The overlay had never been run against a fresh volume. Two faults, the first
hiding the second:
- postgres:16-alpine ships libssl but not the openssl CLI, so the first-boot
certificate generation exited 127 in a restart loop. It failed invisibly:
the 2>/dev/null on the openssl line swallowed sh's "not found" as well, so
`docker logs` was completely empty. openssl is now installed on the boot
that generates the certificate, inside the same guard, so a restart still
needs no network.
- the certificate was written into /var/lib/postgresql/data BEFORE initdb
ran, and initdb refuses to initialise a directory that is not empty. That
made a fresh volume unstartable regardless of the first fault. The
certificate now lives in its own volume, which keeps it persistent — the
reason it was put in the data directory — without touching the cluster's.
Separately, docker-compose.yml did not pass ANTHROPIC_API_KEY to the api
container, so a compose deployment could never register the agent run routes:
POST /agents/{id}/runs answered 404 and /version reported two endpoints fewer.
The model and embedder variables are now passed through, all defaulting to
empty so a deployment without them behaves exactly as it did.
Verified on a fresh volume: 56/56 verify-deploy checks against the resulting
stack, including a live agent run and 34 chunks embedded through Ollama.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g
infrastructure
Deployment and local-environment definitions.
Empty in Phase 1, on purpose. The Phase 1 scope is the Go module, the
database connection and the initial migration, run against a PostgreSQL 18.6
instance that already exists on the developer's machine. Nothing here is needed
to get make migrate-up && make run working.
What lands here in later phases, once each is actually approved:
| File | Phase | Contents |
|---|---|---|
docker-compose.dev.yml |
2 | PostgreSQL + pgvector, so the dev database stops being a machine-local install |
docker-compose.dev.yml (extended) |
later | Redis, MinIO — each only when the phase that needs it starts |
Dockerfile.api |
later | Multi-stage build for go-api |
Dockerfile.owliver |
later | The Python service |
otel-collector.yaml |
later | OpenTelemetry collector config |
NATS is deliberately absent from that table: it is not part of the target architecture, and nothing here should reintroduce it.
Adding any of these before its phase would be speculative, so the directory holds only this note for now.