Commit Graph
154 Commits
Author SHA1 Message Date
marcopan d42fdf4b71 build: make embedded pi images reproducible 2026-08-04 16:19:04 +02:00
marcopan 87b0fda3f6 fix(dev): proxy local API and restrict frontend upstream 2026-08-04 15:58:13 +02:00
marcopan 8ffcaf3db9 deploy: route frontend and core through one origin 2026-08-04 15:48:15 +02:00
marcopan fe5c428354 fix(docs): export compose tool paths 2026-08-04 15:37:42 +02:00
marcopan 4f26a71156 fix(docs): enforce compose preflight workflow 2026-08-04 15:33:04 +02:00
marcopan eb01979072 fix(deploy): generalize connector secret overrides 2026-08-04 15:21:49 +02:00
marcopan b5071f1494 deploy: isolate git and connector secrets 2026-08-04 15:04:39 +02:00
marcopan 2ce2e0089a fix: harden compose Pi auth mounts 2026-08-04 14:55:05 +02:00
marcopan 2595d35682 deploy: unify local and server compose stack 2026-08-04 14:47:16 +02:00
marcopan f4b9542c92 fix: allow PowerShell CRLF line endings 2026-08-04 14:39:58 +02:00
marcopan ad07a75490 build: enforce portable line endings 2026-08-04 14:33:45 +02:00
marcopan 3d5d26c20c fix: validate workspace secret source paths 2026-08-04 08:29:02 +02:00
marcopan 37404512ce fix: bind workspace connector configuration safely 2026-08-04 08:22:09 +02:00
marcopan e5219deab1 fix: harden workspace registry installation docs 2026-08-04 08:11:28 +02:00
marcopan 72e16dd5ea docs: add workspace registry installation manuals 2026-08-04 07:57:09 +02:00
marcopan 802b564200 fix: harden workspace registry deployment 2026-08-04 07:42:35 +02:00
marcopan f71feecaea feat: deploy portable workspace registry 2026-08-04 07:26:45 +02:00
marcopan 801f847ec4 fix: use Pi user auth and handle startup failures 2026-07-21 14:01:47 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
marcopanandClaude Opus 4.8 3453f3ae23 feat: pre-check DWH reachability before creating a session (local dev only)
New session now refuses to spawn a Pi runtime that would only die in bootstrap
retrieval when the DWH/vector host is unreachable (e.g. a dropped VPN). Before
`session new`, POST /sessions probes the DWH via `tht db ping`; if it is down it
returns 503 {code:"dwh_unreachable"} with a clear message and creates nothing.

- Gated behind the THT_DWH_PRECHECK flag (default off), enabled only by the local
  dev launcher (run-stack.sh) — containers/CI never pay the probe, and existing
  tests that don't set it are unaffected.
- ThtRunner.dbPing() runs `tht db ping` with a 10s timeout (run() gains an optional
  timeout that SIGKILLs a hung child).
- Frontend: apiFetch throws a typed ApiError (status + parsed payload); the new-
  session composer shows the specific alert on `dwh_unreachable` instead of the
  generic retry hint, keeping the question for retry.

Verified live on an isolated backend (precheck on + broken DWH host → 503
dwh_unreachable, no session created) and via unit tests (backend 228, frontend 308).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 12:08:47 +02:00
User df1e7dea9c fix(resume): recover cleanly after Pi exits 2026-07-14 21:35:50 +02:00
User 5891bb4a18 fix(deploy): connect core to local Qwen 2026-07-14 20:58:19 +02:00
User 2bd2f72356 Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
User 67d030b24d feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
marcopan 449a333365 fix(security): validate bundle and clean runtime secrets 2026-07-12 11:52:02 +02:00
marcopan 10465917a5 test(compose): validate bundle deployment contract 2026-07-12 11:48:43 +02:00
marcopan 07967bf589 docs: document one-command Docker installation 2026-07-12 11:44:00 +02:00
marcopan 70a19f290d feat(compose): use one secret bundle for local services 2026-07-12 11:30:43 +02:00
marcopan 32a2b71687 build(compose): make root startup the default 2026-07-12 11:14:36 +02:00
marcopan 72bc50ab2e fix(preprocess): enforce local vector startup chain 2026-07-12 07:54:09 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan ee92ef45ab fix(vector): track packaged migrations in restore smoke 2026-07-12 07:49:58 +02:00
marcopan 5cc023f390 fix(evidence): harden unchanged job snapshot 2026-07-12 06:29:31 +02:00
marcopan 7d41c4cefc fix(preprocess): verify canonical generations and cleanup 2026-07-12 06:18:18 +02:00
marcopan e6d44ba082 fix(evidence): close S3 and smoke safety gaps 2026-07-12 06:09:15 +02:00
marcopan c6966f3d15 fix(preprocess): harden S3 and real Compose jobs 2026-07-12 06:01:06 +02:00
marcopan 4028ef7821 feat(preprocess): add deployment jobs and S3 source 2026-07-12 05:42:07 +02:00
marcopan 532073d550 fix(deploy): isolate local vector compose secrets 2026-07-12 02:56:00 +02:00
marcopan 6c67235caf fix(vector): close local pgvector final review 2026-07-12 02:48:10 +02:00
marcopan 407c4a6faf fix(vector): publish backups without replacement 2026-07-12 02:32:32 +02:00
marcopan 015c496bda fix(vector): harden backup restore parity gates 2026-07-12 02:29:53 +02:00
marcopan e4db2ea5e1 docs(vector): add local backup restore and parity gate 2026-07-12 02:18:29 +02:00
marcopan 1145ae20bc fix(deploy): align vector bootstrap identity policy 2026-07-12 02:04:57 +02:00
marcopan 144acf2093 fix(deploy): support bootstrap password rotation 2026-07-12 01:57:33 +02:00
marcopan 62e0ff1f12 fix(deploy): reconcile local vector credentials safely 2026-07-12 01:50:42 +02:00
marcopan 0ca9783f61 feat(deploy): add optional local pgvector profile 2026-07-12 01:42:37 +02:00
marcopan 3588a7749b fix(vector): harden packaged migrations 2026-07-12 01:32:33 +02:00
marcopan ebdd3aa2c5 fix(deploy): unify backend URL policy 2026-07-12 00:54:39 +02:00
marcopan a3a266fd81 fix(deploy): close container final review 2026-07-12 00:44:39 +02:00