fix: validate deployment rollback and server topology
This commit is contained in:
@@ -25,11 +25,17 @@ contains its Pi runtime; no host `pi` executable is used. For a server installat
|
||||
```sh
|
||||
cp deploy/env/server.env.example deploy/env/server.env
|
||||
# Edit all absolute storage, Pi/secret/session files, and endpoint paths.
|
||||
sudo scripts/prepare-server-pi-state.sh /srv/thothii/pi-state 10001 10001
|
||||
docker compose --env-file deploy/env/server.env \
|
||||
-f compose.yaml -f deploy/compose.server.yaml \
|
||||
-f deploy/compose.session-server.yaml.example up --build -d
|
||||
```
|
||||
|
||||
The initializer is required for an empty or restored server Pi-state bind. It atomically creates
|
||||
the three regular targets hidden below the writable parent bind; protected Pi auth and tracked
|
||||
model/settings sources remain separate read-only mounts. See the server manual before substituting
|
||||
a root other than `/srv/thothii/pi-state`.
|
||||
|
||||
Workspace descriptors come from the Git remote configured by `THT_WORKSPACE_GIT_REMOTE`; their
|
||||
runtime endpoint and secret bindings remain installation-local. Open
|
||||
<http://127.0.0.1:8080> (set `THOTH_HTTP_PORT` in `deploy/env/local.env` to choose another
|
||||
@@ -124,15 +130,24 @@ secret files, upstream-auth checks, and a fail-closed `503` assertion for its de
|
||||
unavailable disposable session endpoint. No real provider, database credential, or repository
|
||||
secret is required.
|
||||
|
||||
For a clean server bind, `scripts/prepare-server-pi-state.sh` creates the hidden regular
|
||||
`agent/auth.json`, `agent/models.json`, and `agent/settings.json` mount targets atomically before
|
||||
Compose. The server smoke starts from an empty Pi-state root and applies this same preflight; the
|
||||
real protected/tracked sources remain separate read-only mounts. Deterministic fixture tests render
|
||||
both profiles, verify that bindings stay on `core`, check mount readability, and run the production
|
||||
workspace resolver. Wrong-service, wrong-value, and broken-secret-mount mutations must fail.
|
||||
|
||||
Each public smoke has its own 30-minute process-group supervisor with TERM/KILL cleanup; CI retains
|
||||
an independent 32-minute outer timeout and does not retry a failed command.
|
||||
|
||||
Current release status (2026-08-05): deterministic contracts are green, but the complete rollback
|
||||
fixture has not passed end to end after its runtime-binding correction. The one observed local
|
||||
server-profile run also stopped before startup because Docker Desktop/VirtioFS rejected the
|
||||
profile's parent Pi-state bind with nested tracked agent-file binds. A fresh single rollback run,
|
||||
native-Linux server-profile run, and native Windows Docker Desktop/WSL2 run remain release gates;
|
||||
the project does not claim those criteria green.
|
||||
Current release status (2026-08-05): clean-root render/setup and the production runtime-binding
|
||||
resolver contracts are green. The single corrected server-profile run proved image build,
|
||||
clean-root startup, and core/frontend health, then stopped at a fixture-authenticated frontend
|
||||
request; its trusted-hop headers are corrected deterministically but were not rerun. The single
|
||||
corrected rollback run reached runtime/Pi/registry/persistence checks and the stopped-candidate
|
||||
preflight, then stopped at active-session inventory before mutation. Full server behavior and
|
||||
bad-Pi compensation with unchanged state therefore remain release gates. Native Windows Docker
|
||||
Desktop/WSL2 remains a separate manual/self-hosted gate.
|
||||
|
||||
The deterministic native Windows contract is:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user