refactor: move every model that reaches fabrikk-infra's deployment out of the factory #16
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ops-split"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The factory's program reaches the forge, with a repository-scoped token, and the registry, anonymously. It reaches nothing fabrikk-infra deploys and holds no credential for it. This repository also carried the models a human uses to operate that infrastructure, with the admin kube context and the fleet and registry-push keys next to the loop. They leave.
Removed, to be re-homed in fabrikk-infra's own swamp with its own vault: the six kube instances (
runner-pods,dataverket-prod-{rbac,pods,secrets,pvcs,deployments}), the Flux HelmRelease instance and itsresetextension, the Omni inventory, the registry mirror, thefabrikk-runnerworkflow, and the forge-wide methods of the forgejo extension (runner_list,runner_prune,runner_registration_token,actions_secret_put,repo_rename). The pulled@swamp/kubernetes,@ginger_pappa/flux, and@mccormick/omniextensions leave the lockfile.Kept:
fabrikk,forgejo(nowtag_protection_ensureandpr_merge_stateonly),references,source-standards.Docs: a "loop boundary" section in how-fabrikk-works, a sentence in the delivery skill, the code map, and the forge, workstation, and CLI pages now point to fabrikk-infra for what moved. README follow-ups updated.
Why structural rather than checked: a 520-line
boundary-checktool was drafted and discarded. No kube context and no such key exists here now, andmodels/andworkflows/are protected paths, so an instance that would cross the line is a change a human sees in Forgejo.Left for the infrastructure side: the fabrikk vault still holds
omni/service_account_keyandregistry/ci_*; delete them once fabrikk-infra's vault has them. The forgejo token can then be narrowed todataverket/fabrikkscope.Verified: 46 extension tests pass, docs-check ok, the three workflows and the factory definition validate. This PR changes protected paths and carries no attestation tag, so
validate-attestationreports failure, as every machinery PR does until point 3 (required status check) is decided.