#!/usr/bin/env bash set -euo pipefail cd "$(dirname "$0")/.." test -f .env.example test -f deploy/env/local.env.example test -f deploy/env/server.env.example rendered=$(mktemp) trap 'rm -f "$rendered"' EXIT HUP INT TERM docker compose --env-file deploy/env/local.env.example \ -f compose.yaml -f deploy/compose.local.yaml config --format json >"$rendered" node - "$rendered" <<'NODE' const fs = require("fs"); const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8")); const services = Object.keys(config.services).sort(); if (services.join(",") !== "core,embedding,embedding-model-init,frontend,qdrant") { throw new Error(`unexpected service set: ${services.join(",")}`); } if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) { throw new Error("default Compose contains application-specific coupling"); } for (const volume of ["settings", "pi-state", "workspace-registry", "sessions", "auth-state", "qdrant-data", "embedding-models"]) { if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`); } const core = config.services.core; const frontend = config.services.frontend; const qdrant = config.services.qdrant; const embedding = config.services.embedding; const modelInit = config.services["embedding-model-init"]; if (!frontend.ports?.some((port) => port.host_ip === "127.0.0.1")) { throw new Error("local frontend must publish a loopback port"); } for (const service of [embedding, modelInit]) { if ((service.ports || []).length !== 0) throw new Error("private semantic services must not publish host ports"); } if (!qdrant.ports?.some((port) => port.host_ip === "127.0.0.1" && Number(port.target) === 6333)) { throw new Error("local Qdrant dashboard must publish only its loopback port"); } if ((qdrant.expose || []).join(",") !== "6333") throw new Error("qdrant must expose only 6333"); if ((embedding.expose || []).join(",") !== "11434") throw new Error("embedding must expose only 11434"); if (!qdrant.healthcheck) throw new Error("qdrant must define a healthcheck"); if (!embedding.healthcheck) throw new Error("embedding must define a healthcheck"); if (qdrant.image !== "qdrant/qdrant:v1.18.2@sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c") { throw new Error("qdrant image must be pinned by version and digest"); } if (embedding.image !== "ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a") { throw new Error("embedding image must be pinned by version and digest"); } if (modelInit.image !== "ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a") { throw new Error("embedding-model-init image must be pinned by version and digest"); } const env = core.environment || {}; for (const [key, value] of Object.entries({ THT_WORKSPACE_INSTALLATION_ID: "local", THT_AUTH_CONFIG_FILE: "/run/thothii-auth/auth.yaml", THT_AUTH_STATE_ROOT: "/data/auth", THT_INTERNAL_QDRANT_URL: "http://qdrant:6333", THT_INTERNAL_EMBEDDING_URL: "http://embedding:11434", THT_INTERNAL_EMBEDDING_MODEL: "qwen3-embedding:0.6b", THT_INTERNAL_EMBEDDING_DIMENSIONS: "1024", })) { if (env[key] !== value) throw new Error(`unexpected core ${key}: ${env[key]}`); } const authConfigMounts = (core.volumes || []).filter((mount) => mount.target === "/run/thothii-auth"); if (authConfigMounts.length !== 1 || authConfigMounts[0].type !== "bind" || !authConfigMounts[0].read_only) { throw new Error("core must receive exactly one read-only authentication configuration bind"); } const authStateMounts = (core.volumes || []).filter((mount) => mount.target === "/data/auth"); if (authStateMounts.length !== 1 || authStateMounts[0].type !== "volume" || authStateMounts[0].source !== "auth-state") { throw new Error("core must receive exactly one auth-state volume"); } const maintenanceMounts = config.services["workspace-maintenance"]?.volumes || []; if (maintenanceMounts.some((mount) => mount.target === "/run/thothii-auth" || mount.target === "/data/auth")) { throw new Error("workspace-maintenance must not receive authentication configuration or state"); } for (const forbidden of ["THT_VEC_REST_URL", "THT_VEC_WRITE_REST_URL", "THT_OLLAMA_URL"]) { if (Object.hasOwn(env, forbidden) && env[forbidden] !== "") { throw new Error(`core must not require external semantic binding ${forbidden}`); } } const depends = core.depends_on || {}; if (depends.qdrant?.condition !== "service_healthy") { throw new Error("core must wait for qdrant health"); } if (depends["embedding-model-init"]?.condition !== "service_completed_successfully") { throw new Error("core must wait for embedding-model-init success"); } if (modelInit.depends_on?.embedding?.condition !== "service_healthy") { throw new Error("embedding-model-init must wait for embedding health"); } if (JSON.stringify(embedding).includes('"devices"')) { throw new Error("base embedding service must stay CPU-only"); } NODE echo "default Compose contract passed."