fix: harden workspace registry installation docs
This commit is contained in:
@@ -33,12 +33,15 @@ workspaces/<workspace-id>.md
|
||||
|
||||
For SSH, use a scoped deploy key, a verified `known_hosts` file, and strict host-key checking. For
|
||||
HTTPS, use Git Credential Manager or a secret-manager-created credentials file. Mount a private
|
||||
HTTPS CA as its own file. Do not disable host or certificate verification.
|
||||
HTTPS CA as its own file. Do not disable host or certificate verification. The base Compose file
|
||||
does not mount a Git credential: add exactly one optional `git-ssh.workspace-registry.yaml` or
|
||||
`git-https.workspace-registry.yaml` override, so unused credential paths are never bind-mounted.
|
||||
|
||||
```dotenv
|
||||
THT_WORKSPACE_GIT_REMOTE=ssh://git@git.example.invalid/platform/thoth-workspaces.git
|
||||
THT_WORKSPACE_GIT_BRANCH=main
|
||||
THT_WORKSPACE_INSTALLATION_ID=local-laptop
|
||||
THT_SOURCE_ROOT=/absolute/path/to/ThothII
|
||||
THT_WORKSPACE_GIT_SSH_KEY_FILE=/absolute/path/installation-secrets/git-ssh-key
|
||||
THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=/absolute/path/installation-secrets/git-known-hosts
|
||||
THT_WORKSPACE_GIT_CA_FILE=/absolute/path/installation-secrets/git-ca.pem
|
||||
@@ -120,18 +123,21 @@ rather than weakening TLS; use runtime-trusted HTTPS or verified direct/SSH nati
|
||||
|
||||
## Bootstrap, first pull, and diagnostics
|
||||
|
||||
Copy [the local Compose example](examples/local-compose.workspace-registry.yaml) into an untracked
|
||||
operator directory, create its local `.env` and mounted secret files, then render it before start.
|
||||
Copy [the local Compose example](examples/local-compose.workspace-registry.yaml) and exactly one
|
||||
selected [SSH Git override](examples/git-ssh.workspace-registry.yaml) or [HTTPS Git override](examples/git-https.workspace-registry.yaml)
|
||||
into an untracked operator directory. Set `THT_SOURCE_ROOT` in its `.env` to the absolute source
|
||||
checkout path; this keeps the copied Compose file buildable. Create only the secret files used by
|
||||
the selected override, then render it before start.
|
||||
|
||||
<!-- verify:command -->
|
||||
```sh
|
||||
docker compose -f docs/install/examples/local-compose.workspace-registry.yaml config --quiet
|
||||
THT_SOURCE_ROOT="$(pwd -P)" docker compose -f docs/install/examples/local-compose.workspace-registry.yaml config --quiet
|
||||
```
|
||||
|
||||
From the operator directory:
|
||||
|
||||
```sh
|
||||
docker compose -f compose.workspace-registry.yaml up --build -d
|
||||
docker compose -f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml up --build -d
|
||||
curl --fail --silent http://127.0.0.1:8787/health
|
||||
curl --fail --silent http://127.0.0.1:8787/workspace-registry/status
|
||||
curl --fail --silent http://127.0.0.1:8787/workspaces
|
||||
@@ -142,13 +148,15 @@ Use `POST /workspace-registry/pull` to fetch later revisions. Run workspace diag
|
||||
required bindings are mounted. The optional writer probe uses a distinct writer file and removes
|
||||
its uniquely named temporary record; ordinary diagnostics are read-only.
|
||||
|
||||
To migrate an existing PSD descriptor, create/clone an empty private remote, transform with
|
||||
absolute paths, review the schema-v1 result, explicitly add vector database/schema and the complete
|
||||
schema-v2 contract, then commit/push. The transformer never imports `${ENV}` values or secrets.
|
||||
To migrate an existing PSD descriptor, create/clone an empty private remote, set the absolute
|
||||
`THT_SOURCE_ROOT`, transform with absolute paths, review the schema-v1 result, explicitly add
|
||||
vector database/schema and the complete schema-v2 contract, then commit/push. The transformer
|
||||
never imports `${ENV}` values or secrets.
|
||||
|
||||
```sh
|
||||
npm --prefix backend run build
|
||||
node backend/dist/workspaces/migrate-legacy.js --input /absolute/path/psd.yaml --output /absolute/path/thoth-workspaces
|
||||
THT_SOURCE_ROOT=/absolute/path/to/ThothII
|
||||
npm --prefix "$THT_SOURCE_ROOT/backend" run build
|
||||
node "$THT_SOURCE_ROOT/backend/dist/workspaces/migrate-legacy.js" --input /absolute/path/psd.yaml --output /absolute/path/thoth-workspaces
|
||||
```
|
||||
|
||||
## Publish, update, backup, outage recovery, and rollback
|
||||
|
||||
Reference in New Issue
Block a user