Files
esh-pfi-infrastructure/stacks/muninn-gate/conf/muninn-gate.example.yaml
T
vh 786462ac9c feat(muninn-gate): WG-internal Muninn ingestion front door stack (#377)
Deployed on corviduo-dev, co-located with the worldtree-personal muninn
watcher. ingestion_root=/data/state/ingestion (shared state volume, byte-
identical to the watcher); runs as uid 1000 to write the queue; staging
bound :ro at the ratified /mnt/muninn-staging/mimir-inbox (local placeholder
until the shared mount + mimir-inbox writer land). Boot verified: /ping
{"service":"ok"}, /health watcher.running=true (byte-identity proven).

Image built out-of-band with the Gitea read token as a BuildKit secret.
Real config (bearer keys) lives on-server at /opt/docker/conf 0600.
2026-07-30 21:33:29 -07:00

33 lines
1.4 KiB
YAML

# muninn-gate mounted config — REDACTED EXAMPLE (committed).
# The real file (with bearer-key secrets) lives on corviduo-dev at
# /opt/docker/conf/muninn-gate/muninn-gate.yaml and is gitignored.
#
# Schema is CLOSED: an unknown field (top-level or per-key) is a BOOT FAILURE,
# not a warning. Read once at boot; every validation failure aborts before the
# socket binds. Four top-level fields only.
# Absolute, existing directory, same volume as the personal muninn watcher.
# Byte-identical to the watcher's view: /data/state/ingestion in both containers.
ingestion_root: /data/state/ingestion
# Submit-path allowlist (non-empty; each absolute, existing, a directory).
# Canonicalized at boot. Ratified 2026-07-30. Currently a LOCAL placeholder dir
# on corviduo-dev; becomes the shared mount when mimir-inbox (the writer) lands.
staging_roots:
- /mnt/muninn-staging/mimir-inbox
# Bearer credentials. `name` = non-secret caller identity, recorded as
# `submitted_by`. Flat scopes (no hierarchy/inheritance): read | submit | control.
# Names AND key values must both be unique; a padded key fails boot.
keys:
- name: mimir-inbox
key: <64-hex-secret, provisioned by infra-ops>
scopes: [read, submit]
- name: ops-curl
key: <different 64-hex-secret>
scopes: [read, submit, control]
# WG-internal address — observability only, NOT read by the app. Keep consistent
# with the launcher's --host/--port (the launcher is authoritative).
bind: 10.250.50.152:8090