Files
Arcrun/kbdb/wrangler.toml
T
uncle6me-web f6728974ea fix(t115 🔴🔴🔴 三修): kbdb 認證完全 fail-closed——沒金鑰一律 401(含讀取)
leo 實證的洞=「知道網址即可讀走全部知識」;一修 fail-open(沒設 secret 就不擋)、
二修仍放行讀取=洞沒補。三修(總管手改):無 token→全部 401(health 豁免),
老實例升級路徑=重跑安裝器(同時注入金鑰與新 workflow),不以繼續外洩換相容。
+結構閘測試:斷言 src/index.ts 的無 token 分支不得有 return next()——
擋「測試複本與真實作漂移」那類假綠(本輪正是它抓到二修的複本沒同步)。
kbdb vitest 60/60 全綠(總管親跑)。
2026-07-28 23:52:43 +08:00

55 lines
3.6 KiB
TOML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
name = "arcrun-kbdb"
main = "src/index.ts"
compatibility_date = "2025-02-19"
workers_dev = true
compatibility_flags = ["nodejs_compat"]
# KBDB Base — atomic universal table (SDD .agents/specs/arcrun/kbdb-base).
# Base needs D1 ONLY (free, no credit card). embed module adds Vectorize+AI bindings
# (optional, self-host opens it themselves). triplet is a separate repo.
[[d1_databases]]
binding = "DB"
database_name = "arcrun-kbdb"
database_id = "0c580910-e00b-4f8e-9c57-ac54ea52242f" # 官方 prod D1arcrun-kbdb);self-hosted deploy.ts 會注入用戶自己的 id 覆蓋
[vars]
ENVIRONMENT = "production"
# ── Auth guard (t115 二修, fail-closed) ────────────────────────────────────────
# The installer generates a random token at deploy time and secrets it into BOTH workers:
# wrangler secret put KBDB_INTERNAL_TOKEN (arcrun-kbdb)
# wrangler secret put KBDB_INTERNAL_TOKEN (arcrun-cypher-executor)
# cypher sends the token as `Authorization: Bearer <token>` via kbdbBase().
# Workflow http_request nodes that hit KBDB directly must include
# `Authorization: Bearer __KBDB_TOKEN__` (installer substitutes the value).
#
# Secret NOT set → writes (POST/PATCH/DELETE) are rejected 401 immediately (fail-closed).
# Reads (GET) pass with a server-side warning — old instances survive the upgrade
# window until both workers receive the secret at the same time.
# Secret SET → all non-health routes require correct Bearer; / and /health exempt.
# ──────────────────────────────────────────────────────────────────────────────
# ── Optional embed module (issue #7 / SDD T2.4) ────────────────────────────────
# Base 預設不開(free-tier 友善)。self-host 開語義查詢時,deploy.ts 偵測 config kbdb_embed:true
# → 取消下面兩段註解(注入 active binding)並 `wrangler vectorize create arcrun-kbdb-embed
# --dimensions=768 --metric=cosine`bge-base-en-v1.5 = 768 維)。官方帳號同理由 deploy 注入。
# ⚠️ Arcrun#11:光建 index 不夠。要對 owner_id/entry_type/source 下 filterowner-scoped/類型-scoped 語意查詢),
# 必須另建 metadata index,否則帶過濾一律回 0 命中:
# wrangler vectorize create-metadata-index arcrun-kbdb-embed --property-name owner_id --type string
# wrangler vectorize create-metadata-index arcrun-kbdb-embed --property-name entry_type --type string
# wrangler vectorize create-metadata-index arcrun-kbdb-embed --property-name source --type string
# wrangler vectorize create-metadata-index arcrun-kbdb-embed --property-name library --type string
# libraryportal-auth P1「庫」filterupsert 端把未標記正規化成 'general',查詢走 $in
# metadata index 只收「建立後 upsert」的向量 → 既有向量須 `POST /embed/backfill {"reindex":true}` 重推
# (建 library index 後同樣要 reindex,否則舊向量帶 library filter 一律 0 命中)。
# deploy.ts 的 ensureVectorizeMetadataIndexes() 已把前三個 index 隨部署冪等建好;library 待補進該清單
# cli/ 屬 portal-auth P1 範圍外,見 portal-auth tasks.md 部署清單附註)。
# 沒有這兩個 binding 時,kbdb/src/embed.ts 的 embedEnabled() 回 false → 維持 LIKE keyword、API 不變。
#
# [[vectorize]]
# binding = "VECTORIZE"
# index_name = "arcrun-kbdb-embed"
#
# [ai]
# binding = "AI"