122.5 t-122.5 -209.5q-4 -12 2.5 -23t18.5 -14l36 -9q3 -1 7 -1q23 0 29 22q27 96 98 166q70 71 166 98q11 3 17.5 13.5t3.5 22.5l-9 35q-3 13 -14 19q-7 4 -15 4zM512 920q-4 0 -9 -2q-80 -24 -138.5 -82.5t-82.5 -138.5q-4 -13 2 -24t19 -14l34 -9q4 -1 8 -1q22 0 28 21 q18 58 58.5 98.5t97.5 58.5q12 3 18 13.5t3 21.5l-9 35q-3 12 -14 19q-7 4 -15 4zM719.5 719.5q-49.5 49.5 -119.5 49.5t-119.5 -49.5t-49.5 -119.5t49.5 -119.5t119.5 -49.5t119.5 49.5t49.5 119.5t-49.5 119.5zM855 551q-22 0 -28 -21q-18 -58 -58.5 -98.5t-98.5 -57.5 q-11 -4 -17 -14.5t-3 -21.5l9 -35q3 -12 14 -19q7 -4 15 -4q4 0 9 2q80 24 138.5 82.5t82.5 138.5q4 13 -2.5 24t-18.5 14l-34 9q-4 1 -8 1zM1000 515q-23 0 -29 -22q-27 -96 -98 -166q-70 -71 -166 -98q-11 -3 -17.5 -13.5t-3.5 -22.5l9 -35q3 -13 14 -19q7 -4 15 -4 q4 0 8 1q121 34 209.5 122.5t122.5 209.5q4 12 -2.5 23t-18.5 14l-36 9q-3 1 -7 1z" />
<glyph unicode="&#xe202;" d="M700 800h300v-380h-180v200h-340v-200h-380v755q0 10 7.5 17.5t17.5 7.5h575v-400zM1000 900h-200v200zM700 300h162l-212 -212l-212 212h162v200h100v-200zM520 0h-395q-10 0 -17.5 7.5t-7.5 17.5v395zM1000 220v-195q0 -10 -7.5 -17.5t-17.5 -7.5h-195z" />
<glyph unicode="&#xe203;" d="M700 800h300v-520l-350 350l-550 -550v1095q0 10 7.5 17.5t17.5 7.5h575v-400zM1000 900h-200v200zM862 200h-162v-200h-100v200h-162l212 212zM480 0h-355q-10 0 -17.5 7.5t-7.5 17.5v55h380v-80zM1000 80v-55q0 -10 -7.5 -17.5t-17.5 -7.5h-155v80h180z" />
<glyph unicode="&#xe204;" d="M1162 800h-162v-200h100l100 -100h-300v300h-162l212 212zM200 800h200q27 0 40 -2t29.5 -10.5t23.5 -30t7 -57.5h300v-100h-600l-200 -350v450h100q0 36 7 57.5t23.5 30t29.5 10.5t40 2zM800 400h240l-240 -400h-800l300 500h500v-100z" />
<glyph unicode="&#xe205;" d="M650 1100h100q21 0 35.5 -14.5t14.5 -35.5v-50h50q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-300q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5h50v50q0 21 14.5 35.5t35.5 14.5zM1000 850v150q41 0 70.5 -29.5t29.5 -70.5v-800 q0 -41 -29.5 -70.5t-70.5 -29.5h-600q-1 0 -20 4l246 246l-326 326v324q0 41 29.5 70.5t70.5 29.5v-150q0 -62 44 -106t106 -44h300q62 0 106 44t44 106zM412 250l-212 -212v162h-200v100h200v162z" />
<glyph unicode="&#xe206;" d="M450 1100h100q21 0 35.5 -14.5t14.5 -35.5v-50h50q21 0 35.5 -14.5t14.5 -35.5v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-300q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5h50v50q0 21 14.5 35.5t35.5 14.5zM800 850v150q41 0 70.5 -29.5t29.5 -70.5v-500 h-200v-300h200q0 -36 -7 -57.5t-23.5 -30t-29.5 -10.5t-40 -2h-600q-41 0 -70.5 29.5t-29.5 70.5v800q0 41 29.5 70.5t70.5 29.5v-150q0 -62 44 -106t106 -44h300q62 0 106 44t44 106zM1212 250l-212 -212v162h-200v100h200v162z" />
<glyph unicode="&#xe209;" d="M658 1197l637 -1104q23 -38 7 -65.5t-60 -27.5h-1276q-44 0 -60 27.5t7 65.5l637 1104q22 39 54 39t54 -39zM704 800h-208q-20 0 -32 -14.5t-8 -34.5l58 -302q4 -20 21.5 -34.5t37.5 -14.5h54q20 0 37.5 14.5t21.5 34.5l58 302q4 20 -8 34.5t-32 14.5zM500 300v-100h200 v100h-200z" />
<glyph unicode="&#xe210;" d="M425 1100h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5zM425 800h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5 t17.5 7.5zM825 800h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5zM25 500h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v150 q0 10 7.5 17.5t17.5 7.5zM425 500h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5zM825 500h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5 v150q0 10 7.5 17.5t17.5 7.5zM25 200h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5zM425 200h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5 t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5zM825 200h250q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-250q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe211;" d="M700 1200h100v-200h-100v-100h350q62 0 86.5 -39.5t-3.5 -94.5l-66 -132q-41 -83 -81 -134h-772q-40 51 -81 134l-66 132q-28 55 -3.5 94.5t86.5 39.5h350v100h-100v200h100v100h200v-100zM250 400h700q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-12l137 -100 h-950l138 100h-13q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5zM50 100h1100q21 0 35.5 -14.5t14.5 -35.5v-50h-1200v50q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe212;" d="M600 1300q40 0 68.5 -29.5t28.5 -70.5h-194q0 41 28.5 70.5t68.5 29.5zM443 1100h314q18 -37 18 -75q0 -8 -3 -25h328q41 0 44.5 -16.5t-30.5 -38.5l-175 -145h-678l-178 145q-34 22 -29 38.5t46 16.5h328q-3 17 -3 25q0 38 18 75zM250 700h700q21 0 35.5 -14.5 t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-150v-200l275 -200h-950l275 200v200h-150q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5zM50 100h1100q21 0 35.5 -14.5t14.5 -35.5v-50h-1200v50q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe213;" d="M600 1181q75 0 128 -53t53 -128t-53 -128t-128 -53t-128 53t-53 128t53 128t128 53zM602 798h46q34 0 55.5 -28.5t21.5 -86.5q0 -76 39 -183h-324q39 107 39 183q0 58 21.5 86.5t56.5 28.5h45zM250 400h700q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-13 l138 -100h-950l137 100h-12q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5zM50 100h1100q21 0 35.5 -14.5t14.5 -35.5v-50h-1200v50q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe214;" d="M600 1300q47 0 92.5 -53.5t71 -123t25.5 -123.5q0 -78 -55.5 -133.5t-133.5 -55.5t-133.5 55.5t-55.5 133.5q0 62 34 143l144 -143l111 111l-163 163q34 26 63 26zM602 798h46q34 0 55.5 -28.5t21.5 -86.5q0 -76 39 -183h-324q39 107 39 183q0 58 21.5 86.5t56.5 28.5h45 zM250 400h700q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-13l138 -100h-950l137 100h-12q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5zM50 100h1100q21 0 35.5 -14.5t14.5 -35.5v-50h-1200v50q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe215;" d="M600 1200l300 -161v-139h-300q0 -57 18.5 -108t50 -91.5t63 -72t70 -67.5t57.5 -61h-530q-60 83 -90.5 177.5t-30.5 178.5t33 164.5t87.5 139.5t126 96.5t145.5 41.5v-98zM250 400h700q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-13l138 -100h-950l137 100 h-12q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5zM50 100h1100q21 0 35.5 -14.5t14.5 -35.5v-50h-1200v50q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe216;" d="M600 1300q41 0 70.5 -29.5t29.5 -70.5v-78q46 -26 73 -72t27 -100v-50h-400v50q0 54 27 100t73 72v78q0 41 29.5 70.5t70.5 29.5zM400 800h400q54 0 100 -27t72 -73h-172v-100h200v-100h-200v-100h200v-100h-200v-100h200q0 -83 -58.5 -141.5t-141.5 -58.5h-400 q-83 0 -141.5 58.5t-58.5 141.5v400q0 83 58.5 141.5t141.5 58.5z" />
<glyph unicode="&#xe218;" d="M150 1100h900q21 0 35.5 -14.5t14.5 -35.5v-500q0 -21 -14.5 -35.5t-35.5 -14.5h-900q-21 0 -35.5 14.5t-14.5 35.5v500q0 21 14.5 35.5t35.5 14.5zM125 400h950q10 0 17.5 -7.5t7.5 -17.5v-50q0 -10 -7.5 -17.5t-17.5 -7.5h-283l224 -224q13 -13 13 -31.5t-13 -32 t-31.5 -13.5t-31.5 13l-88 88h-524l-87 -88q-13 -13 -32 -13t-32 13.5t-13 32t13 31.5l224 224h-289q-10 0 -17.5 7.5t-7.5 17.5v50q0 10 7.5 17.5t17.5 7.5zM541 300l-100 -100h324l-100 100h-124z" />
<glyph unicode="&#xe219;" d="M200 1100h800q83 0 141.5 -58.5t58.5 -141.5v-200h-100q0 41 -29.5 70.5t-70.5 29.5h-250q-41 0 -70.5 -29.5t-29.5 -70.5h-100q0 41 -29.5 70.5t-70.5 29.5h-250q-41 0 -70.5 -29.5t-29.5 -70.5h-100v200q0 83 58.5 141.5t141.5 58.5zM100 600h1000q41 0 70.5 -29.5 t29.5 -70.5v-300h-1200v300q0 41 29.5 70.5t70.5 29.5zM300 100v-50q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v50h200zM1100 100v-50q0 -21 -14.5 -35.5t-35.5 -14.5h-100q-21 0 -35.5 14.5t-14.5 35.5v50h200z" />
<glyph unicode="&#xe221;" d="M480 1165l682 -683q31 -31 31 -75.5t-31 -75.5l-131 -131h-481l-517 518q-32 31 -32 75.5t32 75.5l295 296q31 31 75.5 31t76.5 -31zM108 794l342 -342l303 304l-341 341zM250 100h800q21 0 35.5 -14.5t14.5 -35.5v-50h-900v50q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe223;" d="M1057 647l-189 506q-8 19 -27.5 33t-40.5 14h-400q-21 0 -40.5 -14t-27.5 -33l-189 -506q-8 -19 1.5 -33t30.5 -14h625v-150q0 -21 14.5 -35.5t35.5 -14.5t35.5 14.5t14.5 35.5v150h125q21 0 30.5 14t1.5 33zM897 0h-595v50q0 21 14.5 35.5t35.5 14.5h50v50 q0 21 14.5 35.5t35.5 14.5h48v300h200v-300h47q21 0 35.5 -14.5t14.5 -35.5v-50h50q21 0 35.5 -14.5t14.5 -35.5v-50z" />
<glyph unicode="&#xe224;" d="M900 800h300v-575q0 -10 -7.5 -17.5t-17.5 -7.5h-375v591l-300 300v84q0 10 7.5 17.5t17.5 7.5h375v-400zM1200 900h-200v200zM400 600h300v-575q0 -10 -7.5 -17.5t-17.5 -7.5h-650q-10 0 -17.5 7.5t-7.5 17.5v950q0 10 7.5 17.5t17.5 7.5h375v-400zM700 700h-200v200z " />
<glyph unicode="&#xe225;" d="M484 1095h195q75 0 146 -32.5t124 -86t89.5 -122.5t48.5 -142q18 -14 35 -20q31 -10 64.5 6.5t43.5 48.5q10 34 -15 71q-19 27 -9 43q5 8 12.5 11t19 -1t23.5 -16q41 -44 39 -105q-3 -63 -46 -106.5t-104 -43.5h-62q-7 -55 -35 -117t-56 -100l-39 -234q-3 -20 -20 -34.5 t-38 -14.5h-100q-21 0 -33 14.5t-9 34.5l12 70q-49 -14 -91 -14h-195q-24 0 -65 8l-11 -64q-3 -20 -20 -34.5t-38 -14.5h-100q-21 0 -33 14.5t-9 34.5l26 157q-84 74 -128 175l-159 53q-19 7 -33 26t-14 40v50q0 21 14.5 35.5t35.5 14.5h124q11 87 56 166l-111 95 q-16 14 -12.5 23.5t24.5 9.5h203q116 101 250 101zM675 1000h-250q-10 0 -17.5 -7.5t-7.5 -17.5v-50q0 -10 7.5 -17.5t17.5 -7.5h250q10 0 17.5 7.5t7.5 17.5v50q0 10 -7.5 17.5t-17.5 7.5z" />
<glyph unicode="&#xe226;" d="M641 900l423 247q19 8 42 2.5t37 -21.5l32 -38q14 -15 12.5 -36t-17.5 -34l-139 -120h-390zM50 1100h106q67 0 103 -17t66 -71l102 -212h823q21 0 35.5 -14.5t14.5 -35.5v-50q0 -21 -14 -40t-33 -26l-737 -132q-23 -4 -40 6t-26 25q-42 67 -100 67h-300q-62 0 -106 44 t-44 106v200q0 62 44 106t106 44zM173 928h-80q-19 0 -28 -14t-9 -35v-56q0 -51 42 -51h134q16 0 21.5 8t5.5 24q0 11 -16 45t-27 51q-18 28 -43 28zM550 727q-32 0 -54.5 -22.5t-22.5 -54.5t22.5 -54.5t54.5 -22.5t54.5 22.5t22.5 54.5t-22.5 54.5t-54.5 22.5zM130 389 l152 130q18 19 34 24t31 -3.5t24.5 -17.5t25.5 -28q28 -35 50.5 -51t48.5 -13l63 5l48 -179q13 -61 -3.5 -97.5t-67.5 -79.5l-80 -69q-47 -40 -109 -35.5t-103 51.5l-130 151q-40 47 -35.5 109.5t51.5 102.5zM380 377l-102 -88q-31 -27 2 -65l37 -43q13 -15 27.5 -19.5 t31.5 6.5l61 53q19 16 14 49q-2 20 -12 56t-17 45q-11 12 -19 14t-23 -8z" />
<glyph unicode="&#xe227;" d="M625 1200h150q10 0 17.5 -7.5t7.5 -17.5v-109q79 -33 131 -87.5t53 -128.5q1 -46 -15 -84.5t-39 -61t-46 -38t-39 -21.5l-17 -6q6 0 15 -1.5t35 -9t50 -17.5t53 -30t50 -45t35.5 -64t14.5 -84q0 -59 -11.5 -105.5t-28.5 -76.5t-44 -51t-49.5 -31.5t-54.5 -16t-49.5 -6.5 t-43.5 -1v-75q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v75h-100v-75q0 -10 -7.5 -17.5t-17.5 -7.5h-150q-10 0 -17.5 7.5t-7.5 17.5v75h-175q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5h75v600h-75q-10 0 -17.5 7.5t-7.5 17.5v150 q0 10 7.5 17.5t17.5 7.5h175v75q0 10 7.5 17.5t17.5 7.5h150q10 0 17.5 -7.5t7.5 -17.5v-75h100v75q0 10 7.5 17.5t17.5 7.5zM400 900v-200h263q28 0 48.5 10.5t30 25t15 29t5.5 25.5l1 10q0 4 -0.5 11t-6 24t-15 30t-30 24t-48.5 11h-263zM400 500v-200h363q28 0 48.5 10.5 t30 25t15 29t5.5 25.5l1 10q0 4 -0.5 11t-6 24t-15 30t-30 24t-48.5 11h-363z" />
<glyph unicode="&#xe230;" d="M212 1198h780q86 0 147 -61t61 -147v-416q0 -51 -18 -142.5t-36 -157.5l-18 -66q-29 -87 -93.5 -146.5t-146.5 -59.5h-572q-82 0 -147 59t-93 147q-8 28 -20 73t-32 143.5t-20 149.5v416q0 86 61 147t147 61zM600 1045q-70 0 -132.5 -11.5t-105.5 -30.5t-78.5 -41.5 t-57 -45t-36 -41t-20.5 -30.5l-6 -12l156 -243h560l156 243q-2 5 -6 12.5t-20 29.5t-36.5 42t-57 44.5t-79 42t-105 29.5t-132.5 12zM762 703h-157l195 261z" />
<glyph unicode="&#xe231;" d="M475 1300h150q103 0 189 -86t86 -189v-500q0 -41 -42 -83t-83 -42h-450q-41 0 -83 42t-42 83v500q0 103 86 189t189 86zM700 300v-225q0 -21 -27 -48t-48 -27h-150q-21 0 -48 27t-27 48v225h300z" />
<glyph unicode="&#xe232;" d="M475 1300h96q0 -150 89.5 -239.5t239.5 -89.5v-446q0 -41 -42 -83t-83 -42h-450q-41 0 -83 42t-42 83v500q0 103 86 189t189 86zM700 300v-225q0 -21 -27 -48t-48 -27h-150q-21 0 -48 27t-27 48v225h300z" />
<glyph unicode="&#xe233;" d="M1294 767l-638 -283l-378 170l-78 -60v-224l100 -150v-199l-150 148l-150 -149v200l100 150v250q0 4 -0.5 10.5t0 9.5t1 8t3 8t6.5 6l47 40l-147 65l642 283zM1000 380l-350 -166l-350 166v147l350 -165l350 165v-147z" />
<glyph unicode="&#xe234;" d="M250 800q62 0 106 -44t44 -106t-44 -106t-106 -44t-106 44t-44 106t44 106t106 44zM650 800q62 0 106 -44t44 -106t-44 -106t-106 -44t-106 44t-44 106t44 106t106 44zM1050 800q62 0 106 -44t44 -106t-44 -106t-106 -44t-106 44t-44 106t44 106t106 44z" />
<glyph unicode="&#xe235;" d="M550 1100q62 0 106 -44t44 -106t-44 -106t-106 -44t-106 44t-44 106t44 106t106 44zM550 700q62 0 106 -44t44 -106t-44 -106t-106 -44t-106 44t-44 106t44 106t106 44zM550 300q62 0 106 -44t44 -106t-44 -106t-106 -44t-106 44t-44 106t44 106t106 44z" />
<glyph unicode="&#xe236;" d="M125 1100h950q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-950q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5zM125 700h950q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-950q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5 t17.5 7.5zM125 300h950q10 0 17.5 -7.5t7.5 -17.5v-150q0 -10 -7.5 -17.5t-17.5 -7.5h-950q-10 0 -17.5 7.5t-7.5 17.5v150q0 10 7.5 17.5t17.5 7.5z" />
<glyph unicode="&#xe237;" d="M350 1200h500q162 0 256 -93.5t94 -256.5v-500q0 -165 -93.5 -257.5t-256.5 -92.5h-500q-165 0 -257.5 92.5t-92.5 257.5v500q0 165 92.5 257.5t257.5 92.5zM900 1000h-600q-41 0 -70.5 -29.5t-29.5 -70.5v-600q0 -41 29.5 -70.5t70.5 -29.5h600q41 0 70.5 29.5 t29.5 70.5v600q0 41 -29.5 70.5t-70.5 29.5zM350 900h500q21 0 35.5 -14.5t14.5 -35.5v-300q0 -21 -14.5 -35.5t-35.5 -14.5h-500q-21 0 -35.5 14.5t-14.5 35.5v300q0 21 14.5 35.5t35.5 14.5zM400 800v-200h400v200h-400z" />
<glyph unicode="&#xe238;" d="M150 1100h1000q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-50v-200h50q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-50v-200h50q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5t-35.5 -14.5h-50v-200h50q21 0 35.5 -14.5t14.5 -35.5t-14.5 -35.5 t-35.5 -14.5h-1000q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5h50v200h-50q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5h50v200h-50q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5h50v200h-50q-21 0 -35.5 14.5t-14.5 35.5t14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe239;" d="M650 1187q87 -67 118.5 -156t0 -178t-118.5 -155q-87 66 -118.5 155t0 178t118.5 156zM300 800q124 0 212 -88t88 -212q-124 0 -212 88t-88 212zM1000 800q0 -124 -88 -212t-212 -88q0 124 88 212t212 88zM300 500q124 0 212 -88t88 -212q-124 0 -212 88t-88 212z M1000 500q0 -124 -88 -212t-212 -88q0 124 88 212t212 88zM700 199v-144q0 -21 -14.5 -35.5t-35.5 -14.5t-35.5 14.5t-14.5 35.5v142q40 -4 43 -4q17 0 57 6z" />
<glyph unicode="&#xe240;" d="M745 878l69 19q25 6 45 -12l298 -295q11 -11 15 -26.5t-2 -30.5q-5 -14 -18 -23.5t-28 -9.5h-8q1 0 1 -13q0 -29 -2 -56t-8.5 -62t-20 -63t-33 -53t-51 -39t-72.5 -14h-146q-184 0 -184 288q0 24 10 47q-20 4 -62 4t-63 -4q11 -24 11 -47q0 -288 -184 -288h-142 q-48 0 -84.5 21t-56 51t-32 71.5t-16 75t-3.5 68.5q0 13 2 13h-7q-15 0 -27.5 9.5t-18.5 23.5q-6 15 -2 30.5t15 25.5l298 296q20 18 46 11l76 -19q20 -5 30.5 -22.5t5.5 -37.5t-22.5 -31t-37.5 -5l-51 12l-182 -193h891l-182 193l-44 -12q-20 -5 -37.5 6t-22.5 31t6 37.5 t31 22.5z" />
<glyph unicode="&#xe241;" d="M1200 900h-50q0 21 -4 37t-9.5 26.5t-18 17.5t-22 11t-28.5 5.5t-31 2t-37 0.5h-200v-850q0 -22 25 -34.5t50 -13.5l25 -2v-100h-400v100q4 0 11 0.5t24 3t30 7t24 15t11 24.5v850h-200q-25 0 -37 -0.5t-31 -2t-28.5 -5.5t-22 -11t-18 -17.5t-9.5 -26.5t-4 -37h-50v300 h1000v-300zM500 450h-25q0 15 -4 24.5t-9 14.5t-17 7.5t-20 3t-25 0.5h-100v-425q0 -11 12.5 -17.5t25.5 -7.5h12v-50h-200v50q50 0 50 25v425h-100q-17 0 -25 -0.5t-20 -3t-17 -7.5t-9 -14.5t-4 -24.5h-25v150h500v-150z" />
<glyph unicode="&#xe242;" d="M1000 300v50q-25 0 -55 32q-14 14 -25 31t-16 27l-4 11l-289 747h-69l-300 -754q-18 -35 -39 -56q-9 -9 -24.5 -18.5t-26.5 -14.5l-11 -5v-50h273v50q-49 0 -78.5 21.5t-11.5 67.5l69 176h293l61 -166q13 -34 -3.5 -66.5t-55.5 -32.5v-50h312zM412 691l134 342l121 -342 h-255zM1100 150v-100q0 -21 -14.5 -35.5t-35.5 -14.5h-1000q-21 0 -35.5 14.5t-14.5 35.5v100q0 21 14.5 35.5t35.5 14.5h1000q21 0 35.5 -14.5t14.5 -35.5z" />
<glyph unicode="&#xe243;" d="M50 1200h1100q21 0 35.5 -14.5t14.5 -35.5v-1100q0 -21 -14.5 -35.5t-35.5 -14.5h-1100q-21 0 -35.5 14.5t-14.5 35.5v1100q0 21 14.5 35.5t35.5 14.5zM611 1118h-70q-13 0 -18 -12l-299 -753q-17 -32 -35 -51q-18 -18 -56 -34q-12 -5 -12 -18v-50q0 -8 5.5 -14t14.5 -6 h273q8 0 14 6t6 14v50q0 8 -6 14t-14 6q-55 0 -71 23q-10 14 0 39l63 163h266l57 -153q11 -31 -6 -55q-12 -17 -36 -17q-8 0 -14 -6t-6 -14v-50q0 -8 6 -14t14 -6h313q8 0 14 6t6 14v50q0 7 -5.5 13t-13.5 7q-17 0 -42 25q-25 27 -40 63h-1l-288 748q-5 12 -19 12zM639 611 h-197l103 264z" />
<glyph unicode="&#xe244;" d="M1200 1100h-1200v100h1200v-100zM50 1000h400q21 0 35.5 -14.5t14.5 -35.5v-900q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v900q0 21 14.5 35.5t35.5 14.5zM650 1000h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-400 q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5zM700 900v-300h300v300h-300z" />
<glyph unicode="&#xe245;" d="M50 1200h400q21 0 35.5 -14.5t14.5 -35.5v-900q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v900q0 21 14.5 35.5t35.5 14.5zM650 700h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v400 q0 21 14.5 35.5t35.5 14.5zM700 600v-300h300v300h-300zM1200 0h-1200v100h1200v-100z" />
<glyph unicode="&#xe246;" d="M50 1000h400q21 0 35.5 -14.5t14.5 -35.5v-350h100v150q0 21 14.5 35.5t35.5 14.5h400q21 0 35.5 -14.5t14.5 -35.5v-150h100v-100h-100v-150q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v150h-100v-350q0 -21 -14.5 -35.5t-35.5 -14.5h-400 q-21 0 -35.5 14.5t-14.5 35.5v800q0 21 14.5 35.5t35.5 14.5zM700 700v-300h300v300h-300z" />
<glyph unicode="&#xe247;" d="M100 0h-100v1200h100v-1200zM250 1100h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5zM300 1000v-300h300v300h-300zM250 500h900q21 0 35.5 -14.5t14.5 -35.5v-400 q0 -21 -14.5 -35.5t-35.5 -14.5h-900q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe248;" d="M600 1100h150q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-150v-100h450q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-900q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5h350v100h-150q-21 0 -35.5 14.5 t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5h150v100h100v-100zM400 1000v-300h300v300h-300z" />
<glyph unicode="&#xe249;" d="M1200 0h-100v1200h100v-1200zM550 1100h400q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-400q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5zM600 1000v-300h300v300h-300zM50 500h900q21 0 35.5 -14.5t14.5 -35.5v-400 q0 -21 -14.5 -35.5t-35.5 -14.5h-900q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5z" />
<glyph unicode="&#xe250;" d="M865 565l-494 -494q-23 -23 -41 -23q-14 0 -22 13.5t-8 38.5v1000q0 25 8 38.5t22 13.5q18 0 41 -23l494 -494q14 -14 14 -35t-14 -35z" />
<glyph unicode="&#xe251;" d="M335 635l494 494q29 29 50 20.5t21 -49.5v-1000q0 -41 -21 -49.5t-50 20.5l-494 494q-14 14 -14 35t14 35z" />
<glyph unicode="&#xe252;" d="M100 900h1000q41 0 49.5 -21t-20.5 -50l-494 -494q-14 -14 -35 -14t-35 14l-494 494q-29 29 -20.5 50t49.5 21z" />
<glyph unicode="&#xe253;" d="M635 865l494 -494q29 -29 20.5 -50t-49.5 -21h-1000q-41 0 -49.5 21t20.5 50l494 494q14 14 35 14t35 -14z" />
<glyph unicode="&#xe254;" d="M700 741v-182l-692 -323v221l413 193l-413 193v221zM1200 0h-800v200h800v-200z" />
<glyph unicode="&#xe255;" d="M1200 900h-200v-100h200v-100h-300v300h200v100h-200v100h300v-300zM0 700h50q0 21 4 37t9.5 26.5t18 17.5t22 11t28.5 5.5t31 2t37 0.5h100v-550q0 -22 -25 -34.5t-50 -13.5l-25 -2v-100h400v100q-4 0 -11 0.5t-24 3t-30 7t-24 15t-11 24.5v550h100q25 0 37 -0.5t31 -2 t28.5 -5.5t22 -11t18 -17.5t9.5 -26.5t4 -37h50v300h-800v-300z" />
<glyph unicode="&#xe256;" d="M800 700h-50q0 21 -4 37t-9.5 26.5t-18 17.5t-22 11t-28.5 5.5t-31 2t-37 0.5h-100v-550q0 -22 25 -34.5t50 -14.5l25 -1v-100h-400v100q4 0 11 0.5t24 3t30 7t24 15t11 24.5v550h-100q-25 0 -37 -0.5t-31 -2t-28.5 -5.5t-22 -11t-18 -17.5t-9.5 -26.5t-4 -37h-50v300 h800v-300zM1100 200h-200v-100h200v-100h-300v300h200v100h-200v100h300v-300z" />
<glyph unicode="&#xe257;" d="M701 1098h160q16 0 21 -11t-7 -23l-464 -464l464 -464q12 -12 7 -23t-21 -11h-160q-13 0 -23 9l-471 471q-7 8 -7 18t7 18l471 471q10 9 23 9z" />
<glyph unicode="&#xe258;" d="M339 1098h160q13 0 23 -9l471 -471q7 -8 7 -18t-7 -18l-471 -471q-10 -9 -23 -9h-160q-16 0 -21 11t7 23l464 464l-464 464q-12 12 -7 23t21 11z" />
<glyph unicode="&#xe259;" d="M1087 882q11 -5 11 -21v-160q0 -13 -9 -23l-471 -471q-8 -7 -18 -7t-18 7l-471 471q-9 10 -9 23v160q0 16 11 21t23 -7l464 -464l464 464q12 12 23 7z" />
<glyph unicode="&#xe260;" d="M618 993l471 -471q9 -10 9 -23v-160q0 -16 -11 -21t-23 7l-464 464l-464 -464q-12 -12 -23 -7t-11 21v160q0 13 9 23l471 471q8 7 18 7t18 -7z" />
<glyph unicode="&#xf8ff;" d="M1000 1200q0 -124 -88 -212t-212 -88q0 124 88 212t212 88zM450 1000h100q21 0 40 -14t26 -33l79 -194q5 1 16 3q34 6 54 9.5t60 7t65.5 1t61 -10t56.5 -23t42.5 -42t29 -64t5 -92t-19.5 -121.5q-1 -7 -3 -19.5t-11 -50t-20.5 -73t-32.5 -81.5t-46.5 -83t-64 -70 t-82.5 -50q-13 -5 -42 -5t-65.5 2.5t-47.5 2.5q-14 0 -49.5 -3.5t-63 -3.5t-43.5 7q-57 25 -104.5 78.5t-75 111.5t-46.5 112t-26 90l-7 35q-15 63 -18 115t4.5 88.5t26 64t39.5 43.5t52 25.5t58.5 13t62.5 2t59.5 -4.5t55.5 -8l-147 192q-12 18 -5.5 30t27.5 12z" />
<glyph unicode="&#x1f511;" d="M250 1200h600q21 0 35.5 -14.5t14.5 -35.5v-400q0 -21 -14.5 -35.5t-35.5 -14.5h-150v-500l-255 -178q-19 -9 -32 -1t-13 29v650h-150q-21 0 -35.5 14.5t-14.5 35.5v400q0 21 14.5 35.5t35.5 14.5zM400 1100v-100h300v100h-300z" />
<glyph unicode="&#x1f6aa;" d="M250 1200h750q39 0 69.5 -40.5t30.5 -84.5v-933l-700 -117v950l600 125h-700v-1000h-100v1025q0 23 15.5 49t34.5 26zM500 525v-100l100 20v100z" />
</font>
</defs></svg>

After

Width:  |  Height:  |  Size: 106 KiB

Binary file not shown.
