feat(reconciler): stage ADR 0035 container for dry-run parallel-run (#202) #217

Sammanfogat
supernaut sammanfogade 2 incheckningar från feat/202-reconciler-container-dryrun in i main 2026-07-26 19:18:06 +00:00
Ägare

Stages the ADR 0035 reconciler container extraction (#202) for a dry-run parallel-run rehearsal, without disturbing the existing bash reconciler.

What

Runs the new bitborg-auth-reconciler container image (the Kanidm→Forgejo entitlement reconciler, extracted into its own repo per ADR 0035) alongside the current bash timer, in dry-run, so its proposed actions can be diffed run-for-run before cutover.

  • New Quadlet oneshot container gitborg-reconciler-next (rootless podman) on its own 5-min timer, with the #63 pull-on-change guard; rejects :latest / AutoUpdate=registry.
  • RECONCILE_APPLY=false — it reads Kanidm + Forgejo and logs DRY-RUN: would …, never writes.
  • EnvironmentFile emits the new repo's full config contract, mapped from the existing role vars + the reused vaulted reconciler tokens (no new secrets).
  • Writes last-run metrics to a dedicated, non-scraped textfile dir, so the bash reconciler.prom and the ReconcilerStale deadman are untouched.
  • docs/runbook.md: the parallel-run rehearsal procedure (diff → flip).

Safety

The existing bash gitborg-reconciler timer/service/script are unchanged and remain the only applier. The new timer is image-present-gated, so applying before the image exists just stages inert units. pnpm ansible:check, ansible-lint (production profile), and Prettier are clean; the bash reconciler templates have a zero-line diff vs main.

Sequencing (coordinated cutover, not merge-and-forget)

  1. Tag v1.0.0 in bitborg-auth-reconciler → the release workflow builds …:v1.0.0.
  2. Apply this branch → both timers run; diff gitborg-reconciler-next's dry-run journal against the bash reconciler's proposed actions for several cycles.
  3. Once they match: flip (reconciler_next_apply: true, reconciler_apply: false, disable the bash timer) and retire the bash role — a documented follow-up, guarded by a double-apply assert.

Review notes

  • Network=host on the container so RESOLVE_IP=127.0.0.1 reaches the host's local Caddy (valid certs, no NAT hairpin) — faithful to the on-host bash script, vs the runner-controller's container-network-by-name pattern.
  • Metrics dir is non-scraped during the rehearsal (the journal is the diff surface); can be wired to a separately-labelled scrape later.

Implements #202. Refs ADR 0035.

Stages the ADR 0035 reconciler container extraction (#202) for a **dry-run parallel-run rehearsal**, without disturbing the existing bash reconciler. ## What Runs the new `bitborg-auth-reconciler` container image (the Kanidm→Forgejo entitlement reconciler, extracted into its own repo per ADR 0035) alongside the current bash timer, in **dry-run**, so its proposed actions can be diffed run-for-run before cutover. - New Quadlet **oneshot container** `gitborg-reconciler-next` (rootless podman) on its own 5-min timer, with the `#63` pull-on-change guard; rejects `:latest` / `AutoUpdate=registry`. - `RECONCILE_APPLY=false` — it reads Kanidm + Forgejo and logs `DRY-RUN: would …`, never writes. - EnvironmentFile emits the new repo's full config contract, mapped from the existing role vars + the **reused** vaulted reconciler tokens (no new secrets). - Writes last-run metrics to a **dedicated, non-scraped** textfile dir, so the bash `reconciler.prom` and the `ReconcilerStale` deadman are untouched. - `docs/runbook.md`: the parallel-run rehearsal procedure (diff → flip). ## Safety The existing bash `gitborg-reconciler` timer/service/script are **unchanged** and remain the only applier. The new timer is **image-present-gated**, so applying before the image exists just stages inert units. `pnpm ansible:check`, `ansible-lint` (production profile), and Prettier are clean; the bash reconciler templates have a zero-line diff vs `main`. ## Sequencing (coordinated cutover, not merge-and-forget) 1. Tag `v1.0.0` in `bitborg-auth-reconciler` → the release workflow builds `…:v1.0.0`. 2. Apply this branch → both timers run; diff `gitborg-reconciler-next`'s dry-run journal against the bash reconciler's proposed actions for several cycles. 3. Once they match: flip (`reconciler_next_apply: true`, `reconciler_apply: false`, disable the bash timer) and retire the bash role — a documented follow-up, guarded by a double-apply assert. ## Review notes - **`Network=host`** on the container so `RESOLVE_IP=127.0.0.1` reaches the host's local Caddy (valid certs, no NAT hairpin) — faithful to the on-host bash script, vs the runner-controller's container-network-by-name pattern. - Metrics dir is non-scraped during the rehearsal (the journal is the diff surface); can be wired to a separately-labelled scrape later. Implements #202. Refs ADR 0035.
supernaut lade till 2 incheckningar 2026-07-26 18:57:16 +00:00
Prep the infra side of the ADR 0035 cutover: run the extracted
gitborg-auth-reconciler container (pinned image) in DRY-RUN alongside the
existing bash reconciler for a run-for-run comparison, before any flip.

- pin gitborg_reconciler_image{,_tag} (v1.0.0) in group_vars with a Renovate
  annotation, alongside web_image/forgejo_image (never :latest, no AutoUpdate)
- add a gitborg-reconciler-next rootless Quadlet oneshot container + its own
  timer + a full-contract EnvironmentFile mapped from the existing role vars and
  the two reused vault tokens (config.ts contract); Network=host so RESOLVE_IP
  reaches the local Caddy like the on-host bash script
- pull-on-change (#63) before install; start the timer only once the pinned
  image is present, so a normal apply before v1.0.0 is built just stages units
- RECONCILE_APPLY=false enforced, plus a double-apply assert and a reject-latest
  assert; the bash gitborg-reconciler timer is untouched and stays the only applier
- dedicated non-scraped textfile dir to avoid clashing with the bash
  reconciler.prom / ReconcilerStale deadman
docs(runbook): document the adr 0035 reconciler dry-run parallel-run rehearsal
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m23s
38998841bf
How to run gitborg-reconciler-next in dry-run beside the bash reconciler, diff
proposed actions run-for-run for several cycles, and the follow-up flip (set
reconciler_next_apply + clear reconciler_apply, disable the bash timer). Notes
the v1.0.0 build prerequisite and the image-present gate.
supernaut sammanfogade incheckning b643c12f9d till main 2026-07-26 19:18:06 +00:00
supernaut tog bort grenen feat/202-reconciler-container-dryrun 2026-07-26 19:18:06 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!217
Ingen beskrivning angiven.