rock
b09d0ee42b
fix: update module path from rock/ to riotpiao-poimen/ org
ci / test (push) Failing after 34s
build / Build and push image (push) Failing after 26s
2026-09-07 22:44:50 -07:00
rock
53bcbcb33c
argocd: add Image Updater annotations for auto-deploy
...
build / Build and push image (push) Successful in 3m1s
ci / test (push) Successful in 5m17s
- management-service and queue-crd watch forgejo.riotpiao.com/rock/kmsvc-manage
- Uses newest-build strategy with SHA tag filter
- Fixed queue-crd image repo and branch (prod→main)
2026-09-03 08:28:30 -07:00
rock
7f4627d010
ci: use DinD pattern matching other repos
...
build / Build and push image (push) Successful in 5m0s
ci / test (push) Successful in 5m26s
Replace docker/build-push-action with raw docker commands that work
reliably with Forgejo runners' DinD sidecar setup.
2026-09-02 20:14:57 -07:00
rock
8b303929bd
test: verify CI works without upload-artifact
build / build-push (push) Canceled after 0s
ci / test (push) Successful in 4m23s
2026-08-30 20:49:30 -07:00
rock
62792853ba
fix: remove upload-artifact actions
ci / test (push) Canceled after 0s
build / build-push (push) Canceled after 0s
2026-08-30 20:49:24 -07:00
rock
24e6e82904
test: final Forgejo CI validation
build / build-push (push) Failing after 22s
ci / test (push) Failing after 8m20s
2026-08-30 20:36:21 -07:00
rock
eab5336e87
test: final CI validation
build / build-push (push) Failing after 6m18s
ci / test (push) Failing after 7m17s
2026-08-30 09:36:57 -07:00
rock
899a900319
fix: remove broken actions/cache - tests pass without it
build / build-push (push) Failing after 17s
ci / test (push) Failing after 3m42s
2026-08-30 09:22:11 -07:00
rock
14cfd247b2
test: run CI without cache
build / build-push (push) Failing after 16s
ci / test (push) Failing after 4m1s
2026-08-30 07:34:31 -07:00
rock
12a9a6f7a9
fix: disable actions cache to debug go vet failures
ci / test (push) Canceled after 0s
build / build-push (push) Failing after 4m24s
2026-08-30 07:34:20 -07:00
rock
f85dd6b013
test: final CI test with REGISTRY_PAT
build / build-push (push) Failing after 17s
ci / test (push) Failing after 1m38s
2026-08-29 22:53:31 -07:00
rock
4743b8544d
fix: use REGISTRY_PAT secret for git auth (exists on all repos)
ci / test (push) Canceled after 0s
build / build-push (push) Failing after 18s
2026-08-29 22:53:22 -07:00
rock
36557148c1
test: trigger CI again
build / build-push (push) Failing after 17s
ci / test (push) Failing after 1m43s
2026-08-29 22:47:17 -07:00
rock
59db74dd59
fix: use GITHUB_TOKEN (Forgejo auto-injected secret)
ci / test (push) Canceled after 0s
build / build-push (push) Failing after 18s
2026-08-29 22:47:16 -07:00
rock
7aaf30843e
test: trigger CI with FORGEJO_TOKEN
build / build-push (push) Failing after 17s
ci / test (push) Failing after 1m31s
2026-08-29 22:44:49 -07:00
rock
62c3f8a1f7
fix: use FORGEJO_TOKEN instead of REGISTRY_PAT for git auth
...
ci / test (push) Canceled after 0s
build / build-push (push) Failing after 19s
Forgejo auto-injects GITHUB_TOKEN secret. Use FORGEJO_TOKEN env var
for clarity since we're retiring GitHub.
2026-08-29 22:44:45 -07:00
rock
41bf810de9
test: trigger CI with proper git auth secret
build / build-push (push) Failing after 14s
ci / test (push) Failing after 1m3s
2026-08-28 16:45:35 -07:00
rock
329002fa9b
fix: use consistent secret name for git auth in CI workflows
ci / test (push) Canceled after 0s
build / build-push (push) Failing after 17s
2026-08-28 16:45:26 -07:00
rock
454f72ebfe
test: trigger CI with Go 1.26 runner
build / build-push (push) Failing after 3m40s
ci / test (push) Failing after 3m6s
2026-08-28 16:35:39 -07:00
rock
eabf8d7459
fix: use golang runner label instead of deprecated docker label
build / build-push (push) Failing after 3m57s
ci / test (push) Failing after 15m57s
2026-08-28 15:36:24 -07:00
rock
6193d9a065
fix: sync ArgoCD apps to main branch for auto-rollout
...
