fix: validate deployment rollback and server topology

This commit is contained in:
2026-08-05 15:15:06 +02:00
parent 5f015a5a37
commit ece9cfda50
16 changed files with 571 additions and 52 deletions
+21 -6
View File
@@ -25,11 +25,17 @@ contains its Pi runtime; no host `pi` executable is used. For a server installat
```sh
cp deploy/env/server.env.example deploy/env/server.env
# Edit all absolute storage, Pi/secret/session files, and endpoint paths.
sudo scripts/prepare-server-pi-state.sh /srv/thothii/pi-state 10001 10001
docker compose --env-file deploy/env/server.env \
-f compose.yaml -f deploy/compose.server.yaml \
-f deploy/compose.session-server.yaml.example up --build -d
```
The initializer is required for an empty or restored server Pi-state bind. It atomically creates
the three regular targets hidden below the writable parent bind; protected Pi auth and tracked
model/settings sources remain separate read-only mounts. See the server manual before substituting
a root other than `/srv/thothii/pi-state`.
Workspace descriptors come from the Git remote configured by `THT_WORKSPACE_GIT_REMOTE`; their
runtime endpoint and secret bindings remain installation-local. Open
<http://127.0.0.1:8080> (set `THOTH_HTTP_PORT` in `deploy/env/local.env` to choose another
@@ -124,15 +130,24 @@ secret files, upstream-auth checks, and a fail-closed `503` assertion for its de
unavailable disposable session endpoint. No real provider, database credential, or repository
secret is required.
For a clean server bind, `scripts/prepare-server-pi-state.sh` creates the hidden regular
`agent/auth.json`, `agent/models.json`, and `agent/settings.json` mount targets atomically before
Compose. The server smoke starts from an empty Pi-state root and applies this same preflight; the
real protected/tracked sources remain separate read-only mounts. Deterministic fixture tests render
both profiles, verify that bindings stay on `core`, check mount readability, and run the production
workspace resolver. Wrong-service, wrong-value, and broken-secret-mount mutations must fail.
Each public smoke has its own 30-minute process-group supervisor with TERM/KILL cleanup; CI retains
an independent 32-minute outer timeout and does not retry a failed command.
Current release status (2026-08-05): deterministic contracts are green, but the complete rollback
fixture has not passed end to end after its runtime-binding correction. The one observed local
server-profile run also stopped before startup because Docker Desktop/VirtioFS rejected the
profile's parent Pi-state bind with nested tracked agent-file binds. A fresh single rollback run,
native-Linux server-profile run, and native Windows Docker Desktop/WSL2 run remain release gates;
the project does not claim those criteria green.
Current release status (2026-08-05): clean-root render/setup and the production runtime-binding
resolver contracts are green. The single corrected server-profile run proved image build,
clean-root startup, and core/frontend health, then stopped at a fixture-authenticated frontend
request; its trusted-hop headers are corrected deterministically but were not rerun. The single
corrected rollback run reached runtime/Pi/registry/persistence checks and the stopped-candidate
preflight, then stopped at active-session inventory before mutation. Full server behavior and
bad-Pi compensation with unchanged state therefore remain release gates. Native Windows Docker
Desktop/WSL2 remains a separate manual/self-hosted gate.
The deterministic native Windows contract is: