2.7 KiB
2.7 KiB
Task 3 report — optional local pgvector profile
Status
Implemented and verified the local-vector Compose profile.
vector-dbuses pgvector 0.8.5 on PostgreSQL 16, pinned to the official multi-arch manifest digest.vector_datais a project-scoped named volume and is not shared with application data.- database readiness gates the packaged one-shot
vector-migratejob; core declares the migration completion dependency while remaining usable in the pre-existing external profile. - bootstrap, migrator, reader, and writer identities are distinct. Bootstrap and migration credentials are supplied as Compose secrets; the application receives only reader/writer credentials.
deploy/workspaces/local-vector.yamlselectspgvector_directwith separate reader and writer connections.- the base loopback port binding,
AUTH_MODE=none, andTHOTH_PUBLIC_EXPOSURE=falsedefaults are unchanged.
Red/green evidence
The initial Compose contract did not list vector-db, as required by the brief. The first real
smoke then failed migration 002 because bootstrap installed the vector extension in public.
The bootstrap was corrected to create the vectors schema under the migration owner and install
the extension there. A clean-volume rerun passed.
Verification
./scripts/local-vector-smoke.sh: PASS- isolated generated Compose project and credentials
- clean migration plus idempotent status rerun
- reader/writer privilege health
- one-record upsert and similarity search
- restart of both
coreandvector-db - persisted search result after restart
- project-only volume cleanup
./scripts/test-container-deployment.sh: PASS./scripts/test-backend-url-policy.sh: PASSdocker compose --profile local-vector config --quiet: PASS- harness: 477 passed, 5 deselected
- backend: 84 passed; TypeScript typecheck PASS
- frontend: 226 passed; TypeScript typecheck PASS
git diff --check: PASS
Self-review / concerns
- Compose cannot make a dependency required only under one profile. The core dependency uses
required: falseso the establishedexternalprofile does not activate local infrastructure; underlocal-vector,compose up --waitstill fails ifvector-migrateexits nonzero, and the smoke verifies that successful migration precedes the healthy stack. - Reader/writer passwords are injected into core environment variables because Compose service attributes cannot be conditional by profile. Bootstrap and migrator credentials remain file-backed secrets and are never exposed to core.
- The smoke intentionally refuses the operator project name
thothiiand removes only its unique project namespace and volumes.