Commit Graph
56 Commits
Author SHA1 Message Date
marcopan 3a3efc3285 feat: expose the Qdrant web dashboard on loopback in the local Compose profile 2026-08-13 20:38:55 +02:00
marcopan 9ca01c77de chore: ignore the local Qdrant dashboard override 2026-08-13 20:36:00 +02:00
marcopan 84b233d937 docs: record P7 publication + live stack (pending VPN) 2026-08-13 16:41:46 +02:00
marcopan 3046ac34c6 feat: restructure PSD repo (P7) and add operator setup templates + checklist 2026-08-13 16:14:32 +02:00
marcopan c5f65d0f15 feat: profile-gated workspace-maintenance service and connector override generator (P2) 2026-08-11 18:40:11 +02:00
marcopan 86af45acb4 refactor: enforce P1.1 registry path ownership 2026-08-11 14:29:00 +02:00
marcopan 80aa989523 docs: define workspace evidence registry contract 2026-08-09 20:37:22 +02:00
marcopan 4e810af516 test: align qdrant ollama verification fixtures 2026-08-08 22:15:02 +02:00
marcopan 22c3512ac8 docs: document internal semantic infrastructure 2026-08-08 20:52:33 +02:00
marcopan 1b1213317b fix: fail safe on missing workspace revisions 2026-08-08 20:03:41 +02:00
marcopan c3a5621737 feat: edit qdrant workspace collections 2026-08-08 19:56:29 +02:00
marcopan a6dbe1d023 fix: retire active pgvector artifacts 2026-08-08 19:27:05 +02:00
marcopan 4e3fecbe8e refactor: retire external vector deployment 2026-08-08 19:05:57 +02:00
marcopan 320d9ea74e feat: run qdrant and ollama inside thothii 2026-08-08 18:38:42 +02:00
marcopan ece9cfda50 fix: validate deployment rollback and server topology 2026-08-05 15:15:06 +02:00
marcopan 96fe5bfa79 fix: make server operations executable 2026-08-05 11:06:34 +02:00
marcopan c01202f06c fix: pass vector rotation operator env 2026-08-05 08:12:38 +02:00
marcopan 09834d5cd4 fix: close deployment decoupling review 2026-08-05 07:52:32 +02:00
marcopan 5d037e97c4 refactor: remove portal deployment coupling 2026-08-05 06:58:19 +02:00
marcopan 55926c75f8 fix: harden pi management verification 2026-08-05 01:00:13 +02:00
marcopan eb01979072 fix(deploy): generalize connector secret overrides 2026-08-04 15:21:49 +02:00
marcopan b5071f1494 deploy: isolate git and connector secrets 2026-08-04 15:04:39 +02:00
marcopan 2ce2e0089a fix: harden compose Pi auth mounts 2026-08-04 14:55:05 +02:00
marcopan 2595d35682 deploy: unify local and server compose stack 2026-08-04 14:47:16 +02:00
marcopan f71feecaea feat: deploy portable workspace registry 2026-08-04 07:26:45 +02:00
marcopan 694b7dd21f fix: harden reviewer workflow and memory handling 2026-07-23 12:34:23 +02:00
marcopan 801f847ec4 fix: use Pi user auth and handle startup failures 2026-07-21 14:01:47 +02:00
marcopan 8aa1676811 Expose PSD frontend locally 2026-07-20 20:27:37 +02:00
marcopan ad6057f0dd Fix PSD frontend network wiring 2026-07-20 20:26:13 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
User 7a65fc80a2 fix(deploy): validate session migrator TLS mode 2026-07-16 19:07:53 +02:00
User cadc4c6947 docs(deploy): document user-owned session cutover 2026-07-16 19:02:58 +02:00
User 2bd2f72356 Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
User 3f816044c3 fix(sql): move ROLE PASSWORD outside DO block (psql skips :var in dollar-quoting) 2026-07-12 17:12:26 +02:00
User 67d030b24d feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
marcopan f67d2c97d8 fix(security): reject invalid optional bundle values 2026-07-12 11:53:15 +02:00
marcopan 449a333365 fix(security): validate bundle and clean runtime secrets 2026-07-12 11:52:02 +02:00
marcopan 385646d574 docs: complete Docker context settings 2026-07-12 11:50:12 +02:00
marcopan 07967bf589 docs: document one-command Docker installation 2026-07-12 11:44:00 +02:00
marcopan 70a19f290d feat(compose): use one secret bundle for local services 2026-07-12 11:30:43 +02:00
marcopan 32a2b71687 build(compose): make root startup the default 2026-07-12 11:14:36 +02:00
marcopan 7f8346ff58 docs: keep installation configuration inside ThothII 2026-07-12 10:21:53 +02:00
marcopan 72bc50ab2e fix(preprocess): enforce local vector startup chain 2026-07-12 07:54:09 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan c6966f3d15 fix(preprocess): harden S3 and real Compose jobs 2026-07-12 06:01:06 +02:00
marcopan 4028ef7821 feat(preprocess): add deployment jobs and S3 source 2026-07-12 05:42:07 +02:00
marcopan 532073d550 fix(deploy): isolate local vector compose secrets 2026-07-12 02:56:00 +02:00
marcopan 6c67235caf fix(vector): close local pgvector final review 2026-07-12 02:48:10 +02:00
marcopan 015c496bda fix(vector): harden backup restore parity gates 2026-07-12 02:29:53 +02:00