46 lines
2.0 KiB
Markdown
46 lines
2.0 KiB
Markdown
# Task 4 report — one-command Docker documentation
|
|
|
|
## Status
|
|
|
|
Implemented. The installation documentation now uses the canonical flow:
|
|
|
|
```sh
|
|
cp .env.example .env
|
|
cp deploy/secrets/thothii.secrets.example deploy/secrets/thothii.secrets
|
|
chmod 600 deploy/secrets/thothii.secrets
|
|
docker compose up --build -d
|
|
```
|
|
|
|
Updated:
|
|
|
|
- `README.md` with root `.env` defaults, one bundle, optional overlay presets, CA limitation,
|
|
preprocessing, and migration notes.
|
|
- `docs/installazione-docker-4-contesti.md` rewritten with exact files to create/edit and the
|
|
four requested contexts (co-located DB/vector, Mac, Windows, and remote DB/Evidence server).
|
|
- `docs/index.md` link text for the one-command installation.
|
|
- `deploy/secrets/README.md` bundle syntax, permissions, runtime mount verification, CA handling,
|
|
and migration guidance.
|
|
- `scripts/docker-smoke.sh` now creates a disposable mode-0600 bundle and exercises the default
|
|
Compose services without the legacy `external` profile.
|
|
- `scripts/test-default-compose.sh` asserts the exact installation command, tracked templates,
|
|
and absence of the legacy setup in the guide.
|
|
|
|
The docs explicitly state that a PEM CA chain cannot be put in the strict single-line bundle. A
|
|
reviewed Compose override/secret-manager mount is required for `THT_SSL_CA`. Direct PostgreSQL
|
|
workspace examples are marked as advanced and require a separate reviewed runtime password mount;
|
|
the base bundle mount is the only default mount.
|
|
|
|
## Verification
|
|
|
|
- `sh -n scripts/docker-smoke.sh scripts/test-default-compose.sh` — passed.
|
|
- `./scripts/test-default-compose.sh` — passed.
|
|
- `git diff --check` — passed.
|
|
- `./scripts/test-docker-smoke.sh` — passed after updating its static assertion to the default
|
|
no-profile invocation.
|
|
|
|
## Concerns
|
|
|
|
The legacy `scripts/vector-rotate-bootstrap-password.sh` maintenance helper still accepts
|
|
old/new standalone files. Its output is intentionally documented as a transitional interface;
|
|
the resulting value must be copied into the bundle before restarting local-vector services.
|