docs(vector): add local backup restore and parity gate

This commit is contained in:
2026-07-12 02:18:29 +02:00
parent 1145ae20bc
commit e4db2ea5e1
8 changed files with 471 additions and 5 deletions
+40
View File
@@ -45,6 +45,46 @@ volume afterward. It never targets the fixed `thothii` operator project or its v
`KEEP_SMOKE_RESOURCES=1` to retain that smoke project's resources for inspection; remove them
later with `docker compose --project-name "$SMOKE_PROJECT" --profile external down --volumes`.
## Optional local pgvector and recovery
Start the persistent local vector profile with `docker compose --profile local-vector up
--build --wait`. Its `vector_data` volume is independent of application state. Reader, writer,
migrator, and bootstrap credentials remain separate; password files must be mode `0600` and
must not be passed as URL arguments.
Create a versioned PostgreSQL custom-format backup (the filename is operator-controlled, so use
an immutable timestamp or release identifier):
```sh
./scripts/vector-backup.sh \
--host 127.0.0.1 --port 5432 --database thoth --user thoth_backup \
--password-file /secure/thoth/vector-backup-password \
--output /secure/backups/thoth-vectors-2026-07-12.dump
```
The dump contains the three allowlisted `vectors` tables, their data and ACLs, plus the
`public.tht_vector_migrations` ledger. Login roles and passwords are deliberately not copied:
provision/reconcile the approved role names on the target first, and install the `vector`
extension in its `vectors` schema. The target must otherwise contain no vector tables or ledger.
Restore always names both the currently active source and a distinct target. The script compares
PostgreSQL cluster identity plus database OID, so host aliases cannot bypass the active-database
guard. It refuses a non-empty target unless `--force-nonempty` is explicit:
```sh
./scripts/vector-restore.sh \
--active-host vector-db --active-database thoth --active-user thoth_backup \
--active-password-file /secure/thoth/vector-active-password \
--target-host vector-db-restore --target-database thoth --target-user thoth_restore \
--target-password-file /secure/thoth/vector-restore-password \
--input /secure/backups/thoth-vectors-2026-07-12.dump
```
After restore, run `tht vector migrate --status --json`, adapter health, and a known retrieval
query against the target before changing any deployment endpoint. Never test recovery against the
active `vector_data` volume. `./scripts/local-vector-smoke.sh --backup-restore` performs this drill
with disposable source and target volumes.
## Production trust boundary and secrets
ThothII does not implement OIDC. Do not expose its application port directly to a network.