Commit Graph
413 Commits
Author SHA1 Message Date
User 122cbfd50d fix(docker): post-merge fixes for codex backend compatibility
- restore COPY harness/ (perso durante edit) -> /app/harness esiste
- cp workflow.yaml in site-packages: tht lo carica module-relative
  (parent.parent del package); non-editable install non lo includeva
  -> session show 500 (FileNotFoundError). pip install -e non accettato da pip.
- cd /app/harness && pip install . : pip 26.1.2 rifiuta il path bare /app/harness
- compose: THT_MODEL_API_KEY_FILE per buildPiChildEnv (codex) -> session create
  prima 500 'model provider credential is unavailable'
Verificato: session show 200 (phase 1), create 200, Pi+model+SSE OK.
2026-07-12 21:30:49 +02:00
User 2bd2f72356 Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
User 9d987f639a fix(backend): configPath from THT_CONFIG env (routes senza workspace fallivano in container)
app.ts hardcodava configPath='config/tht.yaml' (symlink solo in dev). Nel container
i route che non passano workspace esplicito (sessionList/sessionShow/documents)
cercavano config/tht.yaml inesistente -> 500. Ora legge THT_CONFIG (entrypoint lo
setta a workspaces/local.yaml), fallback al default per dev. Compose lo esplicita.
Verificato: GET /sessions ora ritorna la lista.
2026-07-12 18:25:38 +02:00
User 4d80ed0b83 fix(compose): use portal network omics_portal_omics_network + DNS aliases
Compose prefissa le reti col project: la rete reale del portale è
omics_portal_omics_network (non omics_network). Aggiunti alias
thothii-core/thothii-frontend per il DNS usato dagli upstream nginx.
Verificato: portal nginx -> thothii-core:8787 = {ok}.
2026-07-12 17:20:51 +02:00
User 5f6647e77a fix(entrypoint): restore server case (lost during doctor->check refactor)
Il caso 'server)' era stato eliminato inavvertitamente: CMD [server]
cadeva nel *) exec $@ -> 'server: not found' (exit 127).
Smoke standalone ora verde: health + config check + db ping (read-only).
2026-07-12 17:17:24 +02:00
User 3f816044c3 fix(sql): move ROLE PASSWORD outside DO block (psql skips :var in dollar-quoting) 2026-07-12 17:12:26 +02:00
User 67d030b24d feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
User 3fd4b0db86 feat(deploy): configurable backend HOST + env-driven vite base/assetsDir
- backend: HOST env (default 127.0.0.1, dev-safe; 0.0.0.0 in container)
- frontend: VITE_BASE drives base/assetsDir/manifest for portal embedding
- backward compatible: no env => identical to previous behavior
2026-07-12 16:32:00 +02:00
User 0c9b44e61f docs(deploy): local docker + portal embed implementation plan 2026-07-12 16:27:44 +02:00
marcopan c446d40e1f docs: define local and server Docker deployment 2026-07-12 16:27:05 +02:00
marcopan 08f0029793 fix: finalize session after memory promotion 2026-07-12 14:26:48 +02:00
marcopan f67d2c97d8 fix(security): reject invalid optional bundle values 2026-07-12 11:53:15 +02:00
marcopan 449a333365 fix(security): validate bundle and clean runtime secrets 2026-07-12 11:52:02 +02:00
marcopan 385646d574 docs: complete Docker context settings 2026-07-12 11:50:12 +02:00
marcopan 10465917a5 test(compose): validate bundle deployment contract 2026-07-12 11:48:43 +02:00
marcopan 07967bf589 docs: document one-command Docker installation 2026-07-12 11:44:00 +02:00
marcopan 2ab91b7c0d docs(sdd): record secret scrub review fixes 2026-07-12 11:34:52 +02:00
marcopan 8518a73685 fix(security): scrub raw deployment secret values 2026-07-12 11:34:32 +02:00
marcopan d500563963 fix(security): scrub deployment secrets from Pi child 2026-07-12 11:33:13 +02:00
marcopan 70a19f290d feat(compose): use one secret bundle for local services 2026-07-12 11:30:43 +02:00
marcopan 32a2b71687 build(compose): make root startup the default 2026-07-12 11:14:36 +02:00
marcopan 3807c65a41 test(config): cover secret bundle inode races 2026-07-12 11:09:09 +02:00
marcopan 390cfd24b5 fix(config): accept raw environment secret lookup 2026-07-12 11:07:22 +02:00
marcopan 5fe74612fb feat(config): load one validated secret bundle 2026-07-12 11:06:19 +02:00
marcopan b539303002 docs: plan simplified Docker configuration implementation 2026-07-12 10:59:31 +02:00
marcopan a6b195b8ae docs: design simplified Docker configuration 2026-07-12 10:54:42 +02:00
marcopan 0b65135153 docs: explain loading deploy environment 2026-07-12 10:46:50 +02:00
marcopan 7f8346ff58 docs: keep installation configuration inside ThothII 2026-07-12 10:21:53 +02:00
marcopan e81a250b47 docs: define secret paths before file creation 2026-07-12 10:13:31 +02:00
marcopan 5e345c5567 docs: clarify host and container secret paths 2026-07-12 10:07:39 +02:00
marcopan 7e829a8414 docs: clarify Docker secrets and workspace configuration 2026-07-12 10:04:41 +02:00
marcopan b07f422bb3 docs: add Docker installation guide for four contexts 2026-07-12 09:49:09 +02:00
marcopan 2302286ea1 fix(backend): reject compound provider credentials 2026-07-12 08:10:47 +02:00
marcopan f064daef09 fix(backend): harden provider credential isolation 2026-07-12 08:05:51 +02:00
marcopan 32e73d66b5 docs(preprocess): restore local startup commands 2026-07-12 07:57:17 +02:00
marcopan 72bc50ab2e fix(preprocess): enforce local vector startup chain 2026-07-12 07:54:09 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan ee92ef45ab fix(vector): track packaged migrations in restore smoke 2026-07-12 07:49:58 +02:00
marcopan 09d50ac9bb fix(dwh): release snapshots before job startup 2026-07-12 07:34:56 +02:00
marcopan 4aae6c433d fix(dwh): bind snapshots to validated bytes 2026-07-12 07:31:46 +02:00
marcopan 2f6daaaea6 fix(dwh): anchor generation operations to lease fd 2026-07-12 07:26:10 +02:00
marcopan 24e61d5713 fix(preprocess): retain DWH root fd through lease 2026-07-12 07:12:28 +02:00
marcopan 4cf0adbdd2 fix(preprocess): initialize fresh DWH writers safely 2026-07-12 07:07:31 +02:00
marcopan 22e806a41b fix(preprocess): restrict DWH root claims to writers 2026-07-12 07:00:51 +02:00
marcopan c4dd6c8900 fix(preprocess): claim DWH roots atomically 2026-07-12 06:51:46 +02:00
marcopan 8110793f61 fix(evidence): make result summaries safe 2026-07-12 06:50:23 +02:00
marcopan b43075289e fix(preprocess): bind DWH artifacts to workspace 2026-07-12 06:46:06 +02:00
marcopan 0a2421c513 fix(evidence): bound reports and fail failed jobs 2026-07-12 06:45:19 +02:00
marcopan 03ee3ffda8 fix(evidence): validate active corpus artifacts 2026-07-12 06:35:27 +02:00