Binary file not shown.
Binary file not shown.
+378
View File
@@ -0,0 +1,378 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/general/pi-configuration/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Model configuration - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Installation Model Catalog", url: "#_top", children: [
{title: "Host instructions in Administration", url: "#host-instructions-in-administration" },
{title: "Minimal catalog", url: "#minimal-catalog" },
{title: "Session adapters", url: "#session-adapters" },
{title: "Authentication", url: "#authentication" },
{title: "Generated runtime projections", url: "#generated-runtime-projections" },
{title: "Migrating a legacy installation", url: "#migrating-a-legacy-installation" },
{title: "Troubleshooting", url: "#troubleshooting" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../../operations/workspaces/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../../operations/workspaces/" class="btn btn-xs btn-link">
Workspaces
</a>
</div>
<div class="wm-article-nav">
<a href="../../install/authentik/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../../install/authentik/" class="btn btn-xs btn-link">
Authentik
</a>
</div>
</div>
<h1 id="installation-model-catalog">Installation Model Catalog<a class="headerlink" href="#installation-model-catalog" title="Permanent link">&para;</a></h1>
<p>ThothII has one operator-authored model source: <code>modelCatalog</code> in
<code>deploy/&lt;installation-id&gt;/thothii-installation.yaml</code>. It declares models used by interactive Pi
sessions, metadata generation, and the internal embedding service. Workspace descriptors never
declare providers, model allowlists, defaults, embeddings, dimensions, or vector-store settings.</p>
<p>Do not edit <code>deploy/pi/models.json</code>, <code>deploy/pi/settings.json</code>, files under <code>generated/</code>, or
provider/model environment defaults. Those former sources are retired.</p>
<h2 id="host-instructions-in-administration">Host instructions in Administration<a class="headerlink" href="#host-instructions-in-administration" title="Permanent link">&para;</a></h2>
<p>The <strong>Pi configuration</strong> navigation button opens <strong>Pi management</strong>. Its Host maintenance
section selects the installation host's Linux, macOS, or Windows tab automatically; the
browser's operating system does not affect it. Selecting another tab is still possible.</p>
<p>The host CLI includes <code>THT_HOST_PLATFORM</code> in the generated Compose projection using the OS
on which it runs. Generate projections on the destination host, not on another computer,
and do not edit generated files. Without this projection (older deployments or native
development), the backend reports its own OS; a Linux Docker container cannot discover
whether the physical host is macOS or Windows. Run the updated host CLI's normal
configuration reload on the destination installation to regenerate this information.</p>
<h2 id="minimal-catalog">Minimal catalog<a class="headerlink" href="#minimal-catalog" title="Permanent link">&para;</a></h2>
<pre class="highlight"><code class="language-yaml">schemaVersion: 2
modelCatalog:
defaults:
interaction: zai/glm-5.3
embedding:
id: ollama/qwen3-embedding:0.6b
dimensions: 1024
providers:
zai:
endpoint:
baseUrl: https://api.z.ai/api/coding/paas/v4
authentication:
mode: secret_env
apiKeyEnv: ZAI_API_KEY
session:
mode: openai_compatible
metadataGeneration:
litellmProvider: openai
models:
glm-5.3:
label: GLM 5.3
session:
reasoning: true
contextWindow: 200000
maxTokens: 131072
metadataGeneration: {}</code></pre>
<p>Provider and model entries are maps. The keys form the canonical identity
<code>&lt;provider-key&gt;/&lt;model-key&gt;</code>; <code>label</code> is only display text. A model is eligible for a use only when
it contains that use block:</p>
<ul>
<li><code>session</code> makes it selectable for interactive sessions;</li>
<li><code>metadataGeneration</code> makes it selectable for description generation;</li>
<li><code>embedding</code> is a single installation-level model rather than a selectable list.</li>
</ul>
<p><code>defaults.interaction</code> is the only LLM default, required once per installation, never per workspace.
Core and Administration share the user's operational model choice. An explicit choice takes priority
over the default and is remembered in this browser for the authenticated user and application mount.
Switching workspace does not change the model. Browser-storage restrictions may limit remembering
to the current visit; preferences do not synchronize across devices or change installation YAML.
An unavailable remembered model is not silently replaced: select another configured model.</p>
<p>When any metadata-generation models are configured, the default and the operational list must
support both <code>session</code> and <code>metadataGeneration</code>. Entries for just one adapter may remain in the
installation inventory, but are not selectable for global interaction. Core-only installations remain
supported when no metadata-generation model is configured; Admin AI is then unavailable.
The embedding model remains separate and is unaffected by the interaction selector.</p>
<p>New sessions record the selected model in their manifest. Resume retains the session's workspace and
revision, but uses the current global model (the installation default for clients that omit a model).
Historical manifest model fields are not rewritten by resume. Archived/finalized sessions remain read-only.</p>
<h3 id="required-operator-verification-for-every-model">Required operator verification for every model<a class="headerlink" href="#required-operator-verification-for-every-model" title="Permanent link">&para;</a></h3>
<p>Catalog validation checks configuration, not model behavior. Before offering a model to users, and
after changing its endpoint, adapters, or the Pi/LiteLLM versions, the operator must verify <strong>both</strong>:</p>
<ol>
<li><strong>Core / Pi:</strong> select the model, start a test session in a prepared test workspace, exercise an
actual tool call and its returned result, a human review gate, and stop/resume. Check streaming,
tool arguments, authentication, and reasoning/token-limit compatibility. A plain chat reply or
<code>tht pi test</code> alone is not sufficient.</li>
<li><strong>Administration / LiteLLM:</strong> select the same model and generate descriptions for a small,
non-sensitive test table. Check the structured result is accepted and the generation completes.
Review the output quality before using it on real metadata. This action writes test metadata
and may incur provider charges: use an authorized test database and approved data.</li>
</ol>
<p>There is no automatic certification flag or startup model probe. The operator owns this verification;
do not infer compatibility from the model label or from success in just one path. Both adapters point
to one catalog identity; Pi does not need to route through a new LiteLLM proxy. Models using only
<code>pi_auth</code> cannot serve the current LiteLLM path and are excluded from shared selection.</p>
<h2 id="session-adapters">Session adapters<a class="headerlink" href="#session-adapters" title="Permanent link">&para;</a></h2>
<p>Use <code>pi_builtin</code> for a model whose technical definition ships with Pi. This does not require
<code>pi_auth</code>: a shared bundle credential lets native Pi and LiteLLM use the same provider identity:</p>
<pre class="highlight"><code class="language-yaml">deepseek:
authentication:
mode: secret_env
apiKeyEnv: DEEPSEEK_API_KEY
session:
mode: pi_builtin
metadataGeneration:
litellmProvider: deepseek
models:
deepseek-v4-pro:
session: {}
metadataGeneration: {}
deepseek-v4-flash:
session: {}
metadataGeneration: {}</code></pre>
<p>Use <code>openai_compatible</code> for an explicit compatible endpoint. Each eligible session model must then
declare the technical limits Pi needs. <code>upstreamModel</code> is optional and is used only when the
endpoint expects a model name different from the catalog key.</p>
<p>Provider integrations remain declarative. Do not register providers from
<code>harness/.pi/extensions/</code>; those extensions implement the workflow and human gates only.</p>
<h3 id="qwen-36-sessions-and-thinking-controls">Qwen 3.6 sessions and thinking controls<a class="headerlink" href="#qwen-36-sessions-and-thinking-controls" title="Permanent link">&para;</a></h3>
<p>For Qwen served through a vLLM-compatible chat template, declare the following inside the
model's <code>session</code> block, alongside its context and output limits:</p>
<pre class="highlight"><code class="language-yaml">reasoning: true
compatibility:
supportsDeveloperRole: false
supportsReasoningEffort: false
supportsStore: false
maxTokensField: max_tokens
thinkingFormat: qwen-chat-template</code></pre>
<p>This makes Pi send <code>chat_template_kwargs.enable_thinking</code> from the selected thinking level,
with <code>preserve_thinking: true</code>. Choose <strong>off</strong> to explicitly disable thinking. The alternative
<code>thinkingFormat: qwen</code> is for endpoints expecting top-level <code>enable_thinking</code>. Both formats
require <code>reasoning: true</code>; declaring <code>reasoning: false</code> does not tell the server to disable
thinking. Omit <code>thinkingFormat</code> to preserve Pi's default behavior for other providers.</p>
<p>Regenerate projections with the updated host CLI and recreate the local core container after
rebuilding it. Do not add these fields directly to generated Pi files. These controls do not
force tool calls or certify the workflow; perform the operator verification above.</p>
<pre class="highlight"><code class="language-sh">tht --installation /absolute/path/thothii-installation.yaml installation generate</code></pre>
<p>Use the model identifier exposed by your endpoint, such as <code>qwen3.6-35b-a3b</code>, and limits
supported by that deployment. The thinking format configures the Pi session adapter;
metadata generation continues to use its separate LiteLLM settings.</p>
<p>If a session displays text such as <code>{"type":"bash","command":"tht session show … --json"}</code>
and never opens a review widget, that text is not an executed tool call. A verified cause
was the Evidence JSON extension being loaded into interactive sessions and forcing
<code>response_format: {type: "json_object"}</code>. Upgrade to the core image containing the fix:
the extension belongs in <code>.pi/evidence-extensions/</code> and is loaded explicitly only by
Evidence authoring. It must not also remain in the automatically loaded <code>.pi/extensions/</code>
directory. Regenerating model configuration alone does not remove an extension from an old image.</p>
<p>After upgrading, reload the browser and resume the session. Verify that Pi executes
<code>tht session show</code> and opens a review widget. This fix does not require changing the Qwen
server, forcing every turn to call a tool, or teaching the model to print tool-call JSON.</p>
<h2 id="authentication">Authentication<a class="headerlink" href="#authentication" title="Permanent link">&para;</a></h2>
<p>Every provider chooses one explicit mode:</p>
<ul>
<li><code>secret_env</code> names an approved key in the protected ThothII secret bundle through <code>apiKeyEnv</code>;</li>
<li><code>pi_auth</code> uses Pi's protected authentication projection and is valid only for session-only
<code>pi_builtin</code> providers;</li>
<li><code>none</code> is valid only with an explicit keyless endpoint.</li>
</ul>
<p>Secret values never belong in installation YAML, generated files, logs, CLI arguments, or browser
requests. The YAML contains only an environment-variable name or an authentication mode. Pi's
protected credential file remains selected by the installation authentication configuration.</p>
<p>For catalog providers using <code>secret_env</code>, the bundle is authoritative in both Core and Admin.
ThothII removes only the selected provider's old auth entry from the temporary Pi session snapshot;
the operator's original Pi auth store and other providers are unchanged. Provider smoke checks use
the same precedence, and model enumeration receives the catalog-declared bundle keys. A missing
declared key is an error, not permission to fall back to Pi auth or the legacy generic key file.
After rotating a bundle key, apply the normal installation lifecycle so processes reload it.</p>
<p>The PSD descriptor now declares only <code>deepseek/deepseek-v4-pro</code> and <code>deepseek/deepseek-v4-flash</code>
for both uses; it no longer duplicates them under <code>deepseek-metadata</code>. Historical records are not
rewritten. A saved obsolete identity must be explicitly reselected from the current catalog;
it is not silently remapped to another model or account.</p>
<h2 id="generated-runtime-projections">Generated runtime projections<a class="headerlink" href="#generated-runtime-projections" title="Permanent link">&para;</a></h2>
<p>Before Compose starts, <code>tht</code> validates the installation and atomically writes deterministic files
under <code>deploy/&lt;installation-id&gt;/generated/</code>:</p>
<pre class="highlight"><code class="language-text">generated/
├── catalog.json
├── pi/
│ ├── models.json
│ └── settings.json
└── compose.models.yaml</code></pre>
<p>The normalized catalog is consumed by the backend. The Pi files and Compose override are boundary
adapters. They are not configuration sources and are excluded from backup. Restore regenerates
them from the installation descriptor.</p>
<p>Run all lifecycle commands from the project root and select the descriptor explicitly when more
than one installation exists:</p>
<pre class="highlight"><code class="language-bash">INSTALLATION=/absolute/path/deploy/example/thothii-installation.yaml
tht --installation "$INSTALLATION" start
tht --installation "$INSTALLATION" doctor</code></pre>
<p>After editing <code>modelCatalog</code> or provider credentials, apply the complete runtime projection with
the normal installation lifecycle, then run the Pi checks:</p>
<pre class="highlight"><code class="language-bash">tht --installation "$INSTALLATION" start
tht --installation "$INSTALLATION" pi doctor
tht --installation "$INSTALLATION" pi test</code></pre>
<p><code>tht pi restart</code>, <code>tht pi update</code>, and <code>tht pi rollback</code> refuse to run while generated model
projections differ from <code>modelCatalog</code>: those commands recreate only <code>core</code>, so they must never
partially apply an embedding change. <code>tht pi update</code> changes the Pi version; it is not the
configuration command. There is no <code>tht pi configure</code> and no separate apply command.</p>
<h2 id="migrating-a-legacy-installation">Migrating a legacy installation<a class="headerlink" href="#migrating-a-legacy-installation" title="Permanent link">&para;</a></h2>
<p>For schema-v2 descriptors with the former <code>defaults.session</code> and <code>defaults.metadataGeneration</code>,
replace both with <code>defaults.interaction</code>. Equal legacy values are accepted and normalized in memory;
the loader never rewrites the descriptor. Different values fail with <code>migration_required</code>: explicitly
choose a model supporting both uses, remove both old fields, and set the single new field. Do not mix
new and legacy fields. A Core-only legacy session default can be normalized when Admin AI is absent.</p>
<p>The generated runtime catalog now uses schema version <strong>2</strong> and only <code>defaultInteraction</code>. Regenerate
and apply all runtime projections with the matching host/backend release using the normal installation
lifecycle; do not deploy only the backend against an old generated catalog or hand-edit generated JSON.</p>
<p>The migrator reads the former installation <code>metadataGeneration</code> block and the two former Pi JSON
files, but never modifies them. Supply the facts that cannot be inferred safely and write a separate
candidate:</p>
<pre class="highlight"><code class="language-bash">tht --installation /absolute/path/legacy/thothii-installation.yaml installation migrate \
--output /absolute/path/thothii-installation.v2.yaml \
--session-default zai/glm-5.3 \
--embedding-id ollama/qwen3-embedding:0.6b \
--embedding-dimensions 1024</code></pre>
<p>Review the candidate, move the legacy source files out of the installation only after approval,
then select the v2 descriptor. Ambiguous aliases, endpoint conflicts, or missing authentication
facts produce field-level errors; the migrator does not guess.
The legacy CLI flag <code>--session-default</code> now supplies the unified interaction default in the candidate;
if it conflicts with the legacy metadata default, align that choice explicitly before retrying.</p>
<h2 id="troubleshooting">Troubleshooting<a class="headerlink" href="#troubleshooting" title="Permanent link">&para;</a></h2>
<table>
<thead>
<tr>
<th>Symptom</th>
<th>Meaning</th>
<th>Action</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>migration_required</code></td>
<td>A retired model source or installation schema is still present</td>
<td>Run the installation migrator and review its candidate</td>
</tr>
<tr>
<td>Invalid interaction default</td>
<td>The canonical ID does not support all configured uses</td>
<td>Correct <code>defaults.interaction</code> or the intended adapter blocks</td>
</tr>
<tr>
<td>Generated projection drift</td>
<td>Runtime files differ from the descriptor-derived bytes</td>
<td>Run <code>tht start</code> or <code>tht pi restart --yes --drain</code></td>
</tr>
<tr>
<td><code>model_unavailable</code> on create/resume</td>
<td>The selected global model is no longer eligible</td>
<td>Explicitly choose an eligible model; no fallback is applied</td>
</tr>
<tr>
<td>Provider smoke failure</td>
<td>Credentials, endpoint, or provider availability is invalid</td>
<td>Correct the protected credential or catalog endpoint, restart, then run <code>tht pi test</code></td>
</tr>
</tbody>
</table>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../../operations/workspaces/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../../operations/workspaces/" class="btn btn-xs btn-link">
Workspaces
</a>
</div>
<div class="wm-article-nav">
<a href="../../install/authentik/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../../install/authentik/" class="btn btn-xs btn-link">
Authentik
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+230
View File
@@ -0,0 +1,230 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/guida-utente/">
<link rel="shortcut icon" href="../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>User guide - ThothII Docs</title>
<link href="../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../css/highlight.css">
<link href="../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../js/jquery-3.2.1.min.js"></script>
<script src="../js/bootstrap-3.3.7.min.js"></script>
<script src="../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '..';
var is_top_frame = false;
var pageToc = [
{title: "User guide: from question to validated SQL", url: "#_top", children: [
{title: "Standalone or inside Omics", url: "#standalone-or-inside-omics" },
{title: "Before creating a session", url: "#before-creating-a-session" },
{title: "Create and review a session", url: "#create-and-review-a-session" },
{title: "Resume, archive, and the meaning of saved state", url: "#resume-archive-and-the-meaning-of-saved-state" },
{title: "Choose the correct neighbouring path", url: "#choose-the-correct-neighbouring-path" },
]},
];
</script>
<script src="../js/base.js"></script>
<script src="../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../install/first-start/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../install/first-start/" class="btn btn-xs btn-link">
Start here
</a>
</div>
<div class="wm-article-nav">
<a href="../skills/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../skills/" class="btn btn-xs btn-link">
Reviewed workflow
</a>
</div>
</div>
<h1 id="user-guide-from-question-to-validated-sql">User guide: from question to validated SQL<a class="headerlink" href="#user-guide-from-question-to-validated-sql" title="Permanent link">&para;</a></h1>
<p>This guide is for a reviewer using a configured ThothII installation. Installation, workspace
publication, preprocessing, and database administration are separate paths; links to them are at
the end of this page.</p>
<h2 id="standalone-or-inside-omics">Standalone or inside Omics<a class="headerlink" href="#standalone-or-inside-omics" title="Permanent link">&para;</a></h2>
<p>In <strong>full</strong> mode, ThothII has its own red header. Sign in using the installation's
local account or the configured identity provider. The header lets you select
English/Italian, light/dark, and fullscreen; Esc exits fullscreen. Open the user
name menu to log out of ThothII. OIDC logout does not necessarily log out other
applications using the same provider.</p>
<p>In <strong>embedded</strong> mode, first sign in to Omics and choose <strong>Datamart Builder</strong> in
its left menu. ThothII opens with that authenticated identity: there is no second
login or duplicate header. Use Omics's language, theme, fullscreen and logout
controls. If portal access expires, return to Omics, sign in and reopen the page.</p>
<p>The Mac starts in English unless the browser remembers another choice. Changing
the UI language affects labels, not saved domain content. A new session takes
the selected language for the model's questions and reviewer choices; an existing
session retains its saved language when resumed. Omics's language change reloads
the page: confirm or cancel any unsaved-work warning. Reopening the saved session
selection shows documents; it does not automatically restart generation.</p>
<h2 id="before-creating-a-session">Before creating a session<a class="headerlink" href="#before-creating-a-session" title="Permanent link">&para;</a></h2>
<p>An administrator must have selected a workspace and configured the installation-wide provider,
model, and thinking settings. The new-question form deliberately asks only for the question.</p>
<p>The workspace is a pinned Git revision. A subsequent workspace update cannot alter a session
already created from an earlier revision. If a workspace cannot reach its configured runtime DWH,
new sessions are refused before any session state is written.</p>
<h2 id="create-and-review-a-session">Create and review a session<a class="headerlink" href="#create-and-review-a-session" title="Permanent link">&para;</a></h2>
<ol>
<li>Sign in and select <strong>Session</strong> (<strong>Sessione</strong> in Italian). If a session is already
open and unfinished, this returns to it without restarting it. Otherwise it
opens a new question; no session is created until you submit that question.</li>
<li>Enter a precise business question, including the relevant time period and desired output. For
example: “List patients discharged in the last 30 days, with ward and discharge date.”</li>
<li>Review each gate and make the decision requested by the widget. A choice with a decision payload
can persist immediately; a multi-choice widget records each selected decision; a confirmation
widget approves an artifact or phase.</li>
<li>Inspect the generated artifacts, especially schema linking, CTEs, and final SQL. The final SQL is
available only after the F7 review gate.</li>
<li>At F8, decide whether a datamart is requested. This is distinct from approving the SQL.</li>
</ol>
<p>The workflow phases are fixed:</p>
<table>
<thead>
<tr>
<th>Phase</th>
<th>What is reviewed</th>
</tr>
</thead>
<tbody>
<tr>
<td>F1–F3</td>
<td>clarification, reusable Memory, and the rewritten question</td>
</tr>
<tr>
<td>F4–F5</td>
<td>proposed tables, columns, Evidence, then their summary</td>
</tr>
<tr>
<td>F6</td>
<td>a CTE plan or an explicit skip</td>
</tr>
<tr>
<td>F7</td>
<td><code>sql_final.sql</code></td>
</tr>
<tr>
<td>F8</td>
<td>the datamart request or refusal</td>
</tr>
</tbody>
</table>
<h2 id="resume-archive-and-the-meaning-of-saved-state">Resume, archive, and the meaning of saved state<a class="headerlink" href="#resume-archive-and-the-meaning-of-saved-state" title="Permanent link">&para;</a></h2>
<p>In Administration, the dot beside <strong>Workspace</strong> is green when readiness is
confirmed and red otherwise. Hover the button for the exact state; assistive
technology receives the same description. Select Workspace to inspect preparation.</p>
<p>The session sidebar has two accordion sections: <strong>Active sessions</strong> and
<strong>Archive</strong>, both initially closed. Only their headers appear below the scope tabs.
