These rules apply to Luci implementation, CI configuration, and deployment work, including related files outside services/luci/.
Identity and ownership
Luci is generic, repository-agnostic CI for public repositories.
Every Luci-visible repository, run, log, and artifact is public-readable.
Laminar is not part of the current repository-managed deployment.
This repository owns generic Luci capabilities, Luci image deployment, and host-side credentials.
Configuration
Keep KDL declarative: no programmable conditions, loops, expressions, or implicit execution of referenced KDL files; computation belongs in repo-owned programs.
If declarative configuration reaches its limits, prefer future dynamic workflows generated as KDL by run commands in the repo author's chosen language, rather than extending KDL into a programming language.
Dynamic workflow generation is a future direction, not currently supported behavior or authorization to implement it.
Runtime and security
Treat Luci secret masking as best-effort, never as a security boundary.
Preserve Luci's dedicated ci user boundary.
Run only one luci serve consumer for one data set.
Verification
Run the complete Go test suite under services/luci for Luci changes.
Validate the rendered Luci Quadlet, Caddy route, relay forwarding, and OpenTofu plan for Luci deployment changes.
The existing CI Quadlet check does not validate the generated Luci Quadlet.
# Luci rules
These rules apply to Luci implementation, CI configuration, and deployment work, including related files outside `services/luci/`.
## Identity and ownership
Luci is generic, repository-agnostic CI for public repositories.
Every Luci-visible repository, run, log, and artifact is public-readable.
Laminar is not part of the current repository-managed deployment.
This repository owns generic Luci capabilities, Luci image deployment, and host-side credentials.
## Configuration
- Keep KDL declarative: no programmable conditions, loops, expressions, or implicit execution of referenced KDL files; computation belongs in repo-owned programs.
- If declarative configuration reaches its limits, prefer future dynamic workflows generated as KDL by `run` commands in the repo author's chosen language, rather than extending KDL into a programming language.
- Dynamic workflow generation is a future direction, not currently supported behavior or authorization to implement it.
## Runtime and security
- Treat Luci secret masking as best-effort, never as a security boundary.
- Preserve Luci's dedicated `ci` user boundary.
- Run only one `luci serve` consumer for one data set.
## Verification
- Run the complete Go test suite under `services/luci` for Luci changes.
- Validate the rendered Luci Quadlet, Caddy route, relay forwarding, and OpenTofu plan for Luci deployment changes.
The existing CI Quadlet check does not validate the generated Luci Quadlet.