4.0 KiB
Policlinico San Donato — setup workspace (nuova gestione)
Authentication acceptance is documented in the manual authentication matrix.
Use generic OIDC with Authentik as the certified group catalog, map only the exact TOT Users and
TOT Admin groups, then run Validate workspace source, tht auth check, tht auth check --interactive,
and Test workspace connections in that order. Browser callback E2E, native Windows execution, approved PSD
manual identities, external L2, and the two parked restore-lock preconditions remain pending the
Task 15/release gates.
Guida operativa per collegare ThothII al DWH di PSD con il nuovo sistema (registry Git + descriptor
v3 + tht).
Stato storico Mac/local (2026-08-13)
Questo stato è storico per Mac/local; il server PSD Project A usa binding separato
postgres_directread-only.Per la rotazione della credenziale DWH, fare riferimento al runbook PSD: non autorizza modifiche finché i due gate non sono approvati. Il ThothII PSD server resta
postgres_direct; il Mac e i client remoti usanorest_apicon una chiave per installazione.postgres_directessh_tunnelnon usano chiavidwh-auth.
- Repository PSD pubblicato:
https://github.com/mptyl/tht-workspace-psd(privato), branchmain, commitd4f9185. Layout P1.1 già migrato e validato. - Deploy key SSH (sola lettura, senza passphrase) in
deploy/psd/secrets/git-ssh-keye registrata sul repo come deploy keythothii-psd; il remote Git usato dall'installazione ègit@github.com:mptyl/tht-workspace-psd.git. - Config operatore pronta (file reali gitignored in
deploy/psd/):operator.env,thothii-installation.yamle i secret d'installazione insecrets/(pi-auth, secret bundle, chiave SSH, known_hosts). L'API key DWH va completata nella gestione Workspace ed è conservata nel vault cifrato del backend. Il certificato REST è self-issued/private: ogni Mac/local senza trust equivalente deve usareTLS_CA_FILEe verificare il fingerprint fuori banda, come indocs/install/dwh-auth-tls.md. - Stack avviato (progetto
thothii-70417a3e30ea, viatht start):qdrant,embedding(conqwen3-embedding:0.6b),core,frontendsani. Il registry ha clonato e attivatopsd-clinical(statoready). tht workspace inspect --workspace psd-clinical= OK (identità descrittore/catalogo risolte); la configurazione runtime va completata e testata dalla GUI.- Bloccante residuo: VPN.
supabase-aritmolab.policlinicosandonato.itnon risolve (NXDOMAIN) → il preprocessing DWH e le sessioni live non possono ancora partire.
Avvio/arresto (canonico)
Usare tht (stesso project name, quindi stessi volumi named):
tht=dist/tht/tht-darwin-arm64
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" start
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" workspace inspect --workspace psd-clinical --json
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" stop
Nota project name:
thtcalcola un project name stabile dall'installation descriptor (thothii-<hash>);docker compose"a mano" usa invecename: thothiidalcompose.yaml, quindi i volumi named non coinciderebbero. Perciò per lo stack si usatht start(noncompose-with-preflight.sh up).
Rimane: smoke live di una domanda (P8 L2)
Il preprocessing è già completato. Resta solo:
- Aprire
http://localhost:8080e selezionarepsd-clinical. - Creare una sessione con una domanda reale in linguaggio naturale.
- Seguire le 8 fasi fino al primo gate di revisione.
Cosa è già stato fatto
- Ristrutturazione del repo PSD nel layout P1.1 + validazione locale.
- Pubblicazione GitHub + deploy key read-only + configurazione Git d'installazione.
- Avvio stack + attivazione registry +
tht inspectverde. - Preprocessing live completato su PSD: DWH → FK → schema → Evidence, idempotente.