Inside each nonempty list, <strong>Select all</strong> selects only that list; its delete action
also applies only to the selected sessions in that list. The other list's selection
is preserved. Opening a section closes the other; clicking the open section closes
it too. Empty lists show only "No sessions yet." Long lists scroll inside
their own panels. Here active means not archived, not necessarily a running model
process. Existing groups and session actions remain inside those sections.</p>
<p>The sidebar lists sessions and their current lifecycle. Resuming returns to the last incomplete
phase. A finalized or archived session cannot be resumed.</p>
<p>The source of truth is the workspace session directory: <code>session_manifest.yaml</code>, phase artifacts,
and <code>review_decisions.jsonl</code>. The visible activity stream is rebuilt from live SSE events and is
not a transcript store. Therefore a decision or artifact that has not been persisted did not
happen from the workflow’s point of view.</p>
<h2 id="choose-the-correct-neighbouring-path">Choose the correct neighbouring path<a class="headerlink" href="#choose-the-correct-neighbouring-path" title="Permanent link">&para;</a></h2>
<ul>
<li>To prepare, update, validate, or preprocess a workspace, use
<a href="../operations/workspaces/">Workspace operations</a>.</li>
<li>To create a database configuration, refresh its physical schema, or generate catalog
descriptions, use <a href="../operations/database-management/">Database management</a>.</li>
<li>To author material the workflow can retrieve, use <a href="../evidence/">Evidence</a>. A proposal from a
session does not become Evidence automatically: a curator must review and publish it in Git.</li>
<li>For login and access recovery, use <a href="../install/authentication-local/">local authentication</a> or
<a href="../install/authentication-oidc/">OIDC authentication</a> for full, or contact the
portal administrator for <a href="../install/shell-and-language/">embedded/upstream access</a>.</li>
</ul>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../install/first-start/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../install/first-start/" class="btn btn-xs btn-link">
Start here
</a>
</div>
<div class="wm-article-nav">
<a href="../skills/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../skills/" class="btn btn-xs btn-link">
Reviewed workflow
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

+295
View File
@@ -0,0 +1,295 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta name="description" content="Understand, install, and use ThothII">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/">
<link rel="shortcut icon" href="./img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>ThothII Docs</title>
<link href="./css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="./css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="./css/base.css" rel="stylesheet">
<link rel="stylesheet" href="./css/highlight.css">
<link href="stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="./js/jquery-3.2.1.min.js"></script>
<script src="./js/bootstrap-3.3.7.min.js"></script>
<script src="./js/highlight.pack.js"></script>
<script src="./js/elasticlunr.min.js"></script>
<base target="_top">
<script>
var base_url = '.';
var is_top_frame = (window === window.parent);
var pageToc = [
{title: "ThothII documentation", url: "#_top", children: [
{title: "Scope of this manual", url: "#scope-of-this-manual" },
]},
];
</script>
<script src="./js/base.js"></script>
<script src="javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<nav class="navbar wm-page-top-frame">
<div class="container-fluid wm-top-container">
<div class="wm-top-tool pull-right wm-vcenter">
<form class="dropdown wm-vcentered" id="wm-search-form" action="./search.html">
<button id="wm-search-show" class="btn btn-sm btn-default" type="submit"
><i class="fa fa-search" aria-hidden="true"></i></button>
<div class="input-group input-group-sm wm-top-search">
<input type="text" name="q" class="form-control" id="mkdocs-search-query" placeholder="Search" autocomplete="off">
<span class="input-group-btn" role="search">
<button class="btn btn-default dropdown-toggle collapse" data-toggle="dropdown" type="button"><span class="caret"></span></button>
<ul id="mkdocs-search-results" class="dropdown-menu dropdown-menu-right"></ul>
<button id="wm-search-go" class="btn btn-default" type="submit"><i class="fa fa-search" aria-hidden="true"></i></button>
</span>
</div>
</form>
</div>
<div class="wm-top-tool wm-vcenter pull-right wm-small-left">
<button id="wm-toc-button" type="button" class="btn btn-sm btn-default wm-vcentered"><i class="fa fa-th-list" aria-hidden="true"></i></button>
</div>
<a href="" class="wm-top-brand wm-top-link wm-vcenter">
<div class="wm-top-title">
ThothII Docs<br>
</div>
</a>
</div>
</nav>
<div id="main-content" class="wm-page-top-frame">
<nav class="wm-toc-pane">
<ul class="wm-toctree">
<li class="wm-toc-li wm-toc-lev1 "><a href="" class="wm-article-link wm-toc-text">Home</a>
</li>
<li class="wm-toc-li wm-toc-lev1 wm-toc-opener"><span class="wm-toc-text">Understand ThothII</span>
</li>
<li class="wm-toc-li-nested collapse">
<ul class="wm-toctree">
<li class="wm-toc-li wm-toc-lev2 "><a href="product-overview/" class="wm-article-link wm-toc-text">Product overview</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="skills/" class="wm-article-link wm-toc-text">Reviewed workflow</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="guida-utente/" class="wm-article-link wm-toc-text">User guide</a>
</li>
</ul>
</li>
<li class="wm-toc-li wm-toc-lev1 wm-toc-opener"><span class="wm-toc-text">Install</span>
</li>
<li class="wm-toc-li-nested collapse">
<ul class="wm-toctree">
<li class="wm-toc-li wm-toc-lev2 "><a href="install/first-start/" class="wm-article-link wm-toc-text">Start here</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="install/standalone-manual-it/" class="wm-article-link wm-toc-text">Mac, Windows, Linux — Italiano</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="install/standalone-manual-en/" class="wm-article-link wm-toc-text">Mac, Windows, Linux — English</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="install/shell-and-language/" class="wm-article-link wm-toc-text">Display mode and language</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="install/authentication-local/" class="wm-article-link wm-toc-text">Local authentication</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="install/authentication-oidc/" class="wm-article-link wm-toc-text">OIDC authentication</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="install/authentik/" class="wm-article-link wm-toc-text">Authentik</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="general/pi-configuration/" class="wm-article-link wm-toc-text">Model configuration</a>
</li>
</ul>
</li>
<li class="wm-toc-li wm-toc-lev1 wm-toc-opener"><span class="wm-toc-text">Administer</span>
</li>
<li class="wm-toc-li-nested collapse">
<ul class="wm-toctree">
<li class="wm-toc-li wm-toc-lev2 "><a href="operations/workspaces/" class="wm-article-link wm-toc-text">Workspaces</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="operations/database-management/" class="wm-article-link wm-toc-text">Databases and descriptions</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="operations/sensitivity-analysis/" class="wm-article-link wm-toc-text">Sensitive columns</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="evidence/" class="wm-article-link wm-toc-text">Evidence</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="usage/memory/" class="wm-article-link wm-toc-text">Memory</a>
</li>
</ul>
</li>
<li class="wm-toc-li wm-toc-lev1 wm-toc-opener"><span class="wm-toc-text">Connect a REST DWH</span>
</li>
<li class="wm-toc-li-nested collapse">
<ul class="wm-toctree">
<li class="wm-toc-li wm-toc-lev2 "><a href="install/dwh-auth-server/" class="wm-article-link wm-toc-text">Server</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="install/dwh-auth-client-enrollment/" class="wm-article-link wm-toc-text">Client enrollment</a>
</li>
<li class="wm-toc-li wm-toc-lev2 "><a href="install/dwh-auth-tls/" class="wm-article-link wm-toc-text">TLS</a>
</li>
</ul>
</li>
</ul>
</nav>
<div class="wm-content-pane">
<iframe class="wm-article" name="article"></iframe>
</div>
</div>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="product-overview/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="product-overview/" class="btn btn-xs btn-link">
Product overview
</a>
</div>
</div>
<h1 id="thothii-documentation">ThothII documentation<a class="headerlink" href="#thothii-documentation" title="Permanent link">&para;</a></h1>
<p>ThothII turns a natural-language question into reviewed SQL. The model proposes;
a human reviewer decides which interpretations, sources and results to accept.</p>
<p>This is the public product manual. Start with the task you need to perform:</p>
<table>
<thead>
<tr>
<th>I need to…</th>
<th>Start here</th>
</tr>
</thead>
<tbody>
<tr>
<td>Understand the product and its boundaries</td>
<td><a href="product-overview/">What ThothII does</a></td>
</tr>
<tr>
<td>Install on Mac, Windows through WSL2, or Linux</td>
<td><a href="install/standalone-manual-it/">Italian procedure</a> · <a href="install/standalone-manual-en/">English procedure</a></td>
</tr>
<tr>
<td>Choose display mode and language</td>
<td><a href="install/shell-and-language/">Display mode and language</a></td>
</tr>
<tr>
<td>Configure login</td>
<td><a href="install/authentication-local/">Local accounts</a> · <a href="install/authentication-oidc/">OIDC</a></td>
</tr>
<tr>
<td>Configure model providers</td>
<td><a href="general/pi-configuration/">Model configuration</a></td>
</tr>
<tr>
<td>Prepare a domain workspace</td>
<td><a href="operations/workspaces/">Workspaces</a></td>
</tr>
<tr>
<td>Configure databases and reviewed descriptions</td>
<td><a href="operations/database-management/">Database management</a></td>
</tr>
<tr>
<td>Ask a question and review SQL</td>
<td><a href="guida-utente/">User guide</a> · <a href="skills/">Workflow</a></td>
</tr>
<tr>
<td>Maintain domain knowledge</td>
<td><a href="evidence/">Evidence</a> · <a href="usage/memory/">Memory</a></td>
</tr>
</tbody>
</table>
<h2 id="scope-of-this-manual">Scope of this manual<a class="headerlink" href="#scope-of-this-manual" title="Permanent link">&para;</a></h2>
<p>The manual covers the product, installation, use and administration. Architecture,
code contracts, design decisions, implementation plans, test reports and site-specific
deployment handoffs are developer/project material maintained in the repository;
they are not pages of this site and are not included in its search index.</p>
<p>The installation procedures distinguish checked documentation from platform and
functional tests that still require execution. A clone does not transfer another
installation's credentials, data or network access.</p>
<p>The host-side <code>tht</code> command operates an installation. The Python workflow CLI inside
the runtime is a separate internal interface; do not substitute its commands for
the host installation procedure.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="product-overview/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="product-overview/" class="btn btn-xs btn-link">
Product overview
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
<!--
MkDocs version : 1.6.1
Build Date UTC : 2026-09-26 22:42:07.304139+00:00
-->
+193
View File
@@ -0,0 +1,193 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/authentication-local/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Local authentication - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Local authentication", url: "#_top", children: [
{title: "Bootstrap", url: "#bootstrap" },
{title: "User administration", url: "#user-administration" },
{title: "Session behavior and recovery", url: "#session-behavior-and-recovery" },
{title: "Projected server installations", url: "#projected-server-installations" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../authentication-oidc/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../authentication-oidc/" class="btn btn-xs btn-link">
OIDC authentication
</a>
</div>
<div class="wm-article-nav">
<a href="../shell-and-language/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../shell-and-language/" class="btn btn-xs btn-link">
Display mode and language
</a>
</div>
</div>
<h1 id="local-authentication">Local authentication<a class="headerlink" href="#local-authentication" title="Permanent link">&para;</a></h1>
<p>Use local mode for a standalone PC or Mac, with <code>shell.mode: full</code> and
<code>shell.defaultLocale: en</code> in the installation descriptor. Presentation and
authentication are independent: selecting full does not create accounts. Omics
embedded instead uses the <a href="../shell-and-language/">upstream guide</a>, not local users.</p>
<p>Configure local authentication through <code>tht</code>; passwords are entered at an
echo-free prompt or read from a protected <code>--password-file</code>, never from a command argument.</p>
<h2 id="bootstrap">Bootstrap<a class="headerlink" href="#bootstrap" title="Permanent link">&para;</a></h2>
<p>After the installation descriptor and protected secret bundle exist, configure the first enabled
administrator:</p>
<pre class="highlight"><code class="language-sh">tht --installation /absolute/path/thothii-installation.yaml auth configure \
--mode local --public-url http://127.0.0.1:8080 \
--admin-user &lt;operator-user&gt; --admin-display-name &lt;display-name&gt; \
--password-file /absolute/path/protected-password-file</code></pre>
<p>The password file is temporary operator input: keep it private and remove it after configuration.
The resulting <code>users.yaml</code> contains Argon2id hashes, never plaintext passwords. To use prompts,
omit the admin and password options in an interactive terminal. <code>tht setup</code> performs the same
bootstrap before it starts the stack.</p>
<p>The non-secret local <code>auth.yaml</code> has this exact shape:</p>
<pre class="highlight"><code class="language-yaml">version: 1
mode: local
publicUrl: http://127.0.0.1:8080
session:
regularTtlSeconds: 43200
regularIdleSeconds: 7200
rememberTtlSeconds: 2592000
rememberIdleSeconds: 604800
oidcTtlSeconds: 28800
local:
usersFile: users.yaml</code></pre>
<h2 id="user-administration">User administration<a class="headerlink" href="#user-administration" title="Permanent link">&para;</a></h2>
<pre class="highlight"><code class="language-sh">tht auth user list [--json]
tht auth user add &lt;username&gt; --role user|admin [--display-name &lt;name&gt;] [--password-file &lt;file&gt;]
tht auth user set-password &lt;username&gt; [--password-file &lt;file&gt;]
tht auth user enable &lt;username&gt;
tht auth user disable &lt;username&gt;
tht auth user grant &lt;username&gt; --role user|admin
tht auth user revoke &lt;username&gt; --role user|admin
tht auth user logout-all &lt;username&gt; --yes</code></pre>
<p>User commands are unavailable in OIDC mode. The last enabled administrator cannot be disabled or
demoted. Every password, role, enabled-state, and <code>logout-all</code> change increments the user’s
<code>authRevision</code>, invalidating its sessions. <code>tht auth status --json</code> is redacted and suitable for
machine use; JSON output is pristine on stdout.</p>
<h2 id="session-behavior-and-recovery">Session behavior and recovery<a class="headerlink" href="#session-behavior-and-recovery" title="Permanent link">&para;</a></h2>
<p>Full shows its own login form and, after login, the verified display name in its
header. The name menu contains Log out. This sends a CSRF-protected request to
<code>/api/auth/logout</code>, revokes the session and returns to login. Language/theme
preferences may remain in the browser; they are not credentials.</p>
<p>An ordinary login expires after 2 hours idle or 12 hours absolute. Selecting <strong>Remember me</strong> makes
the cookie persistent and changes the limits to 7 days idle or 30 days absolute. Remembered
sessions survive a browser and backend restart, but not a user revision change, configuration
revision change, logout, or restore. Restore does not include sessions or OIDC state and requires
every user to authenticate again.</p>
<p>If access is lost, use <code>tht auth user set-password</code>, <code>enable</code>, role changes, or <code>logout-all</code> as
appropriate, then log in again. Do not copy passwords, hashes, cookies, CSRF values, or secret
values into tickets, logs, or evidence.</p>
<p>Check readiness with <code>tht auth check</code>; add <code>--json</code> for the machine contract. Use
<code>tht doctor --json</code> for the aggregate installation report.</p>
<h2 id="projected-server-installations">Projected server installations<a class="headerlink" href="#projected-server-installations" title="Permanent link">&para;</a></h2>
<p>This section applies only when a Linux <code>profile: server</code> descriptor declares a runtime projection.
The canonical authentication root stays root-owned and is the only authority. The container reads
only the separate read-only runtime projection selected by <code>CURRENT</code>; it never falls back to the
canonical files or to a previous generation. Run projected mutations and repairs through the
root-operated <code>tht</code> commands, and never edit runtime files directly.</p>
<p>Mac, Windows, and local direct-file authentication remain unchanged when the projection is absent.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../authentication-oidc/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../authentication-oidc/" class="btn btn-xs btn-link">
OIDC authentication
</a>
</div>
<div class="wm-article-nav">
<a href="../shell-and-language/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../shell-and-language/" class="btn btn-xs btn-link">
Display mode and language
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+218
View File
@@ -0,0 +1,218 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/authentication-oidc/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>OIDC authentication - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Generic OIDC authentication", url: "#_top", children: [
{title: "The groups claim is mandatory", url: "#the-groups-claim-is-mandatory" },
{title: "Checks and diagnostics", url: "#checks-and-diagnostics" },
{title: "Browser login and logout", url: "#browser-login-and-logout" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../authentik/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../authentik/" class="btn btn-xs btn-link">
Authentik
</a>
</div>
<div class="wm-article-nav">
<a href="../authentication-local/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../authentication-local/" class="btn btn-xs btn-link">
Local authentication
</a>
</div>
</div>
<h1 id="generic-oidc-authentication">Generic OIDC authentication<a class="headerlink" href="#generic-oidc-authentication" title="Permanent link">&para;</a></h1>
<p>Use this guide for <strong>ThothII's own login</strong>, normally <code>shell.mode: full</code> on an
autonomous server. It is not the integration procedure for an already logged-in
Omics user. That deployment uses <a href="../shell-and-language/">embedded/upstream</a>,
even when Omics's identity provider is Authentik.</p>
<p>OIDC mode supports a standards-based provider. The browser flow is generic: Authorization Code,
PKCE S256, state, nonce, issuer/signature/audience/expiry validation, and the fixed callback
<code>&lt;publicUrl&gt;/api/auth/oidc/callback</code>. The browser and API must use the same origin; configure the
reverse proxy to preserve that public origin and callback path.</p>
<p><code>publicUrl</code> is the public origin, without an application subpath. The current
full OIDC browser entry and callback use <code>/api/auth/oidc/login</code> and
<code>/api/auth/oidc/callback</code>; arbitrary prefixed OIDC hosting is not implemented by
selecting a different <code>backendBaseUrl</code>.</p>
<p>Configure the installation with <code>tht</code>:</p>
<pre class="highlight"><code class="language-sh">tht auth configure --mode oidc --public-url &lt;https-public-origin&gt; \
--issuer &lt;https-issuer&gt; --client-id &lt;client-id&gt; \
--authentik-base-url &lt;https-provider-origin&gt; \
--user-group 'TOT Users' --admin-group 'TOT Admin'</code></pre>
<p>The OIDC client secret is supplied through the protected secret bundle under the exact key
<code>THT_OIDC_CLIENT_SECRET</code>; it is never written into <code>auth.yaml</code>. The default scopes are exactly
<code>openid</code>, <code>profile</code>, and <code>email</code>.</p>
<p>Keep <code>AUTH_MODE</code> unset when using this file. A simultaneously mounted local/OIDC
configuration and <code>AUTH_MODE=upstream</code> is an error, not a fallback chain.</p>
<p>The non-secret OIDC configuration has this exact shape (replace angle-bracket placeholders with
operator values):</p>
<pre class="highlight"><code class="language-yaml">version: 1
mode: oidc
publicUrl: &lt;https-public-origin&gt;
session:
regularTtlSeconds: 43200
regularIdleSeconds: 7200
rememberTtlSeconds: 2592000
rememberIdleSeconds: 604800
oidcTtlSeconds: 28800
oidc:
issuer: &lt;https-issuer&gt;
clientId: &lt;client-id&gt;
clientSecretRef: THT_OIDC_CLIENT_SECRET
scopes: [openid, profile, email]
groupsClaim: groups
groupCatalog:
driver: authentik
baseUrl: &lt;https-provider-origin&gt;
apiTokenRef: THT_AUTHENTIK_API_TOKEN
authorization:
groupRoles:
TOT Users: [user]
TOT Admin: [admin]</code></pre>
<h2 id="the-groups-claim-is-mandatory">The groups claim is mandatory<a class="headerlink" href="#the-groups-claim-is-mandatory" title="Permanent link">&para;</a></h2>
<p>The ID token must contain a direct, non-empty <code>groups</code> array of strings. ThothII does not follow
distributed claims, overage links, or indirect provider expansion. Missing or malformed claims fail
closed. A browser callback exposes only HTTP 401 <code>oidc_callback_failed</code>; it never reveals whether
the claim was missing, malformed, indirect, or overage-style. The redacted diagnostic and
interactive device-flow contract uses <code>oidc_groups_claim_invalid</code> for invalid group-claim or
device-flow identity results.</p>
<p>Configured group names are exact and case-sensitive. The union of matched mappings determines the
Thoth roles. A token with no mapped group is authenticated but has no role and cannot use protected
routes. Additional provider groups are ignored silently, without an error or warning. Group
existence is separately proven by the configured catalog adapter; this is why a generic OIDC
provider may authenticate while still failing installation readiness.</p>
<h2 id="checks-and-diagnostics">Checks and diagnostics<a class="headerlink" href="#checks-and-diagnostics" title="Permanent link">&para;</a></h2>
<p>The surfaces have distinct semantics and this order is recommended:</p>
<ol>
<li>Workspace Validate performs static authentication validation without contacting the provider.</li>
<li><code>tht auth check</code> performs live, non-interactive authentication diagnosis, including discovery,
issuer/JWKS, catalog credentials, and all configured mapped groups.</li>
<li><code>tht auth check --interactive</code> repeats live diagnosis and additionally validates a device-flow
identity and its direct <code>groups</code> claim when Device Authorization is available.</li>
<li>Installation diagnostics perform aggregate live workspace and authentication validation.</li>
</ol>
<p>The live CLI forms are:</p>
<pre class="highlight"><code class="language-sh">tht auth check
tht auth check --json</code></pre>
<p>For a provider that advertises Device Authorization, <code>tht auth check --interactive</code> presents a
verification URI and one-time user code on the terminal, waits for completion, and validates a
real ID token including <code>groups</code>. It is an operator check, not a replacement for browser login.</p>
<p><code>tht doctor</code> emits this exact ordered report: <code>descriptor</code>, <code>files</code>, <code>docker</code>, <code>compose</code>,
<code>configuration</code>, <code>authentication</code>, <code>services</code>, <code>core-http</code>, <code>frontend-http</code>,
<code>workspace-registry</code>, <code>workflow</code>, <code>pi</code>. Its authentication entry is live and non-interactive.
Any authentication failure prevents activation according to the static or live scope of the
relevant diagnostic surface.</p>
<p>The complete closed diagnostic-code union and exact role-to-permission expansion are in the
<a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/architecture/authentication.md">authentication architecture</a>.</p>
<h2 id="browser-login-and-logout">Browser login and logout<a class="headerlink" href="#browser-login-and-logout" title="Permanent link">&para;</a></h2>
<p>ThothII redirects the browser to the provider and creates its own opaque session
after validating the callback. An existing provider SSO session may avoid another
password prompt, but this remains a distinct ThothII login/session, unlike Omics
upstream. Full's name menu logs out of ThothII only. It does not revoke the
provider session or log out other applications, so a subsequent login can return
immediately through SSO. No provider token is placed in the UI adapter or browser
storage. See the <a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/testing/authentication-manual-acceptance.md">manual acceptance matrix</a>.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../authentik/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../authentik/" class="btn btn-xs btn-link">
Authentik
</a>
</div>
<div class="wm-article-nav">
<a href="../authentication-local/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../authentication-local/" class="btn btn-xs btn-link">
Local authentication
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+130
View File
@@ -0,0 +1,130 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8"/>
<meta content="IE=edge" http-equiv="X-UA-Compatible"/>
<meta content="width=device-width, initial-scale=1.0" name="viewport"/>
<link href="https://git.tylconsulting.it/thothii-docs/install/authentik/" rel="canonical"/>
<link href="../../img/favicon.ico" rel="shortcut icon"/>
<meta content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" name="viewport"/>
<title>Authentik - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet"/>
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet"/>
<link href="../../css/base.css" rel="stylesheet"/>
<link href="../../css/highlight.css" rel="stylesheet"/>
<link href="../../stylesheets/extra.css" rel="stylesheet"/>
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top"/>
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Authentik provider configuration", url: "#_top", children: [
{title: "OIDC provider", url: "#oidc-provider" },
{title: "Group catalog", url: "#group-catalog" },
{title: "Diagnostics", url: "#diagnostics" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
<div class="wm-article-nav pull-right">
<a class="btn btn-xs btn-default pull-right" href="../../general/pi-configuration/">
Next
<i aria-hidden="true" class="fa fa-chevron-right"></i>
</a>
<a class="btn btn-xs btn-link" href="../../general/pi-configuration/">
Model configuration
</a>
</div>
<div class="wm-article-nav">
<a class="btn btn-xs btn-default pull-left" href="../authentication-oidc/">
<i aria-hidden="true" class="fa fa-chevron-left"></i>
Previous</a><a class="btn btn-xs btn-link" href="../authentication-oidc/">
OIDC authentication
</a>
</div>
</div>
<h1 id="authentik-provider-configuration">Authentik provider configuration<a class="headerlink" href="#authentik-provider-configuration" title="Permanent link"></a></h1>
<p>For <strong>full with direct OIDC</strong>, ThothII uses generic OIDC in the browser. Authentik
provides the identity provider and group catalog without adding a proprietary flow.
The provider/client/group setup below applies to that case only.</p>
<p>For <strong>embedded in Omics</strong>, retain Omics's existing Authentik authentication and
configure ThothII as upstream. Omics verifies <code>datamart_builder.access</code> and
administrator status and the proxy supplies the identity; no additional ThothII
OIDC client, login or local user is required for that path. Follow the
<a href="../shell-and-language/">portal integration guide</a>.</p>
<div class="mermaid">sequenceDiagram
participant Browser
participant ThothII
participant Authentik
Browser-&gt;&gt;ThothII: Sign in
ThothII-&gt;&gt;Authentik: Authorization Code with PKCE
Authentik--&gt;&gt;Browser: Login and consent
Browser-&gt;&gt;ThothII: Callback with code
ThothII-&gt;&gt;Authentik: Token exchange
Authentik--&gt;&gt;ThothII: Identity and groups
ThothII--&gt;&gt;Browser: Opaque session
</div>
<h2 id="oidc-provider">OIDC provider<a class="headerlink" href="#oidc-provider" title="Permanent link"></a></h2>
<ol>
<li>Create an OAuth2/OIDC application and provider.</li>
<li>Register exactly <code>PUBLIC_URL/api/auth/oidc/callback</code>.</li>
<li>Enable the <code>openid</code>, <code>profile</code>, and <code>email</code> scopes.</li>
<li>Configure a direct <code>groups</code> claim as an array of strings.</li>
</ol>
<h2 id="group-catalog">Group catalog<a class="headerlink" href="#group-catalog" title="Permanent link"></a></h2>
<p>Create a dedicated service account with read-only access to groups. Store its token in the
protected bundle as <code>THT_AUTHENTIK_API_TOKEN</code>.</p>
<p>Map the exact enterprise group names to the ThothII <code>user</code> and <code>admin</code> roles in <code>auth.yaml</code>.
Unmapped groups are ignored. A configured group that does not exist produces a closed error.</p>
<h2 id="diagnostics">Diagnostics<a class="headerlink" href="#diagnostics" title="Permanent link"></a></h2>
<p><code>tht auth check</code> checks discovery, the issuer, JWKS, catalog access, and the configured groups.
The <code>--interactive</code> option also verifies identity through device flow when the provider supports it.</p>
<p>Rotate the OIDC secret and group-catalog token separately. Neither may appear in YAML, shell
history, logs, or diagnostic output.</p>
<br/>
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
<div class="wm-article-nav pull-right">
<a class="btn btn-xs btn-default pull-right" href="../../general/pi-configuration/">
Next
<i aria-hidden="true" class="fa fa-chevron-right"></i>
</a>
<a class="btn btn-xs btn-link" href="../../general/pi-configuration/">
Model configuration
</a>
</div>
<div class="wm-article-nav">
<a class="btn btn-xs btn-default pull-left" href="../authentication-oidc/">
<i aria-hidden="true" class="fa fa-chevron-left"></i>
Previous</a><a class="btn btn-xs btn-link" href="../authentication-oidc/">
OIDC authentication
</a>
</div>
</div>
<br/>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
<script type="module">import mermaid from "https://unpkg.com/mermaid@10.4.0/dist/mermaid.esm.min.mjs";
mermaid.initialize({});</script></body>
</html>
@@ -0,0 +1,170 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/dwh-auth-client-enrollment/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Client enrollment - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "DWH REST client enrollment", url: "#_top", children: [
{title: "Delivery and storage", url: "#delivery-and-storage" },
{title: "ACME Limited configuration", url: "#acme-limited-configuration" },
{title: "Rotation and revocation", url: "#rotation-and-revocation" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../dwh-auth-tls/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../dwh-auth-tls/" class="btn btn-xs btn-link">
TLS
</a>
</div>
<div class="wm-article-nav">
<a href="../dwh-auth-server/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../dwh-auth-server/" class="btn btn-xs btn-link">
Server
</a>
</div>
</div>
<h1 id="dwh-rest-client-enrollment">DWH REST client enrollment<a class="headerlink" href="#dwh-rest-client-enrollment" title="Permanent link">&para;</a></h1>
<p>The <code>dwh-auth</code> credential belongs to one ThothII installation and is needed only when the
workspace uses the <code>rest_api</code> transport.</p>
<table>
<thead>
<tr>
<th>Trasporto</th>
<th>Materiale richiesto</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>rest_api</code></td>
<td>URL HTTPS, <code>API_KEY_FILE</code>, eventuale <code>TLS_CA_FILE</code></td>
</tr>
<tr>
<td><code>postgres_direct</code></td>
<td>Credenziali PostgreSQL e configurazione TLS PostgreSQL</td>
</tr>
<tr>
<td><code>ssh_tunnel</code></td>
<td>Credenziali PostgreSQL e materiale SSH</td>
</tr>
</tbody>
</table>
<h2 id="delivery-and-storage">Delivery and storage<a class="headerlink" href="#delivery-and-storage" title="Permanent link">&para;</a></h2>
<p>Receive the key and CA through separate protected channels. Store the key in the installation
vault or in a regular file accessible only to the authorized account. Do not put it in Git, YAML
files, arguments, logs, or shared screens.</p>
<h2 id="acme-limited-configuration">ACME Limited configuration<a class="headerlink" href="#acme-limited-configuration" title="Permanent link">&para;</a></h2>
<p>Esempio di binding headless per il workspace <code>acme-ebikes</code>:</p>
<pre class="highlight"><code class="language-dotenv">THT_WS_ACME_EBIKES_DWH_TRANSPORT=rest_api
THT_WS_ACME_EBIKES_DWH_BASE_URL=https://dwh.acme.example/dwh/
THT_WS_ACME_EBIKES_DWH_API_KEY_FILE=/run/secrets/acme-ebikes-dwh-api-key
THT_WS_ACME_EBIKES_DWH_TLS_CA_FILE=/run/secrets/acme-ebikes-dwh-ca.pem</code></pre>
<p>The workspace suffix comes from the immutable ID, with hyphens changed to underscores and letters
converted to uppercase. <code>API_KEY_FILE</code> contains the mounted file path, not the key value.</p>
<h2 id="rotation-and-revocation">Rotation and revocation<a class="headerlink" href="#rotation-and-revocation" title="Permanent link">&para;</a></h2>
<p>During rotation, receive the new generation, update the vault or mounted file, and confirm
connectivity through the harmless <code>/rpc/ping</code> route. The server owner revokes the previous
generation only after this confirmation.</p>
<p>A <code>401</code> means the key is missing, unknown, expired, or revoked. A <code>503</code> means the authorization
service or registry is unavailable. In either case, do not bypass REST or weaken TLS verification.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../dwh-auth-tls/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../dwh-auth-tls/" class="btn btn-xs btn-link">
TLS
</a>
</div>
<div class="wm-article-nav">
<a href="../dwh-auth-server/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../dwh-auth-server/" class="btn btn-xs btn-link">
Server
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+160
View File
@@ -0,0 +1,160 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8"/>
<meta content="IE=edge" http-equiv="X-UA-Compatible"/>
<meta content="width=device-width, initial-scale=1.0" name="viewport"/>
<link href="https://git.tylconsulting.it/thothii-docs/install/dwh-auth-server/" rel="canonical"/>
<link href="../../img/favicon.ico" rel="shortcut icon"/>
<meta content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" name="viewport"/>
<title>Server - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet"/>
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet"/>
<link href="../../css/base.css" rel="stylesheet"/>
<link href="../../css/highlight.css" rel="stylesheet"/>
<link href="../../stylesheets/extra.css" rel="stylesheet"/>
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top"/>
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "dwh-auth: server guide", url: "#_top", children: [
{title: "Security boundaries", url: "#security-boundaries" },
{title: "Installation", url: "#installation" },
{title: "Creating and revoking keys", url: "#creating-and-revoking-keys" },
{title: "Nginx integration", url: "#nginx-integration" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
<div class="wm-article-nav pull-right">
<a class="btn btn-xs btn-default pull-right" href="../dwh-auth-client-enrollment/">
Next
<i aria-hidden="true" class="fa fa-chevron-right"></i>
</a>
<a class="btn btn-xs btn-link" href="../dwh-auth-client-enrollment/">
Client enrollment
</a>
</div>
<div class="wm-article-nav">
<a class="btn btn-xs btn-default pull-left" href="../../usage/memory/">
<i aria-hidden="true" class="fa fa-chevron-left"></i>
Previous</a><a class="btn btn-xs btn-link" href="../../usage/memory/">
Memory
</a>
</div>
</div>
<h1 id="dwh-auth-server-guide"><code>dwh-auth</code>: server guide<a class="headerlink" href="#dwh-auth-server-guide" title="Permanent link"></a></h1>
<p><code>dwh-auth</code> protects the REST <code>/dwh/</code> route with a separate key for each ThothII installation.
