Extract the Kanidm→Forgejo entitlement reconciler into its own repo (bitborg-auth-reconciler, ADR 0035) #226
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#226
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Tracking issue for the ADR 0035 extraction of the Kanidm→Forgejo entitlement reconciler out of bitborg-infra's bash script into the standalone, unit-tested TypeScript container
bitborg-auth-reconciler(the ADR 0033 / runner-controller-extraction pattern).Status
bitborg-auth-reconcilerbuilt (v1.0.0tagged + image published), 73 unit tests, faithful TS port of the bash projection logic (fail-closed, dry-run, idempotent, most-permissive-merge trap).gitborg-reconciler-nextQuadlet container runs DRY-RUN alongside the existing bash reconciler, on its own timer.keep-id) — the container's textfile metrics write cleanly.reconciler_next_apply: true+reconciler_apply: false+reconciler_enabled: false(bash timer retired), andreconciler_next_textfile_dirrepointed to the scrapednode_textfile_dirso the container ownsreconciler.prom(the deadman feed). Verified: bash timer inactive/disabled; container runAPPLY=trueexit 0 with sane projections; scraped metric fresh (status=0, staleness ≪ 30 min, single series); health gates green; idempotent re-apply.gitborg-reconciler.sh.j2+ its templates/tasks, and drop the now-stale "DRY-RUN parallel run" labels from thegitborg-reconciler-nextunit descriptions (it is the sole reconciler now, not "next").Implements ADR 0035 (bitborg-docs PR #48).
Bash-removal cleanup opened as WIP PR #227 (draft) — retires the bash reconciler + de-rehearsals the container role. Gated on the post-cutover burn-in before it merges/applies. Open question in the PR: whether to also rename
gitborg-reconciler-next→gitborg-reconciler.✅ ADR 0035 reconciler extraction complete — closing
Bash-removal cleanup (PR #227) merged + applied to prod 2026-07-28. The last open item on this tracking issue is done.
Applied + verified:
gitborg-reconciler.service/.timer, the script,reconciler.env); the bash timer is nownot-foundto systemd.reconcile complete (APPLY=true)exit 0, scrapedreconciler.promfresh (status=0,degraded=0); re-apply idempotent (changed=0).End state: the
bitborg-auth-reconcilercontainer is the sole Kanidm→Forgejo reconciler (ADR 0035 / ADR 0033 pattern). Thegitborg-reconciler-nextunit/var names were kept (a historical artifact of the parallel run); an optional rename togitborg-reconcilerwas raised in #227 and can be a future tidy-up if wanted.Implements ADR 0035 (bitborg-docs PR #48).
Extract the Kanidm→Forgejo entitlement reconciler into its own repo (gitborg-auth-reconciler, ADR 0035)till Extract the Kanidm→Forgejo entitlement reconciler into its own repo (bitborg-auth-reconciler, ADR 0035)