docs: refresh stale documentation to match ansible/opentofu/production #31
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!31
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "docs/refresh-staleness"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Summary
Audited all documentation in
bitborg-infraagainst the actualansible/,opentofu/, and live production, and corrected the drift that had accumulated (ADRs 0021–0024, the dedicated backup volume, ephemeral runners, self-hosted Renovate, state encryption, off-site backups). Verification was done with four parallel read-only audit passes cross-checked against code, plus live Prometheus checks (Renovate + runner-controller metrics confirm both are running; backup volume confirmed 100 GB).Mermaid diagrams (8 total, all re-verified)
AES-256→ age / ChaCha20-Poly1305 (it contradicted its own prose)./srv/gitborg-backupvolume.Prose / factual corrections
CLAUDE.md0001–0021→0001–0024; roles list +renovate,registry-mirror(14); noteencryption.tofu+ encrypted state; backup off-site Bahnhof → Hetzner (enabled)README.mdopentofu/README.md.tf→.tofu; addedencryption/monitoring/ephemeral-runnersfiles; documented the now-mandatoryTF_VAR_state_encryption_passphrasestepdocs/runbook.mdrunner_controller_dry_runshipsfalsenottrue(rollout text corrected); added the online backup-volume grow procedure (was missing) + current 100 GB sizedocs/design/forgejo-actions-runners.mdrunner.tofu/roles/runner; pool labelgitborg-shared→cidocs/design/monitoring.md15 d→7 d(matches privacy policy)docs/roadmap.mdREADME-runner-image.mdv12.8→v12.12.0; Debian 12 → 13; dropped retired standing runner VM; download hostdata.→code.forgejo.orgdocs/bahnhof-vpc.mdceph-nvmeprice1→5SEK/GB (matchescost/prices.yml+ its own table)docs/decisions/0012Follow-up flagged (NOT in this PR — it's a code issue, not a doc issue)
roles/runner-controller/defaults/main.ymlsetsrunner_controller_dry_run: false, but the role's own code comments (defaults,controller.py, container template) all say "default is true". So a fresh--tags runner-controllerapply runs live (boots/reaps real VMs) contrary to the comments' intent. This PR fixes the docs to match reality; the code default + contradictory comments should be reconciled separately (likely flip the default back totrue).supernaut refererade till denna ändringsförfrågan2026-07-21 19:29:42 +00:00