Files
homelab/.gitea/EDU_HANDOFF.md
T

5.7 KiB

EDU ownership handoff

Review findings

The current main branch can verify and roll back changed workloads across the cluster. This is unsafe when an external repository owns an application. Open PR #99 already changes this behavior to use selected workload references and immutable releases. This change is based on PR #99 branch codex/ci-visible-checks and keeps its protected check names:

  • ci / Compose*
  • ci / Workflows*
  • ci / Shell*
  • ci / Formatting*
  • ci / Python and tests*
  • ci / YAML*
  • ci / Dockerfiles*
  • ci / Kubernetes*

Open PR #100 adds service metrics. It is independent and is not required for this handoff.

Live Gitea 28.0.0 supports dynamic job outputs, matrices, and max-parallel. The runner has 1 CPU, 1.7 GiB RAM, and 6 GiB free disk. Its capacity details could not be verified because the diagnostic required a sudo password. Runner concurrency capacity remains unverified.

The workstation checkout /srv/edu-master exists, is clean at 7ed537f, and uses the SSH remote gitssh.forust.xyz:2221. In Kubernetes context Default, namespace edu-master, the session-keeper and webinar-checker workloads are Ready. Their health and live endpoints return 200. Their running image digests match the digests in the old homelab configuration. The Redis PVC redis-data-pvc is bound to PV pvc-a4f2a79a-363a-4c12-ae91-92cdfc2a0d2e; its reclaim policy is Delete. Never delete, recreate, or apply this PVC.

The EDU repository still needs its live playwright-service manifest and reconciled auto-reloader annotations. Those changes, plus backup and monitoring verification improvements, are in the separate EDU branch fix/handoff-runtime.

Implementation decisions

The homelab change removes the complete edu_master subtree, EDU build and deploy selection, image pinning, rollback and verification cases, route probes, related tests, and Renovate references. It removes the external EDU image bypass from generic image scans. Application source and release ownership: forust/edu-master.

The image plan compares fingerprints for all three homelab images with the last successful CI release. Each matrix job builds its image or reuses the matching immutable digest. The matrix runs one job at a time and continues after a job failure so each image has a visible result. The final build job waits for all image jobs, checks the commit, inputs, and digests, applies the full-SHA tags, and writes the existing release artifact format. This preserves the deploy gate. A manifest-only change still runs three reuse jobs and the final tag stage. Pull requests do not publish images.

Retain the protected check names from PR #99. Keep CI and deploy separate. AUTODEPLOY=false is configured explicitly. The EDU main-push deploy policy is independent of this setting.

Dependencies and rollout order

  1. Merge PR #99 first, because this change uses its selected-workload and immutable-release behavior. PR #100 is not a dependency.
  2. Complete the EDU runtime reconciliation on the EDU feature branch. Do not merge EDU into main yet. Configure and verify the EDU deployment secrets and trusted SSH host key outside Git.
  3. Confirm the EDU release can pass its CI and immutable-SHA deploy gate. Keep the existing namespace, Secret, Redis data, Fernet key, and runtime credentials.
  4. Stop or drain pending homelab runs that can deploy EDU. Remove the EDU active marker from the authoritative homelab source before any later homelab deploy. Confirm that the removal path does not prune resources.
  5. Merge the homelab removal. Then merge EDU PR #1 into main to start a successful main-push release and deployment.
  6. Verify that homelab no longer selects EDU and that EDU is the sole owner. Check rollout health, /health, /live, Redis AUTH, session TTL, delivery backlog, and monitoring. Record the release SHA, image digests, downtime, and any remaining limits in the relevant PR.

Rollback

For an EDU release failure, use the EDU release snapshot and reapply the last recorded immutable digests. Inspect workload and application health after recovery. Do not restore old Redis data unless recovery requires it.

To reverse the ownership handoff, stop EDU deployment triggers and runs first. Restore the reviewed homelab configuration and active marker only after EDU is inactive. Reapply the recorded image digests and verify workload health. Never enable both deployment paths at the same time. The PVC and its PV must remain intact.

Verification status

Verified: Gitea version and matrix support; current runner CPU, memory, and free disk readings; clean EDU checkout and SSH remote; Kubernetes context and namespace; workload readiness and health endpoints; matching live image digests; and Redis PVC binding and reclaim policy.

Not verified: runner capacity limits, merged PR state, post-merge image release, EDU deployment, or final handoff acceptance. The merge and live deployment steps remain pending. Do not report the handoff as complete until the live checks above pass.

Live pre-handoff checks also passed: Redis AUTH (NOAUTH without credentials and PONG with them), positive session TTL, zero delivery backlog, and nine EDU vmalert rules with matching expressions and healthy evaluation. The private snapshot is /home/forust/.local/state/edu-master-deploy/handoff-20261007T080838Z on workstation. It includes the Redis RDB, Secret, manifests, source files, and checkout commits. Workloads have not been redeployed.

The Redis RDB checksum passed with twelve keys. The unauthorized Redis pod test passed and the pod was removed. VictoriaMetrics reported the EDU scrape target UP. EDU Actions has the dedicated path and port secrets and EDU_KUBE_CONTEXT=Default. Existing deployment and registry credentials were retained.