DWH REST client enrollment

The dwh-auth credential belongs to one ThothII installation and is needed only when the workspace uses the rest_api transport.

Trasporto Materiale richiesto
rest_api URL HTTPS, API_KEY_FILE, eventuale TLS_CA_FILE
postgres_direct Credenziali PostgreSQL e configurazione TLS PostgreSQL
ssh_tunnel Credenziali PostgreSQL e materiale SSH

Delivery and storage

Receive the key and CA through separate protected channels. Store the key in the installation vault or in a regular file accessible only to the authorized account. Do not put it in Git, YAML files, arguments, logs, or shared screens.

ACME Limited configuration

Esempio di binding headless per il workspace acme-ebikes:

THT_WS_ACME_EBIKES_DWH_TRANSPORT=rest_api
THT_WS_ACME_EBIKES_DWH_BASE_URL=https://dwh.acme.example/dwh/
THT_WS_ACME_EBIKES_DWH_API_KEY_FILE=/run/secrets/acme-ebikes-dwh-api-key
THT_WS_ACME_EBIKES_DWH_TLS_CA_FILE=/run/secrets/acme-ebikes-dwh-ca.pem

The workspace suffix comes from the immutable ID, with hyphens changed to underscores and letters converted to uppercase. API_KEY_FILE contains the mounted file path, not the key value.

Rotation and revocation

During rotation, receive the new generation, update the vault or mounted file, and confirm connectivity through the harmless /rpc/ping route. The server owner revokes the previous generation only after this confirmation.

A 401 means the key is missing, unknown, expired, or revoked. A 503 means the authorization service or registry is unavailable. In either case, do not bypass REST or weaken TLS verification.