Files
ThothII/scripts/test-default-compose.sh
Codex cffa60772e
Publish documentation / publish (push) Successful in 2m12s
feat: complete catalog-driven preprocessing
2026-09-06 17:49:35 +02:00

153 lines
7.2 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
cd "$(dirname "$0")/.."
test -f .env.example
test -f deploy/env/local.env.example
test -f deploy/env/server.env.example
test -f docker/catalog-db-init.sql
grep -q "pg_read_file('/run/secrets/catalog_runtime_password')" docker/catalog-db-init.sql
grep -q "CREATE ROLE thothii_catalog_runtime" docker/catalog-db-init.sql
rendered=$(mktemp)
installation_rendered=$(mktemp)
trap 'rm -f "$rendered" "$installation_rendered"' EXIT HUP INT TERM
docker compose --env-file deploy/env/local.env.example \
-f compose.yaml -f deploy/compose.local.yaml config --format json >"$rendered"
node - "$rendered" <<'NODE'
const fs = require("fs");
const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8"));
const services = Object.keys(config.services).sort();
if (services.join(",") !== "catalog-db,core,embedding,embedding-model-init,frontend,qdrant") {
throw new Error(`unexpected service set: ${services.join(",")}`);
}
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
throw new Error("default Compose contains application-specific coupling");
}
const expectedVolumes = [
"auth-state",
"catalog-data",
"embedding-models",
"pi-state",
"qdrant-data",
"sessions",
"settings",
"workspace-registry",
"workspace-secrets",
];
const actualVolumes = Object.keys(config.volumes || {});
if (actualVolumes.join(",") !== expectedVolumes.join(",")) {
throw new Error(`unexpected ordered volume set: ${actualVolumes.join(",")}`);
}
const core = config.services.core;
const frontend = config.services.frontend;
const qdrant = config.services.qdrant;
const embedding = config.services.embedding;
const modelInit = config.services["embedding-model-init"];
const catalog = config.services["catalog-db"];
if (!frontend.ports?.some((port) => port.host_ip === "127.0.0.1")) {
throw new Error("local frontend must publish a loopback port");
}
for (const service of [embedding, modelInit]) {
if ((service.ports || []).length !== 0) throw new Error("private semantic services must not publish host ports");
}
if ((catalog.ports || []).length !== 0) throw new Error("catalog database must not publish host ports");
if (!catalog.healthcheck) throw new Error("catalog database must define a healthcheck");
const catalogHealthcheck = JSON.stringify(catalog.healthcheck.test || []);
if (!catalogHealthcheck.includes("pg_isready") || !catalogHealthcheck.includes("thothii_catalog_runtime")) {
throw new Error("catalog database healthcheck must verify readiness and the runtime role");
}
if (!qdrant.ports?.some((port) => port.host_ip === "127.0.0.1" && Number(port.target) === 6333)) {
throw new Error("local Qdrant dashboard must publish only its loopback port");
}
if ((qdrant.expose || []).join(",") !== "6333") throw new Error("qdrant must expose only 6333");
if ((embedding.expose || []).join(",") !== "11434") throw new Error("embedding must expose only 11434");
if (!qdrant.healthcheck) throw new Error("qdrant must define a healthcheck");
if (!embedding.healthcheck) throw new Error("embedding must define a healthcheck");
if (qdrant.image !== "qdrant/qdrant:v1.18.2@sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c") {
throw new Error("qdrant image must be pinned by version and digest");
}
if (embedding.image !== "ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a") {
throw new Error("embedding image must be pinned by version and digest");
}
if (modelInit.image !== "ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a") {
throw new Error("embedding-model-init image must be pinned by version and digest");
}
if (catalog.image !== "postgres:17.6-bookworm@sha256:f3bd19c606e442c3d7bdfa8002e03fe260a1023351e0ea4598032022b68dd6e3") {
throw new Error("catalog PostgreSQL image must be pinned by version and digest");
}
const env = core.environment || {};
for (const [key, value] of Object.entries({
THT_WORKSPACE_INSTALLATION_ID: "local",
THT_AUTH_CONFIG_FILE: "/run/thothii-auth/auth.yaml",
THT_AUTH_STATE_ROOT: "/data/auth",
THT_INTERNAL_QDRANT_URL: "http://qdrant:6333",
THT_INTERNAL_EMBEDDING_URL: "http://embedding:11434",
THT_CATALOG_DB_HOST: "catalog-db",
THT_CATALOG_DB_NAME: "thothii_catalog",
THT_CATALOG_RUNTIME_USER: "thothii_catalog_runtime",
THT_CATALOG_RUNTIME_PASSWORD_FILE: "/run/secrets/catalog_runtime_password",
})) {
if (env[key] !== value) throw new Error(`unexpected core ${key}: ${env[key]}`);
}
for (const key of ["THT_INTERNAL_EMBEDDING_ID", "THT_INTERNAL_EMBEDDING_MODEL", "THT_INTERNAL_EMBEDDING_DIMENSIONS"]) {
if (Object.hasOwn(env, key)) throw new Error(`${key} must come only from the generated installation projection`);
}
const authConfigMounts = (core.volumes || []).filter((mount) => mount.target === "/run/thothii-auth");
if (authConfigMounts.length !== 1 || authConfigMounts[0].type !== "bind" || !authConfigMounts[0].read_only) {
throw new Error("core must receive exactly one read-only authentication configuration bind");
}
const authStateMounts = (core.volumes || []).filter((mount) => mount.target === "/data/auth");
if (authStateMounts.length !== 1 || authStateMounts[0].type !== "volume" || authStateMounts[0].source !== "auth-state") {
throw new Error("core must receive exactly one auth-state volume");
}
const maintenanceMounts = config.services["workspace-maintenance"]?.volumes || [];
if (maintenanceMounts.some((mount) => mount.target === "/run/thothii-auth" || mount.target === "/data/auth")) {
throw new Error("workspace-maintenance must not receive authentication configuration or state");
}
for (const forbidden of ["THT_VEC_REST_URL", "THT_VEC_WRITE_REST_URL", "THT_OLLAMA_URL"]) {
if (Object.hasOwn(env, forbidden) && env[forbidden] !== "") {
throw new Error(`core must not require external semantic binding ${forbidden}`);
}
}
const depends = core.depends_on || {};
if (depends.qdrant?.condition !== "service_healthy") {
throw new Error("core must wait for qdrant health");
}
if (depends["catalog-db"]?.condition !== "service_healthy") {
throw new Error("core must wait for catalog database health");
}
if (depends["embedding-model-init"]?.condition !== "service_completed_successfully") {
throw new Error("core must wait for embedding-model-init success");
}
if (modelInit.depends_on?.embedding?.condition !== "service_healthy") {
throw new Error("embedding-model-init must wait for embedding health");
}
if (JSON.stringify(embedding).includes('"devices"')) {
throw new Error("base embedding service must stay CPU-only");
}
NODE
THT_WORKSPACE_INSTALLATION_ID=psd-local docker compose \
--env-file deploy/env/local.env.example \
-f compose.yaml -f deploy/compose.local.yaml \
--profile workspace-maintenance config --format json >"$installation_rendered"
node - "$installation_rendered" <<'NODE'
const fs = require("fs");
const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8"));
for (const serviceName of ["core", "workspace-maintenance"]) {
const actual = config.services[serviceName]?.environment?.THT_WORKSPACE_INSTALLATION_ID;
if (actual !== "psd-local") {
throw new Error(`${serviceName} must preserve the configured installation ID, got: ${actual}`);
}
}
NODE
echo "default Compose contract passed."