repositories / bugabinga.net
bugabinga.net
personal infrastructure for bugabinga!
owned by admin
services/luci/internal/web/assets/docs.tmpl
Raw{{define "body"}}
<section class="docs">
<h1>UI + CLI.<br>Same runs. Same values.</h1>
<p>Run pages keep diagnosis close: parent failure, affected execution, actual log evidence, then configuration at recorded revision.</p>
<section class="docs-card">
<h2>Read-only Nushell commands</h2>
<pre>{{commandHTML "luci" "status" "--all"}}
{{commandHTML "luci" "repo" "<repo>"}}
{{commandHTML "luci" "show" "<run-id|repo>"}}
{{commandHTML "luci" "watch" "<run-id|repo>" "--logs" "--timeout" "30m"}}
{{commandHTML "luci" "log" "<run-id|repo>" "<child-id or job>"}}
{{commandHTML "luci" "artifact" "<run-id|repo>" "[path]"}}</pre>
<p>Run IDs display as shortest unique proquints. UI copy actions use complete proquints. CLI accepts unique prefixes, repository names, or decimal IDs.</p>
<p><code>watch</code> resolves once, follows that run only, and has no default timeout. <code>--timeout</code> needs a positive duration. It exits 0 for success, 1 for an unsuccessful run, 2 for command or operational errors, 124 for timeout, and 130 when cancelled.</p>
</section>
<section class="docs-card">
<h2>Configuration</h2>
<pre>{{kdl "job \"test\" {\n image \"docker.io/library/alpine:latest\"\n trigger { push { branch \"trunk\" } }\n run \"project-test-command\"\n}"}}</pre>
<p>Jobs without triggers are manual-only. Manual submission resolves its requested ref or commit and validates its job before queueing; execution stays pinned to that commit while retaining requested ref provenance. Push filters, schedules, matrices, caches, secrets, and publish targets are defined in direct <code>.ci/*.kdl</code> files.</p>
<p>Registry jobs write an OCI archive during <code>run</code>, then use <code>publish "registry" { from "image.oci" to "registry.example/app:tag" }</code>. Luci rejects legacy <code>image</code> registry publishing, stale checkout outputs, cache/artifact overlap, and non-registry targets; it stages archive input and copies it with daemonless Skopeo. Only a successful publication emits machine-readable evidence with requested destination, manifest digest, and canonical <code>repository@digest</code> reference.</p>
</section>
<section class="docs-card">
<h2>Security model</h2>
<p>Web UI and local CLI read same Luci data. SSH endpoints accept restricted <code>ci</code> commands, not copied local <code>luci</code> commands. Connect using deployed endpoint details, then run <code>ci docs</code>.</p>
<p>Repositories, logs, and artifacts are public. Masking is best-effort, never a secret boundary.</p>
<p>Artifact sets stage privately, then become visible atomically. Durable cache and auth mounts live under Luci data storage, are owner-only, and serialize access with private locks. Secret binds are read-only and temporary secret files never enter workspaces, caches, artifacts, or logs.</p>
<p>See <a href="/llms.txt">llms.txt</a> for complete machine-readable reference.</p>
</section>
</section>
{{end}}