#!/usr/bin/env bash # Entrypoints logici del container thothii-core: # server (default) | check | tht | preprocess # THT_CONFIG punta al workspace attivo (local.yaml nel deploy co-locato). set -euo pipefail export THT_CONFIG="${THT_CONFIG:-/app/harness/workspaces/local.yaml}" # Pi 0.80 gates every project-local extension, prompt and skill behind its persistent # trust store. The mounted profile may come from another host and therefore not contain # the container path. Preserve its existing decisions and authorize only this harness. node /app/docker/ensure-pi-trust.mjs "${THT_HARNESS_DIR:-/app/harness}" cmd="${1:-server}" case "$cmd" in server) [[ "${THT_AUTH_STATE_ROOT:-/data/auth}" == /data/auth ]] \ || { printf '%s\n' 'authentication state root is invalid' >&2; exit 1; } printf '%s\n' '{"version":1,"operation":"ensure-layout","root":"/data/auth"}' \ | "${THT_AUTH_STORAGE_BIN:-/usr/local/bin/tht-auth-storage}" _auth-storage >/dev/null exec node /app/backend/dist/server.js ;; check) # Diagnostica di wiring: validazione config/env + ping DWH (read-only). shift tht config check -c "$THT_CONFIG" tht db ping -c "$THT_CONFIG" || echo "(db ping non verde: verificare .env/ruoli/VPN)" ;; tht) shift exec tht "$@" ;; preprocess) shift exec tht evidence index "$@" ;; *) exec "$@" ;; esac