Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

.system/specs/BB-SPEC-579A27BC-repository-operating-contract/index.md

Raw
Rendered preview

id: BB-SPEC-579A27BC type: spec title: Repository operating contract research:

  • BB-RESEARCH-4D80C31E

Repository operating contract

Tools

Use OpenTofu through tofu, never terraform. Use just for repository tasks and lefthook for Git hooks. Do not install or upgrade providers unless the change explicitly requires it.

Infrastructure workflow

Before an infrastructure change:

  1. inspect root modules, affected klops modules, variables, providers, templates, and deployment scripts;
  2. make the smallest coherent change;
  3. run tofu fmt -recursive;
  4. run tofu validate;
  5. validate affected Caddy and rendered Quadlet configuration;
  6. create and review a tofu plan;
  7. apply only the reviewed saved plan.

tofu apply executes remote klops deployment and can restart services. Validation alone is not deployment acceptance.

just check mutates formatting. Use tofu fmt -check -recursive, tofu validate, and caddy fmt --diff for read-only validation. The current direct-directory CI Quadlet check does not validate the generated Luci Quadlet.

OpenTofu conventions

Use two-space canonical formatting and snake_case names. Every variable and output has an explicit type and description. Use precise types rather than any. Set nullable = false when null is not handled. Secret inputs are marked sensitive. Use relative local modules and pinned external revisions. Keep provider constraints deliberate and lock-file changes explicit.

Secrets and state

Never commit secret values, variable-value files, state, state backups, saved plans, or generated sensitive files. State may contain plaintext secrets. Sensitive marking affects display, not storage. Use operator environment or ignored variable-value files for credentials.

Verification by surface

Luci changes run the complete Go test suite under services/luci plus affected packaged and deployment checks. Public-site changes run the real Chrome verifier at desktop and mobile viewports. Nugu assets are regenerated with just nugu; generated palette files are not hand-edited.

Do not claim a check passed unless its complete fresh result was read. Do not claim a revision is deployed without live deployment evidence.

---
id: BB-SPEC-579A27BC
type: spec
title: Repository operating contract
research:
  - BB-RESEARCH-4D80C31E
---

# Repository operating contract

## Tools

Use OpenTofu through `tofu`, never `terraform`.
Use `just` for repository tasks and lefthook for Git hooks.
Do not install or upgrade providers unless the change explicitly requires it.

## Infrastructure workflow

Before an infrastructure change:

1. inspect root modules, affected klops modules, variables, providers, templates, and deployment scripts;
2. make the smallest coherent change;
3. run `tofu fmt -recursive`;
4. run `tofu validate`;
5. validate affected Caddy and rendered Quadlet configuration;
6. create and review a `tofu plan`;
7. apply only the reviewed saved plan.

`tofu apply` executes remote klops deployment and can restart services.
Validation alone is not deployment acceptance.

`just check` mutates formatting.
Use `tofu fmt -check -recursive`, `tofu validate`, and `caddy fmt --diff` for read-only validation.
The current direct-directory CI Quadlet check does not validate the generated Luci Quadlet.

## OpenTofu conventions

Use two-space canonical formatting and `snake_case` names.
Every variable and output has an explicit type and description.
Use precise types rather than `any`.
Set `nullable = false` when null is not handled.
Secret inputs are marked sensitive.
Use relative local modules and pinned external revisions.
Keep provider constraints deliberate and lock-file changes explicit.

## Secrets and state

Never commit secret values, variable-value files, state, state backups, saved plans, or generated sensitive files.
State may contain plaintext secrets.
Sensitive marking affects display, not storage.
Use operator environment or ignored variable-value files for credentials.

## Verification by surface

Luci changes run the complete Go test suite under `services/luci` plus affected packaged and deployment checks.
Public-site changes run the real Chrome verifier at desktop and mobile viewports.
Nugu assets are regenerated with `just nugu`; generated palette files are not hand-edited.

Do not claim a check passed unless its complete fresh result was read.
Do not claim a revision is deployed without live deployment evidence.