- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
16 lines
701 B
SQL
16 lines
701 B
SQL
-- ThothII — ruolo DWH read-only (schema datawarehouse).
|
|
-- Eseguire sulla stessa istanza Postgres usata da ThothII (porta 5438, accesso diretto).
|
|
-- Sostituire :PWD con un secret forte al momento dell'esecuzione:
|
|
-- psql -h localhost -p 5438 -U postgres -d postgres -v PWD='<secret>' -f 10-dwh-roles.sql
|
|
DO $$
|
|
BEGIN
|
|
IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'thoth_dwh_reader') THEN
|
|
CREATE ROLE thoth_dwh_reader LOGIN PASSWORD :'PWD';
|
|
END IF;
|
|
END $$;
|
|
|
|
GRANT USAGE ON SCHEMA datawarehouse TO thoth_dwh_reader;
|
|
GRANT SELECT ON ALL TABLES IN SCHEMA datawarehouse TO thoth_dwh_reader;
|
|
ALTER DEFAULT PRIVILEGES IN SCHEMA datawarehouse
|
|
GRANT SELECT ON TABLES TO thoth_dwh_reader;
|