Commit Graph
52 Commits
Author SHA1 Message Date
User 28db30bd78 fix(ops): make server diagnostics release-safe 2026-09-07 01:15:28 +02:00
Codex f114d0065a feat: classify sensitive columns locally 2026-09-03 02:11:13 +02:00
Codex 7b7927bfe5 feat: unify installation model catalog 2026-09-02 18:45:33 +02:00
Codex 79c4c925b5 feat: implement metadata catalog database management 2026-08-27 22:43:54 +02:00
marcopan 3e106d5262 fix(ci): restore deployment release gates 2026-08-25 16:45:56 +02:00
User 3fdc278e7a fix(frontend): prevent stale bundle white screens 2026-08-22 21:14:48 +02:00
User 120816d81c fix(docker): preserve frontend script executability 2026-08-22 20:53:02 +02:00
User 87606c73c1 build: package standalone DWH authentication service 2026-08-21 02:32:26 +02:00
marcopan 7e52df2702 fix(auth): address Task 13 deployment review findings 2026-08-17 21:31:25 +02:00
marcopan d464f3a982 build: align authentication runtime on Node 24 2026-08-16 17:13:55 +02:00
marcopan 3e0c864c85 fix(pi): isolate resolved package builds 2026-08-16 00:20:30 +02:00
marcopan aa8a2e9278 refactor(cli): rename operator command to tht 2026-08-15 21:56:40 +02:00
marcopan 9414a4b4dd fix: initialize workspace secret volume for runtime 2026-08-14 18:13:52 +02:00
marcopan c5f65d0f15 feat: profile-gated workspace-maintenance service and connector override generator (P2) 2026-08-11 18:40:11 +02:00
marcopan 320d9ea74e feat: run qdrant and ollama inside thothii 2026-08-08 18:38:42 +02:00
marcopan 5d037e97c4 refactor: remove portal deployment coupling 2026-08-05 06:58:19 +02:00
marcopan 55926c75f8 fix: harden pi management verification 2026-08-05 01:00:13 +02:00
marcopan 935bb1db0e fix: harden embedded Pi lifecycle recovery 2026-08-04 23:14:47 +02:00
marcopan 4158990c10 fix: harden thothctl diagnostics 2026-08-04 17:00:05 +02:00
marcopan 853a151796 feat: add cross-platform thothctl 2026-08-04 16:48:40 +02:00
marcopan e2264ee295 build: harden image build inputs 2026-08-04 16:33:39 +02:00
marcopan d42fdf4b71 build: make embedded pi images reproducible 2026-08-04 16:19:04 +02:00
marcopan a248fb46d0 fix(deploy): reject ambiguous frontend upstream paths 2026-08-04 16:02:25 +02:00
marcopan 87b0fda3f6 fix(dev): proxy local API and restrict frontend upstream 2026-08-04 15:58:13 +02:00
marcopan 8ffcaf3db9 deploy: route frontend and core through one origin 2026-08-04 15:48:15 +02:00
marcopan ad07a75490 build: enforce portable line endings 2026-08-04 14:33:45 +02:00
marcopan f71feecaea feat: deploy portable workspace registry 2026-08-04 07:26:45 +02:00
marcopan ff795d1c91 feat: diagnose workspace connector bindings 2026-08-03 22:52:29 +02:00
marcopan 801f847ec4 fix: use Pi user auth and handle startup failures 2026-07-21 14:01:47 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
User 7a65fc80a2 fix(deploy): validate session migrator TLS mode 2026-07-16 19:07:53 +02:00
User cadc4c6947 docs(deploy): document user-owned session cutover 2026-07-16 19:02:58 +02:00
User 6dbf93fff9 feat: harden runtime readiness and session workflow 2026-07-14 10:27:25 +02:00
User 664d392859 fix: remove verbose tool logs from UI + symlink config/tht.yaml
Two fixes:
1. Revert tool_execution_* forwarding: these cluttered the UI with raw
   bash/read output the user never asked for. Only text_delta, system_event
   and ui_request are forwarded, as before.

2. tht ignores THT_CONFIG env var and always looks for config/tht.yaml
   relative to CWD. Create a symlink so the PI agent can run tht commands
   without -c flag.
2026-07-13 00:29:28 +02:00
User ac333f99ac fix(docker): chown .pi to thoth so Pi locks survive rebuilds 2026-07-13 00:14:37 +02:00
User 122cbfd50d fix(docker): post-merge fixes for codex backend compatibility
- restore COPY harness/ (perso durante edit) -> /app/harness esiste
- cp workflow.yaml in site-packages: tht lo carica module-relative
  (parent.parent del package); non-editable install non lo includeva
  -> session show 500 (FileNotFoundError). pip install -e non accettato da pip.
- cd /app/harness && pip install . : pip 26.1.2 rifiuta il path bare /app/harness
- compose: THT_MODEL_API_KEY_FILE per buildPiChildEnv (codex) -> session create
  prima 500 'model provider credential is unavailable'
Verificato: session show 200 (phase 1), create 200, Pi+model+SSE OK.
2026-07-12 21:30:49 +02:00
User 2bd2f72356 Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
User 5f6647e77a fix(entrypoint): restore server case (lost during doctor->check refactor)
Il caso 'server)' era stato eliminato inavvertitamente: CMD [server]
cadeva nel *) exec $@ -> 'server: not found' (exit 127).
Smoke standalone ora verde: health + config check + db ping (read-only).
2026-07-12 17:17:24 +02:00
User 67d030b24d feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
marcopan f67d2c97d8 fix(security): reject invalid optional bundle values 2026-07-12 11:53:15 +02:00
marcopan 449a333365 fix(security): validate bundle and clean runtime secrets 2026-07-12 11:52:02 +02:00
marcopan 70a19f290d feat(compose): use one secret bundle for local services 2026-07-12 11:30:43 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan 4028ef7821 feat(preprocess): add deployment jobs and S3 source 2026-07-12 05:42:07 +02:00
marcopan 3588a7749b fix(vector): harden packaged migrations 2026-07-12 01:32:33 +02:00
marcopan ebdd3aa2c5 fix(deploy): unify backend URL policy 2026-07-12 00:54:39 +02:00
marcopan a3a266fd81 fix(deploy): close container final review 2026-07-12 00:44:39 +02:00
marcopan 715de6649b fix(docker): harden frontend runtime config 2026-07-11 22:03:24 +02:00
marcopan 3d939426b1 build(docker): add runtime-configured frontend image 2026-07-11 21:57:53 +02:00