It runs as a separate Linux service, does not read DWH data, and does not connect directly to
PostgreSQL.</p>
<div class="mermaid">flowchart LR
CLIENT["Installazione ThothII"] --&gt;|"X-API-Key"| NGINX["Nginx"]
NGINX --&gt; AUTH["dwh-auth\nUnix socket"]
AUTH --&gt; REGISTRY["Registro chiavi\nactive e revoked"]
AUTH --&gt;|"authorized"| REST["DWH REST"]
</div>
<h2 id="security-boundaries">Security boundaries<a class="headerlink" href="#security-boundaries" title="Permanent link"></a></h2>
<ul>
<li>A key identifies an installation, not a person.</li>
<li>Keys and backups stay in protected files and never enter Git, logs, arguments, or public JSON.</li>
<li>The registry stores digests and metadata, never the key in plaintext.</li>
<li>The REST route must be exposed only through verified TLS.</li>
</ul>
<h2 id="installation">Installation<a class="headerlink" href="#installation" title="Permanent link"></a></h2>
<p>Il servizio usa questi percorsi:</p>
<table>
<thead>
<tr>
<th>Oggetto</th>
<th>Percorso</th>
</tr>
</thead>
<tbody>
<tr>
<td>Binario</td>
<td><code>/usr/local/sbin/dwh-auth</code></td>
</tr>
<tr>
<td>Unit systemd</td>
<td><code>/etc/systemd/system/dwh-auth.service</code></td>
</tr>
<tr>
<td>Registro</td>
<td><code>/var/lib/dwh-auth/</code></td>
</tr>
<tr>
<td>Socket</td>
<td><code>/run/dwh-auth/verify.sock</code></td>
</tr>
<tr>
<td>Consegne protette</td>
<td><code>/root/dwh-auth-provision/</code></td>
</tr>
</tbody>
</table>
<p>Install the binary and unit with <code>root</code> ownership, create the <code>dwh-auth</code> service user, and enable
the unit with <code>systemctl enable --now dwh-auth</code>. The socket must be accessible to Nginx's group.</p>
<h2 id="creating-and-revoking-keys">Creating and revoking keys<a class="headerlink" href="#creating-and-revoking-keys" title="Permanent link"></a></h2>
<p>Esempio per l'installazione ACME Limited:</p>
<pre class="highlight"><code class="language-bash">sudo dwh-auth --registry-root /var/lib/dwh-auth key create \
--installation-id acme-factory-primary \
--description acme-factory-primary \
--output /root/dwh-auth-provision/acme-factory-primary.key</code></pre>
<p>Deliver the file through an enterprise vault or an authenticated channel. To rotate a key, create
a new one, distribute it, update the client, and revoke the old one using its public ID:</p>
<pre class="highlight"><code class="language-bash">sudo dwh-auth --registry-root /var/lib/dwh-auth key revoke \
--key-id PUBLIC_KEY_ID \
--reason scheduled-rotation</code></pre>
<p>Revocation is permanent. Keep encrypted registry backups before every mutation.</p>
<h2 id="nginx-integration">Nginx integration<a class="headerlink" href="#nginx-integration" title="Permanent link"></a></h2>
<p>Nginx forwards the key to the <code>dwh-auth</code> socket. Only an authorized response allows the request
to reach DWH REST. Missing, unknown, expired, or revoked keys receive <code>401</code>; an unavailable
service or registry produces <code>503</code>.</p>
<br/>
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
<div class="wm-article-nav pull-right">
<a class="btn btn-xs btn-default pull-right" href="../dwh-auth-client-enrollment/">
Next
<i aria-hidden="true" class="fa fa-chevron-right"></i>
</a>
<a class="btn btn-xs btn-link" href="../dwh-auth-client-enrollment/">
Client enrollment
</a>
</div>
<div class="wm-article-nav">
<a class="btn btn-xs btn-default pull-left" href="../../usage/memory/">
<i aria-hidden="true" class="fa fa-chevron-left"></i>
Previous</a><a class="btn btn-xs btn-link" href="../../usage/memory/">
Memory
</a>
</div>
</div>
<br/>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
<script type="module">import mermaid from "https://unpkg.com/mermaid@10.4.0/dist/mermaid.esm.min.mjs";
mermaid.initialize({});</script></body>
</html>
+131
View File
@@ -0,0 +1,131 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/dwh-auth-tls/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>TLS - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "TLS for DWH REST", url: "#_top", children: [
{title: "Private CA", url: "#private-ca" },
{title: "Out-of-band fingerprint", url: "#out-of-band-fingerprint" },
{title: "Renewal", url: "#renewal" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav">
<a href="../dwh-auth-client-enrollment/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../dwh-auth-client-enrollment/" class="btn btn-xs btn-link">
Client enrollment
</a>
</div>
</div>
<h1 id="tls-for-dwh-rest">TLS for DWH REST<a class="headerlink" href="#tls-for-dwh-rest" title="Permanent link">&para;</a></h1>
<p>The DWH key may be used only over verified TLS. Authorization or availability errors never justify
disabling certificate verification.</p>
<h2 id="private-ca">Private CA<a class="headerlink" href="#private-ca" title="Permanent link">&para;</a></h2>
<p>When DWH REST uses an enterprise CA, deliver the certificate separately from the API key. The CA
is not a credential, but its integrity is part of the security boundary. Keep it out of Git and
make it unwritable by unauthorized users.</p>
<p>Esempio ACME Limited:</p>
<pre class="highlight"><code class="language-dotenv">THT_WS_ACME_EBIKES_DWH_TLS_CA_FILE=/run/secrets/acme-ebikes-dwh-ca.pem</code></pre>
<h2 id="out-of-band-fingerprint">Out-of-band fingerprint<a class="headerlink" href="#out-of-band-fingerprint" title="Permanent link">&para;</a></h2>
<p>Calculate the fingerprint of the received file and compare it through an independent channel:</p>
<pre class="highlight"><code class="language-bash">openssl x509 -noout -fingerprint -sha256 \
-in /absolute/protected/acme-ebikes-dwh-ca.pem</code></pre>
<p>The certificate SAN must include the exact name used by the binding, such as <code>dwh.acme.example</code>.</p>
<h2 id="renewal">Renewal<a class="headerlink" href="#renewal" title="Permanent link">&para;</a></h2>
<ol>
<li>Prepare the new certificate and chain.</li>
<li>Confirm the SAN and fingerprint out of band.</li>
<li>Distribute the new CA to clients while temporarily keeping the old one.</li>
<li>Update the binding and confirm connectivity with normal TLS.</li>
<li>Install the server certificate.</li>
<li>Remove the old trust after the agreed window.</li>
</ol>
<p>Do not use <code>curl -k</code>, disable TLS, or embed complete certificates or fingerprints in shared documents.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav">
<a href="../dwh-auth-client-enrollment/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../dwh-auth-client-enrollment/" class="btn btn-xs btn-link">
Client enrollment
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
@@ -0,0 +1,39 @@
# Copy this file to a protected operator-controlled path named exactly thothii-installation.yaml
# and set mode 0600 (or 0400) before using it as THT_INSTALLATION_CONFIG_SOURCE.
# Replace every absolute placeholder. Select exactly one Git transport override.
schemaVersion: 2
profile: local
shell:
mode: full
defaultLocale: en
projectDirectory: "/absolute/path/to/ThothII"
envFile: "/absolute/path/to/ThothII/deploy/env/local.env"
workspaceRepository:
remote: git@git.example.com:organization/workspaces.git
branch: main
access: ssh
modelCatalog:
defaults:
session: deepseek/deepseek-v4-pro
metadataGeneration: openai/gpt-4.1-mini
embedding:
id: ollama/qwen3-embedding:0.6b
dimensions: 1024
providers:
deepseek:
authentication: {mode: pi_auth}
session: {mode: pi_builtin}
models:
deepseek-v4-pro:
session: {}
openai:
authentication: {mode: secret_env, apiKeyEnv: OPENAI_API_KEY}
metadataGeneration: {litellmProvider: openai}
models:
gpt-4.1-mini:
label: OpenAI Mini
metadataGeneration: {}
authentication:
configDirectory: "/absolute/path/to/thothii-auth"
overrides:
- "/absolute/path/to/ThothII/deploy/compose.git-ssh.yaml"
@@ -0,0 +1,49 @@
# Copy this file to a protected operator path named exactly thothii-installation.yaml
# and set mode 0600 (or 0400) before using it as THT_INSTALLATION_CONFIG_SOURCE.
# Replace every absolute placeholder. Select exactly one Git transport override.
schemaVersion: 2
profile: server
# Standalone server with protected direct OIDC auth, not the Omics upstream path.
# For Omics use authentication-upstream.md: embedded, no auth runtime projection.
shell:
mode: full
defaultLocale: en
projectDirectory: "/absolute/path/to/ThothII"
envFile: "/absolute/path/to/thothii-server-operator/server.env"
workspaceRepository:
remote: git@git.example.com:organization/workspaces.git
branch: main
access: ssh
modelCatalog:
defaults:
session: deepseek/deepseek-v4-pro
metadataGeneration: openai/gpt-4.1-mini
embedding:
id: ollama/qwen3-embedding:0.6b
dimensions: 1024
providers:
deepseek:
authentication: {mode: pi_auth}
session: {mode: pi_builtin}
models:
deepseek-v4-pro:
session: {}
openai:
endpoint: {baseUrl: https://api.openai.example/v1}
authentication: {mode: secret_env, apiKeyEnv: OPENAI_API_KEY}
metadataGeneration: {litellmProvider: openai}
models:
gpt-4.1-mini:
label: OpenAI Mini
metadataGeneration: {}
authentication:
# Root-operated source of truth; it is never mounted into core.
configDirectory: "/srv/example/thothii/auth-canonical"
runtimeProjection:
# The only authentication bind exposed to core by the automatic override.
directory: "/srv/example/thothii/auth-runtime"
uid: 10001
gid: 10001
overrides:
- "/absolute/path/to/ThothII/deploy/compose.session-server.yaml.example"
- "/absolute/path/to/ThothII/deploy/compose.git-ssh.yaml"
@@ -0,0 +1,14 @@
# Copy to an untracked operator file. This file contains only non-secret THT_WS_* bindings.
# Every *_FILE value is a container path supplied by the generated local connector override.
THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT=postgres_direct
THT_WS_NORTH_STAR_RESEARCH_DWH_HOST=dwh.internal.example
THT_WS_NORTH_STAR_RESEARCH_DWH_PORT=5432
THT_WS_NORTH_STAR_RESEARCH_DWH_USER=thoth_reader
THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE=/run/secrets/north-star-research-dwh-password
# Evidence examples use separate illustrative namespaces because one descriptor selects one mode.
# Values are container file paths only; signed URLs and credential contents stay in those files.
THT_WS_SIGNED_HTTP_EVIDENCE_SIGNED_URLS_FILE=/run/secrets/signed-http-evidence-urls.json
THT_WS_STATIC_S3_EVIDENCE_ACCESS_KEY_FILE=/run/secrets/static-s3-evidence-access-key
THT_WS_STATIC_S3_EVIDENCE_SECRET_KEY_FILE=/run/secrets/static-s3-evidence-secret-key
THT_WS_STATIC_S3_EVIDENCE_SESSION_TOKEN_FILE=/run/secrets/static-s3-evidence-session-token
+175
View File
@@ -0,0 +1,175 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/first-start/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Start here - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Install and first start", url: "#_top", children: [
{title: "What must be ready", url: "#what-must-be-ready" },
{title: "Follow the ordered procedure", url: "#follow-the-ordered-procedure" },
{title: "After startup", url: "#after-startup" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../standalone-manual-it/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../standalone-manual-it/" class="btn btn-xs btn-link">
Mac, Windows, Linux — Italiano
</a>
</div>
<div class="wm-article-nav">
<a href="../../guida-utente/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../../guida-utente/" class="btn btn-xs btn-link">
User guide
</a>
</div>
</div>
<h1 id="install-and-first-start">Install and first start<a class="headerlink" href="#install-and-first-start" title="Permanent link">&para;</a></h1>
<p>Use one complete procedure for a fresh installation:</p>
<ul>
<li><a href="../standalone-manual-it/">Italian manual installation</a></li>
<li><a href="../standalone-manual-en/">English manual installation</a></li>
</ul>
<p>Both cover macOS, Windows through Ubuntu WSL2, and Linux. They use a Gitea clone,
protected local configuration and manual terminal commands, without an application
installer or launcher. See their verification matrix for tests still pending.</p>
<h2 id="what-must-be-ready">What must be ready<a class="headerlink" href="#what-must-be-ready" title="Permanent link">&para;</a></h2>
<p>You need Docker with Compose, the host operator command <code>tht</code>, access to the workspace
repository, and the credentials and network routes for the configured DWH and model
providers. Pi runs inside the application runtime; no host Pi installation is needed.</p>
<p>The stack includes <code>frontend</code>, <code>core</code>, <code>catalog-db</code>, <code>qdrant</code>, <code>embedding</code>, plus the
one-shot <code>embedding-model-init</code> and <code>catalog-migrate</code> services. DWH and generative-model
endpoints remain separate installation settings.</p>
<p>Secrets, certificates, Pi authentication and endpoint bindings are protected local files.
Do not commit them or copy the configuration of another machine unchanged.</p>
<h2 id="follow-the-ordered-procedure">Follow the ordered procedure<a class="headerlink" href="#follow-the-ordered-procedure" title="Permanent link">&para;</a></h2>
<p>The bilingual guides provide the exact commands for:</p>
<ol>
<li>Cloning the selected revision and checking prerequisites.</li>
<li>Bootstrapping the native host command.</li>
<li>Preparing catalog passwords and using
<code>tht setup --profile local --shell-mode full --shell-default-locale en --configure-only</code>.</li>
<li>Completing model, authentication and workspace credentials.</li>
<li>Generating configuration, building images and explicitly running <code>catalog-migrate</code>.</li>
<li>Starting the installation and checking health and readiness.</li>
</ol>
<p>Do not run setup alone as a substitute for that sequence. Migrations are not an
implicit effect of backend startup or <code>tht start</code>. Do not mix this installation's
descriptor/project with a different low-level Compose environment.</p>
<p>For an already configured installation:</p>
<pre class="highlight"><code class="language-sh">tht --installation /absolute/path/thothii-installation.yaml status
tht --installation /absolute/path/thothii-installation.yaml doctor --json</code></pre>
<p><code>/health</code> checks application-process readiness. Doctor also checks configuration,
workspace, workflow and Pi prerequisites; a healthy web page alone does not prove
that a real database question can complete.</p>
<h2 id="after-startup">After startup<a class="headerlink" href="#after-startup" title="Permanent link">&para;</a></h2>
<p>Prepare <a href="../../operations/workspaces/">workspaces</a>, configure a database in
<a href="../../operations/database-management/">Database Management</a>, and complete the functional
checks in the installation guide before using real data.</p>
<p>See <a href="../shell-and-language/">display mode and language</a>, <a href="../authentication-local/">local authentication</a>,
<a href="../authentication-oidc/">OIDC</a> and <a href="../../general/pi-configuration/">model configuration</a>
for later changes. Embedded portal integration is separate from a fresh standalone setup.</p>
<p>Use the installation's normal <code>tht start</code>, <code>tht stop</code> and diagnostic commands.
Preserve its descriptor, credentials, database and persistent volumes; do not use
<code>down --volumes</code> as a routine stop or upgrade.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../standalone-manual-it/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../standalone-manual-it/" class="btn btn-xs btn-link">
Mac, Windows, Linux — Italiano
</a>
</div>
<div class="wm-article-nav">
<a href="../../guida-utente/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../../guida-utente/" class="btn btn-xs btn-link">
User guide
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+199
View File
@@ -0,0 +1,199 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/shell-and-language/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Display mode and language - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Display mode and language", url: "#_top", children: [
{title: "Standalone setup", url: "#standalone-setup" },
{title: "Authentication and embedded deployments", url: "#authentication-and-embedded-deployments" },
{title: "Three different languages", url: "#three-different-languages" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../authentication-local/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../authentication-local/" class="btn btn-xs btn-link">
Local authentication
</a>
</div>
<div class="wm-article-nav">
<a href="../standalone-manual-en/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../standalone-manual-en/" class="btn btn-xs btn-link">
Mac, Windows, Linux — English
</a>
</div>
</div>
<h1 id="display-mode-and-language">Display mode and language<a class="headerlink" href="#display-mode-and-language" title="Permanent link">&para;</a></h1>
<p>ThothII can run with its own application header (<strong>full</strong>) or inside an integrated
portal (<strong>embedded</strong>). Display mode and authentication are separate choices.</p>
<table>
<thead>
<tr>
<th>Installation</th>
<th>Display</th>
<th>Authentication</th>
</tr>
</thead>
<tbody>
<tr>
<td>Standalone local instance</td>
<td><code>full</code></td>
<td>Local ThothII account</td>
</tr>
<tr>
<td>Standalone server</td>
<td><code>full</code></td>
<td>Local accounts or configured OIDC provider</td>
</tr>
<tr>
<td>Integrated portal</td>
<td><code>embedded</code></td>
<td>Identity verified by the portal's trusted server proxy</td>
</tr>
</tbody>
</table>
<h2 id="standalone-setup">Standalone setup<a class="headerlink" href="#standalone-setup" title="Permanent link">&para;</a></h2>
<p>Follow the complete <a href="../standalone-manual-it/">Italian</a> or
<a href="../standalone-manual-en/">English</a> installation procedure. It explicitly selects
<code>--shell-mode full --shell-default-locale en</code> and separates configuration, credentials,
initial migrations and startup. Do not skip those steps by running setup alone.</p>
<p>The authored installation descriptor contains:</p>
<pre class="highlight"><code class="language-yaml">shell:
mode: full
defaultLocale: en</code></pre>
<p>Use <code>it</code> for an Italian initial interface. Existing browser language preferences can
override that initial value. Full mode remembers language and theme in the browser.</p>
<p>For an existing installation, preserve the current descriptor and edit only the intended
settings; do not rerun setup to overwrite it. With a current host <code>tht</code> binary:</p>
<pre class="highlight"><code class="language-sh">tht --installation /absolute/path/thothii-installation.yaml installation generate
tht --installation /absolute/path/thothii-installation.yaml start
tht --installation /absolute/path/thothii-installation.yaml status
tht --installation /absolute/path/thothii-installation.yaml doctor --json</code></pre>
<p>Generation updates derived configuration; it does not start services. <code>start</code> applies
the installation's normal lifecycle and is not guaranteed to touch only the frontend.
Follow the deployment's maintenance procedure and retain its network, authentication and
model settings. Do not edit generated files or remove persistent volumes.</p>
<h2 id="authentication-and-embedded-deployments">Authentication and embedded deployments<a class="headerlink" href="#authentication-and-embedded-deployments" title="Permanent link">&para;</a></h2>
<p>Full mode does not configure login by itself. See <a href="../authentication-local/">local authentication</a>
or <a href="../authentication-oidc/">OIDC</a>, with <a href="../authentik/">Authentik</a> as a provider option.</p>
<p>Embedded mode requires a compatible portal integration, not just a descriptor toggle.
The portal owns login/logout and supplies a server-verified identity. A presentation
adapter does not authenticate users. The core must not be reachable by a route that
bypasses the trusted proxy. Do not add a second OIDC login to an already authenticated
upstream deployment.</p>
<p>Portal implementation details belong to the
<a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/install/authentication-upstream.md">developer integration reference in the repository</a>,
not to the standalone installation procedure.</p>
<h2 id="three-different-languages">Three different languages<a class="headerlink" href="#three-different-languages" title="Permanent link">&para;</a></h2>
<ul>
<li><strong>Interface language</strong> controls labels, forms and application messages.</li>
<li><strong>Session interaction language</strong> is captured when a session is created. Resuming it
retains that language even if the interface language changes later.</li>
<li><strong>Workspace language</strong> concerns domain content and retrieval; switching the interface
does not translate Evidence, SQL, identifiers or database values.</li>
</ul>
<p>In embedded mode the interface follows the portal's language and theme. A portal language
change may reload the page. Saved session artifacts remain available, but resuming work
is explicit; a reload does not by itself request a new model generation.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../authentication-local/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../authentication-local/" class="btn btn-xs btn-link">
Local authentication
</a>
</div>
<div class="wm-article-nav">
<a href="../standalone-manual-en/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../standalone-manual-en/" class="btn btn-xs btn-link">
Mac, Windows, Linux — English
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+466
View File
@@ -0,0 +1,466 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/standalone-manual-en/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Mac, Windows, Linux — English - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Manual standalone installation", url: "#_top", children: [
{title: "Verification matrix", url: "#verification-matrix" },
{title: "Before you start", url: "#before-you-start" },
{title: "1. Clone a project revision", url: "#1-clone-a-project-revision" },
{title: "2. Check prerequisites and install the operator command", url: "#2-check-prerequisites-and-install-the-operator-command" },
{title: "3. Configure and start the local installation", url: "#3-configure-and-start-the-local-installation" },
{title: "4. Verify the installation", url: "#4-verify-the-installation" },
{title: "Daily lifecycle", url: "#daily-lifecycle" },
{title: "Quick diagnosis", url: "#quick-diagnosis" },
{title: "Acceptance checklist", url: "#acceptance-checklist" },
{title: "Out of scope for this release", url: "#out-of-scope-for-this-release" },
{title: "Related documents", url: "#related-documents" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../shell-and-language/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../shell-and-language/" class="btn btn-xs btn-link">
Display mode and language
</a>
</div>
<div class="wm-article-nav">
<a href="../standalone-manual-it/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../standalone-manual-it/" class="btn btn-xs btn-link">
Mac, Windows, Linux — Italiano
</a>
</div>
</div>
<h1 id="manual-standalone-installation">Manual standalone installation<a class="headerlink" href="#manual-standalone-installation" title="Permanent link">&para;</a></h1>
<p><a href="../standalone-manual-it/">Versione italiana</a></p>
<p>This is the verification procedure for preparing THothII as a standalone application in <code>full</code>
mode on macOS, Windows, and Linux.</p>
<p>In this document, “standalone” means that the user does not need to install Node.js, Python or Pi
on the host: the application services and local semantic
services run through Docker. DWH and LLM providers remain external endpoints configured by the
installation; this is not an offline package.</p>
<p>This path uses no graphical installer, native launcher, or Docker Hub image. It starts from a Gitea
clone and uses explicit terminal commands. Publishing pre-built images is a later step.</p>
<h2 id="verification-matrix">Verification matrix<a class="headerlink" href="#verification-matrix" title="Permanent link">&para;</a></h2>
<table>
<thead>
<tr>
<th>System</th>
<th>Recommended terminal</th>
<th>Runtime</th>
<th>Test architecture</th>
</tr>
</thead>
<tbody>
<tr>
<td>macOS supported by the installed Docker Desktop version</td>
<td>Bash in Terminal</td>
<td>Docker Desktop</td>
<td>Apple Silicon (<code>arm64</code>)</td>
</tr>
<tr>
<td>Windows 11</td>
<td>Ubuntu inside WSL2</td>
<td>Docker Desktop with WSL2 integration</td>
<td>x64 (<code>amd64</code>)</td>
</tr>
<tr>
<td>Ubuntu Linux 22.04 or 24.04</td>
<td>Bash</td>
<td>Docker Engine + Compose v2</td>
<td>x64 (<code>amd64</code>)</td>
</tr>
</tbody>
</table>
<p>Intel macOS is excluded from the first verification campaign. ARM Linux may be tested when the
machine’s Docker runtime reports <code>arm64</code>, but it is not part of the minimum matrix.</p>
<p>Documentation and Mac prerequisite checks have passed. Complete fresh installations on all three
systems remain pending; this matrix describes the tests to perform, not completed certification.</p>
<h2 id="before-you-start">Before you start<a class="headerlink" href="#before-you-start" title="Permanent link">&para;</a></h2>
<p>You need:</p>
<ul>
<li>access to the THothII Gitea repository and the workspace Git repository;</li>
<li>Git;</li>
<li>Docker Desktop on macOS and Windows, or Docker Engine with the Compose v2 plugin on Linux;</li>
<li>Bash, <code>curl</code>, OpenSSL and <code>shasum</code> (Ubuntu package: <code>libdigest-sha-perl</code>);</li>
<li>enough disk space to build the images and download the embedding model;</li>
<li>the DWH and LLM endpoints, plus the credentials required by the installation.</li>
</ul>
<p>On Linux, the current user must be able to run Docker. If the system requires <code>sudo</code>, add the user
to the Docker group according to local policy and open a new session before continuing.</p>
<p>On Windows, run every command in this guide from Ubuntu under WSL2. In Docker Desktop, enable WSL2
integration for that distribution. Clone the project inside the WSL2 Linux filesystem, for example
under <code>~/src</code>, rather than under <code>/mnt/c</code>: this avoids slow builds and path/line-ending issues. Pi
does not need to be installed on the host.</p>
<p>Check the runtime before or immediately after cloning:</p>
<pre class="highlight"><code class="language-sh">docker version
docker compose version
docker version --format '{{.Server.Arch}}'</code></pre>
<p>The last command must return <code>amd64</code>, <code>x86_64</code>, <code>arm64</code>, or <code>aarch64</code>.</p>
<h2 id="1-clone-a-project-revision">1. Clone a project revision<a class="headerlink" href="#1-clone-a-project-revision" title="Permanent link">&para;</a></h2>
<p>Use the project repository on Gitea:</p>
<pre class="highlight"><code class="language-sh">mkdir -p "$HOME/src"
cd "$HOME/src"
git clone https://git.tylconsulting.it/mptyl/ThothII.git
cd ThothII
git rev-parse --short HEAD</code></pre>
<p>For an SSH clone, when the key is already authorized on Gitea:</p>
<pre class="highlight"><code class="language-sh">git clone git@git.tylconsulting.it:mptyl/ThothII.git</code></pre>
<p>Record the hash printed by <code>git rev-parse</code> for a repeatable test. In a later campaign, use the
maintainer-approved revision/tag rather than implicitly following a mutable <code>main</code> branch.</p>
<h2 id="2-check-prerequisites-and-install-the-operator-command">2. Check prerequisites and install the operator command<a class="headerlink" href="#2-check-prerequisites-and-install-the-operator-command" title="Permanent link">&para;</a></h2>
<p>From the clone root:</p>
<pre class="highlight"><code class="language-sh">bash scripts/check-standalone-prerequisites.sh
export PATH="$HOME/.local/bin:$PATH"
THT_INSTALL_DIRECTORY="$HOME/.local/bin" bash scripts/install-tht.sh
tht version</code></pre>
<p><code>install-tht.sh</code> bootstraps only the native <code>tht</code> operator command; it does not install a desktop
version of THothII. It uses the repository’s Docker builder, installs the binary for the current
terminal environment, and installs it in the user directory. Persist <code>$HOME/.local/bin</code> in your
shell PATH for new terminals too. An existing <code>tht</code> in this directory will be updated.</p>
<p>On Windows, run these commands inside WSL2. The installed <code>tht</code> binary is the Linux binary inside
WSL2; the application runtime remains Docker Desktop. Do not use <code>scripts/install-tht.ps1</code> as the
primary path for this test.</p>
<h2 id="3-configure-and-start-the-local-installation">3. Configure and start the local installation<a class="headerlink" href="#3-configure-and-start-the-local-installation" title="Permanent link">&para;</a></h2>
<p>Run the remaining blocks in one Bash session from the physical clone root (<code>pwd -P</code>).
