docs(vector): add local backup restore and parity gate
This commit is contained in:
@@ -45,6 +45,46 @@ volume afterward. It never targets the fixed `thothii` operator project or its v
|
||||
`KEEP_SMOKE_RESOURCES=1` to retain that smoke project's resources for inspection; remove them
|
||||
later with `docker compose --project-name "$SMOKE_PROJECT" --profile external down --volumes`.
|
||||
|
||||
## Optional local pgvector and recovery
|
||||
|
||||
Start the persistent local vector profile with `docker compose --profile local-vector up
|
||||
--build --wait`. Its `vector_data` volume is independent of application state. Reader, writer,
|
||||
migrator, and bootstrap credentials remain separate; password files must be mode `0600` and
|
||||
must not be passed as URL arguments.
|
||||
|
||||
Create a versioned PostgreSQL custom-format backup (the filename is operator-controlled, so use
|
||||
an immutable timestamp or release identifier):
|
||||
|
||||
```sh
|
||||
./scripts/vector-backup.sh \
|
||||
--host 127.0.0.1 --port 5432 --database thoth --user thoth_backup \
|
||||
--password-file /secure/thoth/vector-backup-password \
|
||||
--output /secure/backups/thoth-vectors-2026-07-12.dump
|
||||
```
|
||||
|
||||
The dump contains the three allowlisted `vectors` tables, their data and ACLs, plus the
|
||||
`public.tht_vector_migrations` ledger. Login roles and passwords are deliberately not copied:
|
||||
provision/reconcile the approved role names on the target first, and install the `vector`
|
||||
extension in its `vectors` schema. The target must otherwise contain no vector tables or ledger.
|
||||
|
||||
Restore always names both the currently active source and a distinct target. The script compares
|
||||
PostgreSQL cluster identity plus database OID, so host aliases cannot bypass the active-database
|
||||
guard. It refuses a non-empty target unless `--force-nonempty` is explicit:
|
||||
|
||||
```sh
|
||||
./scripts/vector-restore.sh \
|
||||
--active-host vector-db --active-database thoth --active-user thoth_backup \
|
||||
--active-password-file /secure/thoth/vector-active-password \
|
||||
--target-host vector-db-restore --target-database thoth --target-user thoth_restore \
|
||||
--target-password-file /secure/thoth/vector-restore-password \
|
||||
--input /secure/backups/thoth-vectors-2026-07-12.dump
|
||||
```
|
||||
|
||||
After restore, run `tht vector migrate --status --json`, adapter health, and a known retrieval
|
||||
query against the target before changing any deployment endpoint. Never test recovery against the
|
||||
active `vector_data` volume. `./scripts/local-vector-smoke.sh --backup-restore` performs this drill
|
||||
with disposable source and target volumes.
|
||||
|
||||
## Production trust boundary and secrets
|
||||
|
||||
ThothII does not implement OIDC. Do not expose its application port directly to a network.
|
||||
|
||||
Reference in New Issue
Block a user