Files
ThothII/scripts/test-unified-compose.sh

246 lines
12 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
cd "$(dirname "$0")/.."
tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
printf 'schema_version: 1\n' >"$tmp/thothii-installation.yaml"
render_profile() {
local profile=$1
local env_file=$2
local compose_file=$3
local rendered="$tmp/$profile.json"
local -a files=(-f compose.yaml -f "$compose_file")
if [[ "$profile" == server ]]; then
files+=(-f deploy/compose.session-server.yaml.example)
fi
docker compose --env-file "$env_file" "${files[@]}" \
config --format json >"$rendered"
node - "$rendered" "$profile" <<'NODE'
const fs = require("fs");
const [configPath, profile] = process.argv.slice(2);
const config = JSON.parse(fs.readFileSync(configPath, "utf8"));
const services = Object.keys(config.services).sort();
if (services.join(",") !== "catalog-db,core,embedding,embedding-model-init,frontend,qdrant") {
throw new Error("mandatory stack must include catalog-db, core, frontend, qdrant, embedding, and embedding-model-init");
}
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
throw new Error("forbidden application coupling");
}
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
for (const volume of ["catalog-data", "qdrant-data", "embedding-models"]) {
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
}
if (profile === "local") {
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions"]) {
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing local required volume: ${volume}`);
}
}
const coreEnv = config.services.core.environment || {};
if (!Object.hasOwn(coreEnv, "THT_LLM_URL")) {
throw new Error("core must expose a generic THT_LLM_URL endpoint contract");
}
for (const [key, value] of Object.entries({
THT_INTERNAL_QDRANT_URL: "http://qdrant:6333",
THT_INTERNAL_EMBEDDING_URL: "http://embedding:11434",
})) {
if (coreEnv[key] !== value) throw new Error(`unexpected core ${key}: ${coreEnv[key]}`);
}
for (const key of ["THT_INTERNAL_EMBEDDING_ID", "THT_INTERNAL_EMBEDDING_MODEL", "THT_INTERNAL_EMBEDDING_DIMENSIONS"]) {
if (Object.hasOwn(coreEnv, key)) throw new Error(`${key} must come only from the generated installation projection`);
}
for (const forbidden of ["THT_VEC_REST_URL", "THT_VEC_WRITE_REST_URL", "THT_OLLAMA_URL"]) {
if (Object.hasOwn(coreEnv, forbidden) && coreEnv[forbidden] !== "") {
throw new Error(`core must not require external semantic binding ${forbidden}`);
}
}
if (/docker\.sock|\/var\/run\/docker|docker[-_]?daemon/i.test(JSON.stringify(config.services))) {
throw new Error("Compose must not mount the Docker socket or daemon");
}
if (config.services.qdrant.image !== "qdrant/qdrant:v1.18.2@sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c") {
throw new Error("qdrant image must be pinned by version and digest");
}
for (const serviceName of ["embedding", "embedding-model-init"]) {
if (config.services[serviceName].image !== "ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a") {
throw new Error(`${serviceName} image must be pinned by version and digest`);
}
}
for (const serviceName of ["embedding", "embedding-model-init"]) {
if ((config.services[serviceName].ports || []).length !== 0) {
throw new Error(`${serviceName} must not publish a host port`);
}
}
const qdrantPorts = config.services.qdrant.ports || [];
if (profile === "local") {
if (qdrantPorts.length !== 1 || qdrantPorts[0].host_ip !== "127.0.0.1"
|| Number(qdrantPorts[0].published) !== 6333 || Number(qdrantPorts[0].target) !== 6333) {
throw new Error("local qdrant may publish only 127.0.0.1:6333");
}
} else if (qdrantPorts.length !== 0) {
throw new Error("server qdrant must not publish a host port");
}
if ((config.services.qdrant.expose || []).join(",") !== "6333") throw new Error("qdrant must expose only 6333");
