2.8 KiB
2.8 KiB
Task 4 report — one-command Docker documentation
Status
Implemented. The installation documentation now uses the canonical flow:
cp .env.example .env
cp deploy/secrets/thothii.secrets.example deploy/secrets/thothii.secrets
chmod 600 deploy/secrets/thothii.secrets
docker compose up --build -d
Updated:
README.mdwith root.envdefaults, one bundle, optional overlay presets, CA limitation, preprocessing, and migration notes.docs/installazione-docker-4-contesti.mdrewritten with exact files to create/edit and the four requested contexts (co-located DB/vector, Mac, Windows, and remote DB/Evidence server).docs/index.mdlink text for the one-command installation.deploy/secrets/README.mdbundle syntax, permissions, runtime mount verification, CA handling, and migration guidance.scripts/docker-smoke.shnow creates a disposable mode-0600 bundle and exercises the default Compose services without the legacyexternalprofile.scripts/test-default-compose.shasserts the exact installation command, tracked templates, and absence of the legacy setup in the guide.scripts/test-container-deployment.shnow validates the bundle mount and rejects legacy per-secret references;.dockerignoreexplicitly re-includes only the required vector policy helper so the Docker build context remains safe.- The Mac/Windows/local-vector and remote-server snippets now include required DWH/database and
Evidence-root settings.
deploy/env.exampleis explicitly deprecated and no longer selects a different Compose overlay.
The docs explicitly state that a PEM CA chain cannot be put in the strict single-line bundle. A
reviewed Compose override/secret-manager mount is required for THT_SSL_CA. Direct PostgreSQL
workspace examples are marked as advanced and require a separate reviewed runtime password mount;
the base bundle mount is the only default mount.
Verification
sh -n scripts/docker-smoke.sh scripts/test-default-compose.sh— passed../scripts/test-default-compose.sh— passed../scripts/test-container-deployment.sh— passed after migrating its local-vector assertions to the single bundle and checking the.dockerignoredeployment allowlist.git diff --check— passed../scripts/test-docker-smoke.sh— passed after updating its static assertion to the default no-profile invocation.docker buildx build --file docker/core.Dockerfile --check .— passed; BuildKit reported no warnings after the.dockerignoreparent-directory fix.
Concerns
The legacy scripts/vector-rotate-bootstrap-password.sh maintenance helper still accepts
old/new standalone files. Its output is intentionally documented as a transitional interface;
the resulting value must be copied into the bundle before restarting local-vector services.