Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

services/luci/AGENTS.md

Raw
Rendered preview

Luci rules

These rules apply to Luci implementation, CI configuration, and deployment work, including related files outside services/luci/.

Identity and ownership

Luci is generic, repository-agnostic CI for public repositories. Every Luci-visible repository, run, log, and artifact is public-readable. Laminar is not part of the current repository-managed deployment.

This repository owns generic Luci capabilities, Luci image deployment, and host-side credentials.

Configuration

  • Keep KDL declarative: no programmable conditions, loops, expressions, or implicit execution of referenced KDL files; computation belongs in repo-owned programs.
  • If declarative configuration reaches its limits, prefer future dynamic workflows generated as KDL by run commands in the repo author's chosen language, rather than extending KDL into a programming language.
  • Dynamic workflow generation is a future direction, not currently supported behavior or authorization to implement it.

Runtime and security

  • Treat Luci secret masking as best-effort, never as a security boundary.
  • Preserve Luci's dedicated ci user boundary.
  • Run only one luci serve consumer for one data set.

Verification

  • Run the complete Go test suite under services/luci for Luci changes.
  • Validate the rendered Luci Quadlet, Caddy route, relay forwarding, and OpenTofu plan for Luci deployment changes.

The existing CI Quadlet check does not validate the generated Luci Quadlet.

# Luci rules

These rules apply to Luci implementation, CI configuration, and deployment work, including related files outside `services/luci/`.

## Identity and ownership

Luci is generic, repository-agnostic CI for public repositories.
Every Luci-visible repository, run, log, and artifact is public-readable.
Laminar is not part of the current repository-managed deployment.

This repository owns generic Luci capabilities, Luci image deployment, and host-side credentials.

## Configuration

- Keep KDL declarative: no programmable conditions, loops, expressions, or implicit execution of referenced KDL files; computation belongs in repo-owned programs.
- If declarative configuration reaches its limits, prefer future dynamic workflows generated as KDL by `run` commands in the repo author's chosen language, rather than extending KDL into a programming language.
- Dynamic workflow generation is a future direction, not currently supported behavior or authorization to implement it.

## Runtime and security

- Treat Luci secret masking as best-effort, never as a security boundary.
- Preserve Luci's dedicated `ci` user boundary.
- Run only one `luci serve` consumer for one data set.

## Verification

- Run the complete Go test suite under `services/luci` for Luci changes.
- Validate the rendered Luci Quadlet, Caddy route, relay forwarding, and OpenTofu plan for Luci deployment changes.

The existing CI Quadlet check does not validate the generated Luci Quadlet.