372fbe0660c92fb413f9e4473ef896160b2241f5
CI / test (push) Failing after 1s
Confirmed the hard way (run 852, attempt 2): setup-envtest v0.25 fetches the envtest kube-apiserver/etcd tarball from github.com's release CDN, not the legacy GCS kubebuilder-tools bucket (that bucket 403s now for any object -- no fallback there for k8s 1.37 either). github.com is unreachable from this job's container the same way terdut-server's ci.yaml already documents for get.helm.sh -- TLS handshake timeout. Dropping `container:` on this job is the same fix terdut-server's `chart` job already uses for that exact class of problem (it reaches get.helm.sh only by running on the host). Unproven for a Go job specifically -- no workflow in this org has run Go outside a container before, so this also bets the runner host has Go installed. If it fails on a missing `go` instead of the envtest fetch, that bet was wrong and the real fix is allowlisting github.com's release CDN on the runner's NetworkPolicy instead (Ryuvia/charts or Ryuvia/k8s, outside this repo).
Terdut operator
Aims to expose most config as CRD's, so end users can self-service over gitops.
See DESIGN.md for the full design: CRD catalog and specs,
reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the
relationship to charts/terdut-server. This README stays a short pitch; the
open questions it used to carry are now resolved decisions there (§2).
CRD's
terdutServers
Creates a server — Deployment, Service, database wiring, bootstrap, operator
credentials, and allowedTeams consent for cross-namespace teams. See
DESIGN.md §4.1, §4.6.
terdutTeams
- team name
- oidc groups
serverRef— explicit reference to itsTerdutServer, may be in a different namespace (one team owns the server, others self-service a team against it), gated by thatTerdutServer's ownallowedTeamsfield (DESIGN.md §2, §4.1, §4.2, §4.6)
terdutEscalationrules
- rule
teamRef— explicit reference to itsTerdutTeam(DESIGN.md §2, §4.3)
terdutDeadmansswitches
- rule
teamRef(DESIGN.md §4.4)
terdutAlertSources
teamRef(DESIGN.md §4.5)- URL/key are generated by the server at creation and surfaced only via a generated Secret, never set explicitly
Description
Languages
Go
90.8%
Makefile
6.5%
Shell
1.4%
Go Template
0.7%
Dockerfile
0.6%