Codex
f114d0065a
feat: classify sensitive columns locally
2026-09-03 02:11:13 +02:00
Codex
7b7927bfe5
feat: unify installation model catalog
2026-09-02 18:45:33 +02:00
Codex
79c4c925b5
feat: implement metadata catalog database management
2026-08-27 22:43:54 +02:00
marcopan
3e106d5262
fix(ci): restore deployment release gates
2026-08-25 16:45:56 +02:00
User
3fdc278e7a
fix(frontend): prevent stale bundle white screens
2026-08-22 21:14:48 +02:00
User
120816d81c
fix(docker): preserve frontend script executability
2026-08-22 20:53:02 +02:00
User
87606c73c1
build: package standalone DWH authentication service
2026-08-21 02:32:26 +02:00
marcopan
7e52df2702
fix(auth): address Task 13 deployment review findings
2026-08-17 21:31:25 +02:00
marcopan
d464f3a982
build: align authentication runtime on Node 24
2026-08-16 17:13:55 +02:00
marcopan
3e0c864c85
fix(pi): isolate resolved package builds
2026-08-16 00:20:30 +02:00
marcopan
aa8a2e9278
refactor(cli): rename operator command to tht
2026-08-15 21:56:40 +02:00
marcopan
9414a4b4dd
fix: initialize workspace secret volume for runtime
2026-08-14 18:13:52 +02:00
marcopan
c5f65d0f15
feat: profile-gated workspace-maintenance service and connector override generator (P2)
2026-08-11 18:40:11 +02:00
marcopan
320d9ea74e
feat: run qdrant and ollama inside thothii
2026-08-08 18:38:42 +02:00
marcopan
5d037e97c4
refactor: remove portal deployment coupling
2026-08-05 06:58:19 +02:00
marcopan
55926c75f8
fix: harden pi management verification
2026-08-05 01:00:13 +02:00
marcopan
935bb1db0e
fix: harden embedded Pi lifecycle recovery
2026-08-04 23:14:47 +02:00
marcopan
4158990c10
fix: harden thothctl diagnostics
2026-08-04 17:00:05 +02:00
marcopan
853a151796
feat: add cross-platform thothctl
2026-08-04 16:48:40 +02:00
marcopan
e2264ee295
build: harden image build inputs
2026-08-04 16:33:39 +02:00
marcopan
d42fdf4b71
build: make embedded pi images reproducible
2026-08-04 16:19:04 +02:00
marcopan
a248fb46d0
fix(deploy): reject ambiguous frontend upstream paths
2026-08-04 16:02:25 +02:00
marcopan
87b0fda3f6
fix(dev): proxy local API and restrict frontend upstream
2026-08-04 15:58:13 +02:00
marcopan
8ffcaf3db9
deploy: route frontend and core through one origin
2026-08-04 15:48:15 +02:00
marcopan
ad07a75490
build: enforce portable line endings
2026-08-04 14:33:45 +02:00
marcopan
f71feecaea
feat: deploy portable workspace registry
2026-08-04 07:26:45 +02:00
marcopan
ff795d1c91
feat: diagnose workspace connector bindings
2026-08-03 22:52:29 +02:00
marcopan
801f847ec4
fix: use Pi user auth and handle startup failures
2026-07-21 14:01:47 +02:00
marcopan
0cf09777f2
Fix session resume and PSD container configuration
2026-07-20 20:22:47 +02:00
User
7a65fc80a2
fix(deploy): validate session migrator TLS mode
2026-07-16 19:07:53 +02:00
User
cadc4c6947
docs(deploy): document user-owned session cutover
2026-07-16 19:02:58 +02:00
User
6dbf93fff9
feat: harden runtime readiness and session workflow
2026-07-14 10:27:25 +02:00
User
664d392859
fix: remove verbose tool logs from UI + symlink config/tht.yaml
...
Two fixes:
1. Revert tool_execution_* forwarding: these cluttered the UI with raw
bash/read output the user never asked for. Only text_delta, system_event
and ui_request are forwarded, as before.
2. tht ignores THT_CONFIG env var and always looks for config/tht.yaml
relative to CWD. Create a symlink so the PI agent can run tht commands
without -c flag.
2026-07-13 00:29:28 +02:00
User
ac333f99ac
fix(docker): chown .pi to thoth so Pi locks survive rebuilds
2026-07-13 00:14:37 +02:00
User
122cbfd50d
fix(docker): post-merge fixes for codex backend compatibility
...
- restore COPY harness/ (perso durante edit) -> /app/harness esiste
- cp workflow.yaml in site-packages: tht lo carica module-relative
(parent.parent del package); non-editable install non lo includeva
-> session show 500 (FileNotFoundError). pip install -e non accettato da pip.
- cd /app/harness && pip install . : pip 26.1.2 rifiuta il path bare /app/harness
- compose: THT_MODEL_API_KEY_FILE per buildPiChildEnv (codex) -> session create
prima 500 'model provider credential is unavailable'
Verificato: session show 200 (phase 1), create 200, Pi+model+SSE OK.
2026-07-12 21:30:49 +02:00
User
2bd2f72356
Merge origin/codex/portable-deployment into feat/docker-local-deploy
...
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan
7628eaa579
fix(docker): run real questions through trusted Pi gate
2026-07-12 19:20:10 +02:00
User
5f6647e77a
fix(entrypoint): restore server case (lost during doctor->check refactor)
...
Il caso 'server)' era stato eliminato inavvertitamente: CMD [server]
cadeva nel *) exec $@ -> 'server: not found' (exit 127).
Smoke standalone ora verde: health + config check + db ping (read-only).
2026-07-12 17:17:24 +02:00
User
67d030b24d
feat(deploy): docker images, compose, roles SQL, local workspace
...
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
marcopan
f67d2c97d8
fix(security): reject invalid optional bundle values
2026-07-12 11:53:15 +02:00
marcopan
449a333365
fix(security): validate bundle and clean runtime secrets
2026-07-12 11:52:02 +02:00
marcopan
70a19f290d
feat(compose): use one secret bundle for local services
2026-07-12 11:30:43 +02:00
marcopan
e40a9d9a56
fix(backend): inject provider credentials from file
2026-07-12 07:53:22 +02:00
marcopan
4028ef7821
feat(preprocess): add deployment jobs and S3 source
2026-07-12 05:42:07 +02:00
marcopan
3588a7749b
fix(vector): harden packaged migrations
2026-07-12 01:32:33 +02:00
marcopan
ebdd3aa2c5
fix(deploy): unify backend URL policy
2026-07-12 00:54:39 +02:00
marcopan
a3a266fd81
fix(deploy): close container final review
2026-07-12 00:44:39 +02:00
marcopan
715de6649b
fix(docker): harden frontend runtime config
2026-07-11 22:03:24 +02:00
marcopan
3d939426b1
build(docker): add runtime-configured frontend image
2026-07-11 21:57:53 +02:00
marcopan
31023f9e7a
build(docker): lock core runtime dependencies
2026-07-11 21:50:30 +02:00