Files
ThothII/compose.yaml
T
Codex 82e2c91f42
Publish documentation / publish (push) Successful in 1m27s
feat: implement memory and evidence administration with guided repairs
Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.

Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
2026-09-10 10:31:34 +02:00

289 lines
9.3 KiB
YAML

name: thothii
services:
core:
build:
context: .
dockerfile: docker/core.Dockerfile
image: thothii-core:local
environment:
HOST: 0.0.0.0
PORT: "8787"
THT_HARNESS_DIR: /app/harness
THT_BIN: /opt/venv/bin/tht
THT_DATA_ROOT: /data
SETTINGS_FILE: /data/settings/settings.json
THT_EVIDENCE_HOST_REGISTRY_ROOT: ${THT_WORKSPACE_REGISTRY_ROOT:-}
THT_MAINTENANCE_FILE: /data/settings/maintenance.json
THT_WORKSPACE_REGISTRY_ROOT: /data/workspace-registry
THT_WORKSPACE_GIT_REMOTE: ${THT_WORKSPACE_GIT_REMOTE:?set THT_WORKSPACE_GIT_REMOTE}
THT_WORKSPACE_GIT_BRANCH: ${THT_WORKSPACE_GIT_BRANCH:-main}
THT_WORKSPACE_INSTALLATION_ID: ${THT_WORKSPACE_INSTALLATION_ID:-local}
THT_WORKSPACE_SECRET_STORE_ROOT: /data/workspace-secrets
THT_WORKSPACE_SECRET_RUNTIME_ROOT: /tmp/thothii-workspace-secrets
THT_WORKSPACE_SECRET_ROOTS: /run/secrets
THT_SECRETS_FILE: /run/secrets/thothii.secrets
THT_INSTALLATION_CONFIG_FILE: /run/thothii-installation/thothii-installation.yaml
THT_PI_AUTH_FILE: /home/thoth/.pi/agent/auth.json
THT_AUTH_CONFIG_FILE: /run/thothii-auth/auth.yaml
THT_AUTH_STATE_ROOT: /data/auth
THT_CATALOG_DB_HOST: catalog-db
THT_CATALOG_DB_PORT: "5432"
THT_CATALOG_DB_NAME: thothii_catalog
THT_CATALOG_RUNTIME_USER: thothii_catalog_runtime
THT_CATALOG_RUNTIME_PASSWORD_FILE: /run/secrets/catalog_runtime_password
THT_DB_NAME: ${THT_DB_NAME:-}
THT_DWH_REST_URL: ${THT_DWH_REST_URL:-}
THT_LLM_URL: ${THT_LLM_URL:-}
THT_INTERNAL_QDRANT_URL: http://qdrant:6333
THT_INTERNAL_EMBEDDING_URL: http://embedding:11434
MAX_PI_PROCESSES: ${MAX_PI_PROCESSES:-4}
volumes:
- settings:/data/settings
- pi-state:/home/thoth/.pi
- ${PI_AUTH_FILE:?set PI_AUTH_FILE}:/home/thoth/.pi/agent/auth.json:ro
- workspace-registry:/data/workspace-registry
- workspace-secrets:/data/workspace-secrets
- sessions:/data/sessions
- ${THT_AUTH_CONFIG_ROOT:?set THT_AUTH_CONFIG_ROOT}:/run/thothii-auth:ro
- auth-state:/data/auth
secrets:
- source: thothii_secrets
target: thothii.secrets
- catalog_runtime_password
configs:
- source: thothii_installation_config
target: /run/thothii-installation/thothii-installation.yaml
healthcheck:
test: ["CMD", "curl", "-fsS", "http://127.0.0.1:8787/health"]
interval: 15s
timeout: 3s
retries: 5
start_period: 30s
depends_on:
catalog-db:
condition: service_healthy
qdrant:
condition: service_healthy
embedding-model-init:
condition: service_completed_successfully
networks:
- thothii
catalog-db:
image: postgres:17.6-bookworm@sha256:f3bd19c606e442c3d7bdfa8002e03fe260a1023351e0ea4598032022b68dd6e3
environment:
POSTGRES_DB: thothii_catalog
POSTGRES_USER: thothii_catalog_migrate
POSTGRES_PASSWORD_FILE: /run/secrets/catalog_migrator_password
volumes:
- catalog-data:/var/lib/postgresql/data
