refactor: remove EDU ownership from homelab

This commit is contained in:
forust committed 2026-10-07 10:19:12 +02:00
1 parent fb400eea6e
commit 1d93588e06
25 files changed
+56 -2706

No files matched your search

+55
View File
@@ -0,0 +1,55 @@
# EDU ownership handoff
## Review findings
The current `main` branch can verify and roll back changed workloads across the cluster. This is unsafe when an external repository owns an application. Open PR #99 already changes this behavior to use selected workload references and immutable releases. This change is based on PR #99 branch `codex/ci-visible-checks` and keeps its protected check names:
- `ci / Compose*`
- `ci / Workflows*`
- `ci / Shell*`
- `ci / Formatting*`
- `ci / Python and tests*`
- `ci / YAML*`
- `ci / Dockerfiles*`
- `ci / Kubernetes*`
Open PR #100 adds service metrics. It is independent and is not required for this handoff.
Live Gitea 28.0.0 supports dynamic job outputs, matrices, and `max-parallel`. The runner has 1 CPU, 1.7 GiB RAM, and 6 GiB free disk. Its capacity details could not be verified because the diagnostic required a sudo password. Runner concurrency capacity remains unverified.
The workstation checkout `/srv/edu-master` exists, is clean at `7ed537f`, and uses the SSH remote `gitssh.forust.xyz:2221`. In Kubernetes context `Default`, namespace `edu-master`, the `session-keeper` and `webinar-checker` workloads are Ready. Their health and live endpoints return 200. Their running image digests match the digests in the old homelab configuration. The Redis PVC `redis-data-pvc` is bound to PV `pvc-a4f2a79a-363a-4c12-ae91-92cdfc2a0d2e`; its reclaim policy is `Delete`. Never delete, recreate, or apply this PVC.
The EDU repository still needs its live `playwright-service` manifest and reconciled auto-reloader annotations. Those changes, plus backup and monitoring verification improvements, are in the separate EDU branch `fix/handoff-runtime`.
## Implementation decisions
The homelab change removes the complete `edu_master` subtree, EDU build and deploy selection, image pinning, rollback and verification cases, route probes, related tests, and Renovate references. It removes the external EDU image bypass from generic image scans. Application source and release ownership: [forust/edu-master](https://git.forust.xyz/forust/edu-master).
The image plan compares fingerprints for all three homelab images with the last successful CI release. Each matrix job builds its image or reuses the matching immutable digest. The matrix runs one job at a time and continues after a job failure so each image has a visible result. The final build job waits for all image jobs, checks the commit, inputs, and digests, applies the full-SHA tags, and writes the existing release artifact format. This preserves the deploy gate. A manifest-only change still runs three reuse jobs and the final tag stage. Pull requests do not publish images.
Retain the protected check names from PR #99. Keep CI and deploy separate. `AUTODEPLOY=false` is configured explicitly. The EDU main-push deploy policy is independent of this setting.
## Dependencies and rollout order
1. Merge PR #99 first, because this change uses its selected-workload and immutable-release behavior. PR #100 is not a dependency.
2. Complete the EDU runtime reconciliation on the EDU feature branch. Do not merge EDU into `main` yet. Configure and verify the EDU deployment secrets and trusted SSH host key outside Git.
3. Confirm the EDU release can pass its CI and immutable-SHA deploy gate. Keep the existing namespace, Secret, Redis data, Fernet key, and runtime credentials.
4. Stop or drain pending homelab runs that can deploy EDU. Remove the EDU active marker from the authoritative homelab source before any later homelab deploy. Confirm that the removal path does not prune resources.
5. Merge the homelab removal. Then merge EDU PR #1 into `main` to start a successful main-push release and deployment.
6. Verify that homelab no longer selects EDU and that EDU is the sole owner. Check rollout health, `/health`, `/live`, Redis AUTH, session TTL, delivery backlog, and monitoring. Record the release SHA, image digests, downtime, and any remaining limits in the relevant PR.
## Rollback
For an EDU release failure, use the EDU release snapshot and reapply the last recorded immutable digests. Inspect workload and application health after recovery. Do not restore old Redis data unless recovery requires it.
To reverse the ownership handoff, stop EDU deployment triggers and runs first. Restore the reviewed homelab configuration and active marker only after EDU is inactive. Reapply the recorded image digests and verify workload health. Never enable both deployment paths at the same time. The PVC and its PV must remain intact.
## Verification status
Verified: Gitea version and matrix support; current runner CPU, memory, and free disk readings; clean EDU checkout and SSH remote; Kubernetes context and namespace; workload readiness and health endpoints; matching live image digests; and Redis PVC binding and reclaim policy.
Not verified: runner capacity limits, merged PR state, post-merge image release, EDU deployment, or final handoff acceptance. The merge and live deployment steps remain pending. Do not report the handoff as complete until the live checks above pass.
Live pre-handoff checks also passed: Redis AUTH (`NOAUTH` without credentials and `PONG` with them), positive session TTL, zero delivery backlog, and nine EDU vmalert rules with matching expressions and healthy evaluation. The private snapshot is `/home/forust/.local/state/edu-master-deploy/handoff-20261007T080838Z` on workstation. It includes the Redis RDB, Secret, manifests, source files, and checkout commits. Workloads have not been redeployed.
The Redis RDB checksum passed with twelve keys. The unauthorized Redis pod test passed and the pod was removed. VictoriaMetrics reported the EDU scrape target UP. EDU Actions has the dedicated path and port secrets and `EDU_KUBE_CONTEXT=Default`. Existing deployment and registry credentials were retained.