olsitec-foundation platform repo
|
All checks were successful
CI / preflight (push) Successful in 4s
CI / typecheck (push) Successful in 15s
ecosystem-selftest / semantic-release-bumptest (push) Successful in 12s
ecosystem-selftest / eslint-gate (push) Successful in 4s
ecosystem-selftest / yamllint-gate (push) Successful in 4s
pulumi-preview / preview (push) Successful in 18s
Correction to the previous commit. Forgejo 11.0.15 DOES support reusable workflows; my earlier "not supported" was a false negative — the test caller omitted `runs-on`, and the pre-v15 "limited" implementation REQUIRES `runs-on` on the calling job (omitting it makes Forgejo silently schedule no run). Verified live: a caller with `runs-on` runs green, same-repo and cross-repo (short ref); the full-URL form fails for reusable workflows (it was only needed for composite ACTIONS, which resolve via DEFAULT_ACTIONS_URL). - Restore the four reusable-*.yml (on: workflow_call), the architecture the handover + 999_testing chose; fix the caller examples to include `runs-on`. - Remove the composite-action layer (actions/) — single mechanism, no redundancy. - .forgejo/workflows/README.md documents the v11 caller-`runs-on` + short-ref quirks (both removed by a future Forgejo v15 upgrade) and the candidate coverage. - ecosystem-selftest paths filter back to reusable-*.yml. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .forgejo/workflows | ||
| backup | ||
| bootstrap | ||
| ci | ||
| containers | ||
| documentation | ||
| dr | ||
| offsite-backup | ||
| packages | ||
| preflight | ||
| provision | ||
| .gitignore | ||
| bun.lock | ||
| package.json | ||
| README.md | ||
| VERSIONS | ||
olsitec-foundation
The self-hosting platform "egg": a single Pulumi project that brings up Forgejo (+ Actions +
OCI/npm registry), PostgreSQL, HashiCorp Vault, RustFS (S3), and a reverse proxy as plain OCI
containers on one VM — recoverable from {a VM, this repo, the master passphrase}.
This is Layer 0. Kubernetes, ArgoCD and everything else are Layer-1 consumers of this foundation (see ADR-004).
Layout
bootstrap/— the egg Pulumi project (phases, components, config).packages/— shared, publishable Pulumi modules (@olsitec/pulumi-*).preflight/— host & toolchain validation (run before any deploy).backup/,dr/— backup + disaster-recovery automation..forgejo/workflows/— CI (preflight, pulumi preview/up, backup-verify).documentation/— planning, ADRs, contracts, baseline overlay. Readdocumentation/000_baseline.mdanddocumentation/000_TOPOLOGY.mdfirst.
Status
Planning complete (PLAN-001 vision, PLAN-002 strategy, ADR-004/005 accepted). Implementation not yet started — next step is T00 (contracts) per PLAN-002 §10.
Recovery in one line
git clone this repo → set PULUMI_CONFIG_PASSPHRASE → ./preflight/preflight.sh →
pulumi up → restore latest offsite backup. Full procedure: dr/RUNBOOK.md (TBD, task T13).