Add CI, repo CLAUDE.md, and finish Stage 0

- .gitea/workflows/ci.yaml: fmt/lint/test, same no-actions/checkout-and-manual-clone
  shape as terdut-server's ci.yaml, and the same reasoning for why (Node/ES2022
  incompatibility on the runner image). No chart/security jobs yet -- nothing for
  either to check until Stage 6 / real controller code exists.
- CLAUDE.md: Checks + Release sections, matching the sibling repos' convention from
  the workspace-level CLAUDE.md ("each repo has its own CLAUDE.md... read it before
  working in that repo"). Release is explicitly marked not-wired-yet rather than
  copying terdut-server's, since there's no chart to release against until Stage 6.
- ROADMAP.md: moved the .release.conf bullet out of Stage 0 (it names a HELM_CHART
  this repo doesn't have yet) -- it was already duplicated into Stage 6, which is
  where it actually belongs.

Stage 0 done: `make fmt lint test` verified green locally. Real open question the CI
workflow's comments flag rather than assume past: whether storage.googleapis.com
(envtest's binary source) is reachable from this Gitea runner's container network the
way proxy.golang.org is -- terdut-server's own ci.yaml notes get.helm.sh/github.com are
not. Only running the workflow for real will confirm; the comment names the fallback
(move the job out of `container:`, like terdut-server's chart job) if it isn't.
This commit is contained in:
Niklas Ye
2026-09-30 19:22:19 +02:00
parent c97571c4c4
commit ba253b7bf7
3 changed files with 112 additions and 12 deletions
+68
View File
@@ -0,0 +1,68 @@
name: CI
# Same shape as terdut-server's ci.yaml: the release workflow gates a tag, which is
# late, so this runs the same checks on the way in instead.
#
# push is scoped to main rather than all branches so a branch pushed as part of a pull
# request is not checked twice.
#
# No actions/checkout, deliberately -- same reason as terdut-server: the runner image's
# `nodejs` package predates ES2022 static initialiser blocks, so actions/checkout@v4
# dies with `SyntaxError: Unexpected token '{'` before running. Cloning with git
# directly avoids JS actions entirely. This repo is public, so the clone needs no
# credential.
#
# `${{ }}` values are passed through `env:` and referenced as quoted shell variables --
# a ref name is attacker-influenced by anyone who can push a branch or open a PR.
on:
push:
branches: [main]
pull_request:
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
env:
REPO_URL: https://git.ryuvia.com/niklas/terdut-operator.git
jobs:
# `make fmt lint test` is exactly what a developer runs locally, so a green job here
# and a green working copy mean the same thing by construction. `test` also drives
# controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test`
# chain), which needs storage.googleapis.com to fetch the envtest kube-apiserver/etcd
# binaries -- unconfirmed whether that host is reachable from this runner's dind
# bridge the way proxy.golang.org and git.ryuvia.com are (terdut-server's ci.yaml
# flags get.helm.sh and github.com as *not* reachable from here); if this job goes
# red on the fetch specifically rather than on a real test failure, move it out of
# `container:` the way the chart job in terdut-server's ci.yaml runs on the host
# instead, for the same "can't reach a fetch target from the dind bridge" reason.
test:
runs-on: ubuntu-latest
container:
image: golang:1.26.6-bookworm
volumes:
- go-mod-cache:/go/pkg/mod
- go-build-cache:/root/.cache/go-build
- gobin-cache:/go/bin
steps:
- name: Checkout
env:
REF_NAME: ${{ github.ref_name }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
if [ -n "$HEAD_SHA" ]; then
# A pull_request ref_name is "<n>/merge", which is not a fetchable branch.
git clone "$REPO_URL" .
git checkout -q "$HEAD_SHA"
else
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
fi
- name: Format, lint and test
run: make fmt lint test
# No `chart` job yet -- there's no Helm chart until Stage 6 (ROADMAP.md). No
# `security` job yet either (govulncheck/gitleaks, as terdut-server has); add one
# alongside `test` once there's controller code worth scanning.
+25
View File
@@ -0,0 +1,25 @@
# terdut-operator
Kubebuilder/controller-runtime operator for terdut-server. See `DESIGN.md` for the
settled design (CRD catalog, reconciliation semantics, bootstrap/auth, RBAC) and
`ROADMAP.md` for the staged build plan this repo is following. `README.md` stays the
short pitch.
