- TypeScript 73.5%
- JavaScript 17.8%
- Dockerfile 8.7%
| Filnamn | Senaste incheckningsmeddelande | Senaste incheckningsdatum |
|---|---|---|
|
Alla kontroller lyckades
ci / ci (push) Successful in 59s
Docs only. The readme now states the release order: merge the version bump, verify `main` and `package.json`, then tag. A tag pushed before the bump merges builds the wrong commit. Co-authored-by: Johannes <445378+supernaut@users.noreply.github.com> Reviewed-on: #50 |
||
| .forgejo/workflows | ||
| .vscode | ||
| src | ||
| .env.example | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .prettierignore | ||
| .prettierrc.json | ||
| Containerfile | ||
| eslint.config.mjs | ||
| lefthook.json | ||
| LICENSE | ||
| package.json | ||
| pnpm-lock.yaml | ||
| pnpm-workspace.yaml | ||
| README.md | ||
| renovate.json | ||
| tsconfig.build.json | ||
| tsconfig.json | ||
| vitest.config.ts | ||
bitborg-reconcile-trigger
A tiny, credential-less auth shim that turns an authenticated HTTP request into a reconcile-trigger sentinel write for bitborg — the network ingress adapter of the event-driven reconcile trigger (ADR 0037).
What it does
The entitlement reconciler (ADR 0035)
is a oneshot fired promptly by a systemd .path unit when a sentinel file appears. Co-located
bitborg-web writes that sentinel directly. Callers that can only reach the host over HTTP — the
Forgejo repository webhook (new repos) and the future payment service (cross-host) — go
through this shim instead:
POST / (Authorization: Bearer <token>) → validate → touch the sentinel → 204
That's the whole job. The shim:
- holds no Forgejo or Kanidm credentials — a valid token can at most request a reconcile the 5-minute timer would run anyway, never dictate its outcome;
- validates a per-source bearer token (constant-time), mapping it to a
sourcelabel used only for logging; - fails closed — refuses to start without a sentinel path and at least one token.
It deliberately does not terminate TLS or do IP filtering: in production it runs as a container
on the internal podman network (reached by name), with TLS + the firewall/allowlist handled at the
edge (Caddy + nftables) by bitborg-infra.
Endpoints
| Method | Path | Auth | Response |
|---|---|---|---|
GET |
/healthz |
none | 200 (container health probe) |
POST |
any | Bearer | 204 on valid token (sentinel written) |
POST |
any | bad/absent | 401 |
| other | — | — | 405 |
Configuration
See .env.example: RECONCILE_SHIM_SENTINEL, RECONCILE_SHIM_TOKENS
(source=token,…), RECONCILE_SHIM_PORT (default 8099).
Development
pnpm install
pnpm test # vitest
pnpm lint # eslint + prettier
pnpm typecheck
pnpm build # → dist/
pnpm dev # run from source
Deployed as a pinned container image (built + pushed by Forgejo Actions on a v* tag); consumed by
bitborg-infra, with Renovate opening the bump PR — the same mechanics as the reconciler
(ADR 0033 / ADR 0035). No :latest. Release order: merge the version bump, verify main and package.json, then tag. A tag pushed before the bump merges builds the wrong commit.