docs: the forge is Flux's source; portable cluster and vault definitions #3

Merged
beddari merged 2 commits from cluster-access into main 2026-09-17 13:24:52 +00:00
Owner

Outcome

The README states the delivery truth as it now is: git.dataverket.org is the source of record and Flux reads it directly. The factory has two identities on the cluster, read-only for itself and admin for setup, and nothing committed names a home directory, so the definitions work for every developer.

What changed

  • README: the forge is the source for fabrikk, miljo, and flux-bootstrap, Codeberg is a push mirror, Flux in dataverket-prod reads the forge since ed79b27. Lesson recorded: flux bootstrap owns fields on the live GitRepository through server-side apply, so removing secretRef in git alone did nothing until the live object was patched.
  • Kubernetes models carry only a context name: runner-pods on fabrikk-readers, the new dataverket-prod-rbac on dataverket-prod-admin. Contexts come from the developer's default kubeconfig, where omnictl kubeconfig merges by default. The admin model is named after the cluster because that identity is cluster-wide.
  • The fabrikk vault reads vaults/fabrikk.enc.json relative to the repo root and leaves ageKeyFile empty, so sops uses the host's default keys file, which holds the factory identity.

Protected paths

Touches models/, vaults/, README.md. No factory run behind this PR.

Test plan

  • With no KUBECONFIG set: swamp model method run runner-pods list shows the runner pod; swamp model method run dataverket-prod-rbac listRoleBindings records the fabrikk-readers binding
  • swamp vault list-keys fabrikk lists both keys; swamp model method run forgejo health green through the vault
  • flux get sources git -n flux-system shows the forge URL, ready, at ed79b27
## Outcome The README states the delivery truth as it now is: git.dataverket.org is the source of record and Flux reads it directly. The factory has two identities on the cluster, read-only for itself and admin for setup, and nothing committed names a home directory, so the definitions work for every developer. ## What changed - README: the forge is the source for fabrikk, miljo, and flux-bootstrap, Codeberg is a push mirror, Flux in `dataverket-prod` reads the forge since `ed79b27`. Lesson recorded: `flux bootstrap` owns fields on the live `GitRepository` through server-side apply, so removing `secretRef` in git alone did nothing until the live object was patched. - Kubernetes models carry only a context name: `runner-pods` on `fabrikk-readers`, the new `dataverket-prod-rbac` on `dataverket-prod-admin`. Contexts come from the developer's default kubeconfig, where `omnictl kubeconfig` merges by default. The admin model is named after the cluster because that identity is cluster-wide. - The `fabrikk` vault reads `vaults/fabrikk.enc.json` relative to the repo root and leaves `ageKeyFile` empty, so sops uses the host's default keys file, which holds the factory identity. ## Protected paths Touches `models/`, `vaults/`, `README.md`. No factory run behind this PR. ## Test plan - With no `KUBECONFIG` set: `swamp model method run runner-pods list` shows the runner pod; `swamp model method run dataverket-prod-rbac listRoleBindings` records the `fabrikk-readers` binding - `swamp vault list-keys fabrikk` lists both keys; `swamp model method run forgejo health` green through the vault - `flux get sources git -n flux-system` shows the forge URL, ready, at `ed79b27`
- README: git.dataverket.org is the source of record for fabrikk, miljo,
  and flux-bootstrap (Codeberg is a push mirror); Flux in dataverket-prod
  reads the forge since ed79b27. Lesson from the switch: flux bootstrap owns
  fields on the live GitRepository via server-side apply, so a git-only
  removal of secretRef did nothing until the live object was patched.
- runner-pods pinned to context fabrikk-readers (view in forgejo-runners
  only); new dataverket-prod-rbac on context dataverket-prod-admin for
  setup work, named after the cluster because that identity is not scoped
  to the factory.
A path under /home/<user> in a committed definition breaks for every other
developer. Now:

- Kubernetes models carry only a context name (fabrikk-readers,
  dataverket-prod-admin); the context comes from the developer's default
  kubeconfig, where omnictl kubeconfig merges by default.
- The fabrikk vault reads vaults/fabrikk.enc.json relative to the repo root
  and leaves ageKeyFile empty, so sops uses the host's default keys file
  (~/.config/sops/age/keys.txt), which holds the factory identity.
- README: the convention, in the layout table and the release
  infrastructure notes.
beddari changed title from docs: the forge is Flux's source; two kubeconfig contexts for the cluster to docs: the forge is Flux's source; portable cluster and vault definitions 2026-09-17 13:24:09 +00:00
beddari deleted branch cluster-access 2026-09-17 13:24:52 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk!3
No description provided.