Add CI, repo CLAUDE.md, and finish Stage 0

- .gitea/workflows/ci.yaml: fmt/lint/test, same no-actions/checkout-and-manual-clone
  shape as terdut-server's ci.yaml, and the same reasoning for why (Node/ES2022
  incompatibility on the runner image). No chart/security jobs yet -- nothing for
  either to check until Stage 6 / real controller code exists.
- CLAUDE.md: Checks + Release sections, matching the sibling repos' convention from
  the workspace-level CLAUDE.md ("each repo has its own CLAUDE.md... read it before
  working in that repo"). Release is explicitly marked not-wired-yet rather than
  copying terdut-server's, since there's no chart to release against until Stage 6.
- ROADMAP.md: moved the .release.conf bullet out of Stage 0 (it names a HELM_CHART
  this repo doesn't have yet) -- it was already duplicated into Stage 6, which is
  where it actually belongs.

Stage 0 done: `make fmt lint test` verified green locally. Real open question the CI
workflow's comments flag rather than assume past: whether storage.googleapis.com
(envtest's binary source) is reachable from this Gitea runner's container network the
way proxy.golang.org is -- terdut-server's own ci.yaml notes get.helm.sh/github.com are
not. Only running the workflow for real will confirm; the comment names the fallback
(move the job out of `container:`, like terdut-server's chart job) if it isn't.
This commit is contained in:
Niklas Ye
2026-09-30 19:22:19 +02:00
parent c97571c4c4
commit ba253b7bf7
3 changed files with 112 additions and 12 deletions
+19 -12
View File
@@ -24,18 +24,25 @@ land in Stage 5, not before.
## Stage 0 — Scaffolding & CI
- `go.mod` (`git.ryuvia.com/niklas/terdut-operator`) + Kubebuilder scaffold
(`cmd/main.go`, `config/`, `Makefile`, `PROJECT`), matching terdut-server's
Go toolchain and house style (§3).
- `.release.conf` + a release-vars Makefile target, same shape as
terdut-server's — this repo ships a Helm chart (§1, §10), so it follows
the wrapper-chart release path, not terdut-tui's binary-only one.
- Gitea Actions CI calling `fmt lint test helm-lint`, mirroring
terdut-server's `ci.yaml`/`release.yaml` convention (its `CLAUDE.md`: "a
green gate here and a green pipeline are the same code, not two
descriptions of it").
- Install `setup-envtest`, wire it into `make test` so the `envtest` suite
(§11) runs without needing the full `kubebuilder` CLI at test time.
- `go.mod` (`git.ryuvia.com/niklas/terdut-operator`) + Kubebuilder v4
scaffold (`cmd/main.go`, `config/`, `Makefile`, `PROJECT`), matching
terdut-server's Go toolchain and house style (§3). Kubebuilder's own
scaffolded `Makefile` already wires `manifests`/`generate`
(`controller-gen`) and `setup-envtest` into `test`, and `golangci-lint`
into `lint`, all fetched on demand into `bin/` — no separate install
step needed beyond what `make test`/`make lint` already do.
- `.release.conf` deliberately **not** added yet: it names a `HELM_CHART`
this repo doesn't have until Stage 6. Adding it now would either be a
stub that lies about what's releasable or dead config nobody can run —
it lands in Stage 6, alongside the chart it describes.
- Gitea Actions CI calling `fmt lint test`, mirroring terdut-server's
`ci.yaml` convention (its `CLAUDE.md`: "a green gate here and a green
pipeline are the same code, not two descriptions of it") minus the
`chart`/`security` jobs, which need a chart (Stage 6) and real controller
code (Stage 1+) respectively to have anything to check.
- Drop kubebuilder's default `.github/workflows/*` scaffold — this org
runs on Gitea, not GitHub; `.gitea/workflows/ci.yaml` is the only CI this
repo has.
- Housekeeping: drop the stray `.DESIGN.md.swp` (leftover vim swapfile,
shouldn't be committed); correct `DESIGN.md` §6/§13's "v1-blocking, not
v1-shippable" language — the service-account feature it was blocking on