## Checks
`make fmt lint test` is the CI gate (`.gitea/workflows/ci.yaml` calls these targets
rather than restating them, same convention as terdut-server). `test` chains through
the Kubebuilder-scaffolded `manifests`/`generate` (`controller-gen`) and `setup-envtest`
targets automatically — everything needed lands in `bin/` (gitignored) on first run, no
separate tool install required beyond Go itself and network access to
`proxy.golang.org`/`storage.googleapis.com`.
`make test-e2e` stands up a real `kind` cluster (`kind`/`docker` must be installed) and
is not part of the CI gate yet — it has no service-image to test against until later
ROADMAP stages produce one.
## Release
Not wired yet. `.release.conf` and the release-vars Makefile target land in ROADMAP.md's
Stage 6, once there's an actual Helm chart to release — see that file before assuming
the `release` skill's terdut-server/terdut-tui conventions already apply here.
+19 -12
View File
@@ -24,18 +24,25 @@ land in Stage 5, not before.
## Stage 0 — Scaffolding & CI ## Stage 0 — Scaffolding & CI
- `go.mod` (`git.ryuvia.com/niklas/terdut-operator`) + Kubebuilder scaffold - `go.mod` (`git.ryuvia.com/niklas/terdut-operator`) + Kubebuilder v4
(`cmd/main.go`, `config/`, `Makefile`, `PROJECT`), matching terdut-server's scaffold (`cmd/main.go`, `config/`, `Makefile`, `PROJECT`), matching
Go toolchain and house style (§3). terdut-server's Go toolchain and house style (§3). Kubebuilder's own
- `.release.conf` + a release-vars Makefile target, same shape as scaffolded `Makefile` already wires `manifests`/`generate`
terdut-server's — this repo ships a Helm chart (§1, §10), so it follows (`controller-gen`) and `setup-envtest` into `test`, and `golangci-lint`
the wrapper-chart release path, not terdut-tui's binary-only one. into `lint`, all fetched on demand into `bin/` — no separate install
- Gitea Actions CI calling `fmt lint test helm-lint`, mirroring step needed beyond what `make test`/`make lint` already do.
terdut-server's `ci.yaml`/`release.yaml` convention (its `CLAUDE.md`: "a - `.release.conf` deliberately **not** added yet: it names a `HELM_CHART`
green gate here and a green pipeline are the same code, not two this repo doesn't have until Stage 6. Adding it now would either be a
descriptions of it"). stub that lies about what's releasable or dead config nobody can run —
- Install `setup-envtest`, wire it into `make test` so the `envtest` suite it lands in Stage 6, alongside the chart it describes.
(§11) runs without needing the full `kubebuilder` CLI at test time. - Gitea Actions CI calling `fmt lint test`, mirroring terdut-server's
`ci.yaml` convention (its `CLAUDE.md`: "a green gate here and a green
pipeline are the same code, not two descriptions of it") minus the
`chart`/`security` jobs, which need a chart (Stage 6) and real controller
code (Stage 1+) respectively to have anything to check.
- Drop kubebuilder's default `.github/workflows/*` scaffold — this org
runs on Gitea, not GitHub; `.gitea/workflows/ci.yaml` is the only CI this
repo has.
- Housekeeping: drop the stray `.DESIGN.md.swp` (leftover vim swapfile, - Housekeeping: drop the stray `.DESIGN.md.swp` (leftover vim swapfile,
shouldn't be committed); correct `DESIGN.md` §6/§13's "v1-blocking, not shouldn't be committed); correct `DESIGN.md` §6/§13's "v1-blocking, not
v1-shippable" language — the service-account feature it was blocking on v1-shippable" language — the service-account feature it was blocking on