fix(backend): inject provider credentials from file
This commit is contained in:
@@ -62,13 +62,23 @@ runtime):
|
||||
|
||||
```sh
|
||||
docker compose -f compose.yaml -f deploy/compose.local-vector.yaml \
|
||||
-f deploy/compose.preprocess.yaml --profile local-vector --profile preprocess \
|
||||
run --rm preprocess-evidence
|
||||
-f deploy/compose.preprocess.yaml -f deploy/compose.preprocess-local-vector.yaml \
|
||||
--profile local-vector --profile preprocess build preprocess-evidence
|
||||
docker compose -f compose.yaml -f deploy/compose.local-vector.yaml \
|
||||
-f deploy/compose.preprocess.yaml --profile local-vector --profile preprocess \
|
||||
run --rm preprocess-dwh
|
||||
-f deploy/compose.preprocess.yaml -f deploy/compose.preprocess-local-vector.yaml \
|
||||
--profile local-vector --profile preprocess run --rm preprocess-evidence
|
||||
docker compose -f compose.yaml -f deploy/compose.local-vector.yaml \
|
||||
-f deploy/compose.preprocess.yaml -f deploy/compose.preprocess-local-vector.yaml \
|
||||
--profile local-vector --profile preprocess build preprocess-dwh
|
||||
docker compose -f compose.yaml -f deploy/compose.local-vector.yaml \
|
||||
-f deploy/compose.preprocess.yaml -f deploy/compose.preprocess-local-vector.yaml \
|
||||
--profile local-vector --profile preprocess run --rm preprocess-dwh
|
||||
```
|
||||
|
||||
The local preprocessing override makes each job wait for the vector database health check,
|
||||
role reconciliation, and a successful migration. These commands are safe on a clean Compose
|
||||
project; no separate database startup or migration command is required.
|
||||
|
||||
S3 Evidence uses the optional `tht[s3]` dependency and canonical `s3://bucket/key` provenance.
|
||||
AWS endpoints are used when no custom URL is supplied. Every custom endpoint is an explicit egress
|
||||
trust-boundary opt-in and uses path-style addressing; private and HTTP endpoints require additional
|
||||
@@ -128,7 +138,7 @@ with the organization's reviewed identity proxy. `AUTH_MODE=upstream` trusts thi
|
||||
rejects requests without the identity header. Setting `THOTH_PUBLIC_EXPOSURE=true` with any other
|
||||
auth mode fails during core startup.
|
||||
|
||||
Production credentials use Compose secrets, not `deploy/.env`. Create four files outside the
|
||||
Production credentials use Compose secrets, not `deploy/.env`. Create five files outside the
|
||||
repository, restrict their host permissions, and point these variables to them:
|
||||
|
||||
```sh
|
||||
@@ -136,6 +146,7 @@ export THT_DWH_API_KEY_SECRET_FILE=/secure/thoth/dwh-api-key
|
||||
export THT_VEC_API_KEY_SECRET_FILE=/secure/thoth/vector-reader-api-key
|
||||
export THT_VEC_WRITE_API_KEY_SECRET_FILE=/secure/thoth/vector-writer-api-key
|
||||
export THT_CA_SECRET_FILE=/secure/thoth/ca-chain.pem
|
||||
export THT_MODEL_API_KEY_SECRET_FILE=/secure/thoth/model-api-key
|
||||
export THT_DB_NAME=warehouse
|
||||
export THT_DWH_REST_URL=https://dwh.example.test
|
||||
export THT_VEC_REST_URL=https://vectors.example.test
|
||||
@@ -150,6 +161,12 @@ accepted only beneath `/run/secrets`. See [`deploy/secrets/README.md`](deploy/se
|
||||
the verification command. The frontend remains on loopback; the authenticated host proxy is the
|
||||
only public listener.
|
||||
|
||||
Set the selected model provider in application settings (or `PI_PROVIDER`). For each Pi spawn the
|
||||
backend validates and reads `THT_MODEL_API_KEY_FILE`, then exposes its value only as the provider's
|
||||
recognized child variable (for example `ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, `GEMINI_API_KEY`, or
|
||||
`ZAI_API_KEY`). Neither the generic file path nor deprecated `PI_PROVIDER_API_KEY` is inherited by
|
||||
Pi. Local providers such as Ollama require no model key.
|
||||
|
||||
## Reproducible image verification
|
||||
|
||||
Base images use exact tags and immutable multi-platform manifest digests. Dependency update and
|
||||
|
||||
Reference in New Issue
Block a user