First create two distinct catalog passwords, preserving any existing files:</p>
<pre class="highlight"><code class="language-bash">umask 077
mkdir -p deploy/local/secrets
for name in catalog-runtime-password catalog-migrator-password; do
target="deploy/local/secrets/$name"
if [ ! -e "$target" ]; then
(set -C; openssl rand -hex 32 &gt; "$target") || exit 1
fi
done
export THT_CATALOG_RUNTIME_PASSWORD_SOURCE="$(pwd -P)/deploy/local/secrets/catalog-runtime-password"
export THT_CATALOG_MIGRATOR_PASSWORD_SOURCE="$(pwd -P)/deploy/local/secrets/catalog-migrator-password"</code></pre>
<p>Do not regenerate passwords for an initialized catalog. Configure without starting services:</p>
<pre class="highlight"><code class="language-sh">tht setup --profile local --shell-mode full --shell-default-locale en --configure-only</code></pre>
<p>Answer the prompts as follows:</p>
<table>
<thead>
<tr>
<th>Prompt</th>
<th>Value or rule</th>
</tr>
</thead>
<tbody>
<tr>
<td>Installation ID</td>
<td><code>local</code>, unless one clone hosts multiple installations</td>
</tr>
<tr>
<td>Deployment profile</td>
<td><code>local</code></td>
</tr>
<tr>
<td>DWH API endpoint</td>
<td>An <code>http(s)</code> URL without user, password, query, or fragment; may be empty for a smoke-only test</td>
</tr>
<tr>
<td>LLM API endpoint</td>
<td>An <code>http(s)</code> URL without credentials; may be empty for a smoke-only test</td>
</tr>
<tr>
<td>Workspace repository URL</td>
<td>The workspace repository URL, not the THothII source clone</td>
</tr>
<tr>
<td>Workspace branch</td>
<td>Normally <code>main</code></td>
</tr>
<tr>
<td>Workspace access</td>
<td><code>ssh</code> with a deploy key, or <code>https</code> with a protected credential file</td>
</tr>
<tr>
<td>File paths</td>
<td>Accept the default paths under <code>deploy/local/secrets/</code> for the first test</td>
</tr>
<tr>
<td>Secret templates</td>
<td>Answer <code>yes</code> when protected files do not exist yet</td>
</tr>
<tr>
<td>Authentication</td>
<td>Configure the local login required by the installation; never put passwords on a command line</td>
</tr>
</tbody>
</table>
<p>The generated configuration is local and ignored by Git:</p>
<pre class="highlight"><code class="language-text">deploy/local/thothii-installation.yaml
deploy/local/operator.env
deploy/local/auth/
deploy/local/secrets/</code></pre>
<p>Edit secrets only in protected local files; never commit them. <code>deploy/env/local.env.example</code> is a tracked reference; the
generated path <code>deploy/local/operator.env</code> is the active path for this installation.</p>
<h3 id="complete-protected-files">Complete protected files<a class="headerlink" href="#complete-protected-files" title="Permanent link">&para;</a></h3>
<p>If setup created blank templates, enter the values with a local editor:</p>
<pre class="highlight"><code class="language-sh">chmod 600 deploy/local/secrets/*
"${EDITOR:-vi}" deploy/local/secrets/thothii.secrets</code></pre>
<p>The bundle must contain only <code>KEY=VALUE</code> lines for credentials actually used by <code>modelCatalog</code>. The
allowed names and credential boundary are documented in the local file
<code>deploy/secrets/README.md</code>. Do not put tokens in URLs, the YAML
descriptor, the Git repository, or commands copied into the shell.</p>
<p>For SSH workspace access, also provide the private key and <code>known_hosts</code> file requested by setup.
For HTTPS access, provide the Git credential file and any required CA. Both must remain protected
and outside version control.</p>
<p>Before starting, complete these additional configuration steps:</p>
<ol>
<li>Add <code>THT_CATALOG_RUNTIME_PASSWORD_SOURCE</code> and <code>THT_CATALOG_MIGRATOR_PASSWORD_SOURCE</code> to
<code>deploy/local/operator.env</code>, with the same absolute paths exported above. Setup does not persist
these two variables. Store paths, not passwords.</li>
<li>Replace the descriptor's generic <code>modelCatalog</code> with the approved provider/model configuration.
The generated defaults do not replicate the existing Mac. See <a href="../../general/pi-configuration/">Pi/model configuration</a>
and the local example <code>deploy/psd/thothii-installation.yaml.example</code>.</li>
<li>Populate the keys referenced by <code>authentication.apiKeyEnv</code> in <code>thothii.secrets</code>. Providers using
<code>pi_auth</code> need valid credentials at <code>PI_AUTH_FILE</code>; the <code>{}</code> template is not authentication.</li>
<li>Complete the workspace Git files. SSH requires an authorized deploy key and verified known-hosts;
HTTPS requires the credential file and CA bundle expected by the overlay. Blank templates cannot
provide repository access.</li>
</ol>
<p>After editing generated configuration, do not rerun setup: it rejects different existing content.
Generate the projections and run the explicit migration below. Use <code>THT_GIT_ACCESS=https</code> if that
was selected during setup. This block targets the fresh <code>local</code> descriptor with only the Git overlay;
custom installations must include their extra descriptor overlays in the same order.</p>
<pre class="highlight"><code class="language-bash">INSTALLATION="$(pwd -P)/deploy/local/thothii-installation.yaml"
tht --installation "$INSTALLATION" installation generate
THT_PROJECT="thothii-$(printf '%s' "$INSTALLATION" | shasum -a 256 | cut -c 1-12)"
THT_GIT_ACCESS=ssh
compose=(
docker compose --project-name "$THT_PROJECT" --project-directory "$(pwd -P)"
--env-file "$(pwd -P)/deploy/local/operator.env"
-f compose.yaml -f deploy/compose.local.yaml
-f "deploy/compose.git-$THT_GIT_ACCESS.yaml"
-f deploy/local/generated/compose.models.yaml
)
"${compose[@]}" config --quiet
"${compose[@]}" build core frontend
"${compose[@]}" up -d catalog-db
"${compose[@]}" run --rm catalog-migrate
tht --installation "$INSTALLATION" start</code></pre>
<p>Stop if a command fails. The project name matches the hash used by <code>tht</code>, preserving volume
identity. <code>catalog-migrate</code> applies Catalog and Memory migrations; <code>tht start</code> does not run it
automatically. Initial embedding-model download may take time. Use this installation-specific
sequence, not <code>run-stack.sh</code> with a different environment/project name.</p>
<h2 id="4-verify-the-installation">4. Verify the installation<a class="headerlink" href="#4-verify-the-installation" title="Permanent link">&para;</a></h2>
<p>The descriptor generated for the default ID is:</p>
<pre class="highlight"><code class="language-sh">INSTALLATION="$(pwd -P)/deploy/local/thothii-installation.yaml"
test -f "$INSTALLATION"
bash scripts/verify-standalone-install.sh "$INSTALLATION"</code></pre>
<p>The verifier is read-only: it runs <code>tht doctor --json</code> and <code>tht status</code> without restarting the
stack, regenerating configuration, or printing secret contents.</p>
<h3 id="gate-a-platform-smoke-test-on-all-three-computers">Gate A — platform smoke test on all three computers<a class="headerlink" href="#gate-a-platform-smoke-test-on-all-three-computers" title="Permanent link">&para;</a></h3>
<p>Record the following for each machine:</p>
<pre class="highlight"><code class="language-sh">uname -a
docker version --format '{{.Server.Version}} {{.Server.Arch}}'
tht version
bash scripts/check-standalone-prerequisites.sh
bash scripts/verify-standalone-install.sh "$INSTALLATION"</code></pre>
<p>The gate passes when the clone is intact, Docker and Compose are reachable, <code>tht doctor</code> is OK, the
stack is running, and the frontend responds at the default local URL <code>http://127.0.0.1:8080</code>.
Doctor also checks workspace and Pi: record their failures separately rather than labeling every
failure as a platform problem. Check HTTP readiness with:</p>
<pre class="highlight"><code class="language-sh">curl --fail --silent --show-error http://127.0.0.1:8080/health</code></pre>
<h3 id="gate-b-functional-verification">Gate B — functional verification<a class="headerlink" href="#gate-b-functional-verification" title="Permanent link">&para;</a></h3>
<p>Run this on at least one machine with available endpoints and credentials:</p>
<p>First follow <a href="../../operations/workspaces/">Workspace operations</a> to import/prepare the workspace
and configure the Database and local binding. The source clone does not transfer catalog data,
secrets or sessions from the Mac. Connect any VPN required by DWH/model endpoints and verify
that their names are reachable from containers too.</p>
<ol>
<li>open <code>http://127.0.0.1:8080</code>;</li>
<li>sign in with the configured local account;</li>
<li>verify that the configured workspace is readable;</li>
<li>start a real question and complete the review gates through final SQL;</li>
<li>stop and restart the installation, then run <code>verify-standalone-install.sh</code> again.</li>
</ol>
<p>A Gate B failure involving DWH, the LLM provider, workspace Git, or credentials does not by itself
prove a Docker portability problem: record the failed endpoint or component separately.</p>
<h2 id="daily-lifecycle">Daily lifecycle<a class="headerlink" href="#daily-lifecycle" title="Permanent link">&para;</a></h2>
<p>Use the explicit descriptor when more than one installation may be discoverable:</p>
<pre class="highlight"><code class="language-sh">INSTALLATION="$PWD/deploy/local/thothii-installation.yaml"
tht --installation "$INSTALLATION" status
tht --installation "$INSTALLATION" start
tht --installation "$INSTALLATION" start --build
tht --installation "$INSTALLATION" logs
tht --installation "$INSTALLATION" doctor --json
tht --installation "$INSTALLATION" stop</code></pre>
<p>Use <code>start --build</code> after source changes or to rebuild images from the current checkout. <code>stop</code>
preserves volumes, sessions, the catalog, Pi state, Qdrant data, and the embedding model. Do not
use <code>docker compose down --volumes</code> during a normal test: it is destructive and removes local data.
For upgrades requiring migrations, follow the release runbook before starting the new application.</p>
<h2 id="quick-diagnosis">Quick diagnosis<a class="headerlink" href="#quick-diagnosis" title="Permanent link">&para;</a></h2>
<table>
<thead>
<tr>
<th>Symptom</th>
<th>Check</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>Docker Engine is not reachable</code></td>
<td>start Docker Desktop or the Docker service and rerun <code>docker info</code></td>
</tr>
<tr>
<td>Windows sees Docker but Bash fails</td>
<td>run the guide inside Ubuntu WSL2 and enable that distribution in Docker Desktop</td>
</tr>
<tr>
<td><code>tht: command not found</code></td>
<td>open a new shell and check <code>command -v tht</code>; rerun the bootstrap if needed</td>
</tr>
<tr>
<td>line-ending or executable-script errors</td>
<td>use a clone in the WSL2/Linux filesystem and rerun <code>bash scripts/...</code></td>
</tr>
<tr>
<td>unsupported architecture</td>
<td>check <code>docker version --format '{{.Server.Arch}}'</code>; the test requires <code>amd64</code> or <code>arm64</code></td>
</tr>
<tr>
<td>missing descriptor or env file</td>
<td>use <code>deploy/local/...</code> generated by <code>tht setup</code>, not an arbitrary copied file</td>
</tr>
<tr>
<td>healthy stack but workflow failure</td>
<td>check external URLs, the credential bundle, workspace Git, and authentication separately</td>
</tr>
<tr>
<td>data appears missing</td>
<td>check that <code>down --volumes</code> was not used; <code>stop</code> does not remove volumes</td>
</tr>
</tbody>
</table>
<h2 id="acceptance-checklist">Acceptance checklist<a class="headerlink" href="#acceptance-checklist" title="Permanent link">&para;</a></h2>
<ul>
<li>[ ] The clone comes from the expected Gitea repository and the revision is recorded.</li>
<li>[ ] Docker Desktop/Engine and Compose v2 are available.</li>
<li>[ ] The runtime reports an allowed architecture.</li>
<li>[ ] <code>tht</code> was built from the repository and responds to <code>tht version</code>.</li>
<li>[ ] Setup uses <code>profile: local</code>, <code>shell.mode: full</code>, and <code>shell.defaultLocale: en</code>.</li>
<li>[ ] The descriptor, <code>operator.env</code>, authentication, and secrets exist only under <code>deploy/local/</code>.</li>
<li>[ ] No secret appears in Git, URLs, public YAML, or recorded commands.</li>
<li>[ ] Gate A passes on Apple Silicon macOS, x64 Windows WSL2, and x64 Linux.</li>
<li>[ ] Gate B runs on at least one machine with DWH and LLM available.</li>
<li>[ ] Stop/start and final verification complete without deleting volumes.</li>
</ul>
<h2 id="out-of-scope-for-this-release">Out of scope for this release<a class="headerlink" href="#out-of-scope-for-this-release" title="Permanent link">&para;</a></h2>
<p>The following remain future work:</p>
<ul>
<li>publishing pre-built images on Docker Hub;</li>
<li>reducing prompts through a dedicated non-interactive configuration;</li>
<li>creating DMG, MSI/EXE, AppImage, or other native installers;</li>
<li>providing an offline runtime or bundling a local DWH/LLM into the application.</li>
</ul>
<h2 id="related-documents">Related documents<a class="headerlink" href="#related-documents" title="Permanent link">&para;</a></h2>
<ul>
<li><a href="../first-start/">Install and first start</a></li>
<li><a href="../shell-and-language/">Shell and localization</a></li>
<li><a href="../../operations/workspaces/">Workspace operations</a></li>
<li><code>deploy/secrets/README.md</code> (runtime secrets)</li>
</ul>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../shell-and-language/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../shell-and-language/" class="btn btn-xs btn-link">
Display mode and language
</a>
</div>
<div class="wm-article-nav">
<a href="../standalone-manual-it/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../standalone-manual-it/" class="btn btn-xs btn-link">
Mac, Windows, Linux — Italiano
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+471
View File
@@ -0,0 +1,471 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/standalone-manual-it/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Mac, Windows, Linux — Italiano - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Installazione manuale standalone", url: "#_top", children: [
{title: "Matrice di verifica", url: "#matrice-di-verifica" },
{title: "Cosa serve prima di iniziare", url: "#cosa-serve-prima-di-iniziare" },
{title: "1. Clonare una revisione del progetto", url: "#1-clonare-una-revisione-del-progetto" },
{title: "2. Verificare i prerequisiti e installare il comando operatore", url: "#2-verificare-i-prerequisiti-e-installare-il-comando-operatore" },
{title: "3. Configurare e avviare l\u2019installazione locale", url: "#3-configurare-e-avviare-linstallazione-locale" },
{title: "4. Verificare l\u2019installazione", url: "#4-verificare-linstallazione" },
{title: "Ciclo di vita quotidiano", url: "#ciclo-di-vita-quotidiano" },
{title: "Diagnosi rapida", url: "#diagnosi-rapida" },
{title: "Checklist di accettazione", url: "#checklist-di-accettazione" },
{title: "Fuori perimetro di questa release", url: "#fuori-perimetro-di-questa-release" },
{title: "Documenti collegati", url: "#documenti-collegati" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../standalone-manual-en/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../standalone-manual-en/" class="btn btn-xs btn-link">
Mac, Windows, Linux — English
</a>
</div>
<div class="wm-article-nav">
<a href="../first-start/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../first-start/" class="btn btn-xs btn-link">
Start here
</a>
</div>
</div>
<h1 id="installazione-manuale-standalone">Installazione manuale standalone<a class="headerlink" href="#installazione-manuale-standalone" title="Permanent link">&para;</a></h1>
<p><a href="../standalone-manual-en/">English version</a></p>
<p>Questa è la procedura di prova per predisporre THothII come applicazione autonoma in modalità
<code>full</code> su macOS, Windows e Linux.</p>
<p>In questo documento “autonoma” significa che l’utente non deve installare Node.js, Python o Pi
sull'host: i servizi applicativi e i servizi semantici
locali vengono eseguiti con Docker. DWH e provider LLM restano endpoint esterni configurati
dall’installazione; questa procedura non è un pacchetto offline.</p>
<p>Il percorso non usa installer grafici, launcher nativi o immagini Docker Hub. Si parte da un clone
Gitea e si usano comandi espliciti da terminale. La pubblicazione di immagini pre-costruite è una
fase successiva.</p>
<h2 id="matrice-di-verifica">Matrice di verifica<a class="headerlink" href="#matrice-di-verifica" title="Permanent link">&para;</a></h2>
<table>
<thead>
<tr>
<th>Sistema</th>
<th>Terminale raccomandato</th>
<th>Runtime</th>
<th>Architettura della prova</th>
</tr>
</thead>
<tbody>
<tr>
<td>macOS supportato dalla versione Docker Desktop installata</td>
<td>Bash nel Terminale</td>
<td>Docker Desktop</td>
<td>Apple Silicon (<code>arm64</code>)</td>
</tr>
<tr>
<td>Windows 11</td>
<td>Ubuntu dentro WSL2</td>
<td>Docker Desktop con integrazione WSL2</td>
<td>x64 (<code>amd64</code>)</td>
</tr>
<tr>
<td>Linux Ubuntu 22.04 o 24.04</td>
<td>Bash</td>
<td>Docker Engine + Compose v2</td>
<td>x64 (<code>amd64</code>)</td>
</tr>
</tbody>
</table>
<p>Intel macOS non fa parte della prima campagna di verifica. ARM Linux può essere provato quando il
runtime Docker della macchina restituisce <code>arm64</code>, ma non è un requisito della matrice minima.</p>
<p>Le verifiche documentali e dei prerequisiti Mac sono passate. Le installazioni complete da zero
sui tre sistemi restano da eseguire: la matrice indica le prove previste, non una certificazione.</p>
<h2 id="cosa-serve-prima-di-iniziare">Cosa serve prima di iniziare<a class="headerlink" href="#cosa-serve-prima-di-iniziare" title="Permanent link">&para;</a></h2>
<p>Servono:</p>
<ul>
<li>accesso al repository Gitea di THothII e al repository Git dei workspace;</li>
<li>Git;</li>
<li>Docker Desktop su macOS e Windows, oppure Docker Engine con il plugin Compose v2 su Linux;</li>
<li>Bash, <code>curl</code>, OpenSSL e <code>shasum</code> (su Ubuntu, pacchetto <code>libdigest-sha-perl</code>);</li>
<li>spazio disco sufficiente per compilare le immagini e scaricare il modello di embedding;</li>
<li>gli endpoint DWH e LLM, più le credenziali che l’installazione deve usare.</li>
</ul>
<p>Su Linux l’utente corrente deve poter eseguire Docker. Se il sistema richiede <code>sudo</code>, aggiungere
l’utente al gruppo Docker secondo la policy locale e aprire una nuova sessione prima di continuare.</p>
<p>Su Windows usare Ubuntu in WSL2 per tutti i comandi di questa guida. In Docker Desktop attivare
l’integrazione WSL2 per quella distribuzione. Clonare il progetto nel filesystem Linux di WSL2,
per esempio sotto <code>~/src</code>, e non sotto <code>/mnt/c</code>: si evitano rallentamenti e problemi di permessi o
line ending. Non è necessario installare Pi sull’host.</p>
<p>Verificare il runtime prima del clone o subito dopo:</p>
<pre class="highlight"><code class="language-sh">docker version
docker compose version
docker version --format '{{.Server.Arch}}'</code></pre>
<p>L’ultima istruzione deve restituire <code>amd64</code>, <code>x86_64</code>, <code>arm64</code> o <code>aarch64</code>.</p>
<h2 id="1-clonare-una-revisione-del-progetto">1. Clonare una revisione del progetto<a class="headerlink" href="#1-clonare-una-revisione-del-progetto" title="Permanent link">&para;</a></h2>
<p>Usare il repository di progetto su Gitea:</p>
<pre class="highlight"><code class="language-sh">mkdir -p "$HOME/src"
cd "$HOME/src"
git clone https://git.tylconsulting.it/mptyl/ThothII.git
cd ThothII
git rev-parse --short HEAD</code></pre>
<p>Per un clone SSH usare, se la chiave è già autorizzata su Gitea:</p>
<pre class="highlight"><code class="language-sh">git clone git@git.tylconsulting.it:mptyl/ThothII.git</code></pre>
<p>Per una prova ripetibile annotare l’hash stampato da <code>git rev-parse</code>. In una campagna successiva
usare la revisione/tag approvata dal maintainer invece di seguire implicitamente una <code>main</code> che
può cambiare.</p>
<h2 id="2-verificare-i-prerequisiti-e-installare-il-comando-operatore">2. Verificare i prerequisiti e installare il comando operatore<a class="headerlink" href="#2-verificare-i-prerequisiti-e-installare-il-comando-operatore" title="Permanent link">&para;</a></h2>
<p>Dal root del clone:</p>
<pre class="highlight"><code class="language-sh">bash scripts/check-standalone-prerequisites.sh
export PATH="$HOME/.local/bin:$PATH"
THT_INSTALL_DIRECTORY="$HOME/.local/bin" bash scripts/install-tht.sh
tht version</code></pre>
<p><code>install-tht.sh</code> è un bootstrap del solo comando operatore nativo <code>tht</code>; non installa una versione
desktop di THothII. Usa il builder Docker del repository, installa il binario adatto all’ambiente
del terminale e lo installa nella directory utente. Aggiungere <code>$HOME/.local/bin</code> al PATH della
shell anche per i terminali successivi. Un <code>tht</code> già presente in quella directory viene aggiornato.</p>
<p>Su Windows, eseguire questi comandi dentro WSL2. Il binario <code>tht</code> installato è quello Linux di WSL2;
il runtime dell’applicazione rimane Docker Desktop. Non usare <code>scripts/install-tht.ps1</code> come percorso
principale di questa prova.</p>
<h2 id="3-configurare-e-avviare-linstallazione-locale">3. Configurare e avviare l’installazione locale<a class="headerlink" href="#3-configurare-e-avviare-linstallazione-locale" title="Permanent link">&para;</a></h2>
<p>Eseguire i blocchi successivi nella stessa sessione Bash dal root fisico del clone (<code>pwd -P</code>).
Creare prima le due password distinte del catalogo, conservando eventuali file già esistenti:</p>
<pre class="highlight"><code class="language-bash">umask 077
mkdir -p deploy/local/secrets
for name in catalog-runtime-password catalog-migrator-password; do
target="deploy/local/secrets/$name"
if [ ! -e "$target" ]; then
(set -C; openssl rand -hex 32 &gt; "$target") || exit 1
fi
done
export THT_CATALOG_RUNTIME_PASSWORD_SOURCE="$(pwd -P)/deploy/local/secrets/catalog-runtime-password"
export THT_CATALOG_MIGRATOR_PASSWORD_SOURCE="$(pwd -P)/deploy/local/secrets/catalog-migrator-password"</code></pre>
<p>Non rigenerare le password di un catalogo già inizializzato. Configurare senza avviare i servizi:</p>
<pre class="highlight"><code class="language-sh">tht setup --profile local --shell-mode full --shell-default-locale en --configure-only</code></pre>
<p>Rispondere ai prompt nel seguente modo:</p>
<table>
<thead>
<tr>
<th>Prompt</th>
<th>Valore o regola</th>
</tr>
</thead>
<tbody>
<tr>
<td>Installation ID</td>
<td><code>local</code>, salvo necessità di più installazioni nello stesso clone</td>
</tr>
<tr>
<td>Deployment profile</td>
<td><code>local</code></td>
</tr>
<tr>
<td>DWH API endpoint</td>
<td>URL <code>http(s)</code> senza user, password, query o fragment; può restare vuoto per il solo smoke test</td>
</tr>
<tr>
<td>LLM API endpoint</td>
<td>URL <code>http(s)</code> senza credenziali; può restare vuoto per il solo smoke test</td>
</tr>
<tr>
<td>Workspace repository URL</td>
<td>URL del repository dei workspace, non il clone sorgente di THothII</td>
</tr>
<tr>
<td>Workspace branch</td>
<td>normalmente <code>main</code></td>
</tr>
<tr>
<td>Workspace access</td>
<td><code>ssh</code> se si usa una chiave deploy; altrimenti <code>https</code> con credential file protetto</td>
</tr>
<tr>
<td>Percorsi dei file</td>
<td>accettare i percorsi predefiniti sotto <code>deploy/local/secrets/</code> nella prima prova</td>
</tr>
<tr>
<td>Secret templates</td>
<td>rispondere <code>yes</code> quando i file protetti non esistono ancora</td>
</tr>
<tr>
<td>Autenticazione</td>
<td>configurare il login locale richiesto dall’installazione; non inserire password in una riga di comando</td>
</tr>
</tbody>
</table>
<p>La configurazione generata è locale e ignorata da Git:</p>
<pre class="highlight"><code class="language-text">deploy/local/thothii-installation.yaml
deploy/local/operator.env
deploy/local/auth/
deploy/local/secrets/</code></pre>
<p>Modificare i segreti solo nei file locali protetti; non committarli. Il file <code>deploy/env/local.env.example</code> è un riferimento
tracciato; il percorso generato da <code>tht setup</code>, <code>deploy/local/operator.env</code>, è quello da usare per
questa installazione.</p>
<h3 id="completare-i-file-protetti">Completare i file protetti<a class="headerlink" href="#completare-i-file-protetti" title="Permanent link">&para;</a></h3>
<p>Se il setup ha creato template vuoti, inserire i valori con un editor locale:</p>
<pre class="highlight"><code class="language-sh">chmod 600 deploy/local/secrets/*
"${EDITOR:-vi}" deploy/local/secrets/thothii.secrets</code></pre>
<p>Il bundle deve contenere solo righe <code>KEY=VALUE</code> per le credenziali effettivamente usate dal
<code>modelCatalog</code>. I nomi ammessi e il confine delle credenziali sono descritti nel file locale
<code>deploy/secrets/README.md</code>. Non mettere token nelle URL, nel
descriptor YAML, nel repository Git o nei comandi copiati nella shell.</p>
<p>Per accesso workspace SSH, predisporre anche la chiave privata e il file <code>known_hosts</code> indicati dal
setup. Per accesso HTTPS, predisporre il credential file Git e l’eventuale CA. Entrambi devono
restare protetti e fuori dal controllo versione.</p>
<p>Prima dell'avvio completare anche questi passaggi:</p>
<ol>
<li>Aggiungere <code>THT_CATALOG_RUNTIME_PASSWORD_SOURCE</code> e <code>THT_CATALOG_MIGRATOR_PASSWORD_SOURCE</code> a
<code>deploy/local/operator.env</code>, con gli stessi percorsi assoluti esportati sopra. Il setup non salva
queste due variabili. Inserire i percorsi, non le password.</li>
<li>Sostituire il <code>modelCatalog</code> generico nel descriptor con la configurazione provider/modelli
approvata. I default generati non replicano il Mac esistente. Vedere <a href="../../general/pi-configuration/">configurazione Pi/modelli</a>
e l'esempio locale <code>deploy/psd/thothii-installation.yaml.example</code>.</li>
<li>Inserire in <code>thothii.secrets</code> le chiavi referenziate da <code>authentication.apiKeyEnv</code>. I provider
<code>pi_auth</code> richiedono credenziali valide nel file <code>PI_AUTH_FILE</code>; il template <code>{}</code> non autentica.</li>
<li>Completare i file Git del workspace. SSH richiede una chiave deploy autorizzata e known-hosts
verificato; HTTPS richiede il credential file e il bundle CA previsti dall'overlay. I template
vuoti non consentono l'accesso al repository.</li>
</ol>
<p>Dopo aver modificato la configurazione generata, non rilanciare setup: rifiuta file esistenti con
contenuti diversi. Generare le proiezioni ed eseguire la migrazione esplicita indicata sotto.
