Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

.system/specs/BB-SPEC-9C4F71E1-klops-service-platform/index.md

Raw
Rendered preview

id: BB-SPEC-9C4F71E1 type: spec title: Klops service platform research:

  • BB-RESEARCH-4D80C31E

Klops service platform

Deployment boundary

OpenTofu renders klops configuration locally. Hash-triggered resources invoke repository-owned SSH, SCP, and rsync scripts. Apply is therefore a remote deployment operation, not only a cloud API operation.

Root operations are limited to host concerns such as WireGuard, ownership boundaries, and dedicated service-user setup. Application services run under designated unprivileged users. Operator SSH configuration and agents resolve authentication; deployment must not hard-code private-key paths.

Service lifecycle

Long-running application containers are repository-managed Podman Quadlets under user systemd unless another specification requires otherwise. Most services use the configured klops user. Luci uses a dedicated rootless ci user, socket, and storage boundary.

Caddy runs rootlessly, terminates public HTTP and HTTPS, routes applications, and serves repository-managed static content. Public Git SSH uses Soft Serve. Repository configuration routes the public Git web interface to Luigit.

Deployment restarts only affected groups when tracked inputs or deployment logic change. An unchanged apply must not imply a full service restart.

Configuration and secrets

Secret inputs are typed, described, and sensitive. Sensitive marking does not remove values from state. Secret values, variable-value files, state, saved plans, and generated sensitive files must not enter version control or shared storage.

OpenTofu variables and outputs use explicit types, descriptions, and snake_case names. Null is rejected where it is not handled. External modules use pinned revisions. Provider and lock-file upgrades are explicit changes.

---
id: BB-SPEC-9C4F71E1
type: spec
title: Klops service platform
research:
  - BB-RESEARCH-4D80C31E
---

# Klops service platform

## Deployment boundary

OpenTofu renders klops configuration locally.
Hash-triggered resources invoke repository-owned SSH, SCP, and rsync scripts.
Apply is therefore a remote deployment operation, not only a cloud API operation.

Root operations are limited to host concerns such as WireGuard, ownership boundaries, and dedicated service-user setup.
Application services run under designated unprivileged users.
Operator SSH configuration and agents resolve authentication; deployment must not hard-code private-key paths.

## Service lifecycle

Long-running application containers are repository-managed Podman Quadlets under user systemd unless another specification requires otherwise.
Most services use the configured klops user.
Luci uses a dedicated rootless `ci` user, socket, and storage boundary.

Caddy runs rootlessly, terminates public HTTP and HTTPS, routes applications, and serves repository-managed static content.
Public Git SSH uses Soft Serve.
Repository configuration routes the public Git web interface to Luigit.

Deployment restarts only affected groups when tracked inputs or deployment logic change.
An unchanged apply must not imply a full service restart.

## Configuration and secrets

Secret inputs are typed, described, and sensitive.
Sensitive marking does not remove values from state.
Secret values, variable-value files, state, saved plans, and generated sensitive files must not enter version control or shared storage.

OpenTofu variables and outputs use explicit types, descriptions, and `snake_case` names.
Null is rejected where it is not handled.
External modules use pinned revisions.
Provider and lock-file upgrades are explicit changes.