#!/bin/sh set -eu root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd) source_env=${1:-"$root/../../harness/.env"} workspace=${2:-"$root/../../../tht-workspace-psd"} auth_file=${3:-"$HOME/.pi/agent/auth.json"} value() { awk -F= -v key="$1" '$1 == key { sub(/^[^=]*=/, ""); sub(/[[:space:]].*$/, ""); print; exit }' "$source_env" } required() { result=$(value "$1") [ -n "$result" ] || { echo "missing $1 in local source configuration" >&2; exit 2; } printf '%s' "$result" } test -f "$source_env" test -d "$workspace" test -f "$auth_file" ca=$(value THT_SSL_CA) [ -z "$ca" ] || test -f "$ca" model_key=$(jq -er '.zai.key' "$auth_file") test -n "$model_key" umask 077 mkdir -p "$root/deploy/secrets" "$root/deploy/workspaces" cp "$root/deploy/compose.psd-local.yaml.example" "$root/deploy/compose.psd-local.yaml" cp "$root/deploy/workspaces/psd.yaml.example" "$root/deploy/workspaces/psd.yaml" cat >"$root/.env" <"$root/deploy/secrets/thothii.secrets" <>"$root/deploy/compose.psd-local.yaml" <>"$root/deploy/secrets/thothii.secrets" else printf '%s\n' 'THT_CA=/etc/ssl/certs/ca-certificates.crt' >>"$root/deploy/secrets/thothii.secrets" fi chmod 600 "$root/.env" "$root/deploy/secrets/thothii.secrets" echo "Local PSD Docker configuration materialized without printing secret values."