Impostare <code>THT_GIT_ACCESS=https</code> se scelto nel setup. Il blocco usa il nuovo descriptor <code>local</code>
con il solo overlay Git; per installazioni personalizzate includere gli overlay aggiuntivi
nello stesso ordine del descriptor.</p>
<pre class="highlight"><code class="language-bash">INSTALLATION="$(pwd -P)/deploy/local/thothii-installation.yaml"
tht --installation "$INSTALLATION" installation generate
THT_PROJECT="thothii-$(printf '%s' "$INSTALLATION" | shasum -a 256 | cut -c 1-12)"
THT_GIT_ACCESS=ssh
compose=(
docker compose --project-name "$THT_PROJECT" --project-directory "$(pwd -P)"
--env-file "$(pwd -P)/deploy/local/operator.env"
-f compose.yaml -f deploy/compose.local.yaml
-f "deploy/compose.git-$THT_GIT_ACCESS.yaml"
-f deploy/local/generated/compose.models.yaml
)
"${compose[@]}" config --quiet
"${compose[@]}" build core frontend
"${compose[@]}" up -d catalog-db
"${compose[@]}" run --rm catalog-migrate
tht --installation "$INSTALLATION" start</code></pre>
<p>Fermarsi se un comando fallisce. Il nome progetto coincide con l'hash usato da <code>tht</code>, preservando
l'identità dei volumi. <code>catalog-migrate</code> applica le migrazioni Catalog e Memory; <code>tht start</code> non
lo esegue automaticamente. Il primo download del modello embedding può richiedere tempo.
Usare questa sequenza legata all'installazione, non <code>run-stack.sh</code> con env/progetto diversi.</p>
<h2 id="4-verificare-linstallazione">4. Verificare l’installazione<a class="headerlink" href="#4-verificare-linstallazione" title="Permanent link">&para;</a></h2>
<p>Il descriptor generato per l’ID predefinito è:</p>
<pre class="highlight"><code class="language-sh">INSTALLATION="$(pwd -P)/deploy/local/thothii-installation.yaml"
test -f "$INSTALLATION"
bash scripts/verify-standalone-install.sh "$INSTALLATION"</code></pre>
<p>Il verificatore è read-only: esegue <code>tht doctor --json</code> e <code>tht status</code>, senza ristartare lo stack,
rigenerare la configurazione o stampare il contenuto dei segreti.</p>
<h3 id="gate-a-smoke-di-piattaforma-su-tutti-e-tre-i-computer">Gate A — smoke di piattaforma, su tutti e tre i computer<a class="headerlink" href="#gate-a-smoke-di-piattaforma-su-tutti-e-tre-i-computer" title="Permanent link">&para;</a></h3>
<p>Registrare per ogni macchina:</p>
<pre class="highlight"><code class="language-sh">uname -a
docker version --format '{{.Server.Version}} {{.Server.Arch}}'
tht version
bash scripts/check-standalone-prerequisites.sh
bash scripts/verify-standalone-install.sh "$INSTALLATION"</code></pre>
<p>Il gate passa quando il clone è integro, Docker e Compose sono raggiungibili, <code>tht doctor</code> è OK,
lo stack è avviato e il frontend risponde sulla porta locale predefinita <code>http://127.0.0.1:8080</code>.
Il doctor controlla anche workspace e Pi: registrare separatamente i loro errori senza attribuire
ogni fallimento alla piattaforma. Verificare la disponibilità HTTP con:</p>
<pre class="highlight"><code class="language-sh">curl --fail --silent --show-error http://127.0.0.1:8080/health</code></pre>
<h3 id="gate-b-verifica-funzionale">Gate B — verifica funzionale<a class="headerlink" href="#gate-b-verifica-funzionale" title="Permanent link">&para;</a></h3>
<p>Eseguire almeno su una macchina con endpoint e credenziali disponibili:</p>
<p>Seguire prima <a href="../../operations/workspaces/">Workspace operations</a> per importare/preparare il
workspace e configurare Database e binding locale. Il clone sorgente non trasferisce catalogo,
segreti o sessioni del Mac. Connettere l'eventuale VPN richiesta da DWH/modelli e verificare
che i relativi nomi siano raggiungibili anche dai container.</p>
<ol>
<li>aprire <code>http://127.0.0.1:8080</code>;</li>
<li>autenticarsi con l’account locale configurato;</li>
<li>verificare che il workspace configurato sia leggibile;</li>
<li>avviare una domanda reale e completare i gate di revisione fino alla SQL finale;</li>
<li>fermare e riavviare l’installazione, poi ripetere <code>verify-standalone-install.sh</code>.</li>
</ol>
<p>Un fallimento del Gate B per DWH, provider LLM, Git workspace o credenziali non dimostra da solo un
problema di portabilità Docker: registrare separatamente l’endpoint o il componente fallito.</p>
<h2 id="ciclo-di-vita-quotidiano">Ciclo di vita quotidiano<a class="headerlink" href="#ciclo-di-vita-quotidiano" title="Permanent link">&para;</a></h2>
<p>Usare il descriptor esplicito quando più installazioni possono essere scoperte:</p>
<pre class="highlight"><code class="language-sh">INSTALLATION="$PWD/deploy/local/thothii-installation.yaml"
tht --installation "$INSTALLATION" status
tht --installation "$INSTALLATION" start
tht --installation "$INSTALLATION" start --build
tht --installation "$INSTALLATION" logs
tht --installation "$INSTALLATION" doctor --json
tht --installation "$INSTALLATION" stop</code></pre>
<p><code>start --build</code> è necessario dopo una modifica al codice o per ricostruire le immagini dal clone
corrente. <code>stop</code> conserva volumi, sessioni, catalogo, stato Pi, dati Qdrant e modello embedding.
Non usare <code>docker compose down --volumes</code> durante una prova normale: è un’operazione distruttiva
che cancella i dati locali.
Per aggiornamenti che richiedono migrazioni, seguire il runbook della release prima dell'avvio.</p>
<h2 id="diagnosi-rapida">Diagnosi rapida<a class="headerlink" href="#diagnosi-rapida" title="Permanent link">&para;</a></h2>
<table>
<thead>
<tr>
<th>Sintomo</th>
<th>Controllo</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>Docker Engine is not reachable</code></td>
<td>avviare Docker Desktop oppure il servizio Docker e ripetere <code>docker info</code></td>
</tr>
<tr>
<td>Windows vede Docker ma Bash fallisce</td>
<td>eseguire la guida dentro Ubuntu WSL2 e abilitare l’integrazione della distribuzione in Docker Desktop</td>
</tr>
<tr>
<td><code>tht: command not found</code></td>
<td>aprire una nuova shell e verificare <code>command -v tht</code>; se necessario ripetere il bootstrap</td>
</tr>
<tr>
<td>line ending o script non eseguibile</td>
<td>usare un clone nel filesystem WSL2/Linux e rieseguire <code>bash scripts/...</code></td>
</tr>
<tr>
<td>architettura non supportata</td>
<td>verificare <code>docker version --format '{{.Server.Arch}}'</code>; la prova richiede <code>amd64</code> o <code>arm64</code></td>
</tr>
<tr>
<td>descriptor o env file mancanti</td>
<td>usare il percorso <code>deploy/local/...</code> generato da <code>tht setup</code>, non un file copiato casualmente</td>
</tr>
<tr>
<td>stack sano ma workflow fallisce</td>
<td>controllare separatamente URL, credential bundle, workspace Git e autenticazione</td>
</tr>
<tr>
<td>dati apparentemente persi</td>
<td>verificare che non sia stato usato <code>down --volumes</code>; <code>stop</code> non rimuove i volumi</td>
</tr>
</tbody>
</table>
<h2 id="checklist-di-accettazione">Checklist di accettazione<a class="headerlink" href="#checklist-di-accettazione" title="Permanent link">&para;</a></h2>
<ul>
<li>[ ] Il clone proviene dal repository Gitea atteso e la revisione è stata annotata.</li>
<li>[ ] Docker Desktop/Engine e Compose v2 sono disponibili.</li>
<li>[ ] Il runtime restituisce un’architettura ammessa.</li>
<li>[ ] <code>tht</code> è stato costruito dal repository e risponde a <code>tht version</code>.</li>
<li>[ ] Il setup usa <code>profile: local</code>, <code>shell.mode: full</code> e <code>shell.defaultLocale: en</code>.</li>
<li>[ ] Descriptor, <code>operator.env</code>, autenticazione e segreti sono presenti solo in <code>deploy/local/</code>.</li>
<li>[ ] Nessun segreto compare in Git, URL, YAML pubblico o comandi registrati.</li>
<li>[ ] Gate A superato su macOS Apple Silicon, Windows WSL2/x64 e Linux x64.</li>
<li>[ ] Gate B eseguito almeno su una macchina con DWH e LLM disponibili.</li>
<li>[ ] Stop/start e verifica finale completati senza cancellare i volumi.</li>
</ul>
<h2 id="fuori-perimetro-di-questa-release">Fuori perimetro di questa release<a class="headerlink" href="#fuori-perimetro-di-questa-release" title="Permanent link">&para;</a></h2>
<p>Restano attività successive:</p>
<ul>
<li>pubblicare immagini pre-costruite su Docker Hub;</li>
<li>ridurre ulteriormente i prompt tramite una configurazione non interattiva dedicata;</li>
<li>creare pacchetti DMG, MSI/EXE, AppImage o altri installer nativi;</li>
<li>fornire un runtime offline o un DWH/LLM locale incluso nell’applicazione.</li>
</ul>
<h2 id="documenti-collegati">Documenti collegati<a class="headerlink" href="#documenti-collegati" title="Permanent link">&para;</a></h2>
<ul>
<li><a href="../first-start/">Install and first start</a></li>
<li><a href="../shell-and-language/">Shell and localization</a></li>
<li><a href="../../operations/workspaces/">Workspace operations</a></li>
<li><code>deploy/secrets/README.md</code> (runtime secrets)</li>
</ul>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../standalone-manual-en/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../standalone-manual-en/" class="btn btn-xs btn-link">
Mac, Windows, Linux — English
</a>
</div>
<div class="wm-article-nav">
<a href="../first-start/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../first-start/" class="btn btn-xs btn-link">
Start here
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+90
View File
@@ -0,0 +1,90 @@
(function () {
function toggleMenus() {
const current = document.querySelector(".bs-sidenav a.current, .bs-sidenav a[aria-current='page']");
if (!current) {
return;
}
const activeList = current.closest("ul");
document.querySelectorAll(".bs-sidenav ul").forEach((list) => {
if (list === activeList || list.contains(current)) {
list.style.display = "";
return;
}
const nested = list.parentElement && list.parentElement.parentElement;
if (nested && nested.classList.contains("bs-sidenav")) {
list.style.display = "";
}
});
}
// Keep the content pane's left padding in sync with the actual width
// of the left TOC sidebar. Fixes the windmill default where the sidebar
// can grow up to 350px but the content padding stays at 250px, so a
// wide item ends up overlapping the article body.
function syncTocSidebarWidth() {
const tocPane = document.querySelector(".wm-toc-pane");
const contentPane = document.querySelector(".wm-content-pane");
if (!tocPane || !contentPane) {
return;
}
// Skip on small screens where the sidebar is a dropdown / hidden.
if (window.matchMedia("(max-width: 600px)").matches) {
contentPane.style.paddingLeft = "";
return;
}
if (tocPane.classList.contains("wm-toc-dropdown")) {
return;
}
if (contentPane.parentElement && contentPane.parentElement.classList.contains("wm-toc-hidden")) {
contentPane.style.paddingLeft = "";
return;
}
const width = Math.ceil(tocPane.getBoundingClientRect().width);
if (width > 0) {
contentPane.style.paddingLeft = width + "px";
}
}
function installTocSidebarSync() {
const tocPane = document.querySelector(".wm-toc-pane");
if (!tocPane) {
return;
}
syncTocSidebarWidth();
if (typeof ResizeObserver === "function") {
const ro = new ResizeObserver(syncTocSidebarWidth);
ro.observe(tocPane);
}
// Re-sync after expand/collapse animations and toggle button clicks.
tocPane.addEventListener("click", function () {
// Bootstrap collapse animation defaults to 350ms.
window.setTimeout(syncTocSidebarWidth, 50);
window.setTimeout(syncTocSidebarWidth, 400);
});
const tocBtn = document.getElementById("wm-toc-button");
if (tocBtn) {
tocBtn.addEventListener("click", function () {
window.setTimeout(syncTocSidebarWidth, 50);
window.setTimeout(syncTocSidebarWidth, 400);
});
}
window.addEventListener("resize", syncTocSidebarWidth);
window.addEventListener("orientationchange", syncTocSidebarWidth);
}
function init() {
toggleMenus();
installTocSidebarSync();
}
if (document.readyState === "loading") {
document.addEventListener("DOMContentLoaded", init);
} else {
init();
}
})();
+568
View File
@@ -0,0 +1,568 @@
/* global window, document, $, hljs, elasticlunr, base_url, is_top_frame */
/* exported getParam, onIframeLoad */
"use strict";
// The full page consists of a main window with navigation and table of contents, and an inner
// iframe containing the current article. Which article is shown is determined by the main
// window's #hash portion of the URL. In fact, we use the simple rule: main window's URL of
// "rootUrl#relPath" corresponds to iframe's URL of "rootUrl/relPath".
//
// The main frame and the contents of the index page actually live in a single generated html
// file: the outer frame hides one half, and the inner hides the other. TODO: this should be
// possible to greatly simplify after mkdocs-1.0 release.
var mainWindow = is_top_frame ? window : (window.parent !== window ? window.parent : null);
var iframeWindow = null;
var rootUrl = qualifyUrl(base_url);
var searchIndex = null;
var showPageToc = true;
var MutationObserver = window.MutationObserver || window.WebKitMutationObserver;
var Keys = {
ENTER: 13,
ESCAPE: 27,
UP: 38,
DOWN: 40,
};
function startsWith(str, prefix) { return str.lastIndexOf(prefix, 0) === 0; }
function endsWith(str, suffix) { return str.indexOf(suffix, str.length - suffix.length) !== -1; }
/**
* Returns whether to use small-screen mode. Note that the same size is used in css @media block.
*/
function isSmallScreen() {
return window.matchMedia("(max-width: 600px)").matches;
}
/**
* Given a relative URL, returns the absolute one, relying on the browser to convert it.
*/
function qualifyUrl(url) {
var a = document.createElement('a');
a.href = url;
return a.href;
}
/**
* Turns an absolute path to relative, stripping out rootUrl + separator.
*/
function getRelPath(separator, absUrl) {
var prefix = rootUrl + (endsWith(rootUrl, separator) ? '' : separator);
return startsWith(absUrl, prefix) ? absUrl.slice(prefix.length) : null;
}
/**
* Turns a relative path to absolute, adding a prefix of rootUrl + separator.
*/
function getAbsUrl(separator, relPath) {
var sep = endsWith(rootUrl, separator) ? '' : separator;
return relPath === null ? null : rootUrl + sep + relPath;
}
/**
* Redirects the iframe to reflect the path represented by the main window's current URL.
* (In our design, nothing should change iframe's src except via updateIframe(), or back/forward
* history is likely to get messed up.)
*/
function updateIframe(enableForwardNav) {
// Grey out the "forward" button if we don't expect 'forward' to work.
$('#hist-fwd').toggleClass('greybtn', !enableForwardNav);
var targetRelPath = getRelPath('#', mainWindow.location.href) || '';
var targetIframeUrl = getAbsUrl('/', targetRelPath);
var loc = iframeWindow.location;
var currentIframeUrl = _safeGetLocationHref(loc);
console.log("updateIframe: %s -> %s (%s)", currentIframeUrl, targetIframeUrl,
currentIframeUrl === targetIframeUrl ? "same" : "replacing");
if (currentIframeUrl !== targetIframeUrl) {
loc.replace(targetIframeUrl);
onIframeBeforeLoad(targetIframeUrl);
}
document.body.scrollTop = 0;
}
/**
* Returns location.href, catching exception that's triggered if the iframe is on a different domain.
*/
function _safeGetLocationHref(location) {
try {
return location.href;
} catch (e) {
return null;
}
}
/**
* Returns the value of the given parameter in the URL's query portion.
*/
function getParam(key) {
var params = window.location.search.substring(1).split('&');
for (var i = 0; i < params.length; i++) {
var param = params[i].split('=');
if (param[0] === key) {
return decodeURIComponent(param[1].replace(/\+/g, '%20'));
}
}
}
/**
* Update the state of the button toggling table-of-contents. TOC has different behavior
* depending on screen size, so the button's behavior depends on that too.
*/
function updateTocButtonState() {
var shown;
if (isSmallScreen()) {
shown = $('.wm-toc-pane').hasClass('wm-toc-dropdown');
} else {
shown = !$('#main-content').hasClass('wm-toc-hidden');
}
$('#wm-toc-button').toggleClass('active', shown);
}
/**
* Update the height of the iframe container. On small screens, we adjust it to fit the iframe
* contents, so that the page scrolls as a whole rather than inside the iframe.
*/
function updateContentHeight() {
if (isSmallScreen()) {
$('.wm-content-pane').height(iframeWindow.document.body.offsetHeight + 20);
$('.wm-article').attr('scrolling', 'no');
} else {
$('.wm-content-pane').height('');
$('.wm-article').attr('scrolling', 'auto');
}
}
/**
* When TOC is a dropdown (on small screens), close it.
*/
function closeTempItems() {
$('.wm-toc-dropdown').removeClass('wm-toc-dropdown');
$('#mkdocs-search-query').closest('.wm-top-tool').removeClass('wm-top-tool-expanded');
updateTocButtonState();
}
/**
* Visit the given URL. This changes the hash of the top page to reflect the new URL's relative
* path, and points the iframe to the new URL.
*/
function visitUrl(url, event) {
var relPath = getRelPath('/', url);
if (relPath !== null) {
event.preventDefault();
var newUrl = getAbsUrl('#', relPath);
if (newUrl !== mainWindow.location.href) {
mainWindow.history.pushState(null, '', newUrl);
updateIframe(false);
}
closeTempItems();
iframeWindow.focus();
}
}
/**
* Adjusts link to point to a top page, converting URL from "base/path" to "base#path". It also
* sets a data-adjusted attribute on the link, to skip adjustments on future clicks.
*/
function adjustLink(linkEl) {
if (!linkEl.hasAttribute('data-wm-adjusted')) {
linkEl.setAttribute('data-wm-adjusted', 'done');
var relPath = getRelPath('/', linkEl.href);
if (relPath !== null) {
var newUrl = getAbsUrl('#', relPath);
linkEl.href = newUrl;
}
}
}
/**
* Given a URL, strips query and fragment, returning just the path.
*/
function cleanUrlPath(relUrl) {
return relUrl.replace(/[#?].*/, '');
}
/**
* Initialize the main window.
*/
function initMainWindow() {
// wm-toc-button either opens the table of contents in the side-pane, or (on smaller screens)
// shows the side-pane as a drop-down.
$('#wm-toc-button').on('click', function(e) {
if (isSmallScreen()) {
$('.wm-toc-pane').toggleClass('wm-toc-dropdown');
$('#wm-main-content').removeClass('wm-toc-hidden');
} else {
$('#main-content').toggleClass('wm-toc-hidden');
closeTempItems();
}
updateTocButtonState();
});
// Update the state of the wm-toc-button
updateTocButtonState();
$(window).on('resize', function() {
updateTocButtonState();
updateContentHeight();
});
// Connect up the Back and Forward buttons (if present).
$('#hist-back').on('click', function(e) { window.history.back(); });
$('#hist-fwd').on('click', function(e) { window.history.forward(); });
// When the side-pane is a dropdown, hide it on click-away.
$(window).on('blur', closeTempItems);
// When we click on an opener in the table of contents, open it.
$('.wm-toc-pane').on('click', '.wm-toc-opener', function(e) {
$(this).toggleClass('wm-toc-open');
$(this).next('.wm-toc-li-nested').collapse('toggle');
});
$('.wm-toc-pane').on('click', '.wm-page-toc-opener', function(e) {
// Ignore clicks while transitioning.
if ($(this).next('.wm-page-toc').hasClass('collapsing')) { return; }
showPageToc = !showPageToc;
$(this).toggleClass('wm-page-toc-open', showPageToc);
$(this).next('.wm-page-toc').collapse(showPageToc ? 'show' : 'hide');
});
// Once the article loads in the side-pane, close the dropdown.
$('.wm-article').on('load', function() {
document.title = iframeWindow.document.title;
updateContentHeight();
// We want to update content height whenever the height of the iframe's content changes.
// Using MutationObserver seems to be the best way to do that.
var observer = new MutationObserver(updateContentHeight);
observer.observe(iframeWindow.document.body, {
attributes: true,
childList: true,
characterData: true,
subtree: true
});
iframeWindow.focus();
});
// Initialize search functionality.
initSearch();
// Load the iframe now, and whenever we navigate the top frame.
setTimeout(function() { updateIframe(false); }, 0);
// For our usage, 'popstate' or 'hashchange' would work, but only 'hashchange' work on IE.
$(window).on('hashchange', function() { updateIframe(true); });
}
function onIframeBeforeLoad(url) {
$('.wm-current').removeClass('wm-current');
closeTempItems();
var tocLi = getTocLi(url);
tocLi.addClass('wm-current');
tocLi.parents('.wm-toc-li-nested')
// It's better to open parent items immediately without a transition.
.removeClass('collapsing').addClass('collapse in').height('')
.prev('.wm-toc-opener').addClass('wm-toc-open');
}
function getTocLi(url) {
var relPath = getAbsUrl('#', getRelPath('/', cleanUrlPath(url)));
var selector = '.wm-article-link[href="' + relPath + '"]';
return $(selector).closest('.wm-toc-li');
}
var _deferIframeLoad = false;
// Sometimes iframe is loaded before main window's ready callback. In this case, we defer
// onIframeLoad call until the main window has initialized.
function ensureIframeLoaded() {
if (_deferIframeLoad) {
onIframeLoad();
}
}
function onIframeLoad() {
if (!iframeWindow) { _deferIframeLoad = true; return; }
var url = iframeWindow.location.href;
onIframeBeforeLoad(url);
if (iframeWindow.pageToc) {
var relPath = getAbsUrl('#', getRelPath('/', cleanUrlPath(url)));
renderPageToc(getTocLi(url), relPath, iframeWindow.pageToc);
}
iframeWindow.focus();
}
/**
* Hides a bootstrap collapsible element, and removes it from DOM once hidden.
*/
function collapseAndRemove(collapsibleElem) {
if (!collapsibleElem.hasClass('in')) {
// If the element is already hidden, just remove it immediately.
collapsibleElem.remove();
} else {
collapsibleElem.on('hidden.bs.collapse', function() {
collapsibleElem.remove();
})
.collapse('hide');
}
}
function renderPageToc(parentElem, pageUrl, pageToc) {
var ul = $('<ul class="wm-toctree">');
function addItem(tocItem) {
ul.append($('<li class="wm-toc-li">')
.append($('<a class="wm-article-link wm-page-toc-text">')
.attr('href', pageUrl + tocItem.url)
.attr('data-wm-adjusted', 'done')
.text(tocItem.title)));
if (tocItem.children) {
tocItem.children.forEach(addItem);
}
}
pageToc.forEach(addItem);
$('.wm-page-toc-opener').removeClass('wm-page-toc-opener wm-page-toc-open');
collapseAndRemove($('.wm-page-toc'));
parentElem.addClass('wm-page-toc-opener').toggleClass('wm-page-toc-open', showPageToc);
$('<li class="wm-page-toc wm-toc-li-nested collapse">').append(ul).insertAfter(parentElem)
.collapse(showPageToc ? 'show' : 'hide');
}
if (!mainWindow) {
// This is a page that ought to be in an iframe. Redirect to load the top page instead.
var topUrl = getAbsUrl('#', getRelPath('/', window.location.href));
if (topUrl) {
window.location.href = topUrl;
}
} else {
// Adjust all links to point to the top page with the right hash fragment.
$(document).ready(function() {
$('a').each(function() { adjustLink(this); });
});
// For any dynamically-created links, adjust them on click.
$(document).on('click', 'a:not([data-wm-adjusted])', function(e) { adjustLink(this); });
}
if (is_top_frame) {
// Main window.
$(document).ready(function() {
iframeWindow = $('.wm-article')[0].contentWindow;
initMainWindow();
ensureIframeLoaded();
});
} else {
// Article contents.
iframeWindow = window;
if (mainWindow) {
mainWindow.onIframeLoad();
}
// Other initialization of iframe contents.
hljs.initHighlightingOnLoad();
$(document).ready(function() {
$('table').addClass('table table-striped table-hover table-bordered table-condensed');
});
}
var searchIndexReady = false;
/**
* Initialize search functionality.
*/
function initSearch() {
// Create elasticlunr index.
searchIndex = elasticlunr(function() {
this.setRef('location');
this.addField('title');
this.addField('text');
});
var searchBox = $('#mkdocs-search-query');
var searchResults = $('#mkdocs-search-results');
// Fetch the prebuilt index data, and add to the index.
