services: core: environment: THOTH_PUBLIC_EXPOSURE: "true" THT_DATA_ROOT: /data THT_WORKSPACE_INSTALLATION_ID: server # prepare-server-pi-state.sh creates the regular child targets before this parent bind is used. # The real configuration sources still remain separate read-only mounts. volumes: !override - type: bind source: ${THT_DATA_ROOT:?set THT_DATA_ROOT} target: /data - type: bind source: ${THT_AUTH_CONFIG_ROOT:?set THT_AUTH_CONFIG_ROOT} target: /run/thothii-auth read_only: true - type: bind source: ${THT_PI_STATE_ROOT:?set THT_PI_STATE_ROOT} target: /home/thoth/.pi - type: bind source: ${PI_AUTH_FILE:?set PI_AUTH_FILE} target: /home/thoth/.pi/agent/auth.json read_only: true - type: bind source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT} target: /data/workspace-registry restart: unless-stopped # Deprecated migration adapter: only use this when no auth.yaml is mounted yet. # AUTH_MODE: upstream frontend: ports: - "${THOTH_SERVER_BIND:-127.0.0.1}:${THOTH_HTTP_PORT:-8080}:8080" restart: unless-stopped workspace-maintenance: environment: THT_DATA_ROOT: /data THT_WORKSPACE_INSTALLATION_ID: server volumes: !override - type: bind source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}/sessions target: /data/sessions - type: bind source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT} target: /data/workspace-registry read_only: false - type: bind source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}/workspace-secrets target: /data/workspace-secrets restart: "no"