feat(core): single-source data_dir/repos_dir via castle.yaml
The `castle` CLI and the `castle-api` service are two independent in-process drivers of `castle_core`. Each resolved DATA_DIR/REPOS_DIR at import time from its own process env (default /data/castle), persisted nowhere — so they silently diverged, and `apply`/dashboard-apply crashed on a non-existent /data. Make the loaded CastleConfig the single source of truth: - Resolve data_dir/repos_dir only in load_config (env > castle.yaml > default), anchored to the config root; drop the DATA_DIR/REPOS_DIR module globals and the import-time file read entirely — no global twin that can disagree with the file. - Thread config.data_dir/repos_dir through ensure_dirs, _env_context, tls_dir_for (now unified — deploy no longer inlines the tls path), and create/add/clone. - ensure_dirs raises an actionable CastleDirError instead of a bare PermissionError; the api surfaces it as 422. - doctor: "data dir writable" check + WARN when CASTLE_DATA_DIR/REPOS_DIR env overrides the file (the one remaining cross-process divergence vector). - install.sh persists data_dir/repos_dir into castle.yaml (idempotent, non-default). - Docs: registry.md globals + AGENTS.md roots. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -247,8 +247,12 @@ defaults:
|
||||
| `${secret:NAME}` | contents of `~/.castle/secrets/NAME` (mode 700) |
|
||||
|
||||
**Never** put secrets in `castle.yaml` or project dirs — use `${secret:…}`.
|
||||
Roots: **`CASTLE_HOME`** (config/code/artifacts/secrets, default `~/.castle`) and
|
||||
**`CASTLE_DATA_DIR`** (program data, default `/data/castle`) — both env-overridable.
|
||||
Roots: **`CASTLE_HOME`** (config/code/artifacts/secrets, default `~/.castle`,
|
||||
env-only — it *contains* castle.yaml) and **program data** (base of `${data_dir}`,
|
||||
default `/data/castle`) + **repos** (default `/data/repos`). The latter two resolve
|
||||
**env > `castle.yaml` > default** — set `data_dir:` / `repos_dir:` in `castle.yaml`
|
||||
(the single source of truth both the CLI and the api read), not a per-shell env var
|
||||
that only one of them sees. → **`docs/registry.md`** (castle.yaml globals).
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user