# Luci rules These rules apply to Luci implementation, CI configuration, and deployment work, including related files outside `services/luci/`. ## Identity and ownership Luci is generic, repository-agnostic CI for public repositories. Every Luci-visible repository, run, log, and artifact is public-readable. Laminar is not part of the current repository-managed deployment. This repository owns generic Luci capabilities, Luci image deployment, and host-side credentials. ## Configuration - Keep KDL declarative: no programmable conditions, loops, expressions, or implicit execution of referenced KDL files; computation belongs in repo-owned programs. - If declarative configuration reaches its limits, prefer future dynamic workflows generated as KDL by `run` commands in the repo author's chosen language, rather than extending KDL into a programming language. - Dynamic workflow generation is a future direction, not currently supported behavior or authorization to implement it. ## Runtime and security - Treat Luci secret masking as best-effort, never as a security boundary. - Preserve Luci's dedicated `ci` user boundary. - Run only one `luci serve` consumer for one data set. ## Verification - Run the complete Go test suite under `services/luci` for Luci changes. - Validate the rendered Luci Quadlet, Caddy route, relay forwarding, and OpenTofu plan for Luci deployment changes. The existing CI Quadlet check does not validate the generated Luci Quadlet.