Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

docs: clarify service authority boundaries

dcb1665b99c0b935214f84b4ce22eddc159c45fe

Oliver Jan Krylow <oliver@bugabinga.net> · 2026-09-28 10:24 UTC

unverifiable SSH 1 parent

Changed files (1)

README.md

ready
@@ -143,13 +143,17 @@
### Source/CI/Package Services
-- `vcs.bugabinga.net` HTTPS serves public repos through legit only.
-- `vcs.bugabinga.net:22` is DNATed by the relay to Soft Serve SSH on klops.
-- Soft Serve data lives in `/data/vcs/public`; legit only scans
- `/data/vcs/public/repos`, so all Soft Serve repos are treated as public.
-- `ci.bugabinga.net` serves Luci from a dedicated `ci` user, with its own
- rootless Podman socket. Build the custom Luci image on klops with
- `just deploy luci-image`.
+Soft Serve owns Git repositories and SSH access at `vcs.bugabinga.net:22`; its data lives in `/data/vcs/public`.
+Luigit is a read-only web interface at `vcs.bugabinga.net` HTTPS, routed by Caddy to `luigit:8080`.
+Luigit reads `/data/vcs/public/repos` read-only and advertises only `refs/heads/*`, `refs/tags/*`, and `refs/notes/*`; it does not own Git data or write refs.
+The configured Caddy route and Quadlets describe intended infrastructure, not proof of currently deployed source or live behavior.
+Luci is CI and artifact publication, served at `ci.bugabinga.net` under a dedicated `ci` user with its own rootless Podman socket.
+Luci manual submissions pin a resolved revision at admission; registry publication reports an immutable manifest digest after successful publication.
+Toad is a separate operator-controlled digest rollout service, not an automatic Luci deploy target.
+Caddy terminates public HTTPS and authentication; for Toad it is the outer authenticated proxy to a private-network Unix-socket ingress gateway.
+There is no CI-to-Toad credential or automatic deployment path.
+Any future automated deployment requires explicit operator-issued service-scoped credentials plus trusted-ref/revision policy enforcement before Toad invocation.
+Build the custom Luci image on klops with `just deploy luci-image`.
- `pkg.bugabinga.net` serves static package/release trees from `/data/pkg`; `/v2/*` proxies to zot for OCI clients.
- `registry.bugabinga.net` serves the zot web UI and registry API.
- `genie.bugabinga.net` serves HallucyGenie behind Caddy basic auth.
@@ -180,7 +184,7 @@
just apply
```
-First Luci repo smoke sequence:
+First Luci repo setup sequence:
```bash
just deploy luci-image
@@ -192,6 +196,7 @@
No per-repo hook install is needed. Luci polls public bare repo refs and
auto-discovers current and future repos. The SSH interface exposes dashboard,
repo, run, log, docs, and manual-run commands through `ci`.
+Manual submissions resolve requested refs/revisions and validate jobs before enqueueing; execution uses the admitted revision rather than resolving a mutable ref again.
Luci supports opt-in push triggers with changed-path filters, five-field UTC
cron schedules, persistent keyed caches, and `registry`, `pkg`, and `site`
@@ -201,6 +206,10 @@
`/data/ci/secrets/zot-auth.json`.
Jobs must write a fresh OCI image archive, then declare `publish "registry"` with `from` archive path and `to` registry target.
Luci stages that archive and runs daemonless `skopeo copy`; legacy host-image `image` publishing is rejected.
+Successful publication retains requested `destination`, logs `digest=sha256:<64 lowercase hex>`, and logs canonical `reference=<repository>@<digest>` without any requested tag.
+Pass only strict bare `digest` field to operator's `toad deploy <service> <digest>` command.
+Toad accepts only `sha256:<64 lowercase hex>` and supplies enrolled repository itself.
+Toad supplies the enrolled image repository and validates the manifest digest; Luci does not invoke Toad or grant deployment authority.
Luci v1 treats every visible repo, log, and artifact as public-readable.
Known declared secret values are masked from ANSI-free logs best-effort;