Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

.system/issues/BB-ISSUE-84FBBB9E-luci-deployment-acceptance-is-blocked/index.md

Raw
Rendered preview

id: BB-ISSUE-84FBBB9E type: issue title: Luci deployment acceptance is blocked specs:

  • BB-SPEC-13004B6F
  • BB-SPEC-9C4F71E1

Luci deployment acceptance is blocked

Deployment defects

  • CI-user setup applies ci ownership to shared package and site roots used by existing oli deployment flows.
  • Authorized-key import strips source, expiry, and other restrictions preceding key material.
  • Non-default Luci peer ports are not propagated to klops firewalld.
  • CI Quadlet deployment deletes the installed file before copying its replacement.
  • Container sshd is backgrounded; its failure does not fail the container.
  • Forced SSH sessions receive image-baked production values instead of deployment configuration.
  • just check-quadlets scans no rendered Luci Quadlet.
  • Image loading uses mutable latest, immediately restarts the service, retains no prior identity, and has no health-gated rollback.
  • Shared deployment-script hashes caused the reviewed OpenTofu plan to replace ten klops resources rather than only Luci.

Missing acceptance

  • The manual E2E is non-hermetic and asserts the obsolete pre-dashboard UI.
  • Statement coverage measured 87.3%.
  • Mutation coverage measured 95.15%, below the declared 100% target.
  • Local image build failed in Podman's overlay build-context setup.
  • Public forced-SSH authentication failed with the available key.
  • Production was observed on 265e469, not reviewed HEAD.

Closure sequence

  1. Fix runtime and deployment blockers with regression tests.
  2. Separate immutable image load from restart and retain the prior image and Quadlet.
  3. Drain queue and active state; back up events and inbox.
  4. Produce and review a Luci-only plan.
  5. Canary HTTP, forced SSH, push, manual run, logs, cache, registry, package, site, interruption, and restart recovery.
  6. Promote only after health checks and preserve tested rollback.
---
id: BB-ISSUE-84FBBB9E
type: issue
title: Luci deployment acceptance is blocked
specs:
  - BB-SPEC-13004B6F
  - BB-SPEC-9C4F71E1
---

# Luci deployment acceptance is blocked

## Deployment defects

- CI-user setup applies `ci` ownership to shared package and site roots used by existing `oli` deployment flows.
- Authorized-key import strips source, expiry, and other restrictions preceding key material.
- Non-default Luci peer ports are not propagated to klops firewalld.
- CI Quadlet deployment deletes the installed file before copying its replacement.
- Container sshd is backgrounded; its failure does not fail the container.
- Forced SSH sessions receive image-baked production values instead of deployment configuration.
- `just check-quadlets` scans no rendered Luci Quadlet.
- Image loading uses mutable `latest`, immediately restarts the service, retains no prior identity, and has no health-gated rollback.
- Shared deployment-script hashes caused the reviewed OpenTofu plan to replace ten klops resources rather than only Luci.

## Missing acceptance

- The manual E2E is non-hermetic and asserts the obsolete pre-dashboard UI.
- Statement coverage measured 87.3%.
- Mutation coverage measured 95.15%, below the declared 100% target.
- Local image build failed in Podman's overlay build-context setup.
- Public forced-SSH authentication failed with the available key.
- Production was observed on `265e469`, not reviewed HEAD.

## Closure sequence

1. Fix runtime and deployment blockers with regression tests.
2. Separate immutable image load from restart and retain the prior image and Quadlet.
3. Drain queue and active state; back up events and inbox.
4. Produce and review a Luci-only plan.
5. Canary HTTP, forced SSH, push, manual run, logs, cache, registry, package, site, interruption, and restart recovery.
6. Promote only after health checks and preserve tested rollback.