1.4 KiB
1.4 KiB
Task 2 report — root Compose startup
Status: DONE
Implemented the root Compose defaults and the single bundle declaration:
- added
.env.examplewith automatic Compose defaults (COMPOSE_FILE=compose.yaml, an empty profile, and the relativeTHT_SECRETS_FILEpath); - removed the mandatory
externalprofile fromcoreandfrontend; - mounted
deploy/secrets/thothii.secretsat/run/secrets/thothii.secretsand passed only the mounted path into the core container; - changed the production overlay to inherit that bundle instead of declaring per-secret mounts;
- removed the local overlay's legacy
env_filedependency; - added the versioned bundle template and
.gitignoreexception; - updated deployment security checks and added
scripts/test-default-compose.sh.
Focused verification:
./scripts/test-default-compose.sh # default Compose contract passed.
./scripts/test-container-deployment.sh # container deployment security contract passed.
./scripts/test-preprocess-compose-config.sh # preprocess compose config: ok
docker compose --env-file .env.example config --quiet
(with a temporary mode-0600 bundle via THT_SECRETS_FILE)
git diff --check
The local-vector and preprocess service secret declarations remain for Task 3, which converts those services to the same bundle helper. Documentation and smoke command migration is reserved for Task 4.