- ./docker/catalog-db-init.sql:/docker-entrypoint-initdb.d/010-runtime-role.sql:ro
secrets:
- catalog_runtime_password
- catalog_migrator_password
healthcheck:
test:
- CMD-SHELL
- >-
pg_isready -U thothii_catalog_migrate -d thothii_catalog
&& test "$(psql -U thothii_catalog_migrate -d thothii_catalog -Atqc
"select count(*) from pg_catalog.pg_roles where rolname = 'thothii_catalog_runtime'")" = "1"
interval: 5s
timeout: 3s
retries: 12
start_period: 10s
networks:
- thothii
catalog-migrate:
image: thothii-core:local
profiles: [catalog-maintenance]
pull_policy: never
command: ["bash", "/app/docker/catalog-migrate.sh"]
environment:
THT_CATALOG_DB_HOST: catalog-db
THT_CATALOG_DB_PORT: "5432"
THT_CATALOG_DB_NAME: thothii_catalog
THT_CATALOG_MIGRATOR_USER: thothii_catalog_migrate
THT_CATALOG_MIGRATOR_PASSWORD_FILE: /run/secrets/catalog_migrator_password
secrets:
- catalog_migrator_password
depends_on:
catalog-db:
condition: service_healthy
networks:
- thothii
workspace-maintenance:
image: thothii-core:local
profiles: [workspace-maintenance]
pull_policy: never
entrypoint: ["/usr/bin/tini", "--", "/app/docker/workspace-maintenance-entrypoint.sh"]
environment:
THT_HARNESS_DIR: /app/harness
THT_BIN: /opt/venv/bin/tht
THT_DATA_ROOT: /data
THT_WORKSPACE_REGISTRY_ROOT: /data/workspace-registry
THT_WORKSPACE_GIT_REMOTE: ${THT_WORKSPACE_GIT_REMOTE:?set THT_WORKSPACE_GIT_REMOTE}
THT_WORKSPACE_GIT_BRANCH: ${THT_WORKSPACE_GIT_BRANCH:-main}
THT_WORKSPACE_INSTALLATION_ID: ${THT_WORKSPACE_INSTALLATION_ID:-local}
THT_WORKSPACE_SECRET_STORE_ROOT: /data/workspace-secrets
THT_WORKSPACE_SECRET_RUNTIME_ROOT: /tmp/thothii-workspace-secrets
THT_WORKSPACE_SECRET_ROOTS: /run/secrets
THT_SECRETS_FILE: /run/secrets/thothii.secrets
THT_DB_NAME: ${THT_DB_NAME:-}
THT_DWH_REST_URL: ${THT_DWH_REST_URL:-}
THT_LLM_URL: ${THT_LLM_URL:-}
THT_INTERNAL_QDRANT_URL: http://qdrant:6333
THT_INTERNAL_EMBEDDING_URL: http://embedding:11434
THT_CATALOG_DB_HOST: catalog-db
THT_CATALOG_DB_PORT: "5432"
THT_CATALOG_DB_NAME: thothii_catalog
THT_CATALOG_RUNTIME_USER: thothii_catalog_runtime
THT_CATALOG_RUNTIME_PASSWORD_FILE: /run/secrets/catalog_runtime_password
HOME: /tmp/thoth
AWS_ACCESS_KEY_ID: ""
AWS_SECRET_ACCESS_KEY: ""
AWS_SESSION_TOKEN: ""
AWS_PROFILE: ""
AWS_DEFAULT_PROFILE: ""
AWS_CONFIG_FILE: /dev/null
AWS_SHARED_CREDENTIALS_FILE: /dev/null
volumes:
- type: volume
source: workspace-registry
target: /data/workspace-registry
read_only: false
- type: volume
source: sessions
target: /data/sessions
- type: volume
source: workspace-secrets
target: /data/workspace-secrets
secrets:
- source: thothii_secrets
target: thothii.secrets
- catalog_runtime_password
user: "10001:10001"
read_only: true
tmpfs:
- /tmp:rw,noexec,nosuid,nodev,size=1g,mode=1777
- /var/tmp:rw,noexec,nosuid,nodev,size=128m,mode=1777
cap_drop:
- ALL
security_opt:
- no-new-privileges:true
restart: "no"
depends_on:
catalog-db:
condition: service_healthy
qdrant:
condition: service_healthy
embedding-model-init:
condition: service_completed_successfully
networks:
- thothii
frontend:
build:
context: .
