Files
ThothII/docs/install/psd-workspace-setup.md
T

4.0 KiB

Policlinico San Donato — setup workspace (nuova gestione)

Authentication acceptance is documented in the manual authentication matrix. Use generic OIDC with Authentik as the certified group catalog, map only the exact TOT Users and TOT Admin groups, then run Validate workspace source, tht auth check, tht auth check --interactive, and Test workspace connections in that order. Browser callback E2E, native Windows execution, approved PSD manual identities, external L2, and the two parked restore-lock preconditions remain pending the Task 15/release gates.

Guida operativa per collegare ThothII al DWH di PSD con il nuovo sistema (registry Git + descriptor v3 + tht).

Stato storico Mac/local (2026-08-13)

Questo stato è storico per Mac/local; il server PSD Project A usa binding separato postgres_direct read-only.

Per la rotazione della credenziale DWH, fare riferimento al runbook PSD: non autorizza modifiche finché i due gate non sono approvati. Il ThothII PSD server resta postgres_direct; il Mac e i client remoti usano rest_api con una chiave per installazione. postgres_direct e ssh_tunnel non usano chiavi dwh-auth.

  • Repository PSD pubblicato: https://github.com/mptyl/tht-workspace-psd (privato), branch main, commit d4f9185. Layout P1.1 già migrato e validato.
  • Deploy key SSH (sola lettura, senza passphrase) in deploy/psd/secrets/git-ssh-key e registrata sul repo come deploy key thothii-psd; il remote Git usato dall'installazione è git@github.com:mptyl/tht-workspace-psd.git.
  • Config operatore pronta (file reali gitignored in deploy/psd/): operator.env, thothii-installation.yaml e i secret d'installazione in secrets/ (pi-auth, secret bundle, chiave SSH, known_hosts). L'API key DWH va completata nella gestione Workspace ed è conservata nel vault cifrato del backend. Il certificato REST è self-issued/private: ogni Mac/local senza trust equivalente deve usare TLS_CA_FILE e verificare il fingerprint fuori banda, come in docs/install/dwh-auth-tls.md.
  • Stack avviato (progetto thothii-70417a3e30ea, via tht start): qdrant, embedding (con qwen3-embedding:0.6b), core, frontend sani. Il registry ha clonato e attivato psd-clinical (stato ready).
  • tht workspace inspect --workspace psd-clinical = OK (identità descrittore/catalogo risolte); la configurazione runtime va completata e testata dalla GUI.
  • Bloccante residuo: VPN. supabase-aritmolab.policlinicosandonato.it non risolve (NXDOMAIN) → il preprocessing DWH e le sessioni live non possono ancora partire.

Avvio/arresto (canonico)

Usare tht (stesso project name, quindi stessi volumi named):

tht=dist/tht/tht-darwin-arm64
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" start
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" workspace inspect --workspace psd-clinical --json
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" stop

Nota project name: tht calcola un project name stabile dall'installation descriptor (thothii-<hash>); docker compose "a mano" usa invece name: thothii dal compose.yaml, quindi i volumi named non coinciderebbero. Perciò per lo stack si usa tht start (non compose-with-preflight.sh up).

Rimane: smoke live di una domanda (P8 L2)

Il preprocessing è già completato. Resta solo:

  1. Aprire http://localhost:8080 e selezionare psd-clinical.
  2. Creare una sessione con una domanda reale in linguaggio naturale.
  3. Seguire le 8 fasi fino al primo gate di revisione.

Cosa è già stato fatto

  • Ristrutturazione del repo PSD nel layout P1.1 + validazione locale.
  • Pubblicazione GitHub + deploy key read-only + configurazione Git d'installazione.
  • Avvio stack + attivazione registry + tht inspect verde.
  • Preprocessing live completato su PSD: DWH → FK → schema → Evidence, idempotente.