Extract the Kanidm→Forgejo entitlement reconciler into its own repo (bitborg-auth-reconciler, ADR 0035) #226

Stängd
öppnade 2026-07-27 12:17:02 +00:00 av supernaut · 2 kommentarer
Ägare

Tracking issue for the ADR 0035 extraction of the Kanidm→Forgejo entitlement reconciler out of bitborg-infra's bash script into the standalone, unit-tested TypeScript container bitborg-auth-reconciler (the ADR 0033 / runner-controller-extraction pattern).

Supersedes the erroneous bitborg-infra#202 reference in ADR 0035 and the reconciler PRs — #202 is an unrelated merged PR. ADR 0035 (docs PR #48) and PR #221 are being corrected to point here.

Status

  • ✅ New repo bitborg-auth-reconciler built (v1.0.0 tagged + image published), 73 unit tests, faithful TS port of the bash projection logic (fail-closed, dry-run, idempotent, most-permissive-merge trap).
  • ✅ Staging landed (PR #217): a gitborg-reconciler-next Quadlet container runs DRY-RUN alongside the existing bash reconciler, on its own timer.
  • ✅ Metric-write fix applied (PR #218, keep-id) — the container's textfile metrics write cleanly.
  • ✅ Dry-run parallel-run validated — 6+ consecutive 5-min cycles where the container's proposed projections match the bash reconciler's applied ones, per user (quota group, org_create, actions, Renovate, org, legacy purge).
  • ✅ Flip to apply — PR #221 merged + applied to prod 2026-07-27: reconciler_next_apply: true + reconciler_apply: false + reconciler_enabled: false (bash timer retired), and reconciler_next_textfile_dir repointed to the scraped node_textfile_dir so the container owns reconciler.prom (the deadman feed). Verified: bash timer inactive/disabled; container run APPLY=true exit 0 with sane projections; scraped metric fresh (status=0, staleness ≪ 30 min, single series); health gates green; idempotent re-apply.
  • ⏳ Follow-up after burn-in: remove the bash gitborg-reconciler.sh.j2 + its templates/tasks, and drop the now-stale "DRY-RUN parallel run" labels from the gitborg-reconciler-next unit descriptions (it is the sole reconciler now, not "next").

Implements ADR 0035 (bitborg-docs PR #48).

Tracking issue for the **ADR 0035** extraction of the Kanidm→Forgejo entitlement reconciler out of bitborg-infra's bash script into the standalone, unit-tested TypeScript container **`bitborg-auth-reconciler`** (the ADR 0033 / runner-controller-extraction pattern). > Supersedes the erroneous `bitborg-infra#202` reference in ADR 0035 and the reconciler PRs — `#202` is an unrelated merged PR. ADR 0035 (docs PR #48) and PR #221 are being corrected to point here. ## Status - ✅ New repo `bitborg-auth-reconciler` built (`v1.0.0` tagged + image published), 73 unit tests, faithful TS port of the bash projection logic (fail-closed, dry-run, idempotent, most-permissive-merge trap). - ✅ Staging landed (**PR #217**): a `gitborg-reconciler-next` Quadlet container runs **DRY-RUN** alongside the existing bash reconciler, on its own timer. - ✅ Metric-write fix applied (**PR #218**, `keep-id`) — the container's textfile metrics write cleanly. - ✅ **Dry-run parallel-run validated** — 6+ consecutive 5-min cycles where the container's proposed projections match the bash reconciler's applied ones, per user (quota group, org_create, actions, Renovate, org, legacy purge). - ✅ **Flip to apply** — **PR #221** merged + applied to prod 2026-07-27: `reconciler_next_apply: true` + `reconciler_apply: false` + `reconciler_enabled: false` (bash timer retired), and `reconciler_next_textfile_dir` repointed to the scraped `node_textfile_dir` so the container owns `reconciler.prom` (the deadman feed). Verified: bash timer inactive/disabled; container run `APPLY=true` exit 0 with sane projections; scraped metric fresh (`status=0`, staleness ≪ 30 min, single series); health gates green; idempotent re-apply. - ⏳ Follow-up after burn-in: remove the bash `gitborg-reconciler.sh.j2` + its templates/tasks, and drop the now-stale "DRY-RUN parallel run" labels from the `gitborg-reconciler-next` unit descriptions (it is the sole reconciler now, not "next"). Implements ADR 0035 (bitborg-docs PR #48).
Upphovsperson
Ägare

Bash-removal cleanup opened as WIP PR #227 (draft) — retires the bash reconciler + de-rehearsals the container role. Gated on the post-cutover burn-in before it merges/applies. Open question in the PR: whether to also rename gitborg-reconciler-next → gitborg-reconciler.

Bash-removal cleanup opened as **WIP PR #227** (draft) — retires the bash reconciler + de-rehearsals the container role. Gated on the post-cutover burn-in before it merges/applies. Open question in the PR: whether to also rename `gitborg-reconciler-next` → `gitborg-reconciler`.
Upphovsperson
Ägare

✅ ADR 0035 reconciler extraction complete — closing

Bash-removal cleanup (PR #227) merged + applied to prod 2026-07-28. The last open item on this tracking issue is done.

Applied + verified:

  • All 4 bash artifacts removed from the host (gitborg-reconciler.service/.timer, the script, reconciler.env); the bash timer is now not-found to systemd.
  • Container reconciler unaffected: timer active/enabled, on-demand run reconcile complete (APPLY=true) exit 0, scraped reconciler.prom fresh (status=0, degraded=0); re-apply idempotent (changed=0).
  • Preceded by a clean 24h+ burn-in: 300/300 5-min cycles, zero failed runs, max staleness 7 min (« 30), no reconciler alerts.

End state: the bitborg-auth-reconciler container is the sole Kanidm→Forgejo reconciler (ADR 0035 / ADR 0033 pattern). The gitborg-reconciler-next unit/var names were kept (a historical artifact of the parallel run); an optional rename to gitborg-reconciler was raised in #227 and can be a future tidy-up if wanted.

Implements ADR 0035 (bitborg-docs PR #48).

## ✅ ADR 0035 reconciler extraction complete — closing Bash-removal cleanup (**PR #227**) merged + applied to prod 2026-07-28. The last open item on this tracking issue is done. **Applied + verified:** - All 4 bash artifacts removed from the host (`gitborg-reconciler.service`/`.timer`, the script, `reconciler.env`); the bash timer is now `not-found` to systemd. - Container reconciler unaffected: timer active/enabled, on-demand run `reconcile complete (APPLY=true)` exit 0, scraped `reconciler.prom` fresh (`status=0`, `degraded=0`); re-apply idempotent (`changed=0`). - Preceded by a clean **24h+ burn-in**: 300/300 5-min cycles, zero failed runs, max staleness 7 min (« 30), no reconciler alerts. **End state:** the `bitborg-auth-reconciler` container is the sole Kanidm→Forgejo reconciler (ADR 0035 / ADR 0033 pattern). The `gitborg-reconciler-next` unit/var names were kept (a historical artifact of the parallel run); an optional rename to `gitborg-reconciler` was raised in #227 and can be a future tidy-up if wanted. Implements ADR 0035 (bitborg-docs PR #48).
supernaut ändrade titeln från Extract the Kanidm→Forgejo entitlement reconciler into its own repo (gitborg-auth-reconciler, ADR 0035) till Extract the Kanidm→Forgejo entitlement reconciler into its own repo (bitborg-auth-reconciler, ADR 0035) 2026-08-03 09:58:35 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#226
Ingen beskrivning angiven.