if ((config.services.embedding.expose || []).join(",") !== "11434") throw new Error("embedding must expose only 11434");
if (!config.services.qdrant.healthcheck) throw new Error("qdrant must define a healthcheck");
if (!config.services.embedding.healthcheck) throw new Error("embedding must define a healthcheck");
if (config.services.core.depends_on?.qdrant?.condition !== "service_healthy") {
throw new Error("core must wait for qdrant health");
}
if (config.services.core.depends_on?.["embedding-model-init"]?.condition !== "service_completed_successfully") {
throw new Error("core must wait for embedding-model-init success");
}
if (config.services["embedding-model-init"].depends_on?.embedding?.condition !== "service_healthy") {
throw new Error("embedding-model-init must wait for embedding health");
}
if (JSON.stringify(config.services.embedding).includes('"devices"')) {
throw new Error("base embedding service must stay CPU-only");
}
const piAuthMounts = (config.services.core.volumes || []).filter(
(mount) => mount.target === "/home/thoth/.pi/agent/auth.json",
);
if (piAuthMounts.length !== 1 || piAuthMounts[0].type !== "bind" || !piAuthMounts[0].read_only) {
throw new Error("Pi auth must be one read-only file bind");
}
if (config.services.core.environment?.THT_SECRETS_FILE !== "/run/secrets/thothii.secrets") {
throw new Error("core must read the canonical runtime secret bundle from /run/secrets");
}
const runtimeSecrets = config.services.core.secrets || [];
const bundleSecrets = runtimeSecrets.filter(
(secret) => secret.source === "thothii_secrets" && secret.target === "thothii.secrets",
);
if (bundleSecrets.length !== 1) {
throw new Error("core must receive exactly one canonical runtime secret bundle");
}
if (profile === "local" && runtimeSecrets.length !== 2) {
throw new Error("local core must receive only its runtime bundle and catalog password");
}
if (profile === "server") {
const targets = new Set(runtimeSecrets.map((secret) => secret.target));
for (const target of ["session_runtime_password", "session_ca.pem"]) {
if (!targets.has(target)) throw new Error("server core lacks " + target);
}
}
if ((config.services.frontend.secrets || []).length !== 0) {
throw new Error("frontend must not receive runtime secrets");
}
const ports = Object.fromEntries(
Object.entries(config.services).map(([name, service]) => [name, service.ports || []]),
);
if (profile === "local") {
if (!ports.frontend.some((port) => port.host_ip === "127.0.0.1")) {
throw new Error("local frontend must publish a loopback port");
}
if (ports.core.length !== 0 && !ports.core.every((port) => port.host_ip === "127.0.0.1")) {
throw new Error("local core may publish only loopback ports");
}
} else {
if (ports.core.length !== 0) throw new Error("server core must not publish a host port");
if (ports.frontend.length === 0) throw new Error("server frontend must publish a host port");
}
NODE
}
assert_remote_required() {
local env_file=$1
local compose_file=$2
local without_remote="$tmp/without-remote.env"
local -a files=(-f compose.yaml -f "$compose_file")
[[ "$compose_file" != deploy/compose.server.yaml ]] \
|| files+=(-f deploy/compose.session-server.yaml.example)
grep -v '^THT_WORKSPACE_GIT_REMOTE=' "$env_file" >"$without_remote"
if env -u THT_WORKSPACE_GIT_REMOTE docker compose --env-file "$without_remote" "${files[@]}" \
config --format json >"$tmp/missing-remote.out" 2>"$tmp/missing-remote.err"; then
echo "Compose must require THT_WORKSPACE_GIT_REMOTE" >&2
exit 1
fi
grep -q 'THT_WORKSPACE_GIT_REMOTE' "$tmp/missing-remote.err"
}
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git \
PI_AUTH_FILE=/dev/null \
THT_SECRETS_FILE=/dev/null \
THT_INSTALLATION_CONFIG_SOURCE="$tmp/thothii-installation.yaml" \
THT_AUTH_CONFIG_ROOT=/tmp/thothii-auth \
