66 lines
4.0 KiB
Markdown
66 lines
4.0 KiB
Markdown
# Policlinico San Donato — setup workspace (nuova gestione)
|
|
|
|
Authentication acceptance is documented in the [manual authentication matrix](../testing/authentication-manual-acceptance.md).
|
|
Use generic OIDC with Authentik as the certified group catalog, map only the exact TOT Users and
|
|
TOT Admin groups, then run **Validate workspace source**, `tht auth check`, `tht auth check --interactive`,
|
|
and **Test workspace connections** in that order. Browser callback E2E, native Windows execution, approved PSD
|
|
manual identities, external L2, and the two parked restore-lock preconditions remain pending the
|
|
Task 15/release gates.
|
|
|
|
Guida operativa per collegare ThothII al DWH di PSD con il nuovo sistema (registry Git + descriptor
|
|
v3 + `tht`).
|
|
|
|
## Stato storico Mac/local (2026-08-13)
|
|
|
|
> Questo stato è storico per Mac/local; il server PSD Project A usa binding separato `postgres_direct` read-only.
|
|
>
|
|
> Per la rotazione della credenziale DWH, fare riferimento al [runbook PSD](../operations/psd-dwh-auth-rollout.md): non autorizza modifiche finché i due gate non sono approvati. Il ThothII PSD server resta `postgres_direct`; il Mac e i client remoti usano `rest_api` con una chiave per installazione. `postgres_direct` e `ssh_tunnel` non usano chiavi `dwh-auth`.
|
|
|
|
- **Repository PSD pubblicato:** `https://github.com/mptyl/tht-workspace-psd` (privato), branch
|
|
`main`, commit `d4f9185`. Layout P1.1 già migrato e validato.
|
|
- **Deploy key SSH** (sola lettura, senza passphrase) in
|
|
`deploy/psd/secrets/git-ssh-key` e registrata sul repo come deploy key `thothii-psd`; il remote
|
|
Git usato dall'installazione è `git@github.com:mptyl/tht-workspace-psd.git`.
|
|
- **Config operatore pronta** (file reali gitignored in `deploy/psd/`): `operator.env`,
|
|
`thothii-installation.yaml` e i secret d'installazione in `secrets/` (pi-auth, secret bundle,
|
|
chiave SSH, known_hosts). L'API key DWH va completata nella gestione Workspace ed è conservata
|
|
nel vault cifrato del backend. Il certificato REST è self-issued/private: ogni Mac/local senza trust equivalente deve usare `TLS_CA_FILE` e verificare il fingerprint fuori banda, come in `docs/install/dwh-auth-tls.md`.
|
|
- **Stack avviato** (progetto `thothii-70417a3e30ea`, via `tht start`): `qdrant`, `embedding`
|
|
(con `qwen3-embedding:0.6b`), `core`, `frontend` sani. Il registry ha **clonato e attivato**
|
|
`psd-clinical` (stato `ready`).
|
|
- **`tht workspace inspect --workspace psd-clinical` = OK** (identità descrittore/catalogo
|
|
risolte); la configurazione runtime va completata e testata dalla GUI.
|
|
- **Bloccante residuo: VPN.** `supabase-aritmolab.policlinicosandonato.it` non risolve
|
|
(`NXDOMAIN`) → il preprocessing DWH e le sessioni live non possono ancora partire.
|
|
|
|
## Avvio/arresto (canonico)
|
|
|
|
Usare `tht` (stesso project name, quindi stessi volumi named):
|
|
|
|
```bash
|
|
tht=dist/tht/tht-darwin-arm64
|
|
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" start
|
|
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" workspace inspect --workspace psd-clinical --json
|
|
"$tht" --installation "$(pwd)/deploy/psd/thothii-installation.yaml" stop
|
|
```
|
|
|
|
> **Nota project name:** `tht` calcola un project name stabile dall'installation descriptor
|
|
> (`thothii-<hash>`); `docker compose` "a mano" usa invece `name: thothii` dal `compose.yaml`, quindi
|
|
> i volumi named non coinciderebbero. Perciò per lo stack si usa `tht start` (non
|
|
> `compose-with-preflight.sh up`).
|
|
|
|
## Rimane: smoke live di una domanda (P8 L2)
|
|
|
|
Il preprocessing è già completato. Resta solo:
|
|
|
|
1. Aprire `http://localhost:8080` e selezionare `psd-clinical`.
|
|
2. Creare una sessione con una domanda reale in linguaggio naturale.
|
|
3. Seguire le 8 fasi fino al primo gate di revisione.
|
|
|
|
## Cosa è già stato fatto
|
|
|
|
- Ristrutturazione del repo PSD nel layout P1.1 + validazione locale.
|
|
- Pubblicazione GitHub + deploy key read-only + configurazione Git d'installazione.
|
|
- Avvio stack + attivazione registry + `tht inspect` verde.
|
|
- **Preprocessing live completato** su PSD: DWH → FK → schema → Evidence, idempotente.
|