ci / test (push) Canceled after 0s
build / build-push (push) Canceled after 0s
- Update kmsvc-root (root.yaml) targetRevision: prod → main
- Update management-service app targetRevision: prod → main
- Build workflow already pushes images on main commits
- Homelab ArgoCD app (60-kmsvc-manage.yaml) watches main with auto-sync enabled
- image.pullPolicy: Always + tag: latest ensures fresh images on rollouts
2026-08-28 14:54:01 -07:00
rock
f3a7e5aa9a
fix: update Go version in CI from 1.25 to 1.26
ci / test (push) Canceled after 0s
build / build-push (push) Canceled after 0s
2026-08-28 14:51:51 -07:00
Story Crater Bot
e9e925b04a
test(ci): verify main-branch CI trigger
build / build-push (push) Canceled after 0s
ci / test (push) Canceled after 0s
2026-08-21 21:07:42 -07:00
Story Crater Bot
c0803f6243
test(ci): trigger build on main
ci / test (push) Canceled after 0s
build / build-push (push) Canceled after 0s
2026-08-21 21:05:11 -07:00
Story Crater Bot
fe2d4de8bf
ci(main): trigger image builds on main branch commits
ci / test (push) Canceled after 0s
build / build-push (push) Canceled after 0s
2026-08-21 20:55:32 -07:00
Story Crater Bot
e95256daf5
test(ci): verify REGISTRY_PAT secret works
build-prod / build-push (push) Canceled after 0s
2026-08-21 20:52:44 -07:00
Story Crater Bot
7f595b51f2
fix(ci): use universal REGISTRY_PAT secret for Forgejo registry auth
build-prod / build-push (push) Canceled after 0s
2026-08-21 20:52:37 -07:00
Story Crater Bot
8e7abf411d
test(ci): trigger prod build and ArgoCD sync
build-prod / build-push (push) Canceled after 0s
2026-08-21 20:48:27 -07:00
Story Crater Bot
58efc45bf4
ci(prod): update image build workflow to push to Forgejo registry with commit SHA
build-prod / build-push (push) Canceled after 0s
2026-08-21 20:44:16 -07:00
Story Crater Bot
8f0e97dacf
ci(prod): add image build workflow for prod deployments
build-prod / build-push (push) Canceled after 0s
2026-08-21 20:36:17 -07:00
Story Crater Bot
7dca7da51d
fix(argocd): update apps and root to track prod branch, fix domain and namespaces
2026-08-21 20:36:06 -07:00
Story Crater Bot
3d52eab41d
fix(ci,deps): migrate to .gitea/workflows, update domain to forgejo.riotpiao.com/rock, fix k8s argocd config
ci / test (push) Canceled after 0s
2026-08-21 20:14:58 -07:00
Story Crater Bot
370b5a894f
(chore) add worker queue
build-push / build-push (push) Canceled after 0s
2026-08-17 12:17:39 -07:00
Story Crater Bot and Claude Sonnet 5
3e81b4454d
fix: grant queue-operator create/delete RBAC on TemporalWorker and Deployment
...
Deployed ClusterRole only had get/list/watch/update/patch on temporalworkers,
missing create/delete needed by reconcileTemporalWorker's cross-namespace
(sqs -> temporal) CreateOrUpdate call, and never granted apps/deployments at
all -- both required for the auto-provisioned TemporalWorker + backing
Deployment to reconcile successfully.
Co-Authored-By: Claude Sonnet 5 <[email protected] >
2026-08-17 09:33:16 -07:00
Story Crater Bot
f599d2d897
fix: drop dead Authentik env-var validation now that auth interceptors are unwired
2026-07-13 16:45:53 -07:00
Story Crater Bot
52b86ab8e8
feat: queue-operator auto-registers Temporal namespace before creating TemporalWorker
...
A Queue's temporal.io/namespace label was trusted as-is -- if the referenced
Temporal namespace was never registered (or typo'd), the failure only
surfaced as a worker pod silently polling a namespace that doesn't exist.
Now reconcileTemporalWorker calls RegisterNamespace (idempotent, ignores
AlreadyExists) via a direct WorkflowService gRPC client before creating the
TemporalWorker, so namespace and worker always come into existence together.
Also grant queue-operator's ClusterRole create/delete on temporalworkers
(previously missing, causing forbidden errors on the create-then-delete path).
2026-07-13 13:02:40 -07:00
Story Crater Bot
a584fb4462
fix: don't set cross-namespace owner ref on TemporalWorker
...
Queue lives in the sqs namespace while its TemporalWorker is created
in the Temporal namespace (KMSVC_TEMPORAL_NAMESPACE), so
SetControllerReference always failed with "cross-namespace owner
references are disallowed". Drop the owner ref (lifecycle already
handled explicitly in reconcileDelete) and move Spec population into
the CreateOrUpdate mutate closure so updates to an existing
TemporalWorker actually stick.
