{{define "body"}}

UI + CLI.
Same runs. Same values.

Run pages keep diagnosis close: parent failure, affected execution, actual log evidence, then configuration at recorded revision.

Read-only Nushell commands

{{commandHTML "luci" "status" "--all"}}
{{commandHTML "luci" "repo" ""}}
{{commandHTML "luci" "show" ""}}
{{commandHTML "luci" "watch" "" "--logs" "--timeout" "30m"}}
{{commandHTML "luci" "log" "" ""}}
{{commandHTML "luci" "artifact" "" "[path]"}}

Run IDs display as shortest unique proquints. UI copy actions use complete proquints. CLI accepts unique prefixes, repository names, or decimal IDs.

watch resolves once, follows that run only, and has no default timeout. --timeout needs a positive duration. It exits 0 for success, 1 for an unsuccessful run, 2 for command or operational errors, 124 for timeout, and 130 when cancelled.

Configuration

{{kdl "job \"test\" {\n  image \"docker.io/library/alpine:latest\"\n  trigger { push { branch \"trunk\" } }\n  run \"project-test-command\"\n}"}}

Jobs without triggers are manual-only. Manual submission resolves its requested ref or commit and validates its job before queueing; execution stays pinned to that commit while retaining requested ref provenance. Push filters, schedules, matrices, caches, secrets, and publish targets are defined in direct .ci/*.kdl files.

Registry jobs write an OCI archive during run, then use publish "registry" { from "image.oci" to "registry.example/app:tag" }. Luci rejects legacy image registry publishing, stale checkout outputs, cache/artifact overlap, and non-registry targets; it stages archive input and copies it with daemonless Skopeo. Only a successful publication emits machine-readable evidence with requested destination, manifest digest, and canonical repository@digest reference.

Security model

Web UI and local CLI read same Luci data. SSH endpoints accept restricted ci commands, not copied local luci commands. Connect using deployed endpoint details, then run ci docs.

Repositories, logs, and artifacts are public. Masking is best-effort, never a secret boundary.

Artifact sets stage privately, then become visible atomically. Durable cache and auth mounts live under Luci data storage, are owner-only, and serialize access with private locks. Secret binds are read-only and temporary secret files never enter workspaces, caches, artifacts, or logs.

See llms.txt for complete machine-readable reference.

{{end}}