feat(reconciler): stage ADR 0035 container for dry-run parallel-run (#202) #217
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!217
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/202-reconciler-container-dryrun"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Stages the ADR 0035 reconciler container extraction (#202) for a dry-run parallel-run rehearsal, without disturbing the existing bash reconciler.
What
Runs the new
bitborg-auth-reconcilercontainer image (the Kanidm→Forgejo entitlement reconciler, extracted into its own repo per ADR 0035) alongside the current bash timer, in dry-run, so its proposed actions can be diffed run-for-run before cutover.gitborg-reconciler-next(rootless podman) on its own 5-min timer, with the#63pull-on-change guard; rejects:latest/AutoUpdate=registry.RECONCILE_APPLY=false— it reads Kanidm + Forgejo and logsDRY-RUN: would …, never writes.reconciler.promand theReconcilerStaledeadman are untouched.docs/runbook.md: the parallel-run rehearsal procedure (diff → flip).Safety
The existing bash
gitborg-reconcilertimer/service/script are unchanged and remain the only applier. The new timer is image-present-gated, so applying before the image exists just stages inert units.pnpm ansible:check,ansible-lint(production profile), and Prettier are clean; the bash reconciler templates have a zero-line diff vsmain.Sequencing (coordinated cutover, not merge-and-forget)
v1.0.0inbitborg-auth-reconciler→ the release workflow builds…:v1.0.0.gitborg-reconciler-next's dry-run journal against the bash reconciler's proposed actions for several cycles.reconciler_next_apply: true,reconciler_apply: false, disable the bash timer) and retire the bash role — a documented follow-up, guarded by a double-apply assert.Review notes
Network=hoston the container soRESOLVE_IP=127.0.0.1reaches the host's local Caddy (valid certs, no NAT hairpin) — faithful to the on-host bash script, vs the runner-controller's container-network-by-name pattern.Implements #202. Refs ADR 0035.
Prep the infra side of the ADR 0035 cutover: run the extracted gitborg-auth-reconciler container (pinned image) in DRY-RUN alongside the existing bash reconciler for a run-for-run comparison, before any flip. - pin gitborg_reconciler_image{,_tag} (v1.0.0) in group_vars with a Renovate annotation, alongside web_image/forgejo_image (never :latest, no AutoUpdate) - add a gitborg-reconciler-next rootless Quadlet oneshot container + its own timer + a full-contract EnvironmentFile mapped from the existing role vars and the two reused vault tokens (config.ts contract); Network=host so RESOLVE_IP reaches the local Caddy like the on-host bash script - pull-on-change (#63) before install; start the timer only once the pinned image is present, so a normal apply before v1.0.0 is built just stages units - RECONCILE_APPLY=false enforced, plus a double-apply assert and a reject-latest assert; the bash gitborg-reconciler timer is untouched and stays the only applier - dedicated non-scraped textfile dir to avoid clashing with the bash reconciler.prom / ReconcilerStale deadman