Also commit the generated TemporalWorker CRD and RBAC rules
(temporalworkers, deployments) that were previously untracked.
2026-07-13 11:32:04 -07:00
Story Crater Bot
a8060444c1
feat: disable OIDC/JWT auth interceptors on gRPC+REST server
...
Server was crash-looping on TLS trust failures fetching Authentik's OIDC
discovery document (private-CA cert not trusted by the container image).
Drop the auth wiring for now to unblock the deployment; internal/auth and
internal/api/interceptors packages are left intact for when auth comes back.
2026-07-13 10:57:28 -07:00
Story Crater Bot
b4cb3a7255
feat: build queue-operator binary alongside kmsvc-server in same image
2026-07-13 10:24:58 -07:00
Story Crater Bot
2f99f8d3d6
fix: cross-compile natively via BUILDPLATFORM/TARGETARCH instead of QEMU-emulating go build
2026-07-13 10:20:14 -07:00
Story Crater Bot
9c01076092
feat: switch to public GitHub kmsvc-proto dependency and GHCR image builds
...
Forgejo registry unreachable from cluster nodes (WireGuard overlay vs LAN
network isolation, plus host-to-ClusterIP routing gaps). Move to public
GitHub dependency and GHCR image hosting to remove the private-network
dependency entirely.
2026-07-13 10:09:41 -07:00
Story Crater Bot
c354876178
test: add comprehensive TemporalWorker tests
...
Queue reconciliation:
- TemporalWorker creation when label present
- Namespace label validation
- Kubernetes name validation
- Cleanup on Queue deletion
Validation helpers:
- isValidTemporalNamespace (8 cases)
- validateKubernetesName (9 cases)
TemporalWorker controller:
- Deployment creation and updates
- Env var injection including TEMPORAL_TASK_QUEUE
- Status tracking
- Delete handling
2026-07-11 07:30:33 -07:00
Story Crater Bot
68672c72e9
fix: wrap TemporalWorker reconciler errors with context
2026-07-11 07:30:18 -07:00
Story Crater Bot
317396e785
feat: add TemporalWorker auto-provisioning from Queue labels
...
- Validate temporal namespace and Kubernetes names
- Configurable via env vars: KMSVC_TEMPORAL_NAMESPACE, KMSVC_TEMPORAL_WORKER_IMAGE
- Set ownerReference for cascade deletion and lifecycle management
- Use CreateOrUpdate for spec propagation (idempotent)
- Clean up TemporalWorker on Queue deletion
2026-07-11 07:30:13 -07:00
Story Crater Bot and Claude Haiku 4.5
6577efc100
feat: add TemporalWorker CRD and controller
...
Add TemporalWorker CRD definition with full status tracking and
TemporalWorkerReconciler that manages Deployment lifecycle:
- Auto-generate DeepCopy methods via kubebuilder markers
- Controller creates/updates Deployments matching worker spec
- Injects TEMPORAL_FRONTEND_ADDRESS and TEMPORAL_NAMESPACE env vars
- Tracks replica count and ready status
- Handles graceful deletion via finalizer
Design document (TEMPORAL_INTEGRATION.md) describes three-phase roadmap:
- Phase 1 (MVP): Manual TemporalWorker CRD creation
- Phase 2: Auto-provisioning from Queue labels
- Phase 3: Autoscaling based on queue depth
Co-Authored-By: Claude Haiku 4.5 <[email protected] >
2026-07-11 07:29:34 -07:00
riotpiaole
674fbb6bfe
fix: consolidate all modules under homelab org for cross-repo resolution
2026-07-04 08:28:00 -07:00
riotpiaole
43ab2092df
ci: add comprehensive CI workflow for server and operator
2026-07-04 07:44:55 -07:00
riotpiaole
c7eeed2617
feat: stamp Queue shard status with availability zones
...
Resolves each shard topic's replica broker IDs (internal/kafka.Admin.
ReplicaBrokerIDs) to the topology.kubernetes.io/zone labels of the nodes
hosting those brokers (ZoneLocator), and writes the result into
ShardStatus.AvailabilityZones each reconcile. Uses mgr.GetAPIReader()
rather than the cached client for the Pod/Node lookups, since the cached
client would otherwise require cluster-wide list/watch RBAC on Pods just
to serve occasional point Gets.
2026-06-22 17:30:26 -07:00
riotpiaole
1ff1ecd563
fix: update kafaka server to kmsvc.riotpiao.homelab.com
2026-06-22 13:05:32 -07:00
riotpiaole
c7961d2599
test: add end-to-end queue send/receive/delete smoke test script
...
Creates a Queue CRD, port-forwards to management-service, fetches an
Authentik client_credentials token, then exercises send/receive/delete
through kmsvc-cli before tearing the queue down.
2026-06-22 12:23:39 -07:00