Skip to content

Install with the ldh CLI, and follow LinkedDataHub onto one Fuseki - #28

Open
namedgraph wants to merge 2 commits into
masterfrom
chore/ldh-cli-and-single-fuseki
Open

namedgraph wants to merge 2 commits into
masterfrom
chore/ldh-cli-and-single-fuseki

Conversation

@namedgraph

Copy link
Copy Markdown
Member

Two changes that follow LinkedDataHub's own, and one convention.

The app installs with the ldh CLI

app/install.sh grants public read with ldh admin make-public and pushes the root and container documents with a single ldh push, so app/update-folder.sh goes; app/import-ns.sh reaches the ontology document through the CLI instead of the platform's deprecated bin/ scripts. Certificates are the PKCS12 keystore the CLI reads rather than the cert.pem those scripts fed curl — and the option is -c, not the -f the CLI no longer accepts, so make install was failing with a usage error before doing anything.

bin/make-public.sh goes with them. It wrote the same two authorizations straight to the admin store so it would need no certificate; ldh admin make-public does it through the API, and make public now calls that.

One Fuseki, both dataspace roles

The mount widens from ./fuseki/<role> to ./fuseki and each tdb2:location gains its role, so the TDB2 folders stay exactly where fuseki-admin and fuseki-end-user wrote them and no data moves — verified after the switch at 1,482,147 quads in end-user and 3,285 in admin. The role used to be encoded in the per-container mount, which one server cannot do. config/system.trig follows to fuseki:3030/admin/ and /end-user/, and both Varnish backends to the one host.

One-time migration note for anyone else running this stack: the pre-existing fuseki-admin and fuseki-end-user containers survive docker compose up as orphans and keep holding fuseki/*/DB2/tdb.lock, so the first start needs docker compose down --remove-orphans and rm -f fuseki/*/DB2/tdb.lock.

docker-compose.yml, Makefile and bin/server-cert-gen.sh are copies of LinkedDataHub's

Byte-identical, with every delta in docker-compose.override.yml, make/config.mk or make/local.mk. diff ../LinkedDataHub/<file> <file> prints nothing for all three.

The compose copy also brings what this repo had drifted behind on: the egress forward proxy confining the store's SPARQL SERVICE and LOAD to public addresses, the sef-compiler the platform calls to compose package stylesheets, the ./sef, ./packages and ./settings mounts, Memento-Datetime in the four CORS expose-header lines, and the ?query= ban that invalidates cached SPARQL results after a write.

Three fixes fell out of the Makefile work:

  • ABS_PATH had exactly one working value and is gone from .env and from bin/server-cert-gen.sh; BASE_URI is derived from .env instead.
  • make sef resolved the platform image with an unanchored grep that matched the sef-compiler's image just as readily, in an order Compose does not guarantee. It is anchored now, and refuses up front when the pinned image is neither built nor pullable rather than failing four commands later.
  • make load clears every dataset's tdb.lock, not only the end-user one: stopping the single server leaves a PID-1 lock in each, and any of them blocks the restart.

Verification

riot --validate on the changed RDF, bash -n on the changed scripts, docker compose config renders, make -n on every target, and the stack brought up end to end — site HTTP 200, platform healthy, both datasets served and counted.

🤖 Generated with Claude Code

namedgraph and others added 2 commits September 27, 2026 17:12
…lic with ldh admin make-public and pushes the root and container documents with a single ldh push, so update-folder.sh goes and import-ns.sh reaches the ontology document through ldh patch, post and clear instead of the platform's bin/ scripts; .ldhignore keeps ns.ttl out of the push, which installs separately. Certificates are the PKCS12 keystore the CLI reads rather than the cert.pem the scripts fed curl, and the option naming follows it: -c, not the -f the CLI no longer has. bin/make-public.sh goes with them - it wrote the same two authorizations straight to the admin store to avoid needing a certificate, which ldh admin make-public now does through the API, so make public calls that too.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tical copies of LinkedDataHub's, and every delta lives in an override or an include. One Fuseki serves both dataspace roles as its own dataset: the mount widens from ./fuseki/<role> to ./fuseki and each location gains the role, so the TDB2 folders stay where fuseki-admin and fuseki-end-user wrote them and no data moves - the role used to be encoded in the per-container mount, which one server cannot do. system.trig follows to fuseki:3030/admin/ and /end-user/, and both Varnish backends to the one host. The copy also brings the egress forward proxy that confines the store's SPARQL SERVICE and LOAD to public addresses, the sef-compiler the platform calls to compose package stylesheets, the ./sef, ./packages and ./settings mounts, Memento-Datetime in the four CORS expose-header lines, and the ?query= ban that invalidates cached SPARQL results after a write.

The Makefile keeps only what every deployment shares; make/config.mk carries this repo's settings and make/local.mk its interactive install. BASE_URI is derived from .env without ABS_PATH, which had exactly one working value and is gone from .env and from bin/server-cert-gen.sh, re-copied from the platform. `make sef` had resolved the platform image with an unanchored grep that matched the sef-compiler's just as readily, in an order Compose does not guarantee, and it now refuses up front when the pinned image is neither built nor pullable instead of failing four commands later. `make load` clears every dataset's tdb.lock rather than only the end-user one: stopping the single server leaves a PID-1 lock in each, and any of them blocks the restart.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@namedgraph
namedgraph force-pushed the chore/ldh-cli-and-single-fuseki branch from f3f118c to ba08c97 Compare September 27, 2026 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant