diff --git a/CLAUDE.md b/CLAUDE.md index 734a9ee..278c78c 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -14,7 +14,7 @@ Preconditions and the plan, without side effects: Config is `.release.conf` here plus `make release-vars`. The process itself lives in `~/.claude/skills/release/`; why it is shaped this way is in README.md §Releasing. -Two things about this repo specifically: +Three things about this repo specifically: - **The image is scanned after it is published, not before.** `scan-image` runs trivy against the pushed image, because trivy cannot read a locally built one on this runner. @@ -25,6 +25,16 @@ Two things about this repo specifically: so `chart-bump` needs `--image "$IMAGE"` to know which one moves. That sidecar backs up SQLite; the Postgres move (#2) retires it in favour of a `postgresql` CR with a k8up `pg_dump` annotation, after which only the app image's tag is left. +- **Two demos pin this image, and `chart-bump` moves neither.** `terdut-demo` in + `Ryuvia/charts` is a `TerdutServer` CR that terdut-operator reconciles, and its + `values.yaml` `image.tag` is meant to match production's pin (same digest). The kind demo + in terdut-operator (`examples/demo/01-server.yaml`) pins a tag too. A release only bumps + the `terdut-server` wrapper, so both drift silently: `terdut-demo` sat at v0.37.0 through + v0.41.0-v0.43.0 until it was synced on 2026-10-08. After a release, bump `terdut-demo`'s + tag to the same `image-digest` and its `Chart.yaml` `version:` (Flux reconciles on + ChartVersion), as its own PR, and say in the release report whether you did. Neither + demo has anything but the pin to change, but read the version range's migrations first: + the demo's Postgres migrates forward at startup. ## Checks