Commit Graph
90 Commits
Author SHA1 Message Date
marcopan 72e16dd5ea docs: add workspace registry installation manuals 2026-08-04 07:57:09 +02:00
marcopan 802b564200 fix: harden workspace registry deployment 2026-08-04 07:42:35 +02:00
marcopan f71feecaea feat: deploy portable workspace registry 2026-08-04 07:26:45 +02:00
marcopan 801f847ec4 fix: use Pi user auth and handle startup failures 2026-07-21 14:01:47 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
marcopanandClaude Opus 4.8 3453f3ae23 feat: pre-check DWH reachability before creating a session (local dev only)
New session now refuses to spawn a Pi runtime that would only die in bootstrap
retrieval when the DWH/vector host is unreachable (e.g. a dropped VPN). Before
`session new`, POST /sessions probes the DWH via `tht db ping`; if it is down it
returns 503 {code:"dwh_unreachable"} with a clear message and creates nothing.

- Gated behind the THT_DWH_PRECHECK flag (default off), enabled only by the local
  dev launcher (run-stack.sh) — containers/CI never pay the probe, and existing
  tests that don't set it are unaffected.
- ThtRunner.dbPing() runs `tht db ping` with a 10s timeout (run() gains an optional
  timeout that SIGKILLs a hung child).
- Frontend: apiFetch throws a typed ApiError (status + parsed payload); the new-
  session composer shows the specific alert on `dwh_unreachable` instead of the
  generic retry hint, keeping the question for retry.

Verified live on an isolated backend (precheck on + broken DWH host → 503
dwh_unreachable, no session created) and via unit tests (backend 228, frontend 308).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 12:08:47 +02:00
User df1e7dea9c fix(resume): recover cleanly after Pi exits 2026-07-14 21:35:50 +02:00
User 5891bb4a18 fix(deploy): connect core to local Qwen 2026-07-14 20:58:19 +02:00
User 2bd2f72356 Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
User 67d030b24d feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
marcopan 449a333365 fix(security): validate bundle and clean runtime secrets 2026-07-12 11:52:02 +02:00
marcopan 10465917a5 test(compose): validate bundle deployment contract 2026-07-12 11:48:43 +02:00
marcopan 07967bf589 docs: document one-command Docker installation 2026-07-12 11:44:00 +02:00
marcopan 70a19f290d feat(compose): use one secret bundle for local services 2026-07-12 11:30:43 +02:00
marcopan 32a2b71687 build(compose): make root startup the default 2026-07-12 11:14:36 +02:00
marcopan 72bc50ab2e fix(preprocess): enforce local vector startup chain 2026-07-12 07:54:09 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan ee92ef45ab fix(vector): track packaged migrations in restore smoke 2026-07-12 07:49:58 +02:00
marcopan 5cc023f390 fix(evidence): harden unchanged job snapshot 2026-07-12 06:29:31 +02:00
marcopan 7d41c4cefc fix(preprocess): verify canonical generations and cleanup 2026-07-12 06:18:18 +02:00
marcopan e6d44ba082 fix(evidence): close S3 and smoke safety gaps 2026-07-12 06:09:15 +02:00
marcopan c6966f3d15 fix(preprocess): harden S3 and real Compose jobs 2026-07-12 06:01:06 +02:00
marcopan 4028ef7821 feat(preprocess): add deployment jobs and S3 source 2026-07-12 05:42:07 +02:00
marcopan 532073d550 fix(deploy): isolate local vector compose secrets 2026-07-12 02:56:00 +02:00
marcopan 6c67235caf fix(vector): close local pgvector final review 2026-07-12 02:48:10 +02:00
marcopan 407c4a6faf fix(vector): publish backups without replacement 2026-07-12 02:32:32 +02:00
marcopan 015c496bda fix(vector): harden backup restore parity gates 2026-07-12 02:29:53 +02:00
marcopan e4db2ea5e1 docs(vector): add local backup restore and parity gate 2026-07-12 02:18:29 +02:00
marcopan 1145ae20bc fix(deploy): align vector bootstrap identity policy 2026-07-12 02:04:57 +02:00
marcopan 144acf2093 fix(deploy): support bootstrap password rotation 2026-07-12 01:57:33 +02:00
marcopan 62e0ff1f12 fix(deploy): reconcile local vector credentials safely 2026-07-12 01:50:42 +02:00
marcopan 0ca9783f61 feat(deploy): add optional local pgvector profile 2026-07-12 01:42:37 +02:00
marcopan 3588a7749b fix(vector): harden packaged migrations 2026-07-12 01:32:33 +02:00
marcopan ebdd3aa2c5 fix(deploy): unify backend URL policy 2026-07-12 00:54:39 +02:00
marcopan a3a266fd81 fix(deploy): close container final review 2026-07-12 00:44:39 +02:00
marcopan 0ca6346f75 fix(deploy): isolate compose smoke resources 2026-07-11 22:16:51 +02:00
marcopan 767df63a33 feat(deploy): add portable external-service stack 2026-07-11 22:12:21 +02:00
marcopan c3a3cb8da5 feat(replay): standalone reviewer-gate replay server on :5333
Reproduces the real reviewer UI for any recorded session, with no VPN/Pi/
Python/DWH. The server (node:http, zero deps) serves the built SPA and a
tiny SSE/REST shim that re-emits the reviewer gates captured in a Pi
transcript, in their original order, with the reviewer's real 3-Jul
choices shown as comparison badges.

- tools/replay/extract.mjs: extracts gates from one or many transcripts
  (session-id, file, or directory). Handles sessions split across resume
  re-entries by sorting on message timestamp and dropping unanswered
  gates. Reads the question from session_manifest.yaml, resolving the
  sessions dir from any workspace yaml (no hardcoded paths).
- tools/replay/server.mjs: same-origin :5333. SSE streams gates; POST
  /response advances the cursor and pushes info badges (scelta reale).
  POST /resume and the final "Ripeti/Esci" widget close the SSE so the
  browser EventSource reconnects (cursor resets, gate 1 re-emitted) — the
  replay is re-runnable any number of times. GET /sessions/:id/documents
  reads the real session files so GateArtifactBody resolves file-reference
  artifacts. Exit emits system_event {event:"session_exit"} to return to
  the landing.
- scripts/replay.sh: launcher (extract / build / run / all).
- tools/replay/README.md: data flow, commands, fidelity notes.
- .gitignore: ignore tools/replay/web/ (built artifact, like dist/).
2026-07-05 18:24:26 +02:00
marcopanandClaude Opus 4.8 18843d7421 chore: run-stack.sh — avvia i 3 layer reali per validazione end-to-end
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 14:45:07 +02:00