docker compose -f compose.yaml config --format json >"$tmp/base.json"
node - "$tmp/base.json" <<'NODE'
const fs = require("fs");
const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8"));
const services = Object.keys(config.services).sort();
if (services.join(",") !== "catalog-db,core,embedding,embedding-model-init,frontend,qdrant") {
throw new Error("mandatory stack must include catalog-db, core, frontend, qdrant, embedding, and embedding-model-init");
}
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
throw new Error("forbidden application coupling");
}
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions", "catalog-data", "qdrant-data", "embedding-models"]) {
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
}
if (!Object.hasOwn(config.services.core.environment || {}, "THT_LLM_URL")) {
throw new Error("core must expose a generic THT_LLM_URL endpoint contract");
}
for (const [key, value] of Object.entries({
THT_INTERNAL_QDRANT_URL: "http://qdrant:6333",
THT_INTERNAL_EMBEDDING_URL: "http://embedding:11434",
})) {
if (config.services.core.environment?.[key] !== value) {
throw new Error(`unexpected core ${key}: ${config.services.core.environment?.[key]}`);
}
}
for (const key of ["THT_INTERNAL_EMBEDDING_ID", "THT_INTERNAL_EMBEDDING_MODEL", "THT_INTERNAL_EMBEDDING_DIMENSIONS"]) {
if (Object.hasOwn(config.services.core.environment || {}, key)) throw new Error(`${key} must come only from the generated installation projection`);
}
for (const serviceName of ["qdrant", "embedding", "embedding-model-init"]) {
if ((config.services[serviceName].ports || []).length !== 0) {
throw new Error(`${serviceName} must not publish a host port`);
}
}
if (config.services.core.depends_on?.qdrant?.condition !== "service_healthy") {
throw new Error("core must wait for qdrant health");
}
if (config.services.core.depends_on?.["embedding-model-init"]?.condition !== "service_completed_successfully") {
throw new Error("core must wait for embedding-model-init success");
}
if (!config.services.embedding.healthcheck) throw new Error("embedding must define a healthcheck");
if (config.services["embedding-model-init"].depends_on?.embedding?.condition !== "service_healthy") {
throw new Error("embedding-model-init must wait for embedding health");
}
if (/docker\.sock|\/var\/run\/docker|docker[-_]?daemon/i.test(JSON.stringify(config.services))) {
throw new Error("Compose must not mount the Docker socket or daemon");
}
const piAuthMounts = (config.services.core.volumes || []).filter(
(mount) => mount.target === "/home/thoth/.pi/agent/auth.json",
);
if (piAuthMounts.length !== 1 || piAuthMounts[0].type !== "bind" || !piAuthMounts[0].read_only) {
throw new Error("Pi auth must be one read-only file bind");
}
if (config.services.core.environment?.THT_SECRETS_FILE !== "/run/secrets/thothii.secrets") {
throw new Error("core must read the canonical runtime secret bundle from /run/secrets");
}
const runtimeSecrets = config.services.core.secrets || [];
const hasTarget = (name) => runtimeSecrets.some((secret) => secret.target === name || secret.target?.endsWith(`/${name}`));
if (runtimeSecrets.length !== 2
|| !hasTarget("thothii.secrets")
|| !hasTarget("catalog_runtime_password")) {
throw new Error("core must receive only the canonical runtime bundle and catalog password");
}
if ((config.services.frontend.secrets || []).length !== 0) {
throw new Error("frontend must not receive runtime secrets");
}
NODE
render_profile local deploy/env/local.env.example deploy/compose.local.yaml
render_profile server deploy/env/server.env.example deploy/compose.server.yaml
assert_remote_required deploy/env/local.env.example deploy/compose.local.yaml
assert_remote_required deploy/env/server.env.example deploy/compose.server.yaml
echo "unified Compose contract passed."