#!/bin/sh set -eu cd "$(dirname "$0")/.." tmp_bundle=$(mktemp) tmp_auth=$(mktemp) trap 'rm -f "$tmp_bundle" "$tmp_auth"' EXIT HUP INT TERM cat >"$tmp_bundle" <<'EOF' THT_VECTOR_BOOTSTRAP_PASSWORD=test-bootstrap THT_VECTOR_MIGRATOR_PASSWORD=test-migrator THT_VECTOR_READER_PASSWORD=test-reader THT_VECTOR_WRITER_PASSWORD=test-writer EOF chmod 0600 "$tmp_bundle" printf '%s\n' '{}' >"$tmp_auth" chmod 0600 "$tmp_auth" export THT_SECRETS_FILE="$tmp_bundle" export PI_AUTH_FILE="$tmp_auth" export THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git local_files="-f compose.yaml -f deploy/compose.local-vector.yaml -f deploy/compose.preprocess.yaml -f deploy/compose.preprocess-local-vector.yaml" local_json=$(docker compose $local_files --profile local-vector --profile preprocess config --format json) printf '%s' "$local_json" | python3 -c ' import json, sys config = json.load(sys.stdin) services = config["services"] assert "thothii_secrets" in config.get("secrets", {}), config.get("secrets") assert "vector_bootstrap_password" not in config.get("secrets", {}) assert "vector_migrator_password" not in config.get("secrets", {}) assert "vector_reader_password" not in config.get("secrets", {}) assert "vector_writer_password" not in config.get("secrets", {}) for name, service in services.items(): if name.startswith("vector-") or name.startswith("preprocess-") or name == "core": assert any(item.get("target") == "thothii.secrets" for item in service.get("secrets", []) if isinstance(item, dict)), (name, service.get("secrets")) assert "vector_reader_password" not in str(service) assert "vector_writer_password" not in str(service) for name in ("preprocess-evidence", "preprocess-dwh"): dependency = services[name].get("depends_on", {}).get("vector-migrate") assert dependency is not None, f"{name} does not depend on vector-migrate" assert dependency["condition"] == "service_completed_successfully", dependency ' external_json=$(docker compose \ -f compose.yaml -f deploy/compose.preprocess.yaml \ --profile preprocess config --format json) printf '%s' "$external_json" | python3 -c ' import json, sys config = json.load(sys.stdin) services = config["services"] assert "vector-db" not in services assert "vector-migrate" not in services assert "vector-reconcile" not in services for name in ("preprocess-evidence", "preprocess-dwh"): service = services[name] assert "depends_on" not in service assert all(item.get("target") == "thothii.secrets" for item in service.get("secrets", []) if isinstance(item, dict)), service.get("secrets") assert "vector_reader_password" not in str(service) assert "vector_writer_password" not in str(service) ' python3 - <<'PY' import os from pathlib import Path os.environ.update({ "THT_DB_NAME": "thoth", "THT_DWH_REST_URL": "http://dwh.invalid", "THT_DWH_API_KEY": "dwh", "THT_VECTOR_DATABASE": "thoth", "THT_VECTOR_READER_USER": "reader", "THT_VECTOR_WRITER_USER": "writer", "THT_VECTOR_READER_PASSWORD_FILE": "/tmp/generated-reader", "THT_VECTOR_WRITER_PASSWORD_FILE": "/tmp/generated-writer", "THT_DOCS_ROOT": "/data/source", "THT_OLLAMA_URL": "http://ollama.invalid", }) text = Path("deploy/workspaces/local-vector.yaml").read_text() assert "password_file: ${THT_VECTOR_READER_PASSWORD_FILE}" in text assert "password_file: ${THT_VECTOR_WRITER_PASSWORD_FILE}" in text assert "${THT_SECRETS_FILE}" not in text print("local-vector workspace resolution contract: ok") PY echo "preprocess compose config: ok"