#!/usr/bin/env bash # Model providers are external endpoints reached through the ordinary application network. set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" tmp_parent="${TMPDIR:-/tmp}" tmp="$(mktemp -d "${tmp_parent%/}/thoth-external-llm.XXXXXX")" trap 'rm -rf "$tmp"' EXIT HUP INT TERM printf '%s\n' '{}' >"$tmp/pi-auth.json" printf '%s\n' 'THT_MODEL_API_KEY=fixture-model-api-key' >"$tmp/thothii.secrets" chmod 0600 "$tmp/pi-auth.json" "$tmp/thothii.secrets" THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git \ PI_AUTH_FILE="$tmp/pi-auth.json" \ THT_SECRETS_FILE="$tmp/thothii.secrets" \ THT_LLM_URL=https://llm.example.invalid/v1 \ docker compose -f "$root/compose.yaml" config --format json >"$tmp/config.json" node - "$tmp/config.json" <<'NODE' const fs = require("fs"); const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8")); if (Object.keys(config.services).sort().join(",") !== "core,frontend") { throw new Error("external LLM deployment must retain the mandatory two-service stack"); } if (Object.keys(config.networks || {}).join(",") !== "thothii") { throw new Error("external LLM endpoint must not require a provider-owned Docker network"); } if (config.services.core.environment?.THT_LLM_URL !== "https://llm.example.invalid/v1") { throw new Error("core did not receive the generic external LLM endpoint"); } const joins = (service, network) => Array.isArray(service.networks) ? service.networks.includes(network) : Object.hasOwn(service.networks || {}, network); if (!joins(config.services.core, "thothii") || !joins(config.services.frontend, "thothii")) { throw new Error("frontend and core must share only the application network"); } NODE echo "external LLM network contract passed."