Files
ThothII/deploy/compose.server.yaml
T
Codex 82e2c91f42
Publish documentation / publish (push) Successful in 1m27s
feat: implement memory and evidence administration with guided repairs
Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.

Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
2026-09-10 10:31:34 +02:00

53 lines
1.8 KiB
YAML

services:
core:
environment:
THOTH_PUBLIC_EXPOSURE: "true"
THT_DATA_ROOT: /data
THT_WORKSPACE_INSTALLATION_ID: server
# prepare-server-pi-state.sh creates the regular child targets before this parent bind is used.
# The real configuration sources still remain separate read-only mounts.
volumes: !override
- type: bind
source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}
target: /data
- type: bind
source: ${THT_AUTH_CONFIG_ROOT:?set THT_AUTH_CONFIG_ROOT}
target: /run/thothii-auth
read_only: true
- type: bind
source: ${THT_PI_STATE_ROOT:?set THT_PI_STATE_ROOT}
target: /home/thoth/.pi
- type: bind
source: ${PI_AUTH_FILE:?set PI_AUTH_FILE}
target: /home/thoth/.pi/agent/auth.json
read_only: true
- type: bind
source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT}
target: /data/workspace-registry
restart: unless-stopped
# Deprecated migration adapter: only use this when no auth.yaml is mounted yet.
# AUTH_MODE: upstream
frontend:
ports:
- "${THOTH_SERVER_BIND:-127.0.0.1}:${THOTH_HTTP_PORT:-8080}:8080"
restart: unless-stopped
workspace-maintenance:
environment:
THT_DATA_ROOT: /data
THT_WORKSPACE_INSTALLATION_ID: server
volumes: !override
- type: bind
source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}/sessions
target: /data/sessions
- type: bind
source: ${THT_WORKSPACE_REGISTRY_ROOT:?set THT_WORKSPACE_REGISTRY_ROOT}
target: /data/workspace-registry
read_only: false
- type: bind
source: ${THT_DATA_ROOT:?set THT_DATA_ROOT}/workspace-secrets
target: /data/workspace-secrets
restart: "no"