75 lines
3.0 KiB
Bash
Executable File
75 lines
3.0 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Base Compose is deliberately model-free; `tht start` appends the generated catalog projection.
|
|
set -euo pipefail
|
|
|
|
root="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
tmp_parent="${TMPDIR:-/tmp}"
|
|
tmp="$(mktemp -d "${tmp_parent%/}/thoth-provider-readiness.XXXXXX")"
|
|
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
|
|
|
printf '%s\n' '{}' >"$tmp/pi-auth.json"
|
|
printf '%s\n' 'THT_MODEL_API_KEY=fixture-model-api-key' >"$tmp/thothii.secrets"
|
|
printf '%s\n' 'schemaVersion: 2' >"$tmp/thothii-installation.yaml"
|
|
printf '%s' 'fixture-catalog-runtime-password' >"$tmp/catalog-runtime-password"
|
|
printf '%s' 'fixture-catalog-migrator-password' >"$tmp/catalog-migrator-password"
|
|
mkdir "$tmp/auth"
|
|
printf '%s\n' 'mode: local' >"$tmp/auth/auth.yaml"
|
|
chmod 0600 "$tmp/pi-auth.json" "$tmp/thothii.secrets" "$tmp/thothii-installation.yaml" \
|
|
"$tmp/catalog-runtime-password" "$tmp/catalog-migrator-password" "$tmp/auth/auth.yaml"
|
|
chmod 0700 "$tmp/auth"
|
|
|
|
rendered="$tmp/rendered.json"
|
|
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git \
|
|
PI_AUTH_FILE="$tmp/pi-auth.json" \
|
|
THT_SECRETS_FILE="$tmp/thothii.secrets" \
|
|
THT_INSTALLATION_CONFIG_SOURCE="$tmp/thothii-installation.yaml" \
|
|
THT_CATALOG_RUNTIME_PASSWORD_SOURCE="$tmp/catalog-runtime-password" \
|
|
THT_CATALOG_MIGRATOR_PASSWORD_SOURCE="$tmp/catalog-migrator-password" \
|
|
THT_AUTH_CONFIG_ROOT="$tmp/auth" \
|
|
docker compose --project-directory "$root" \
|
|
-f "$root/compose.yaml" -f "$root/deploy/compose.local.yaml" \
|
|
config --format json >"$rendered"
|
|
|
|
node - "$rendered" <<'NODE'
|
|
const { readFileSync } = require("node:fs");
|
|
const config = JSON.parse(readFileSync(process.argv[2], "utf8"));
|
|
const core = config.services?.core;
|
|
if (!core) throw new Error("base Compose lacks core");
|
|
for (const name of [
|
|
"THT_MODEL_CATALOG_FILE",
|
|
"THT_MODEL_CATALOG_REVISION",
|
|
"THT_DEFAULT_SESSION_MODEL",
|
|
"THT_INTERNAL_EMBEDDING_ID",
|
|
"THT_INTERNAL_EMBEDDING_MODEL",
|
|
"THT_INTERNAL_EMBEDDING_DIMENSIONS",
|
|
]) {
|
|
if (Object.hasOwn(core.environment || {}, name)) {
|
|
throw new Error(`base Compose invented installation-owned model input ${name}`);
|
|
}
|
|
}
|
|
for (const target of (core.volumes || []).map((mount) => mount.target)) {
|
|
if (target === "/run/thothii-model-catalog/catalog.json"
|
|
|| target === "/home/thoth/.pi/agent/models.json"
|
|
|| target === "/home/thoth/.pi/agent/settings.json") {
|
|
throw new Error(`base Compose mounted a generated model adapter: ${target}`);
|
|
}
|
|
}
|
|
const installation = (core.configs || []).filter(
|
|
(entry) => entry.target === "/run/thothii-installation/thothii-installation.yaml",
|
|
);
|
|
if (installation.length !== 1 || installation[0].source !== "thothii_installation_config") {
|
|
throw new Error("base Compose lacks the protected installation descriptor mount");
|
|
}
|
|
NODE
|
|
|
|
if grep -Fq 'fixture-model-api-key' "$rendered"; then
|
|
echo "rendered base Compose leaked the model key" >&2
|
|
exit 1
|
|
fi
|
|
if [[ -e "$root/deploy/pi/models.json" || -e "$root/deploy/pi/settings.json" ]]; then
|
|
echo "legacy authored Pi model sources still exist" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "Base Compose model fail-closed contract passed."
|