fix: harden workspace activation and snapshot retention
This commit is contained in:
@@ -111,7 +111,7 @@ THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE=/run/secrets/psd-vector-api-key
|
||||
```
|
||||
|
||||
```dotenv
|
||||
# SSH tunnel; host-key verification and TLS target name remain mandatory.
|
||||
# SSH tunnel diagnostic only; runtime sessions are fail-closed in this release.
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT=ssh_tunnel
|
||||
THT_WS_PSD_CLINICAL_DWH_USER=thoth_reader
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE=/run/secrets/psd-dwh-reader
|
||||
@@ -128,6 +128,10 @@ Repeat the SSH names for `VECTOR` where needed. REST diagnostics reject a privat
|
||||
rather than weakening TLS; use runtime-trusted HTTPS or verified direct/SSH native TLS. See the
|
||||
[diagnostic protocol](../workspace-diagnostic-protocol.md).
|
||||
|
||||
An SSH connector can prove installation reachability, host-key verification, authentication, and
|
||||
target identity, but it intentionally returns `workspace_not_activatable`; select direct or REST
|
||||
before creating sessions. Git pull/push over SSH remains fully supported and is independent.
|
||||
|
||||
## Bootstrap, first pull, and diagnostics
|
||||
|
||||
Copy [the local Compose example](examples/local-compose.workspace-registry.yaml) and exactly one
|
||||
|
||||
Reference in New Issue
Block a user