Publish documentation for 2f53512e4d
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
# Copy this file to a protected operator-controlled path named exactly thothii-installation.yaml
|
||||
# and set mode 0600 (or 0400) before using it as THT_INSTALLATION_CONFIG_SOURCE.
|
||||
# Replace every absolute placeholder. Select exactly one Git transport override.
|
||||
schemaVersion: 2
|
||||
profile: local
|
||||
shell:
|
||||
mode: full
|
||||
defaultLocale: en
|
||||
projectDirectory: "/absolute/path/to/ThothII"
|
||||
envFile: "/absolute/path/to/ThothII/deploy/env/local.env"
|
||||
workspaceRepository:
|
||||
remote: git@git.example.com:organization/workspaces.git
|
||||
branch: main
|
||||
access: ssh
|
||||
modelCatalog:
|
||||
defaults:
|
||||
session: deepseek/deepseek-v4-pro
|
||||
metadataGeneration: openai/gpt-4.1-mini
|
||||
embedding:
|
||||
id: ollama/qwen3-embedding:0.6b
|
||||
dimensions: 1024
|
||||
providers:
|
||||
deepseek:
|
||||
authentication: {mode: pi_auth}
|
||||
session: {mode: pi_builtin}
|
||||
models:
|
||||
deepseek-v4-pro:
|
||||
session: {}
|
||||
openai:
|
||||
authentication: {mode: secret_env, apiKeyEnv: OPENAI_API_KEY}
|
||||
metadataGeneration: {litellmProvider: openai}
|
||||
models:
|
||||
gpt-4.1-mini:
|
||||
label: OpenAI Mini
|
||||
metadataGeneration: {}
|
||||
authentication:
|
||||
configDirectory: "/absolute/path/to/thothii-auth"
|
||||
overrides:
|
||||
- "/absolute/path/to/ThothII/deploy/compose.git-ssh.yaml"
|
||||
@@ -0,0 +1,49 @@
|
||||
# Copy this file to a protected operator path named exactly thothii-installation.yaml
|
||||
# and set mode 0600 (or 0400) before using it as THT_INSTALLATION_CONFIG_SOURCE.
|
||||
# Replace every absolute placeholder. Select exactly one Git transport override.
|
||||
schemaVersion: 2
|
||||
profile: server
|
||||
# Standalone server with protected direct OIDC auth, not the Omics upstream path.
|
||||
# For Omics use authentication-upstream.md: embedded, no auth runtime projection.
|
||||
shell:
|
||||
mode: full
|
||||
defaultLocale: en
|
||||
projectDirectory: "/absolute/path/to/ThothII"
|
||||
envFile: "/absolute/path/to/thothii-server-operator/server.env"
|
||||
workspaceRepository:
|
||||
remote: git@git.example.com:organization/workspaces.git
|
||||
branch: main
|
||||
access: ssh
|
||||
modelCatalog:
|
||||
defaults:
|
||||
session: deepseek/deepseek-v4-pro
|
||||
metadataGeneration: openai/gpt-4.1-mini
|
||||
embedding:
|
||||
id: ollama/qwen3-embedding:0.6b
|
||||
dimensions: 1024
|
||||
providers:
|
||||
deepseek:
|
||||
authentication: {mode: pi_auth}
|
||||
session: {mode: pi_builtin}
|
||||
models:
|
||||
deepseek-v4-pro:
|
||||
session: {}
|
||||
openai:
|
||||
endpoint: {baseUrl: https://api.openai.example/v1}
|
||||
authentication: {mode: secret_env, apiKeyEnv: OPENAI_API_KEY}
|
||||
metadataGeneration: {litellmProvider: openai}
|
||||
models:
|
||||
gpt-4.1-mini:
|
||||
label: OpenAI Mini
|
||||
metadataGeneration: {}
|
||||
authentication:
|
||||
# Root-operated source of truth; it is never mounted into core.
|
||||
configDirectory: "/srv/example/thothii/auth-canonical"
|
||||
runtimeProjection:
|
||||
# The only authentication bind exposed to core by the automatic override.
|
||||
directory: "/srv/example/thothii/auth-runtime"
|
||||
uid: 10001
|
||||
gid: 10001
|
||||
overrides:
|
||||
- "/absolute/path/to/ThothII/deploy/compose.session-server.yaml.example"
|
||||
- "/absolute/path/to/ThothII/deploy/compose.git-ssh.yaml"
|
||||
@@ -0,0 +1,14 @@
|
||||
# Copy to an untracked operator file. This file contains only non-secret THT_WS_* bindings.
|
||||
# Every *_FILE value is a container path supplied by the generated local connector override.
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT=postgres_direct
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_HOST=dwh.internal.example
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_PORT=5432
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_USER=thoth_reader
|
||||
THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE=/run/secrets/north-star-research-dwh-password
|
||||
|
||||
# Evidence examples use separate illustrative namespaces because one descriptor selects one mode.
|
||||
# Values are container file paths only; signed URLs and credential contents stay in those files.
|
||||
THT_WS_SIGNED_HTTP_EVIDENCE_SIGNED_URLS_FILE=/run/secrets/signed-http-evidence-urls.json
|
||||
THT_WS_STATIC_S3_EVIDENCE_ACCESS_KEY_FILE=/run/secrets/static-s3-evidence-access-key
|
||||
THT_WS_STATIC_S3_EVIDENCE_SECRET_KEY_FILE=/run/secrets/static-s3-evidence-secret-key
|
||||
THT_WS_STATIC_S3_EVIDENCE_SESSION_TOKEN_FILE=/run/secrets/static-s3-evidence-session-token
|
||||
Reference in New Issue
Block a user