$.getJSON(base_url + '/search/search_index.json')
.done(function(data) {
data.docs.forEach(function(doc) {
searchIndex.addDoc(doc);
});
searchIndexReady = true;
$(document).trigger('searchIndexReady');
});
function showSearchResults(optShow) {
var show = (optShow === false ? false : Boolean(searchBox.val()));
if (show) {
doSearch({
resultsElem: searchResults,
query: searchBox.val(),
snippetLen: 100,
limit: 10
});
}
searchResults.parent().toggleClass('open', show);
return show;
}
searchBox.on('click', function(e) {
if (!searchResults.parent().hasClass('open')) {
if (showSearchResults()) {
e.stopPropagation();
}
}
});
// Search automatically and show results on keyup event.
searchBox.on('keyup', function(e) {
var show = (e.which !== Keys.ESCAPE && e.which !== Keys.ENTER);
showSearchResults(show);
});
// Open the search box (and run the search) on up/down arrow keys.
searchBox.on('keydown', function(e) {
if (e.which === Keys.UP || e.which === Keys.DOWN) {
if (showSearchResults()) {
e.stopPropagation();
e.preventDefault();
setTimeout(function() {
searchResults.find('a').eq(e.which === Keys.UP ? -1 : 0).focus();
}, 0);
}
}
});
searchResults.on('keydown', function(e) {
if (e.which === Keys.UP || e.which === Keys.DOWN) {
if (searchResults.find('a').eq(e.which === Keys.UP ? 0 : -1)[0] === e.target) {
searchBox.focus();
e.stopPropagation();
e.preventDefault();
}
}
});
$(searchResults).on('click', '.search-all', function(e) {
e.stopPropagation();
e.preventDefault();
$('#wm-search-form').trigger('submit');
});
// Redirect to the search page on Enter or button-click (form submit).
$('#wm-search-form').on('submit', function(e) {
var url = this.action + '?' + $(this).serialize();
visitUrl(url, e);
searchResults.parent().removeClass('open');
});
$('#wm-search-show,#wm-search-go').on('click', function(e) {
if (isSmallScreen()) {
e.preventDefault();
var el = $('#mkdocs-search-query').closest('.wm-top-tool');
el.toggleClass('wm-top-tool-expanded');
if (el.hasClass('wm-top-tool-expanded')) {
setTimeout(function() {
$('#mkdocs-search-query').focus();
showSearchResults();
}, 0);
$('#mkdocs-search-query').focus();
}
}
});
}
function escapeRegex(s) {
return s.replace(/[-\/\\^$*+?.()|[\]{}]/g, '\\$&');
}
/**
* This helps construct useful snippets to show in search results, and highlight matches.
*/
function SnippetBuilder(query) {
var termsPattern = elasticlunr.tokenizer(query).map(escapeRegex).join("|");
this._termsRegex = termsPattern ? new RegExp(termsPattern, "gi") : null;
}
SnippetBuilder.prototype.getSnippet = function(text, len) {
if (!this._termsRegex) {
return text.slice(0, len);
}
// Find a position that includes something we searched for.
var pos = text.search(this._termsRegex);
if (pos < 0) { pos = 0; }
// Find a period before that position (a good starting point).
var start = text.lastIndexOf('.', pos) + 1;
if (pos - start > 30) {
// If too long to previous period, give it 30 characters, and find a space before that.
start = text.lastIndexOf(' ', pos - 30) + 1;
}
var rawSnippet = text.slice(start, start + len);
return rawSnippet.replace(this._termsRegex, '<b>$&</b>');
};
/**
* Search the elasticlunr index for the given query, and populate the dropdown with results.
*/
function doSearch(options) {
var resultsElem = options.resultsElem;
resultsElem.empty();
// If the index isn't ready, wait for it, and search again when ready.
if (!searchIndexReady) {
resultsElem.append($('<li class="disabled"><a class="search-link">SEARCHING...</a></li>'));
$(document).one('searchIndexReady', function() { doSearch(options); });
return;
}
var query = options.query;
var snippetLen = options.snippetLen;
var limit = options.limit;
if (query === '') { return; }
var results = searchIndex.search(query, {
fields: { title: {boost: 10}, text: { boost: 1 } },
expand: true,
bool: "AND"
});
var snippetBuilder = new SnippetBuilder(query);
if (results.length > 0){
var len = Math.min(results.length, limit || Infinity);
for (var i = 0; i < len; i++) {
var doc = searchIndex.documentStore.getDoc(results[i].ref);
var snippet = snippetBuilder.getSnippet(doc.text, snippetLen);
resultsElem.append(
$('<li>').append($('<a class="search-link">').attr('href', pathJoin(base_url, doc.location))
.append($('<div class="search-title">').text(doc.title))
.append($('<div class="search-text">').html(snippet)))
);
}
resultsElem.find('a').each(function() { adjustLink(this); });
if (limit) {
resultsElem.append($('<li role="separator" class="divider"></li>'));
resultsElem.append($(
'<li><a class="search-link search-all" href="' + base_url + '/search.html">' +
'<div class="search-title">SEE ALL RESULTS</div></a></li>'));
}
} else {
resultsElem.append($('<li class="disabled"><a class="search-link">NO RESULTS FOUND</a></li>'));
}
}
function pathJoin(prefix, suffix) {
var nPrefix = endsWith(prefix, "/") ? prefix.slice(0, -1) : prefix;
var nSuffix = startsWith(suffix, "/") ? suffix.slice(1) : suffix;
return nPrefix + "/" + nSuffix;
}
+2377
View File
File diff suppressed because it is too large Load Diff
+7
View File
File diff suppressed because one or more lines are too long
+2485
View File
File diff suppressed because it is too large Load Diff
+10
View File
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+10253
View File
File diff suppressed because it is too large Load Diff
+4
View File
File diff suppressed because one or more lines are too long
+316
View File
@@ -0,0 +1,316 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/operations/database-management/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Databases and descriptions - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Database management", url: "#_top", children: [
{title: "What the catalog owns", url: "#what-the-catalog-owns" },
{title: "Navigate the Fleet Ledger surface", url: "#navigate-the-fleet-ledger-surface" },
{title: "Configure and test a database", url: "#configure-and-test-a-database" },
{title: "Synchronize authoritative schema metadata", url: "#synchronize-authoritative-schema-metadata" },
{title: "Generate and consolidate descriptions", url: "#generate-and-consolidate-descriptions" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../sensitivity-analysis/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../sensitivity-analysis/" class="btn btn-xs btn-link">
Sensitive columns
</a>
</div>
<div class="wm-article-nav">
<a href="../workspaces/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../workspaces/" class="btn btn-xs btn-link">
Workspaces
</a>
</div>
</div>
<h1 id="database-management">Database management<a class="headerlink" href="#database-management" title="Permanent link">&para;</a></h1>
<p>Database Management is the administrative PostgreSQL Metadata Catalog for an external PostgreSQL
schema. Its binding and metadata are the sole database source used by workspace preprocessing and
the NL→SQL session workflow.</p>
<h2 id="what-the-catalog-owns">What the catalog owns<a class="headerlink" href="#what-the-catalog-owns" title="Permanent link">&para;</a></h2>
<p>For each workspace identity, an administrator may configure at most one Metadata Catalog binding. It holds
the database name, schema, connection binding, write-only encrypted secrets, observed physical
schema, optional curated descriptions, generated descriptions, and durable operation history.</p>
<p>It does <strong>not</strong> become the external source of truth. Tables, columns, types, defaults,
nullability, primary-key positions, and ordered foreign-key pairs are observations of the source
schema and cannot be manually created, renamed, or structurally edited. Descriptions are the
editable metadata.</p>
<h2 id="navigate-the-fleet-ledger-surface">Navigate the Fleet Ledger surface<a class="headerlink" href="#navigate-the-fleet-ledger-surface" title="Permanent link">&para;</a></h2>
<p>Database Management opens Fleet Ledger inside the normal application shell. Only one data grid is
shown at a time: choose a database to see its tables, choose a table to see its columns, or open the
database's relationships view. Use the emphasized back control or breadcrumb to return to the parent
grid.</p>
<p>The KPI strip reports tables, columns, sensitive columns, relationships, and description coverage.
It uses <code>GET /catalog/metrics</code> without <code>databaseId</code> for installation totals and with <code>databaseId</code> for
the current database. Choose a selection-scoped operation from the action selector and then press
<strong>Run</strong>; unavailable operations remain listed with an explanation. Row-specific actions are the icon
controls in the final column, and each navigation or action icon has an immediate conceptual tooltip.
An unconfigured workspace exposes <strong>Configure catalog</strong> directly on its row; there is no global
database-creation action and the selected workspace cannot be changed in the configuration form.</p>
<p>The master grid keeps three independent states visible:</p>
<ul>
<li><strong>Revision / Evidence</strong> comes from the active immutable workspace revision. Filesystem Evidence is
materialized with that revision; remote Evidence is reported as configured-but-unverified or as
requiring credentials.</li>
<li><strong>NL→SQL runtime</strong> is calculated from the workspace DWH/Evidence requirements and runtime secret
store. It also reports transports, such as SSH, that are diagnostic-only and unsupported by sessions.</li>
<li><strong>Metadata Catalog</strong> reports whether the installation-local catalog configuration exists, then shows
its separately versioned connection-test or synchronization state.</li>
</ul>
<p>Configuration, object details, metadata editors, synchronization history, description history,
sensitive-field review, and suggestion-run history open in right-side drawers backed by the
production catalog APIs.
Closing a history drawer does not cancel a durable background run. Existing permission checks,
dirty/busy navigation guards, stale-state handling, and write-only secret behavior continue to
apply.</p>
<p>For temporary comparison in development or staging, add <code>?db-ui=legacy</code>; the parameter is honored
only by Vite development or an environment explicitly configured with
<code>VITE_DB_MANAGEMENT_LEGACY=true</code>. The separate prototype on port <code>5173</code> is not the application and
remains available only until the integrated Fleet Ledger surface passes owner acceptance.</p>
<h2 id="configure-and-test-a-database">Configure and test a database<a class="headerlink" href="#configure-and-test-a-database" title="Permanent link">&para;</a></h2>
<ol>
<li>Open <strong>Database Management</strong> and find the repository workspace marked <strong>Not configured</strong>.</li>
<li>Choose <strong>Configure catalog</strong> on that row. Configure its PostgreSQL catalog binding with
<code>postgres_direct</code>, <code>rest_api</code>, or <code>ssh_tunnel</code> and
complete the binding fields that the chosen transport requires.</li>
<li>Enter secrets only when replacing them. They remain write-only and are never returned by the
application.</li>
<li>Use <strong>Test connection</strong> whenever you want an informational connectivity check. Its result does
not enable or disable catalog operations.</li>
</ol>
<p>SSH uses a private key, optional key passphrase, mandatory <code>known_hosts</code>, and optional PostgreSQL
TLS CA/server name. REST prefers <code>POST /rpc/schema_snapshot</code>; when it is absent, the catalog may
use the same strict v1 snapshot through one read-only <code>POST /rpc/run_query</code>. An unavailable
capability, malformed snapshot, or connector error applies no catalog changes. See the
<a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/catalog-schema-snapshot.md">schema snapshot contract</a>.</p>
<h2 id="synchronize-authoritative-schema-metadata">Synchronize authoritative schema metadata<a class="headerlink" href="#synchronize-authoritative-schema-metadata" title="Permanent link">&para;</a></h2>
<p>Schema synchronization reads the external database and reconciles the installation-local catalog.
It never changes the source database. Every synchronization attempts a fresh connection when it
runs; an unreachable server or rejected credential fails that run without changing catalog data.
The available synchronization scopes are <strong>tables</strong>,
<strong>columns</strong>, <strong>relationships</strong>, and <strong>all</strong>, but the UI exposes them at different levels:</p>
<table>
<thead>
<tr>
<th>Location</th>
<th>Action</th>
<th>Effective scope</th>
</tr>
</thead>
<tbody>
<tr>
<td>Database view</td>
<td><strong>Synchronize tables</strong></td>
<td>All tables in the selected database</td>
</tr>
<tr>
<td>Database view</td>
<td><strong>Synchronize relationships</strong></td>
<td>All physical foreign-key relationships in the selected database</td>
</tr>
<tr>
<td>Database view</td>
<td><strong>Synchronize all</strong></td>
<td>Tables, columns, and physical relationships in the selected database</td>
</tr>
<tr>
<td>Tables view</td>
<td><strong>Synchronize database tables</strong></td>
<td>All tables in the selected database. Selecting a table enables the action, but does not narrow its scope.</td>
</tr>
<tr>
<td>Tables view</td>
<td><strong>Synchronize columns for selected tables</strong></td>
<td>Columns belonging to the selected tables</td>
</tr>
<tr>
<td>Columns view</td>
<td><strong>Synchronize columns for this table</strong></td>
<td>All columns belonging to the table currently open. Selecting at least one column enables the action, but does not narrow its scope to that column.</td>
</tr>
</tbody>
</table>
<p>There is no database-level column action and no synchronization action for an individual column.
The selection requirement in the tables and columns views controls whether the action selector can
be used; it is not always the same as the synchronization target. The <strong>Sync all</strong> button in the
tables view is the direct shortcut for the full-database scope.</p>
<p>Connection tests are informational and are never a synchronization prerequisite. Each
synchronization tests its own access while reading the schema; an unavailable connection fails
that operation with a connector error. Only one catalog operation can be active for a database at
a time; explicit cleanup shares this exclusion.</p>
<h3 id="what-a-synchronization-does">What a synchronization does<a class="headerlink" href="#what-a-synchronization-does" title="Permanent link">&para;</a></h3>
<p>Every run first creates a durable queued operation and reads a schema snapshot. The scan reports
these phases:</p>
<ol>
<li>Connect to the database.</li>
<li>Read tables.</li>
<li>Read columns and primary-key positions.</li>
<li>Read foreign-key relationships.</li>
<li>Calculate the planned catalog difference.</li>
<li>Apply only the requested scope.</li>
</ol>
<p>The scan currently reads the complete physical snapshot, including foreign keys, even when the
requested scope is only tables or columns. This is required by the introspection contract and is
why the log can mention foreign-key reading during a table synchronization. Reading those keys
does not by itself create or update catalog relationships:</p>
<ul>
<li><strong>Synchronize tables</strong> writes table membership and source comments. If a table disappears, its
catalog columns and physical relationships are removed through the table cascade.</li>
<li><strong>Synchronize columns</strong> writes column membership and structural attributes for all tables or for
the selected table subset. It does not write physical relationships.</li>
<li><strong>Synchronize relationships</strong> writes the physical relationships derived from the source foreign
keys. It does not create generated or manual logical relationships.</li>
<li><strong>Synchronize all</strong> applies all three scopes and marks the database schema version as fully
synchronized.</li>
</ul>
<p>The run scans first and publishes a durable operation. If it detects a destructive difference, it
requires confirmation and re-scans before applying. You can cancel before apply; completed and
failed runs remain in history. The live log is delivered over SSE with a polling fallback.</p>
<p>The synchronization history records the requested scope, progress phases, planned changes,
confirmation, result counts, and errors. Closing the history drawer does not cancel a running
operation; it can be reopened from the database synchronization history control.</p>
<p>Explicit cleanup is different from source synchronization: administrators can clear selected
table/relationship or column/relationship catalog metadata without changing the external source,
the connection binding, or secrets. Deleting a table cascades to its columns and relationships.</p>
<h2 id="generate-and-consolidate-descriptions">Generate and consolidate descriptions<a class="headerlink" href="#generate-and-consolidate-descriptions" title="Permanent link">&para;</a></h2>
<p>Generated descriptions can be requested for selected tables, selected columns, every eligible
target, or targets with a missing generated description. The backend accepts one installation-wide
run and processes targets sequentially. Every catalog column has a <strong>Sensitive</strong> flag, which defaults
to <code>false</code>, including after a newly discovered column is synchronized. Before generation, an
administrator can run local sensitivity analysis over the selected database, tables, or columns.
The analysis combines structural metadata with bounded read-only inspection of source values. It
uses no generative AI and no installation-catalog model. Assessments remain an unsaved draft until
a human reviews and saves them; the reviewer may reverse any proposal.</p>
<p>The page exposes separate histories for description generation and sensitivity analysis. Analysis
history stores the local policy version, scope, status, aggregate <code>sensitive</code>, <code>non_sensitive</code>, and
<code>unknown</code> counts, timestamps, and sanitized events. It does not store source values, per-column
proposals, NER spans, or worker diagnostics; closing an unsaved review discards that draft. The
rules, time bounds, and optional CPU-only NER profile are documented in
<a href="../sensitivity-analysis/">Local sensitivity analysis</a>.</p>
<p>For a column with <code>sensitive=false</code>, the worker may read at most five source rows and five
representative non-null values through a read-only connector. For <code>sensitive=true</code>, the source query
does not request that column's values; deterministic plausible values derived only from its name and
type take their place in the model prompt. The prompt does not identify those values as synthetic, so
the model can still describe the field as if it had received representative data.</p>
<p>Each successful result is persisted immediately. Stop terminates the active helper but retains
earlier results. A helper has at most one provider retry; three consecutively exhausted technical
batches fail the run. Stale queued/running work is marked interrupted at startup and can be
unlocked only when no local worker/helper is live. There is no automatic resume and no public
description-generation CLI.</p>
<p>Review generated text before copying it into the curated <strong>Description</strong> field. Because the flag
defaults to <code>false</code>, an administrator must review the classification and mark protected fields before
starting generation. Changing a flag affects future generations only; existing generated or curated
descriptions are not regenerated. Real and substituted samples remain transient and are not persisted
or returned to the browser.</p>
<p>The database-level <strong>Copy generated description to descriptions</strong> action applies every non-empty
AI-generated table and column description to the corresponding curated <strong>Description</strong> field in one
atomic operation. It skips empty generated descriptions, reports aggregate copied and skipped
counts, and retains the generated text. Because this can replace reviewed descriptions, the
interface requires explicit confirmation before applying it.</p>
<p>The decisions behind this surface are <a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/adr/0001-postgres-metadata-catalog.md">ADRs 0001–0011</a>
and the detailed acceptance record is
<a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/testing/2026-08-29-ai-catalog-description-generation-acceptance.md">AI catalog description generation acceptance</a>.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../sensitivity-analysis/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../sensitivity-analysis/" class="btn btn-xs btn-link">
Sensitive columns
</a>
</div>
<div class="wm-article-nav">
<a href="../workspaces/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../workspaces/" class="btn btn-xs btn-link">
Workspaces
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+245
View File
@@ -0,0 +1,245 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/operations/sensitivity-analysis/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Sensitive columns - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Local sensitivity analysis", url: "#_top", children: [
{title: "Default policy", url: "#default-policy" },
{title: "Optional CPU-only GLiNER2 evidence", url: "#optional-cpu-only-gliner2-evidence" },
{title: "Prepare and enable the optional profile", url: "#prepare-and-enable-the-optional-profile" },
{title: "Acceptance on a real database", url: "#acceptance-on-a-real-database" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../../evidence/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../../evidence/" class="btn btn-xs btn-link">
Evidence
</a>
</div>
<div class="wm-article-nav">
<a href="../database-management/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../database-management/" class="btn btn-xs btn-link">
Databases and descriptions
</a>
</div>
</div>
<h1 id="local-sensitivity-analysis">Local sensitivity analysis<a class="headerlink" href="#local-sensitivity-analysis" title="Permanent link">&para;</a></h1>
<p>Database Management can assess selected columns without sending their metadata or contents to a
generative model. The feature is advisory: it creates a transient review draft, while the catalog's
Sensitive Data Flag changes only when an administrator explicitly saves a choice. The administrator
may set either value, including overriding a <code>sensitive</code> proposal.</p>
<h2 id="default-policy">Default policy<a class="headerlink" href="#default-policy" title="Permanent link">&para;</a></h2>
<p><code>SensitivityClassifier</code> is the only column-level decision point. The versioned <code>sensitivity-v4</code>
policy combines:</p>
<ul>
<li>a structural exclusion for declared <code>bigint</code> primary-key columns and undeclared <code>bigint</code>
columns following the exact <code>pk</code> naming convention; their values are non-informative identifiers
and are therefore not inspected as possible sensitive content. The evidence distinguishes
declared constraints from convention-based inference;</li>
<li>normalized column-name rules for direct identifiers, credentials, and health data;</li>
<li>validated content rules for email, Italian fiscal code and VAT, passport, identity-card and
driving-licence identifiers, phone numbers, IBAN/BIC, payment-card checksums, IP/MAC addresses,
URLs, UUIDs, access keys, private-key markers, sensitive keys inside bounded recursive JSON, and
a reviewed Italian clinical-term dictionary;</li>
<li>a conservative length rule: any observed textual value longer than 500 characters makes the
entire column sensitive.</li>
</ul>
<p>One decisive value is enough to classify the column as <code>sensitive</code> and removes it from subsequent
passes. Binary or otherwise uninspectable column types are also proposed as <code>sensitive</code>, because
their contents cannot be cleared by the textual rules. A completed analysis has only two draft
outcomes: <code>sensitive</code> and <code>non_sensitive</code>. Empty or all-null columns are <code>non_sensitive</code> with
<code>no_values</code> coverage; a sampled column with no match is <code>non_sensitive</code> with explicit sampled
coverage. The administrator remains free to reverse either proposal before saving it.</p>
<p>Source reads are database-specific, but decisions are database-independent. PostgreSQL direct and
REST <code>run_query</code> adapters project at most 501 characters per value, use only <code>SELECT</code>, and never
persist source values. Tables proven to contain at most 1,000 rows are fully scanned. Larger tables
are processed breadth-first so every table gets the cheapest pass before any table gets a deeper
one:</p>
<ol>
<li>inspect up to 300 non-null values per unresolved column;</li>
<li>inspect up to 700 additional values, reaching a 1,000-value target;</li>
<li>for unresolved text, JSON, and XML columns only, inspect up to 2,000 additional values, reaching
a 3,000-value target.</li>
</ol>
<p>At most two tables are scanned concurrently, and the database adapter groups at most 25 columns in
one source query. Each probe or value query has a five-second statement timeout; PostgreSQL-wire
reads run in a read-only transaction and always end with rollback. Sampling is bounded and
repeatable for a policy version. If a randomized sample is empty or reaches its query timeout, the
adapter tries one sequential bounded sample; if that also times out, the source error fails the run
and returns no review instead of manufacturing <code>unknown</code> decisions.</p>
<p>There is no global sixty-second analysis deadline. Work is bounded by sample counts, per-query
timeouts, and early column exits. The operation is interrupted only when its request connection is
aborted or the backend restarts. Historical or interrupted run counters named <code>unknown</code> represent
columns that were not processed; <code>unknown</code> is not a <code>sensitivity-v4</code> column assessment.</p>
<p>History stores only the policy version, aggregate outcomes, timestamps, and fixed operational
events. Sanitized rule IDs are returned in the transient review and shadow report, not persisted.
Neither path stores values, matched spans, prompts, or free-form model output.</p>
<h2 id="optional-cpu-only-gliner2-evidence">Optional CPU-only GLiNER2 evidence<a class="headerlink" href="#optional-cpu-only-gliner2-evidence" title="Permanent link">&para;</a></h2>
<p>The deterministic engine works without Python NER. An installation may opt into
<code>fastino/gliner2-privacy-filter-PII-multi</code> for unresolved short text. It runs in a persistent local
Python worker, adds sanitized evidence, and never becomes a second decision point. The worker:</p>
<ul>
<li>loads a local model directory only and forces Hugging Face/Transformers offline mode;</li>
<li>starts warming in the background when the backend starts; an analysis never waits for warm-up
and skips NER until the worker is ready, so loading cannot consume the run's NER allowance;</li>
<li>hides CUDA and HIP devices and loads weights with <code>map_location="cpu"</code>;</li>
<li>starts with a scrubbed environment, then installs a fail-closed seccomp filter that denies
network syscalls before accepting source text (the Python socket API is disabled as defense in depth);</li>
<li>receives at most two 500-character candidates per table by default, selected breadth-first
across unresolved columns, and shares a ten-second NER allowance across the whole run;</li>
<li>returns only column ID, normalized label, and confidence; source text and entity spans are not
returned or stored;</li>
<li>is skipped on timeout, startup failure, invalid output, or absent configuration. No LLM fallback
is selected.</li>
</ul>
<p>The pinned model revision is <code>c153999da5f4c509df4322b0c6a1baf3d2c284d7</code>. GLiNER2 and the model
are Apache-2.0; the published mDeBERTa base is MIT. The optional runtime pins
<code>gliner2[local]==2.0.0</code>, <code>transformers==4.57.6</code>, and the CPU-only PyTorch wheel
<code>torch==2.14.0+cpu</code>. It lives in <code>/opt/sensitivity-ner</code>, is not installed in the default core image,
and does not install CUDA packages.</p>
<p>The current upstream checkpoint was saved by Transformers 5.8 even though GLiNER2 2.0.0 officially
requires Transformers <code>&lt;5</code>; the resulting tokenizer error is independently reported in
<a href="https://github.com/fastino-ai/GLiNER2/issues/145">GLiNER2 issue 145</a>. At startup ThothII leaves the
pinned model directory unchanged and creates a temporary symlink view that maps the checkpoint's
<code>extra_special_tokens</code> list to the Transformers 4 name <code>additional_special_tokens</code>. Any other or
ambiguous shape fails closed and leaves the optional NER unavailable. The offline CPU smoke test
must remain part of every dependency or model revision update.</p>
<h2 id="prepare-and-enable-the-optional-profile">Prepare and enable the optional profile<a class="headerlink" href="#prepare-and-enable-the-optional-profile" title="Permanent link">&para;</a></h2>
<p>Download happens during explicit installation, never during inference:</p>
<pre class="highlight"><code class="language-bash">./scripts/fetch-sensitivity-ner-model.sh /absolute/path/to/gliner2-pii</code></pre>
<p>The script builds the separate <code>thothii-core:sensitivity-ner</code> image, downloads the exact revision, and writes
<code>MODEL_SHA256SUMS</code>. Keep the model directory outside the repository. Then set:</p>
<pre class="highlight"><code class="language-bash">export THOTH_ENABLE_SENSITIVITY_NER=1
export THT_SENSITIVITY_NER_MODEL_DIR=/absolute/path/to/gliner2-pii
export THT_SENSITIVITY_NER_THREADS=2
./scripts/run-stack.sh</code></pre>
<p>For an operator-managed Compose invocation, include <code>deploy/compose.sensitivity-ner.yaml</code> after the
base and installation overlays. The core build argument <code>INSTALL_SENSITIVITY_NER=true</code> installs the
optional Python dependencies into their isolated virtualenv. The model mount is read-only. Values
above eight threads are rejected; start with two so classification cannot contend heavily with
other CPU workloads.</p>
<h2 id="acceptance-on-a-real-database">Acceptance on a real database<a class="headerlink" href="#acceptance-on-a-real-database" title="Permanent link">&para;</a></h2>
<p>Run the first evaluation in shadow mode: read the source with its existing read-only role, do not
save proposed flags, and report only aggregate counts, rule IDs, coverage, and timings. Never copy
matched values into test output. Use a separately approved, labeled Italian corpus to calculate
precision and recall; source values must remain inside the authorized environment.</p>
<p>Inside the configured core runtime, the non-mutating command is:</p>
<pre class="highlight"><code class="language-bash">npm run sensitivity:shadow -- &lt;workspace-id&gt;</code></pre>
<p>It reads catalog metadata and source values but emits one aggregate JSON object with no database,
table, column, or source-value detail. It neither creates an analysis run nor updates a flag.</p>
<p>Enabling NER by default requires all of these gates:</p>
<ol>
<li>the pinned artifact and <code>MODEL_SHA256SUMS</code> are archived with the installation inventory;</li>
<li>the Python dependency/license inventory contains only redistribution-compatible licenses;</li>
<li>the CPU benchmark stays within the configured NER allowance and does not use a GPU;</li>
<li>the labeled Italian evaluation meets thresholds approved by the product owner.</li>
</ol>
<p>If a gate fails, leave NER disabled. The deterministic policy remains available and produces the
binary draft from its scan coverage; no content is sent to an internal or external LLM.</p>
<p>Benchmarks from a particular installation are not a guarantee for another database or machine.
