--- id: BB-SPEC-13004B6F type: spec title: Luci bugabinga.net integration research: - BB-RESEARCH-0B529BC1 --- # Luci bugabinga.net integration ## VCS and visibility Soft Serve provides Git SSH over public bare repositories. Luci reads first-level public repositories from the VCS data root. Every visible repository and served CI result is public. No per-repository hook is required. ## HTTP and SSH The public HTTP service is `ci.bugabinga.net`. Caddy proxies to klops host port 8081; the Luci container listens on 8080. Public Luci SSH uses configurable relay and peer ports, currently defaulting to 2223. Traffic lands in the container OpenSSH server. A forced command confines sessions to `luci ssh`. Deployment must preserve authorized-key source, expiry, and other restrictions. Forced commands must receive deployment configuration rather than image-baked production constants. ## Runtime Luci runs as dedicated rootless user `ci`. OpenTofu renders and installs the Luci Quadlet. The container receives: - Luci state storage; - public repositories read-only; - the `ci` Podman socket; - package and site publication roots; - registry authentication through a read-only secret mount; - Nugu CSS through a deployment mount. Shared publication roots must remain writable by both existing deployment flows and Luci without ownership races. The generated Quadlet must be validated before installation. ## Deployment Image loading and service restart are separate operations. A deployment uses an immutable image identity, retains the previous image and Quadlet, drains in-flight work, verifies state readability, and has a tested rollback. Health acceptance covers HTTP, forced SSH, push discovery, manual submission, logs, cache, registry, package, site, interruption, and restart recovery. Laminar is absent and is not a rollback mechanism.