fix(deploy): generalize connector secret overrides

This commit is contained in:
2026-08-04 15:21:49 +02:00
parent b5071f1494
commit eb01979072
9 changed files with 384 additions and 91 deletions
-15
View File
@@ -1,15 +0,0 @@
# Selected direct PostgreSQL/pgvector connector secrets. Each target must match a corresponding
# THT_WS_*_FILE=/run/secrets/<target> binding; source paths are host-only operator configuration.
services:
core:
secrets:
- source: psd_clinical_dwh_password
target: psd-clinical-dwh-password
- source: psd_clinical_vector_password
target: psd-clinical-vector-password
secrets:
psd_clinical_dwh_password:
file: ${THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE:?set THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE}
psd_clinical_vector_password:
file: ${THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE:?set THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE}
+2
View File
@@ -1,5 +1,7 @@
# Select this override only for an HTTPS Git remote. The separate CA mount keeps TLS validation
# explicit; neither host-only source file nor its contents belongs in the base Compose contract.
x-thoth-git-transport: https
services:
core:
environment:
+2
View File
@@ -1,5 +1,7 @@
# Select this override only for an SSH Git remote. The host-only source files must be absolute,
# normalized paths; strict host-key checking is mandatory for registry pull and publish.
x-thoth-git-transport: ssh
services:
core:
environment:
+8 -6
View File
@@ -1,6 +1,5 @@
# Copy these non-secret registry settings into the installation environment.
# Select at most one Git transport override and only the connector-secret entries whose matching
# THT_WS_*_FILE bindings are declared. Every host path below must be absolute and normalized.
# Select at most one Git transport override. Every host path below must be absolute and normalized.
# Their contents are never committed, emitted by the API, or stored in the registry.
THT_WORKSPACE_REGISTRY_ROOT=/data/workspace-registry
THT_WORKSPACE_GIT_BRANCH=main
@@ -15,7 +14,10 @@ THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@localhost
# THT_WORKSPACE_GIT_SSH_KEY_FILE=/absolute/path/to/git-ssh-key
# THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=/absolute/path/to/git-known-hosts
# Host-only connector sources consumed only by deploy/compose.connector-secrets.yaml. The matching
# THT_WS_*_FILE values belong in the separate workspace bindings env file and target /run/secrets.
# THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE=/absolute/path/to/psd-clinical-dwh-password
# THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE=/absolute/path/to/psd-clinical-vector-password
# Generate an untracked connector override from arbitrary THT_WS_*_FILE bindings and their
# matching host-only THT_WS_*_SOURCE paths. The generator records paths and variable names only;
# it never writes secret values into the generated Compose file.
# scripts/generate-connector-secrets-override.sh --bindings-env /absolute/path/workspace-bindings.env \
# --operator-env /absolute/path/operator.env --output deploy/compose.connector-secrets.local.yaml
# Run Compose through scripts/compose-with-preflight.sh so relative, non-normalized, and mixed
# SSH/HTTPS selections are rejected before Docker receives the invocation.