# Task 4 report — one-command Docker documentation ## Status Implemented. The installation documentation now uses the canonical flow: ```sh cp .env.example .env cp deploy/secrets/thothii.secrets.example deploy/secrets/thothii.secrets chmod 600 deploy/secrets/thothii.secrets docker compose up --build -d ``` Updated: - `README.md` with root `.env` defaults, one bundle, optional overlay presets, CA limitation, preprocessing, and migration notes. - `docs/installazione-docker-4-contesti.md` rewritten with exact files to create/edit and the four requested contexts (co-located DB/vector, Mac, Windows, and remote DB/Evidence server). - `docs/index.md` link text for the one-command installation. - `deploy/secrets/README.md` bundle syntax, permissions, runtime mount verification, CA handling, and migration guidance. - `scripts/docker-smoke.sh` now creates a disposable mode-0600 bundle and exercises the default Compose services without the legacy `external` profile. - `scripts/test-default-compose.sh` asserts the exact installation command, tracked templates, and absence of the legacy setup in the guide. - `scripts/test-container-deployment.sh` now validates the bundle mount and rejects legacy per-secret references; `.dockerignore` explicitly re-includes only the required vector policy helper so the Docker build context remains safe. - The Mac/Windows/local-vector and remote-server snippets now include required DWH/database and Evidence-root settings. `deploy/env.example` is explicitly deprecated and no longer selects a different Compose overlay. The docs explicitly state that a PEM CA chain cannot be put in the strict single-line bundle. A reviewed Compose override/secret-manager mount is required for `THT_SSL_CA`. Direct PostgreSQL workspace examples are marked as advanced and require a separate reviewed runtime password mount; the base bundle mount is the only default mount. ## Verification - `sh -n scripts/docker-smoke.sh scripts/test-default-compose.sh` — passed. - `./scripts/test-default-compose.sh` — passed. - `./scripts/test-container-deployment.sh` — passed after migrating its local-vector assertions to the single bundle and checking the `.dockerignore` deployment allowlist. - `git diff --check` — passed. - `./scripts/test-docker-smoke.sh` — passed after updating its static assertion to the default no-profile invocation. - `docker buildx build --file docker/core.Dockerfile --check .` — passed; BuildKit reported no warnings after the `.dockerignore` parent-directory fix. ## Concerns The legacy `scripts/vector-rotate-bootstrap-password.sh` maintenance helper still accepts old/new standalone files. Its output is intentionally documented as a transitional interface; the resulting value must be copied into the bundle before restarting local-vector services.