docs(adr): 0035 extract the Kanidm-Forgejo reconciler (proposed) #48
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-docs!48
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "adr-0035-extract-reconciler"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Proposes extracting the Kanidm→Forgejo entitlement reconciler out of bitborg-infra's
Ansible-templated bash role into its own first-class, unit-tested service/repo (
gitborg/reconciler,TypeScript, OCI images via the Forgejo registry). Kanidm stays the entitlement source of truth and the
reconciler stays a pure one-way Kanidm→Forgejo projector.
realistic unit-test story and unclear ownership.
bash timer → diff proposed actions → cut over → remove the old role. Idempotent, so double-running
during burn-in is safe; backout = re-enable the old timer.
c6cafbf49e5a87e7f0de