dockerfile: docker/frontend.Dockerfile
args:
VITE_BASE: /
VITE_BACKEND_URL: /api
image: thothii-frontend:local
depends_on:
core:
condition: service_healthy
healthcheck:
test: ["CMD-SHELL", "wget -q -O /dev/null http://127.0.0.1:8080/ || exit 1"]
interval: 15s
timeout: 3s
retries: 5
start_period: 10s
networks:
- thothii
qdrant:
image: qdrant/qdrant:v1.18.2@sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c
expose:
- "6333"
volumes:
- qdrant-data:/qdrant/storage
healthcheck:
test:
- CMD-SHELL
- >
/usr/bin/bash -lc "exec 3<>/dev/tcp/127.0.0.1/6333 &&
printf 'GET /healthz HTTP/1.1\r\nHost: 127.0.0.1\r\nConnection: close\r\n\r\n' >&3 &&
grep -q '200 OK' <&3"
interval: 15s
timeout: 3s
retries: 10
start_period: 10s
networks:
- thothii
embedding:
image: ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a
command: ["serve"]
expose:
- "11434"
volumes:
- embedding-models:/root/.ollama
healthcheck:
test:
- CMD-SHELL
- >
/usr/bin/bash -lc "exec 3<>/dev/tcp/127.0.0.1/11434 &&
printf 'GET /api/tags HTTP/1.1\r\nHost: 127.0.0.1\r\nConnection: close\r\n\r\n' >&3 &&
grep -q '200 OK' <&3"
interval: 15s
timeout: 5s
retries: 20
start_period: 10s
networks:
- thothii
embedding-model-init:
image: ollama/ollama:0.32.0@sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a
entrypoint: ["/usr/bin/bash", "/opt/thoth/embedding-model-init.sh"]
environment:
OLLAMA_BASE_URL: http://embedding:11434
OLLAMA_WAIT_TIMEOUT_SEC: "180"
volumes:
- embedding-models:/root/.ollama
- ./docker/embedding-model-init.sh:/opt/thoth/embedding-model-init.sh:ro
depends_on:
embedding:
condition: service_healthy
networks:
- thothii
networks:
thothii:
volumes:
settings:
pi-state:
workspace-registry:
workspace-secrets:
sessions:
qdrant-data:
embedding-models:
auth-state:
catalog-data:
secrets:
thothii_secrets:
file: "${THT_SECRETS_FILE:?set THT_SECRETS_FILE}"
catalog_runtime_password:
file: "${THT_CATALOG_RUNTIME_PASSWORD_SOURCE:-./deploy/secrets/catalog-runtime-password}"
catalog_migrator_password:
file: "${THT_CATALOG_MIGRATOR_PASSWORD_SOURCE:-./deploy/secrets/catalog-migrator-password}"
configs:
thothii_installation_config:
file: "${THT_INSTALLATION_CONFIG_SOURCE:?set THT_INSTALLATION_CONFIG_SOURCE}"