# Task 3 report — Remove external semantic bindings and render internal endpoints Date: 2026-08-08 ## Scope Implemented backend-owned schema-v3 semantic runtime rendering so workspace descriptors and installation contracts remain free of external Qdrant/Ollama endpoints and credentials, while DWH bindings stay unchanged. ## RED evidence Focused RED command: `cd backend && npx vitest run test/workspaces-contracts.test.ts test/workspaces-bindings.test.ts test/workspace-runtime-renderer.test.ts test/config.test.ts` Observed failures before implementation: - `config.test.ts` - missing `internalQdrantUrl` - missing `internalEmbeddingUrl` - `workspaces-bindings.test.ts` - schema v3 semantic binding resolution threw unsupported errors - `workspace-runtime-renderer.test.ts` - schema v3 runtime rendering threw `Schema version 3 runtime rendering is unsupported until the internal semantic runtime is implemented` ## GREEN evidence Focused GREEN command: `cd backend && npx vitest run test/workspaces-contracts.test.ts test/workspaces-bindings.test.ts test/workspace-runtime-renderer.test.ts test/config.test.ts` Result: - 4 test files passed - 36 tests passed Typecheck: `cd backend && npx tsc --noEmit -p .` Result: - passed Hygiene: - `git diff --check` passed ## Files changed Listed-task files changed: - `backend/src/config.ts` - `backend/src/workspaces/bindings.ts` - `backend/src/workspaces/runtime-renderer.ts` - `backend/test/config.test.ts` - `backend/test/workspace-runtime-renderer.test.ts` - `backend/test/workspaces-bindings.test.ts` - `backend/test/workspaces-contracts.test.ts` Listed-task files inspected but not changed: - `backend/src/workspaces/contracts.ts` Unavoidable additional wiring changes: - `backend/src/app.ts` - `backend/src/tht/tht-runner.ts` Reason: the new typed internal semantic runtime config had to flow from backend config into ephemeral harness config rendering at runtime. ## Behavior delivered - schema-v3 installation contract exposes DWH bindings only - schema-v3 binding resolution ignores external semantic env vars instead of sourcing runtime semantics from them - runtime rendering for schema v3 emits backend-owned internal semantic endpoints: - Qdrant: `http://qdrant:6333` - Embedding: `http://embedding:11434` - Model: `qwen3-embedding:0.6b` - Dimensions: `1024` - internal semantic URLs are validated to allow only `qdrant` / `embedding` / `localhost` / loopback hosts - DWH transport/runtime behavior remains unchanged ## Self-review - Confirmed schema-v3 contracts/docs no longer advertise VECTOR or EMBEDDING installation variables. - Confirmed schema-v3 runtime output ignores injected external semantic endpoints from env bindings. - Confirmed semantic endpoints are rendered only in the ephemeral backend-owned harness config path. - Confirmed type wiring is explicit from `AppConfig` → `ThtRunner` → runtime renderer. ## Concerns - Host validation currently permits both `http` and `https` on the allowed internal hosts. That keeps the configuration flexible, but if the installation contract intended `http` only, that restriction is not enforced here. ## Fix round 1/5 Scope: - moved schema-v3 internal embeddings under `resources.embeddings` - enforced `http`-only internal semantic URLs RED evidence: `cd backend && npx vitest run test/workspace-runtime-renderer.test.ts test/config.test.ts` Observed failures on `bc8afe0`: - `workspace-runtime-renderer.test.ts` - schema-v3 output omitted `resources.embeddings` - schema-v3 still exposed top-level `embeddings` - `config.test.ts` - `https://qdrant:6333` was accepted GREEN evidence: `cd backend && npx vitest run test/workspace-runtime-renderer.test.ts test/config.test.ts` Result: - 2 test files passed - 16 tests passed Typecheck: `cd backend && npx tsc --noEmit -p .` Result: - passed Updated concerns: - none for this round beyond future tightening if exact-port rejection is later requested explicitly.