CI: self-host bitborg-infra via pull-based Actions deploy #38

Öppen
öppnade 2026-07-09 23:03:57 +00:00 av supernaut · 2 kommentarer
Ägare

Bring bitborg-infra under the same pull-based Actions deploy used for bitborg-web (ADR 0019).

Epic: gitborg/gitborg-docs#1

Bring bitborg-infra under the same pull-based Actions deploy used for bitborg-web (ADR 0019). Epic: gitborg/gitborg-docs#1
Upphovsperson
Ägare

Design doc drafted internally, covering the runner-controller extraction and how it unblocks this issue.

The blocker for #38 is a circular dependency: the runner that would deploy bitborg-infra is defined inside bitborg-infra (the runner-controller role + its host-built image + config). A self-deploy pipeline can't safely depend on the CI substrate that lives in its own payload.

Unblock = extract the controller first into gitborg/runner-controller with semver-tagged images published to the Forgejo registry (ADR 0019 pattern), consumed by infra as a pinned, Renovate-updated image. The deploy runner then becomes a neutral, externally-versioned artifact — no circularity.

Proposed #38 design (pull-based, host-side, Ansible-only):

  • On merge to main, CI runs validate/lint only and promotes a deploy/ok ref. No prod mutation, no secrets in CI.
  • A systemd timer on the services host (sibling to reconciler/runner-controller) git fetches, and on a new known-good ref runs ansible-playbook site.yml locally. Vault password + SSH stay on the host, never on a runner — the decisive advantage of pull-over-push (ADR 0019).
  • OpenTofu stays manual behind the infra-apply gates (it can replace VMs / delete volumes / lock out admin SSH). Only Ansible (host config, idempotent, low blast radius) is on the auto-path; reuse ci.yml's changed-area detection to keep tofu changes off it.
  • Preserve the safety gates: the "confirm" step becomes "promote the ref"; the deploy timer runs --check first and emits a converge textfile metric for Grafana alerting.

Sequencing: do the controller extraction, then this. Full doc has the phased plan, risks (esp. the #63 pull-on-tag-change gap), and open questions.

Design doc drafted internally, covering the runner-controller extraction and how it unblocks this issue. **The blocker for #38 is a circular dependency:** the runner that would deploy `bitborg-infra` is defined *inside* `bitborg-infra` (the `runner-controller` role + its host-built image + config). A self-deploy pipeline can't safely depend on the CI substrate that lives in its own payload. **Unblock = extract the controller first** into `gitborg/runner-controller` with semver-tagged images published to the Forgejo registry (ADR 0019 pattern), consumed by infra as a pinned, Renovate-updated image. The deploy runner then becomes a neutral, externally-versioned artifact — no circularity. **Proposed #38 design (pull-based, host-side, Ansible-only):** - On merge to `main`, CI runs validate/lint only and promotes a `deploy/ok` ref. **No prod mutation, no secrets in CI.** - A systemd timer on the services host (sibling to `reconciler`/`runner-controller`) `git fetch`es, and on a new known-good ref runs `ansible-playbook site.yml` **locally**. Vault password + SSH stay **on the host**, never on a runner — the decisive advantage of pull-over-push (ADR 0019). - **OpenTofu stays manual** behind the `infra-apply` gates (it can replace VMs / delete volumes / lock out admin SSH). Only Ansible (host config, idempotent, low blast radius) is on the auto-path; reuse `ci.yml`'s changed-area detection to keep tofu changes off it. - Preserve the safety gates: the "confirm" step becomes "promote the ref"; the deploy timer runs `--check` first and emits a converge textfile metric for Grafana alerting. **Sequencing:** do the controller extraction, then this. Full doc has the phased plan, risks (esp. the #63 pull-on-tag-change gap), and open questions.
Upphovsperson
Ägare

Planned, building on the internal design doc.

Blocked by #201 (extract runner-controller) — this issue is Phase B. The runner that would deploy infra is built inside infra (circular dep), so #201 must land first: the controller becomes a semver-tagged registry image infra pins + Renovate-updates.

Phase B design (post-#201): on merge to main, CI validates/lints + promotes a Forgejo Release as the deploy/ok marker (no secrets, no prod mutation); a host-side systemd timer (sibling to reconciler) fetches and, on a new known-good release, runs ansible-playbook site.yml locally with the vault password staying on-host. Emits a converge textfile metric for Grafana.

Decisions locked: bake the runner cloud-init template into the controller image (version-locked); Forgejo Release as the promotion primitive; OpenTofu stays 100% manual behind infra-apply — add only a plan-only (read-only) CI check for drift visibility, never auto-apply. Health gate inherited from ADR 0030 (always play); fix-forward, no auto-rollback.

Removing ready-for-implementation (blocked on #201). ADRs to follow: amend 0021 (extraction), new ADR for pull-based infra deploy.

Planned, building on the internal design doc. **Blocked by #201** (extract runner-controller) — this issue is *Phase B*. The runner that would deploy infra is built inside infra (circular dep), so #201 must land first: the controller becomes a semver-tagged registry image infra pins + Renovate-updates. **Phase B design (post-#201):** on merge to `main`, CI validates/lints + promotes a **Forgejo Release** as the `deploy/ok` marker (no secrets, no prod mutation); a host-side systemd timer (sibling to `reconciler`) fetches and, on a new known-good release, runs `ansible-playbook site.yml` **locally** with the vault password staying on-host. Emits a converge textfile metric for Grafana. **Decisions locked:** bake the runner cloud-init template into the controller image (version-locked); Forgejo Release as the promotion primitive; **OpenTofu stays 100% manual** behind infra-apply — add only a *plan-only* (read-only) CI check for drift visibility, never auto-apply. Health gate inherited from ADR 0030 (`always` play); fix-forward, no auto-rollback. Removing `ready-for-implementation` (blocked on #201). ADRs to follow: amend 0021 (extraction), new ADR for pull-based infra deploy.
supernaut ändrade titeln från CI: self-host gitborg-infra via pull-based Actions deploy till CI: self-host bitborg-infra via pull-based Actions deploy 2026-08-03 09:58:47 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#38
Ingen beskrivning angiven.