Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

.system/specs/BB-SPEC-13004B6F-luci-bugabinga-net-integration/index.md

Raw
Rendered preview

id: BB-SPEC-13004B6F type: spec title: Luci bugabinga.net integration research:

  • BB-RESEARCH-0B529BC1

Luci bugabinga.net integration

VCS and visibility

Soft Serve provides Git SSH over public bare repositories. Luci reads first-level public repositories from the VCS data root. Every visible repository and served CI result is public. No per-repository hook is required.

HTTP and SSH

The public HTTP service is ci.bugabinga.net. Caddy proxies to klops host port 8081; the Luci container listens on 8080.

Public Luci SSH uses configurable relay and peer ports, currently defaulting to 2223. Traffic lands in the container OpenSSH server. A forced command confines sessions to luci ssh. Deployment must preserve authorized-key source, expiry, and other restrictions. Forced commands must receive deployment configuration rather than image-baked production constants.

Runtime

Luci runs as dedicated rootless user ci. OpenTofu renders and installs the Luci Quadlet. The container receives:

  • Luci state storage;
  • public repositories read-only;
  • the ci Podman socket;
  • package and site publication roots;
  • registry authentication through a read-only secret mount;
  • Nugu CSS through a deployment mount.

Shared publication roots must remain writable by both existing deployment flows and Luci without ownership races. The generated Quadlet must be validated before installation.

Deployment

Image loading and service restart are separate operations. A deployment uses an immutable image identity, retains the previous image and Quadlet, drains in-flight work, verifies state readability, and has a tested rollback. Health acceptance covers HTTP, forced SSH, push discovery, manual submission, logs, cache, registry, package, site, interruption, and restart recovery.

Laminar is absent and is not a rollback mechanism.

---
id: BB-SPEC-13004B6F
type: spec
title: Luci bugabinga.net integration
research:
  - BB-RESEARCH-0B529BC1
---

# Luci bugabinga.net integration

## VCS and visibility

Soft Serve provides Git SSH over public bare repositories.
Luci reads first-level public repositories from the VCS data root.
Every visible repository and served CI result is public.
No per-repository hook is required.

## HTTP and SSH

The public HTTP service is `ci.bugabinga.net`.
Caddy proxies to klops host port 8081; the Luci container listens on 8080.

Public Luci SSH uses configurable relay and peer ports, currently defaulting to 2223.
Traffic lands in the container OpenSSH server.
A forced command confines sessions to `luci ssh`.
Deployment must preserve authorized-key source, expiry, and other restrictions.
Forced commands must receive deployment configuration rather than image-baked production constants.

## Runtime

Luci runs as dedicated rootless user `ci`.
OpenTofu renders and installs the Luci Quadlet.
The container receives:

- Luci state storage;
- public repositories read-only;
- the `ci` Podman socket;
- package and site publication roots;
- registry authentication through a read-only secret mount;
- Nugu CSS through a deployment mount.

Shared publication roots must remain writable by both existing deployment flows and Luci without ownership races.
The generated Quadlet must be validated before installation.

## Deployment

Image loading and service restart are separate operations.
A deployment uses an immutable image identity, retains the previous image and Quadlet, drains in-flight work, verifies state readability, and has a tested rollback.
Health acceptance covers HTTP, forced SSH, push discovery, manual submission, logs, cache, registry, package, site, interruption, and restart recovery.

Laminar is absent and is not a rollback mechanism.