Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

.system/issues/BB-ISSUE-AC5EBBDD-luci-adw-prerequisite-drift/index.md

Raw
Rendered preview

id: BB-ISSUE-AC5EBBDD type: issue title: Luci ADW prerequisite drift specs:

  • BB-SPEC-251EC85B

Luci ADW prerequisite drift

Current Luci does not implement the approved generic prerequisites for Smith ADW:

  • durable auth and cache mounts;
  • temporary read-only file-secret binds;
  • temporary env files instead of secret-bearing process arguments;
  • immutable bounded artifacts and sandboxed HTML serving;
  • scheduled triggers with frozen revisions and coalescing;
  • per-job resource overrides;
  • generic frozen-plan CI_* metadata.

Current file secrets are copied into retained workspaces. Current environment secrets are passed as --env NAME=value arguments. The image and embedded docs also contain bugabinga-specific deployment values, contradicting Luci's generic boundary.

Close only after each generic capability is implemented and verified without Smith concepts entering Luci production code.

---
id: BB-ISSUE-AC5EBBDD
type: issue
title: Luci ADW prerequisite drift
specs:
  - BB-SPEC-251EC85B
---

# Luci ADW prerequisite drift

Current Luci does not implement the approved generic prerequisites for Smith ADW:

- durable `auth` and `cache` mounts;
- temporary read-only file-secret binds;
- temporary env files instead of secret-bearing process arguments;
- immutable bounded artifacts and sandboxed HTML serving;
- scheduled triggers with frozen revisions and coalescing;
- per-job resource overrides;
- generic frozen-plan `CI_*` metadata.

Current file secrets are copied into retained workspaces.
Current environment secrets are passed as `--env NAME=value` arguments.
The image and embedded docs also contain bugabinga-specific deployment values, contradicting Luci's generic boundary.

Close only after each generic capability is implemented and verified without Smith concepts entering Luci production code.