a241007135eb47a481af71b9d200025b5ad44ef1
CI / test (push) Failing after 2m42s
Host-mode (previous commit) fails earlier and differently: "go: command not found" -- the runner host has no Go, so that path is dead. Checked Ryuvia/charts' act-runner/templates/networkpolicy.yaml directly rather than assuming: it's the only NetworkPolicy in the cluster, and it is explicitly deny-ingress only -- its own comment states egress is deliberately untouched, "CI pulls from registries and package indexes that are not enumerable here" (issue #128). So my earlier claim that this needs "allowlisting github.com on the runner's NetworkPolicy" was wrong: there is no in-repo egress rule governing this at all. Whatever blocks github.com from the dind bridge is outside anything Ryuvia/charts or Ryuvia/k8s expresses in a Kubernetes object -- back to container-based (matching every other Go job in this org) as the known-good shape, with `make test` left red on the envtest fetch until that's actually found.
Terdut operator
Aims to expose most config as CRD's, so end users can self-service over gitops.
See DESIGN.md for the full design: CRD catalog and specs,
reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the
relationship to charts/terdut-server. This README stays a short pitch; the
open questions it used to carry are now resolved decisions there (§2).
CRD's
terdutServers
Creates a server — Deployment, Service, database wiring, bootstrap, operator
credentials, and allowedTeams consent for cross-namespace teams. See
DESIGN.md §4.1, §4.6.
terdutTeams
- team name
- oidc groups
serverRef— explicit reference to itsTerdutServer, may be in a different namespace (one team owns the server, others self-service a team against it), gated by thatTerdutServer's ownallowedTeamsfield (DESIGN.md §2, §4.1, §4.2, §4.6)
terdutEscalationrules
- rule
teamRef— explicit reference to itsTerdutTeam(DESIGN.md §2, §4.3)
terdutDeadmansswitches
- rule
teamRef(DESIGN.md §4.4)
terdutAlertSources
teamRef(DESIGN.md §4.5)- URL/key are generated by the server at creation and surfaced only via a generated Secret, never set explicitly
Description
Languages
Go
90.8%
Makefile
6.5%
Shell
1.4%
Go Template
0.7%
Dockerfile
0.6%