User
2bd2f72356
Merge origin/codex/portable-deployment into feat/docker-local-deploy
...
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan
7628eaa579
fix(docker): run real questions through trusted Pi gate
2026-07-12 19:20:10 +02:00
User
9d987f639a
fix(backend): configPath from THT_CONFIG env (routes senza workspace fallivano in container)
...
app.ts hardcodava configPath='config/tht.yaml' (symlink solo in dev). Nel container
i route che non passano workspace esplicito (sessionList/sessionShow/documents)
cercavano config/tht.yaml inesistente -> 500. Ora legge THT_CONFIG (entrypoint lo
setta a workspaces/local.yaml), fallback al default per dev. Compose lo esplicita.
Verificato: GET /sessions ora ritorna la lista.
2026-07-12 18:25:38 +02:00
User
4d80ed0b83
fix(compose): use portal network omics_portal_omics_network + DNS aliases
...
Compose prefissa le reti col project: la rete reale del portale è
omics_portal_omics_network (non omics_network). Aggiunti alias
thothii-core/thothii-frontend per il DNS usato dagli upstream nginx.
Verificato: portal nginx -> thothii-core:8787 = {ok}.
2026-07-12 17:20:51 +02:00
User
5f6647e77a
fix(entrypoint): restore server case (lost during doctor->check refactor)
...
Il caso 'server)' era stato eliminato inavvertitamente: CMD [server]
cadeva nel *) exec $@ -> 'server: not found' (exit 127).
Smoke standalone ora verde: health + config check + db ping (read-only).
2026-07-12 17:17:24 +02:00
User
3f816044c3
fix(sql): move ROLE PASSWORD outside DO block (psql skips :var in dollar-quoting)
2026-07-12 17:12:26 +02:00
User
67d030b24d
feat(deploy): docker images, compose, roles SQL, local workspace
...
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
User
3fd4b0db86
feat(deploy): configurable backend HOST + env-driven vite base/assetsDir
...
- backend: HOST env (default 127.0.0.1, dev-safe; 0.0.0.0 in container)
- frontend: VITE_BASE drives base/assetsDir/manifest for portal embedding
- backward compatible: no env => identical to previous behavior
2026-07-12 16:32:00 +02:00
User
0c9b44e61f
docs(deploy): local docker + portal embed implementation plan
2026-07-12 16:27:44 +02:00
marcopan
c446d40e1f
docs: define local and server Docker deployment
2026-07-12 16:27:05 +02:00
marcopan
08f0029793
fix: finalize session after memory promotion
2026-07-12 14:26:48 +02:00
marcopan
f67d2c97d8
fix(security): reject invalid optional bundle values
2026-07-12 11:53:15 +02:00
marcopan
449a333365
fix(security): validate bundle and clean runtime secrets
2026-07-12 11:52:02 +02:00
marcopan
385646d574
docs: complete Docker context settings
2026-07-12 11:50:12 +02:00
marcopan
10465917a5
test(compose): validate bundle deployment contract
2026-07-12 11:48:43 +02:00
marcopan
07967bf589
docs: document one-command Docker installation
2026-07-12 11:44:00 +02:00
marcopan
2ab91b7c0d
docs(sdd): record secret scrub review fixes
2026-07-12 11:34:52 +02:00
marcopan
8518a73685
fix(security): scrub raw deployment secret values
2026-07-12 11:34:32 +02:00
marcopan
d500563963
fix(security): scrub deployment secrets from Pi child
2026-07-12 11:33:13 +02:00
marcopan
70a19f290d
feat(compose): use one secret bundle for local services
2026-07-12 11:30:43 +02:00
marcopan
32a2b71687
build(compose): make root startup the default
2026-07-12 11:14:36 +02:00
marcopan
3807c65a41
test(config): cover secret bundle inode races
2026-07-12 11:09:09 +02:00
marcopan
390cfd24b5
fix(config): accept raw environment secret lookup
2026-07-12 11:07:22 +02:00
marcopan
5fe74612fb
feat(config): load one validated secret bundle
2026-07-12 11:06:19 +02:00
marcopan
b539303002
docs: plan simplified Docker configuration implementation
2026-07-12 10:59:31 +02:00
marcopan
a6b195b8ae
docs: design simplified Docker configuration
2026-07-12 10:54:42 +02:00
marcopan
0b65135153
docs: explain loading deploy environment
2026-07-12 10:46:50 +02:00
marcopan
7f8346ff58
docs: keep installation configuration inside ThothII
2026-07-12 10:21:53 +02:00
marcopan
e81a250b47
docs: define secret paths before file creation
2026-07-12 10:13:31 +02:00
marcopan
5e345c5567
docs: clarify host and container secret paths
2026-07-12 10:07:39 +02:00
marcopan
7e829a8414
docs: clarify Docker secrets and workspace configuration
2026-07-12 10:04:41 +02:00
marcopan
b07f422bb3
docs: add Docker installation guide for four contexts
2026-07-12 09:49:09 +02:00
marcopan
2302286ea1
fix(backend): reject compound provider credentials
2026-07-12 08:10:47 +02:00
marcopan
f064daef09
fix(backend): harden provider credential isolation
2026-07-12 08:05:51 +02:00
marcopan
32e73d66b5
docs(preprocess): restore local startup commands
2026-07-12 07:57:17 +02:00
marcopan
72bc50ab2e
fix(preprocess): enforce local vector startup chain
2026-07-12 07:54:09 +02:00
marcopan
e40a9d9a56
fix(backend): inject provider credentials from file
2026-07-12 07:53:22 +02:00
marcopan
ee92ef45ab
fix(vector): track packaged migrations in restore smoke
2026-07-12 07:49:58 +02:00
marcopan
09d50ac9bb
fix(dwh): release snapshots before job startup
2026-07-12 07:34:56 +02:00
marcopan
4aae6c433d
fix(dwh): bind snapshots to validated bytes
2026-07-12 07:31:46 +02:00
marcopan
2f6daaaea6
fix(dwh): anchor generation operations to lease fd
2026-07-12 07:26:10 +02:00
marcopan
24e61d5713
fix(preprocess): retain DWH root fd through lease
2026-07-12 07:12:28 +02:00
marcopan
4cf0adbdd2
fix(preprocess): initialize fresh DWH writers safely
2026-07-12 07:07:31 +02:00
marcopan
22e806a41b
fix(preprocess): restrict DWH root claims to writers
2026-07-12 07:00:51 +02:00
marcopan
c4dd6c8900
fix(preprocess): claim DWH roots atomically
2026-07-12 06:51:46 +02:00
marcopan
8110793f61
fix(evidence): make result summaries safe
2026-07-12 06:50:23 +02:00
marcopan
b43075289e
fix(preprocess): bind DWH artifacts to workspace
2026-07-12 06:46:06 +02:00
marcopan
0a2421c513
fix(evidence): bound reports and fail failed jobs
2026-07-12 06:45:19 +02:00
marcopan
03ee3ffda8
fix(evidence): validate active corpus artifacts
2026-07-12 06:35:27 +02:00
marcopan
5cc023f390
fix(evidence): harden unchanged job snapshot
2026-07-12 06:29:31 +02:00