NER remains opt-in until an approved evaluation establishes that additional findings justify
their false-positive rate and operational cost. Keep benchmark and release records with the
installation's technical evidence, separate from this operator procedure.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../../evidence/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../../evidence/" class="btn btn-xs btn-link">
Evidence
</a>
</div>
<div class="wm-article-nav">
<a href="../database-management/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../database-management/" class="btn btn-xs btn-link">
Databases and descriptions
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+224
View File
@@ -0,0 +1,224 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/operations/workspaces/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Workspaces - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Workspace operations", url: "#_top", children: [
{title: "Roles and ownership", url: "#roles-and-ownership" },
{title: "Operator sequence", url: "#operator-sequence" },
{title: "Transport and revision rules", url: "#transport-and-revision-rules" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../database-management/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../database-management/" class="btn btn-xs btn-link">
Databases and descriptions
</a>
</div>
<div class="wm-article-nav">
<a href="../../general/pi-configuration/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../../general/pi-configuration/" class="btn btn-xs btn-link">
Model configuration
</a>
</div>
</div>
<h1 id="workspace-operations">Workspace operations<a class="headerlink" href="#workspace-operations" title="Permanent link">&para;</a></h1>
<p>A workspace is curator-owned Git content plus installation-local runtime bindings. It is the
boundary between what can be published and what can be used by an installation.</p>
<h2 id="roles-and-ownership">Roles and ownership<a class="headerlink" href="#roles-and-ownership" title="Permanent link">&para;</a></h2>
<table>
<thead>
<tr>
<th>Role</th>
<th>Owns</th>
<th>Does not own</th>
</tr>
</thead>
<tbody>
<tr>
<td>Curator</td>
<td><code>thoth-workspaces.yaml</code>, <code>&lt;id&gt;/workspace.yaml</code>, and Evidence</td>
<td>database metadata, installation secrets, or active runtime bindings</td>
</tr>
<tr>
<td>Installation operator</td>
<td>Git source, selected workspace, write-only runtime secrets, validation, connectivity, and preprocessing</td>
<td>commits or pushes to the workspace repository</td>
</tr>
<tr>
<td>Reviewer</td>
<td>NL→SQL decisions in a pinned session</td>
<td>workspace publication or preprocessing</td>
</tr>
</tbody>
</table>
<!-- non-workspace-migration:start -->
<p>The root catalog has <code>schema_version: 1</code> and an ordered list of workspace identities.</p>
<!-- non-workspace-migration:end -->
<!-- workspace-descriptor-contract:start -->
<p>Schema v4 is the only accepted workspace descriptor. Schema v1, v2, and v3 workspace descriptors
are rejected before activation. Each catalog entry must have a matching descriptor at
<code>&lt;id&gt;/workspace.yaml</code> in the same Git commit. The application validates a complete candidate
revision and activates it atomically; invalid content leaves the preceding active revision in
place. A v4 descriptor contains only workspace identity and optional Evidence configuration; it
does not contain a database or database metadata.</p>
<!-- workspace-descriptor-contract:end -->
<!-- non-workspace-migration:start -->
<p>Create a clean v4 descriptor with <code>workspace</code> and optional <code>evidence</code>. Do not import the old DWH,
diagnostics, annotation, <code>llm_policy</code>, or <code>semantic_index</code> blocks. Configure the database in
Database Management. ThothII never rewrites the curator-owned repository during pull.</p>
<!-- non-workspace-migration:end -->
<h2 id="operator-sequence">Operator sequence<a class="headerlink" href="#operator-sequence" title="Permanent link">&para;</a></h2>
<ol>
<li>Curate and push a complete repository revision. Do not put DWH passwords, API keys, private
keys, or signed URLs in this repository.</li>
<li>In the application, update the workspace repository. This fetches and validates the candidate;
it never edits the remote repository.</li>
<li>Select the workspace. Supply or replace its write-only Evidence runtime secrets, configure its
database in <strong>Database Management</strong>, then run <strong>Validate workspace source</strong> and <strong>Test workspace
connections</strong>. The workspace connection test uses that same current database configuration for
DWH connectivity and also checks the workspace Evidence and installation semantic services.</li>
<li>Select it as the installation workspace before creating sessions.</li>
<li>Expand <strong>Administration</strong> in the right sidebar and run <strong>Preprocessing</strong>. The button is available
when all prerequisites are satisfied: it shows <strong>Run</strong> when preprocessing is required,
<strong>Run again</strong> when the workspace is already current, and <strong>Retry</strong> after a failure. The same
operation is available from the host CLI for unattended administration. <strong>Clear</strong>, immediately
to the left, removes only replaceable Schema/Evidence vectors, LSH, corpus, and checkpoints after
an inline confirmation; it preserves Memory and solved questions. <code>--json</code> keeps CLI stdout
machine-readable.</li>
</ol>
<pre class="highlight"><code class="language-sh">INSTALLATION=/absolute/path/thothii-installation.yaml
WORKSPACE=example-workspace
tht --installation "$INSTALLATION" workspace inspect --workspace "$WORKSPACE" --json
tht --installation "$INSTALLATION" workspace preprocess run --workspace "$WORKSPACE" --json
tht --installation "$INSTALLATION" workspace preprocess clear --workspace "$WORKSPACE" --json</code></pre>
<p>The command snapshots tables, columns, descriptions, sensitivity, and active relationships from
PostgreSQL, samples eligible DWH values for LSH, and replaces the schema/Evidence vector slices.
It is rerunnable but not resumable and has no rollback. Catalog sync and description generation
remain separate operations and must already be complete.</p>
<p>After clear, the sidebar reports <strong>Required</strong> and the core rejects new sessions until a complete run
succeeds. Clear can be repeated safely: an already absent reference collection or derived path is a
no-op, and the separate Memory collection is never a cleanup target.</p>
<p>The sidebar retains no run history. If the current prerequisite blocks a start, it explains what
must be completed and correctly reports that there is no run log. If the last run failed, it shows
only that run's safe stage, error code, and finish time; use <code>docker compose logs core</code> for the
corresponding service log.</p>
<p>The contract gives exact validation, exit code, and JSON rules in
<a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/workspace-preprocessing-cli.md">Workspace preprocessing CLI</a>. For Evidence source
forms and the schema-v4 descriptor contract, see
<a href="https://git.tylconsulting.it/mptyl/ThothII/src/branch/main/docs/contracts/workspace-evidence-v3.md">Workspace Evidence v3</a>.</p>
<h2 id="transport-and-revision-rules">Transport and revision rules<a class="headerlink" href="#transport-and-revision-rules" title="Permanent link">&para;</a></h2>
<p>Runtime sessions support direct PostgreSQL and REST bindings. SSH tunnel bindings are diagnostic
only for this path, so they cannot admit an NL→SQL session. Database Management and <strong>Test
workspace connections</strong> share the current database binding, including its strict known-host SSH
path; the remaining workspace diagnostics cover Evidence and installation semantic services.</p>
<p>Every new session pins the active Git revision. Snapshot cleanup retains revisions still
referenced by unarchived sessions. A later pull can prepare a future session but cannot alter a
resume.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../database-management/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../database-management/" class="btn btn-xs btn-link">
Databases and descriptions
</a>
</div>
<div class="wm-article-nav">
<a href="../../general/pi-configuration/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../../general/pi-configuration/" class="btn btn-xs btn-link">
Model configuration
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+163
View File
@@ -0,0 +1,163 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/product-overview/">
<link rel="shortcut icon" href="../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Product overview - ThothII Docs</title>
<link href="../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../css/highlight.css">
<link href="../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../js/jquery-3.2.1.min.js"></script>
<script src="../js/bootstrap-3.3.7.min.js"></script>
<script src="../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '..';
var is_top_frame = false;
var pageToc = [
{title: "What ThothII does", url: "#_top", children: [
{title: "From a question to a reusable result", url: "#from-a-question-to-a-reusable-result" },
{title: "What an installation includes", url: "#what-an-installation-includes" },
{title: "Choose your next step", url: "#choose-your-next-step" },
]},
];
</script>
<script src="../js/base.js"></script>
<script src="../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../skills/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../skills/" class="btn btn-xs btn-link">
Reviewed workflow
</a>
</div>
<div class="wm-article-nav">
<a href=".." class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href=".." class="btn btn-xs btn-link">
Home
</a>
</div>
</div>
<h1 id="what-thothii-does">What ThothII does<a class="headerlink" href="#what-thothii-does" title="Permanent link">&para;</a></h1>
<p>ThothII helps turn a natural-language question into reviewed SQL. It is intended for
people who know the meaning of their data and need to make the assumptions behind a
query explicit. The model proposes; a human reviewer approves, corrects or rejects.</p>
<h2 id="from-a-question-to-a-reusable-result">From a question to a reusable result<a class="headerlink" href="#from-a-question-to-a-reusable-result" title="Permanent link">&para;</a></h2>
<p>The <a href="../skills/">eight-phase workflow</a> clarifies the question, consults reusable knowledge,
selects relevant Evidence and database objects, prepares a query plan, and produces SQL
for review. Approved knowledge can be saved for later questions.</p>
<ul>
<li><strong>Workspace:</strong> the domain context and its Evidence configuration.</li>
<li><strong>Database catalog:</strong> tables, columns, relationships and reviewed descriptions.</li>
<li><strong>Evidence:</strong> domain sources and rules with provenance that a reviewer can inspect.</li>
<li><strong>Memory:</strong> reusable clarifications, SQL rules, solved questions and explained errors.</li>
<li><strong>Session:</strong> the saved artifacts and decisions for one question, not a permanent chat transcript.</li>
</ul>
<p>Resuming a session uses its saved state. Model output is a proposal, not a guarantee of
correctness: review the scope, assumptions, sources and SQL before relying on the result.</p>
<h2 id="what-an-installation-includes">What an installation includes<a class="headerlink" href="#what-an-installation-includes" title="Permanent link">&para;</a></h2>
<p>The Docker stack includes the web application, its runtime, a PostgreSQL metadata/Memory
catalog, Qdrant and the embedding service. A browser is the normal user interface; the
host <code>tht</code> command is used to configure and operate the installation.</p>
<p>The data warehouse and generative model endpoints are configured separately. Docker
does not supply their credentials, network access or domain data. A standalone installation
is therefore self-hosted, but is not automatically offline or independent of those services.
Review data-access permissions and the model-provider configuration before using real data.</p>
<h2 id="choose-your-next-step">Choose your next step<a class="headerlink" href="#choose-your-next-step" title="Permanent link">&para;</a></h2>
<ul>
<li>Install on Mac, Windows through WSL2, or Linux: <a href="../install/standalone-manual-it/">Italian</a>
or <a href="../install/standalone-manual-en/">English</a> manual procedure.</li>
<li>Configure <a href="../install/shell-and-language/">display mode and language</a>,
<a href="../install/authentication-local/">authentication</a> and <a href="../general/pi-configuration/">models</a>.</li>
<li>Prepare <a href="../operations/workspaces/">workspaces</a> and <a href="../operations/database-management/">databases</a>.</li>
<li>Start a reviewed question using the <a href="../guida-utente/">user guide</a>.</li>
</ul>
<p>The installation guides state the platform tests still to complete. Availability of a
procedure is not a certification that every target machine has been tested.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../skills/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../skills/" class="btn btn-xs btn-link">
Reviewed workflow
</a>
</div>
<div class="wm-article-nav">
<a href=".." class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href=".." class="btn btn-xs btn-link">
Home
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
+79
View File
@@ -0,0 +1,79 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="shortcut icon" href="./img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>ThothII Docs</title>
<link href="./css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="./css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="./css/base.css" rel="stylesheet">
<link rel="stylesheet" href="./css/highlight.css">
<link href="./stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="./js/jquery-3.2.1.min.js"></script>
<script src="./js/bootstrap-3.3.7.min.js"></script>
<script src="./js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '.';
var is_top_frame = false;
var page_toc = null;
</script>
<script src="./js/base.js"></script>
<script src="./javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<h1 id="search">Search Results</h1>
<ul id="mkdocs-search-results" class="wm-search-page">
Searching...
</ul>
<script>
window.top.doSearch({
resultsElem: $('#mkdocs-search-results'),
query: getParam('q'),
snippetLen: 200,
limit: 0
});
</script>
<br>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>
File diff suppressed because one or more lines are too long
+83
View File
@@ -0,0 +1,83 @@
<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://git.tylconsulting.it/thothii-docs/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/evidence/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/guida-utente/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/product-overview/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/skills/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/general/pi-configuration/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/authentication-local/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/authentication-oidc/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/authentik/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/dwh-auth-client-enrollment/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/dwh-auth-server/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/dwh-auth-tls/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/first-start/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/shell-and-language/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/standalone-manual-en/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/install/standalone-manual-it/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/operations/database-management/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/operations/sensitivity-analysis/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/operations/workspaces/</loc>
<lastmod>2026-09-26</lastmod>
</url>
<url>
<loc>https://git.tylconsulting.it/thothii-docs/usage/memory/</loc>
<lastmod>2026-09-26</lastmod>
</url>
</urlset>
BIN
View File
Binary file not shown.
+178
View File
@@ -0,0 +1,178 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8"/>
<meta content="IE=edge" http-equiv="X-UA-Compatible"/>
<meta content="width=device-width, initial-scale=1.0" name="viewport"/>
<link href="https://git.tylconsulting.it/thothii-docs/skills/" rel="canonical"/>
<link href="../img/favicon.ico" rel="shortcut icon"/>
<meta content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" name="viewport"/>
<title>Reviewed workflow - ThothII Docs</title>
<link href="../css/bootstrap-3.3.7.min.css" rel="stylesheet"/>
<link href="../css/font-awesome-4.7.0.css" rel="stylesheet"/>
<link href="../css/base.css" rel="stylesheet"/>
<link href="../css/highlight.css" rel="stylesheet"/>
<link href="../stylesheets/extra.css" rel="stylesheet"/>
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../js/jquery-3.2.1.min.js"></script>
<script src="../js/bootstrap-3.3.7.min.js"></script>
<script src="../js/highlight.pack.js"></script>
<base target="_top"/>
<script>
var base_url = '..';
var is_top_frame = false;
var pageToc = [
{title: "ThothII operating workflow", url: "#_top", children: [
{title: "Workflow principles", url: "#workflow-principles" },
{title: "F1: clarification", url: "#f1-clarification" },
{title: "F2: Memory", url: "#f2-memory" },
{title: "F3: rewriting", url: "#f3-rewriting" },
{title: "F4: Evidence", url: "#f4-evidence" },
{title: "F5: schema", url: "#f5-schema" },
{title: "F6: CTE plan", url: "#f6-cte-plan" },
{title: "F7: final SQL", url: "#f7-final-sql" },
{title: "F8: Memory promotion", url: "#f8-memory-promotion" },
{title: "Available gates", url: "#available-gates" },
{title: "Resume and reopening", url: "#resume-and-reopening" },
]},
];
</script>
<script src="../js/base.js"></script>
<script src="../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
<div class="wm-article-nav pull-right">
<a class="btn btn-xs btn-default pull-right" href="../guida-utente/">
Next
<i aria-hidden="true" class="fa fa-chevron-right"></i>
</a>
<a class="btn btn-xs btn-link" href="../guida-utente/">
User guide
</a>
</div>
<div class="wm-article-nav">
<a class="btn btn-xs btn-default pull-left" href="../product-overview/">
<i aria-hidden="true" class="fa fa-chevron-left"></i>
Previous</a><a class="btn btn-xs btn-link" href="../product-overview/">
Product overview
</a>
</div>
</div>
<h1 id="thothii-operating-workflow">ThothII operating workflow<a class="headerlink" href="#thothii-operating-workflow" title="Permanent link"></a></h1>
<p>ThothII guides every question through eight phases. The model proposes the work, the reviewer
makes decisions at gates, and the system records persistent artifacts and decisions.</p>
<div class="mermaid">flowchart LR
Q["Question"] --&gt; F1["F1 Clarification"]
F1 --&gt; F2["F2 Memory"]
F2 --&gt; F3["F3 Rewriting"]
F3 --&gt; F4["F4 Evidence"]
F4 --&gt; F5["F5 Schema"]
F5 --&gt; F6["F6 CTE plan"]
F6 --&gt; F7["F7 SQL"]
F7 --&gt; F8["F8 Promotion"]
F8 --&gt; DONE["Finalized session"]
</div>
<h2 id="workflow-principles">Workflow principles<a class="headerlink" href="#workflow-principles" title="Permanent link"></a></h2>
<ul>
<li>The model proposes; the reviewer approves, corrects, or rejects.</li>
<li>The session ledger records every material decision.</li>
<li>Persisted state is the source of truth.</li>
<li>A phase advances only when its artifacts and gates are complete.</li>
<li>Resume rebuilds context from persisted artifacts, not from the conversation.</li>
</ul>
<h2 id="f1-clarification">F1: clarification<a class="headerlink" href="#f1-clarification" title="Permanent link"></a></h2>
<p>The system identifies the ambiguity most likely to change the meaning of the question and presents
one decision at a time. Mutually exclusive interpretations use a single choice; multiple valid
answers use a multiple choice.</p>
<h2 id="f2-memory">F2: Memory<a class="headerlink" href="#f2-memory" title="Permanent link"></a></h2>
<p>The system proposes Memory items that fit the question. Selected items enter the current session
context; unselected items remain available for future questions.</p>
<h2 id="f3-rewriting">F3: rewriting<a class="headerlink" href="#f3-rewriting" title="Permanent link"></a></h2>
<p>The system rewrites the question explicitly using the approved clarifications. The reviewer checks
the resulting question and its assumptions before continuing.</p>
<h2 id="f4-evidence">F4: Evidence<a class="headerlink" href="#f4-evidence" title="Permanent link"></a></h2>
<p>The system retrieves Evidence from the active corpus and presents citations and provenance. The
reviewer decides which items apply to the question.</p>
<h2 id="f5-schema">F5: schema<a class="headerlink" href="#f5-schema" title="Permanent link"></a></h2>
<p>Tables, columns, relationships, and filters are linked to the approved meaning of the question.
The summary closes the phase when the question, assumptions, and DWH elements are consistent.</p>
<h2 id="f6-cte-plan">F6: CTE plan<a class="headerlink" href="#f6-cte-plan" title="Permanent link"></a></h2>
<p>The query is broken into named CTEs with a purpose, dependencies, tables, filters, and output
columns. The reviewer sees each step before the system produces the final SQL.</p>
<h2 id="f7-final-sql">F7: final SQL<a class="headerlink" href="#f7-final-sql" title="Permanent link"></a></h2>
<p>The system produces <code>sql_final.sql</code>, checks it against the approved plan, and presents the artifact
to the reviewer. A correction can reopen the CTE plan without discarding decisions that remain valid.</p>
<h2 id="f8-memory-promotion">F8: Memory promotion<a class="headerlink" href="#f8-memory-promotion" title="Permanent link"></a></h2>
<p>At the end of the session, the system proposes reusable Memory cards, including the approved
solved question. The reviewer selects and edits the additions or updates to retain in the
workspace's Memory archive, or declines them all. The session is then finalized.</p>
<h2 id="available-gates">Available gates<a class="headerlink" href="#available-gates" title="Permanent link"></a></h2>
<table>
<thead>
<tr>
<th>Gate</th>
<th>Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Single choice</td>
<td>Only one interpretation can be valid</td>
</tr>
<tr>
<td>Multiple choice</td>
<td>Several items can be valid at the same time</td>
</tr>
<tr>
<td>Artifact confirmation</td>
<td>Approval of a document or phase result</td>
</tr>
<tr>
<td>Phase confirmation</td>
<td>Explicitly closes a phase</td>
</tr>
</tbody>
</table>
<h2 id="resume-and-reopening">Resume and reopening<a class="headerlink" href="#resume-and-reopening" title="Permanent link"></a></h2>
<p>A resumed session returns to its last incomplete phase. Reopening invalidates only the decisions
and artifacts that depend on the changed point; the rest of the work remains valid.</p>
<br/>
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
<div class="wm-article-nav pull-right">
<a class="btn btn-xs btn-default pull-right" href="../guida-utente/">
Next
<i aria-hidden="true" class="fa fa-chevron-right"></i>
</a>
<a class="btn btn-xs btn-link" href="../guida-utente/">
User guide
</a>
</div>
<div class="wm-article-nav">
<a class="btn btn-xs btn-default pull-left" href="../product-overview/">
<i aria-hidden="true" class="fa fa-chevron-left"></i>
Previous</a><a class="btn btn-xs btn-link" href="../product-overview/">
Product overview
</a>
</div>
</div>
<br/>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
<script type="module">import mermaid from "https://unpkg.com/mermaid@10.4.0/dist/mermaid.esm.min.mjs";
mermaid.initialize({});</script></body>
</html>
+134
View File
@@ -0,0 +1,134 @@
html {
font-size: 62.5%; /* 1rem = 10px */
width: 100%;
}
body {
font-size: 1.3rem; /* 13px */
width: 100%;
}
.wm-page-content {
width: 100% !important;
box-sizing: border-box !important;
max-width: 1400px !important;
margin-left: auto !important;
margin-right: auto !important;
}
.wm-content-pane {
width: 100% !important;
max-width: none !important;
box-sizing: border-box !important;
}
.wm-article,
.col-md-9[role="main"],
[role="main"] .col-md-9,
[role="main"] {
width: 100% !important;
box-sizing: border-box !important;
max-width: 1400px !important;
margin-left: auto !important;
margin-right: auto !important;
}
@media (min-width: 992px) {
.container,
.container-fluid {
width: 100% !important;
box-sizing: border-box !important;
max-width: 1400px !important;
margin-left: auto !important;
margin-right: auto !important;
padding-left: 24px;
padding-right: 24px;
}
}
@media (min-width: 900px) and (max-width: 1199px) {
.wm-toc-pane {
min-width: 200px;
width: 200px;
}
.wm-content-pane {
padding-left: 200px;
}
}
@media (max-width: 899px) {
.wm-toc-pane {
margin-left: -250px;
}
.wm-content-pane {
padding-left: 0;
}
}
.wm-article {
display: block !important;
}
/* Headings — scala gerarchica (base: 1rem = 10px) */
.wm-page-content h1 { font-size: 2.0rem; } /* 20px */
.wm-page-content h2 { font-size: 1.8rem; } /* 18px */
.wm-page-content h3 { font-size: 1.6rem; } /* 16px */
.wm-page-content h4 { font-size: 1.4rem; } /* 14px */
.wm-page-content h5 { font-size: 1.3rem; } /* 13px */
.wm-page-content h6 { font-size: 1.2rem; } /* 12px */
/* Testo corpo */
.wm-page-content p,
.wm-page-content li,
.wm-page-content blockquote,
.wm-page-content .admonition {
font-size: 1.3rem; /* 13px */
}
/* Tabelle */
.wm-page-content td,
.wm-page-content th {
font-size: 1.2rem; /* 12px */
}
/* Codice */
.wm-page-content .highlight pre,
.wm-page-content pre,
.wm-page-content code {
font-size: 1.2rem; /* 12px */
}
/* TOC laterale */
.wm-toc-pane,
.wm-toc-pane a,
.wm-toctree,
.wm-toctree li,
.wm-toctree .wm-toc-text {
font-size: 1.2rem; /* 12px */
}
/* Navbar e ricerca */
.navbar,
.navbar a,
#wm-search-form,
#mkdocs-search-query {
font-size: 1.2rem; /* 12px */
}
.bs-sidebar {
max-height: none;
}
.table,
table,
pre,
.mermaid {
width: 100%;
max-width: none !important;
}
table {
table-layout: auto;
}
+184
View File
@@ -0,0 +1,184 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/usage/memory/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Memory - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Use and administer Memory", url: "#_top", children: [
{title: "Browse and edit", url: "#browse-and-edit" },
{title: "Saved content and search availability", url: "#saved-content-and-search-availability" },
{title: "Memory in a reviewed session", url: "#memory-in-a-reviewed-session" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../../install/dwh-auth-server/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../../install/dwh-auth-server/" class="btn btn-xs btn-link">
Server
</a>
</div>
<div class="wm-article-nav">
<a href="../../evidence/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../../evidence/" class="btn btn-xs btn-link">
Evidence
</a>
</div>
</div>
<h1 id="use-and-administer-memory">Use and administer Memory<a class="headerlink" href="#use-and-administer-memory" title="Permanent link">&para;</a></h1>
<p>Memory stores reusable knowledge for a workspace. It is separate from Evidence sources
and from the saved documents of an individual session.</p>
<table>
<thead>
<tr>
<th>Card family</th>
<th>Purpose</th>
</tr>
</thead>
<tbody>
<tr>
<td>Domain clarification</td>
<td>Define a term or interpretation, with its scope.</td>
</tr>
<tr>
<td>SQL rule</td>
<td>Explain how to construct SQL and why.</td>
</tr>
<tr>
<td>Solved question</td>
<td>Retain an approved question and SQL as a consultative example.</td>
</tr>
<tr>
<td>Explained error</td>
<td>Record a correction and its rationale.</td>
</tr>
</tbody>
</table>
<h2 id="browse-and-edit">Browse and edit<a class="headerlink" href="#browse-and-edit" title="Permanent link">&para;</a></h2>
<p>Open <strong>Administration → Memory management</strong> and select the workspace. Administration
requires the appropriate permissions. You can search, filter, open a card's complete
content, edit it, manage its dependencies and links, or explicitly confirm deletion.</p>
<p>Browsing and editing require the PostgreSQL archive but do not require an active session
or a working DWH or search index. Cards retain their identity and origin when edited;
there is no editorial revision history. Deleting a card also removes its links and
dependencies, not the other cards or the workspace's Evidence.</p>
<p>Links connect cards in the same workspace. Record scope and physical dependencies
carefully so knowledge is not applied to unrelated databases, tables or columns.</p>
<h2 id="saved-content-and-search-availability">Saved content and search availability<a class="headerlink" href="#saved-content-and-search-availability" title="Permanent link">&para;</a></h2>
<p>Saving a card and updating its search index are different outcomes. <strong>Saved, index update
incomplete</strong> means the content is already in the archive but is not ready for recall.
Use <strong>Pending index updates</strong> to retry. Do not create a duplicate card to work around an
indexing failure. A restart does not discard the pending operation.</p>
<p>Qdrant is a rebuildable search projection, not the authoritative archive. Rebuilding it
does not recover deleted cards from old sessions or vector payloads. Back up the
authoritative installation data before maintenance.</p>
<p>After a successful physical schema synchronization, cards dependent on removed database
objects can be deleted. Workspace-wide cards and unrelated dependencies remain. Review
the synchronization result and any pending cleanup before starting another synchronization.</p>
<h2 id="memory-in-a-reviewed-session">Memory in a reviewed session<a class="headerlink" href="#memory-in-a-reviewed-session" title="Permanent link">&para;</a></h2>
<p>The workflow proposes relevant clarifications, rules and examples. A search result is
not approval: the reviewer decides whether it applies. At the final Memory review,
select the additions or updates worth retaining, edit their content and scope, or decline
them all. Finalizing a session does not silently approve every proposed card.</p>
<p>Approved SQL is read-only at that final review. To change the solution, return to SQL
review. See the <a href="../../skills/">workflow guide</a> and <a href="../../guida-utente/">user guide</a>.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../../install/dwh-auth-server/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../../install/dwh-auth-server/" class="btn btn-xs btn-link">
Server
</a>
</div>
<div class="wm-article-nav">
<a href="../../evidence/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../../evidence/" class="btn btn-xs btn-link">
Evidence
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>