refactor: move every model that reaches fabrikk-infra's deployment out of the factory #16

Merged
beddari merged 4 commits from ops-split into main 2026-09-18 13:08:48 +00:00
Owner

The factory's program reaches the forge, with a repository-scoped token, and the registry, anonymously. It reaches nothing fabrikk-infra deploys and holds no credential for it. This repository also carried the models a human uses to operate that infrastructure, with the admin kube context and the fleet and registry-push keys next to the loop. They leave.

Removed, to be re-homed in fabrikk-infra's own swamp with its own vault: the six kube instances (runner-pods, dataverket-prod-{rbac,pods,secrets,pvcs,deployments}), the Flux HelmRelease instance and its reset extension, the Omni inventory, the registry mirror, the fabrikk-runner workflow, and the forge-wide methods of the forgejo extension (runner_list, runner_prune, runner_registration_token, actions_secret_put, repo_rename). The pulled @swamp/kubernetes, @ginger_pappa/flux, and @mccormick/omni extensions leave the lockfile.

Kept: fabrikk, forgejo (now tag_protection_ensure and pr_merge_state only), references, source-standards.

Docs: a "loop boundary" section in how-fabrikk-works, a sentence in the delivery skill, the code map, and the forge, workstation, and CLI pages now point to fabrikk-infra for what moved. README follow-ups updated.

Why structural rather than checked: a 520-line boundary-check tool was drafted and discarded. No kube context and no such key exists here now, and models/ and workflows/ are protected paths, so an instance that would cross the line is a change a human sees in Forgejo.

Left for the infrastructure side: the fabrikk vault still holds omni/service_account_key and registry/ci_*; delete them once fabrikk-infra's vault has them. The forgejo token can then be narrowed to dataverket/fabrikk scope.

Verified: 46 extension tests pass, docs-check ok, the three workflows and the factory definition validate. This PR changes protected paths and carries no attestation tag, so validate-attestation reports failure, as every machinery PR does until point 3 (required status check) is decided.

The factory's program reaches the forge, with a repository-scoped token, and the registry, anonymously. It reaches nothing fabrikk-infra deploys and holds no credential for it. This repository also carried the models a human uses to operate that infrastructure, with the admin kube context and the fleet and registry-push keys next to the loop. They leave. **Removed, to be re-homed in fabrikk-infra's own swamp with its own vault:** the six kube instances (`runner-pods`, `dataverket-prod-{rbac,pods,secrets,pvcs,deployments}`), the Flux HelmRelease instance and its `reset` extension, the Omni inventory, the registry mirror, the `fabrikk-runner` workflow, and the forge-wide methods of the forgejo extension (`runner_list`, `runner_prune`, `runner_registration_token`, `actions_secret_put`, `repo_rename`). The pulled `@swamp/kubernetes`, `@ginger_pappa/flux`, and `@mccormick/omni` extensions leave the lockfile. **Kept:** `fabrikk`, `forgejo` (now `tag_protection_ensure` and `pr_merge_state` only), `references`, `source-standards`. **Docs:** a "loop boundary" section in how-fabrikk-works, a sentence in the delivery skill, the code map, and the forge, workstation, and CLI pages now point to fabrikk-infra for what moved. README follow-ups updated. **Why structural rather than checked:** a 520-line `boundary-check` tool was drafted and discarded. No kube context and no such key exists here now, and `models/` and `workflows/` are protected paths, so an instance that would cross the line is a change a human sees in Forgejo. **Left for the infrastructure side:** the fabrikk vault still holds `omni/service_account_key` and `registry/ci_*`; delete them once fabrikk-infra's vault has them. The forgejo token can then be narrowed to `dataverket/fabrikk` scope. Verified: 46 extension tests pass, docs-check ok, the three workflows and the factory definition validate. This PR changes protected paths and carries no attestation tag, so `validate-attestation` reports failure, as every machinery PR does until point 3 (required status check) is decided.
refactor: move every model that reaches fabrikk-infra's deployment out of the factory
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m51s
72280e344d
The factory's program reaches the forge, with a repository-scoped token,
and the registry, anonymously. It reaches nothing fabrikk-infra deploys
and holds no credential for it. Until now this repository also carried
the models a human uses to operate that infrastructure, with the admin
kube context and the fleet and registry-push keys next to the loop.

Removed here, to be re-homed in fabrikk-infra's own swamp with its own
vault: the six kube instances, the Flux HelmRelease instance and its
reset extension, the Omni inventory, the registry mirror, the release
runner workflow, and the forge-wide methods of the forgejo extension
(runners, Actions secrets, renames). The forgejo extension keeps tag
protection (the forge half of .forgejo/attesters) and merge state. The
pulled kubernetes, flux, and omni extensions leave the lockfile.

The boundary is structural, not checked: no kube context and no such
key exists here, and models/ and workflows/ are protected paths, so an
instance that would cross it is a change a human sees. The explanation
page gains the section, the delivery skill the sentence, and the guides
point to fabrikk-infra for what moved.

Left for the infrastructure side: the fabrikk vault still holds
omni/service_account_key and registry/ci_*; delete them once
fabrikk-infra's vault has them.
chore(vault): keep only the forge token
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m46s
0df3698a68
The Omni key, the registry push credential, the release runner's two
Secret data records, and the runner registration token now live in
fabrikk-infra's vault (its PR #7); the copies were verified identical
before removal. The sops-age provider has no delete, so the keys were
unset with the sops CLI under the same recipients.
A new Forgejo token, repository read and write and nothing else, limited
to this repository (per-repository tokens since Forgejo 15). Verified from
this branch: health and pull-request reads succeed, and the same call
against dataverket/miljo is refused. The old, broad token stays in use
on the fabrikk-infra side until it has its own.
Merge main into ops-split
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m49s
157e27a7f3
Resolves the last-verified stamp of how-fabrikk-works.md and the
extension lockfile, where main added @rjeschmi/helm-chart next to the
flux entry this branch removes; main's addition is kept.
beddari deleted branch ops-split 2026-09-18 13:08:48 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk!16
No description provided.