CI: self-host bitborg-infra via pull-based Actions deploy #38
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#38
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Bring bitborg-infra under the same pull-based Actions deploy used for bitborg-web (ADR 0019).
Epic: gitborg/gitborg-docs#1
supernaut refererade till detta ärende från bitborg/bitborg-docs2026-07-09 23:04:17 +00:00
Design doc drafted internally, covering the runner-controller extraction and how it unblocks this issue.
The blocker for #38 is a circular dependency: the runner that would deploy
bitborg-infrais defined insidebitborg-infra(therunner-controllerrole + its host-built image + config). A self-deploy pipeline can't safely depend on the CI substrate that lives in its own payload.Unblock = extract the controller first into
gitborg/runner-controllerwith semver-tagged images published to the Forgejo registry (ADR 0019 pattern), consumed by infra as a pinned, Renovate-updated image. The deploy runner then becomes a neutral, externally-versioned artifact — no circularity.Proposed #38 design (pull-based, host-side, Ansible-only):
main, CI runs validate/lint only and promotes adeploy/okref. No prod mutation, no secrets in CI.reconciler/runner-controller)git fetches, and on a new known-good ref runsansible-playbook site.ymllocally. Vault password + SSH stay on the host, never on a runner — the decisive advantage of pull-over-push (ADR 0019).infra-applygates (it can replace VMs / delete volumes / lock out admin SSH). Only Ansible (host config, idempotent, low blast radius) is on the auto-path; reuseci.yml's changed-area detection to keep tofu changes off it.--checkfirst and emits a converge textfile metric for Grafana alerting.Sequencing: do the controller extraction, then this. Full doc has the phased plan, risks (esp. the #63 pull-on-tag-change gap), and open questions.
Planned, building on the internal design doc.
Blocked by #201 (extract runner-controller) — this issue is Phase B. The runner that would deploy infra is built inside infra (circular dep), so #201 must land first: the controller becomes a semver-tagged registry image infra pins + Renovate-updates.
Phase B design (post-#201): on merge to
main, CI validates/lints + promotes a Forgejo Release as thedeploy/okmarker (no secrets, no prod mutation); a host-side systemd timer (sibling toreconciler) fetches and, on a new known-good release, runsansible-playbook site.ymllocally with the vault password staying on-host. Emits a converge textfile metric for Grafana.Decisions locked: bake the runner cloud-init template into the controller image (version-locked); Forgejo Release as the promotion primitive; OpenTofu stays 100% manual behind infra-apply — add only a plan-only (read-only) CI check for drift visibility, never auto-apply. Health gate inherited from ADR 0030 (
alwaysplay); fix-forward, no auto-rollback.Removing
ready-for-implementation(blocked on #201). ADRs to follow: amend 0021 (extraction), new ADR for pull-based infra deploy.CI: self-host gitborg-infra via pull-based Actions deploytill CI: self-host bitborg-infra via pull-based Actions deploy