fix: harden workspace activation and snapshot retention

This commit is contained in:
2026-08-04 09:25:06 +02:00
parent 3b23cf3714
commit e4fdbed864
14 changed files with 474 additions and 103 deletions
+5 -1
View File
@@ -111,7 +111,7 @@ THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE=/run/secrets/psd-vector-api-key
```
```dotenv
# SSH tunnel; host-key verification and TLS target name remain mandatory.
# SSH tunnel diagnostic only; runtime sessions are fail-closed in this release.
THT_WS_PSD_CLINICAL_DWH_TRANSPORT=ssh_tunnel
THT_WS_PSD_CLINICAL_DWH_USER=thoth_reader
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE=/run/secrets/psd-dwh-reader
@@ -128,6 +128,10 @@ Repeat the SSH names for `VECTOR` where needed. REST diagnostics reject a privat
rather than weakening TLS; use runtime-trusted HTTPS or verified direct/SSH native TLS. See the
[diagnostic protocol](../workspace-diagnostic-protocol.md).
An SSH connector can prove installation reachability, host-key verification, authentication, and
target identity, but it intentionally returns `workspace_not_activatable`; select direct or REST
before creating sessions. Git pull/push over SSH remains fully supported and is independent.
## Bootstrap, first pull, and diagnostics
Copy [the local Compose example](examples/local-compose.workspace-registry.yaml) and exactly one
+5 -1
View File
@@ -114,7 +114,7 @@ THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL=https://embeddings.internal.example
```
```dotenv
# SSH tunnel requires explicit host-key verification and TLS target identity.
# SSH tunnel diagnostic only; runtime sessions are fail-closed in this release.
THT_WS_PSD_CLINICAL_DWH_TRANSPORT=ssh_tunnel
THT_WS_PSD_CLINICAL_DWH_USER=thoth_reader
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE=/run/secrets/psd-dwh-reader
@@ -132,6 +132,10 @@ rather than disable verification; use runtime-trusted HTTPS or verified direct/S
the [diagnostic protocol](../workspace-diagnostic-protocol.md) for its read-only checks and optional
reversible writer probe.
An SSH connector can be tested with strict host-key and target verification, but it intentionally
returns `workspace_not_activatable`; configure direct or REST transport before starting sessions.
The Git registry itself may still use SSH normally.
## Same-origin reverse proxy, bootstrap, and health
Copy [the server Compose example](examples/server-compose.workspace-registry.yaml) plus exactly one
+6
View File
@@ -227,6 +227,12 @@ The local listener is `127.0.0.1` only. The process is terminated in cleanup aft
probe, on timeout, or on failure. There is no accept-new mode, no disabled host-key checking, and
no persistent forwarding.
In this release, `ssh_tunnel` is therefore a diagnostic-only connector transport. A successful
probe is followed by `workspace_not_activatable`, and `POST /sessions` rejects the workspace before
persisting a manifest or starting Pi. Use direct PostgreSQL/pgvector or REST for runtime sessions
until the backend owns a tunnel for the full runtime lifecycle. This restriction does not apply to
using SSH as the transport for the workspace Git remote.
## Reader-only fallback
A workspace may be fully valid in Git but non-activatable locally when a required reader binding,