Files
ThothII/.superpowers/sdd/task-4-report.md
T

2.6 KiB

Task 4 report — one-command Docker documentation

Status

Implemented. The installation documentation now uses the canonical flow:

cp .env.example .env
cp deploy/secrets/thothii.secrets.example deploy/secrets/thothii.secrets
chmod 600 deploy/secrets/thothii.secrets
docker compose up --build -d

Updated:

  • README.md with root .env defaults, one bundle, optional overlay presets, CA limitation, preprocessing, and migration notes.
  • docs/installazione-docker-4-contesti.md rewritten with exact files to create/edit and the four requested contexts (co-located DB/vector, Mac, Windows, and remote DB/Evidence server).
  • docs/index.md link text for the one-command installation.
  • deploy/secrets/README.md bundle syntax, permissions, runtime mount verification, CA handling, and migration guidance.
  • scripts/docker-smoke.sh now creates a disposable mode-0600 bundle and exercises the default Compose services without the legacy external profile.
  • scripts/test-default-compose.sh asserts the exact installation command, tracked templates, and absence of the legacy setup in the guide.
  • scripts/test-container-deployment.sh now validates the bundle mount and rejects legacy per-secret references; .dockerignore explicitly re-includes only the required vector policy helper so the Docker build context remains safe.

The docs explicitly state that a PEM CA chain cannot be put in the strict single-line bundle. A reviewed Compose override/secret-manager mount is required for THT_SSL_CA. Direct PostgreSQL workspace examples are marked as advanced and require a separate reviewed runtime password mount; the base bundle mount is the only default mount.

Verification

  • sh -n scripts/docker-smoke.sh scripts/test-default-compose.sh — passed.
  • ./scripts/test-default-compose.sh — passed.
  • ./scripts/test-container-deployment.sh — passed after migrating its local-vector assertions to the single bundle and checking the .dockerignore deployment allowlist.
  • git diff --check — passed.
  • ./scripts/test-docker-smoke.sh — passed after updating its static assertion to the default no-profile invocation.
  • docker buildx build --file docker/core.Dockerfile --check . — passed; BuildKit reported no warnings after the .dockerignore parent-directory fix.

Concerns

The legacy scripts/vector-rotate-bootstrap-password.sh maintenance helper still accepts old/new standalone files. Its output is intentionally documented as a transitional interface; the resulting value must be copied into the bundle before restarting local-vector services.