feat: the registry is registry.dataverket.org; Flux and Zitadel models; registry credential in the vault #4

Merged
beddari merged 1 commit from registry-and-flux-models into main 2026-09-17 16:02:33 +00:00
Owner

Registry

zot runs in dataverket-prod at registry.dataverket.org (flux-bootstrap #2-#4, delivered gitless). Every registry.dataverket.internal (Makefile, .forgejo/workflows/release.yaml, workflow-fabrikk-release.yaml, delivery skill, README) now says registry.dataverket.org. The README follow-up list records what is left for the release runner.

Credential

fabrikk-ci is owned by the cluster repo (artifacts/zot/zot-ci-credentials.enc.yaml) and copied into the fabrikk vault as registry/ci_username / registry/ci_password, per the standard: the cluster repo owns, the factory copies.

Models

  • Pulled @ginger_pappa/flux; dataverket-prod-helm is the HelmRelease model for the cluster (context dataverket-prod-admin, wraps the pinned flux, run with _tools/bin on PATH).
  • extensions/models/flux_reset.ts adds reset (reconcile with --reset). Used once already: the cert-manager release had been failed since its first install timed out on 2026-09-09; after the reset helm-controller upgraded to v2, Ready, no pod restarted. Unit test passes (deno test, run in a container; deno is not installed on the workbench).
  • Pulled @thomas/zitadel; no model yet, it waits for a service-user key in the vault.

Protected paths touched: skills/delivery/SKILL.md, Makefile, .forgejo/.

## Registry zot runs in `dataverket-prod` at `registry.dataverket.org` (flux-bootstrap #2-#4, delivered gitless). Every `registry.dataverket.internal` (Makefile, `.forgejo/workflows/release.yaml`, `workflow-fabrikk-release.yaml`, delivery skill, README) now says `registry.dataverket.org`. The README follow-up list records what is left for the release runner. ## Credential `fabrikk-ci` is owned by the cluster repo (`artifacts/zot/zot-ci-credentials.enc.yaml`) and copied into the `fabrikk` vault as `registry/ci_username` / `registry/ci_password`, per the standard: the cluster repo owns, the factory copies. ## Models - Pulled `@ginger_pappa/flux`; `dataverket-prod-helm` is the HelmRelease model for the cluster (context `dataverket-prod-admin`, wraps the pinned `flux`, run with `_tools/bin` on PATH). - `extensions/models/flux_reset.ts` adds `reset` (reconcile with `--reset`). Used once already: the cert-manager release had been `failed` since its first install timed out on 2026-09-09; after the reset helm-controller upgraded to v2, Ready, no pod restarted. Unit test passes (`deno test`, run in a container; deno is not installed on the workbench). - Pulled `@thomas/zitadel`; no model yet, it waits for a service-user key in the vault. Protected paths touched: `skills/delivery/SKILL.md`, `Makefile`, `.forgejo/`.
The registry exists: zot in dataverket-prod, delivered gitless from flux-bootstrap. Every reference to
registry.dataverket.internal (Makefile, release workflow, fabrikk-release workflow, delivery skill, README) now says
registry.dataverket.org, and the README records what is left for the release runner.

The fabrikk-ci credential is owned by the cluster repo (flux-bootstrap artifacts/zot/zot-ci-credentials.enc.yaml)
and copied here into the fabrikk vault as registry/ci_username and registry/ci_password, as the standard says.

Pulled @ginger_pappa/flux and @thomas/zitadel. dataverket-prod-helm is the Flux HelmRelease model for the cluster;
extensions/models/flux_reset.ts adds the one method upstream lacks, reconcile with --reset, which unstuck the
cert-manager release that had been failed since its first install timed out. The Zitadel model waits for a
service-user key in the vault.
beddari deleted branch registry-and-flux-models 2026-09-17 16:02:33 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk!4
No description provided.