fix: harden workspace activation and snapshot retention
This commit is contained in:
@@ -114,7 +114,7 @@ THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL=https://embeddings.internal.example
|
||||
```
|
||||
|
||||
```dotenv
|
||||
# SSH tunnel requires explicit host-key verification and TLS target identity.
|
||||
# SSH tunnel diagnostic only; runtime sessions are fail-closed in this release.
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT=ssh_tunnel
|
||||
THT_WS_PSD_CLINICAL_DWH_USER=thoth_reader
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE=/run/secrets/psd-dwh-reader
|
||||
@@ -132,6 +132,10 @@ rather than disable verification; use runtime-trusted HTTPS or verified direct/S
|
||||
the [diagnostic protocol](../workspace-diagnostic-protocol.md) for its read-only checks and optional
|
||||
reversible writer probe.
|
||||
|
||||
An SSH connector can be tested with strict host-key and target verification, but it intentionally
|
||||
returns `workspace_not_activatable`; configure direct or REST transport before starting sessions.
|
||||
The Git registry itself may still use SSH normally.
|
||||
|
||||
## Same-origin reverse proxy, bootstrap, and health
|
||||
|
||||
Copy [the server Compose example](examples/server-compose.workspace-registry.yaml) plus exactly one
|
||||
|
||||
Reference in New Issue
Block a user