c7540e97ad
feat(ci): enforce runtime-validation image separation ( #69 )
...
CICD Start / Sanity and Base Decision (push) Successful in 17s
## Summary
Implements issue #59 by enforcing a hard boundary between CI validation tooling and deployable runtime images.
This PR:
- Adds automated deployable-runtime boundary checks in CI.
- Verifies deployable backend/frontend artifacts are free of CI/development tooling.
- Documents runtime-vs-validation ownership and enforcement behavior.
## What Changed
### CI workflow enforcement
- Updated `.gitea/workflows/docker-build-main.yaml` to:
- Checkout additional verification inputs (`Dockerfile.backend`, `Dockerfile.frontend`, scripts, backend/frontend directories).
- Run `scripts/check-dockerfile-boundaries.sh`.
- Build deployable runtime images (`Dockerfile.backend`, `Dockerfile.frontend --target production`).
- Run `scripts/verify-deployable-image-purity.sh` against both images before publishing CICD image.
- Updated `.gitea/workflows/cicd-checks.yaml` to add:
- `dockerfile-boundary-check` job.
- Boundary validation execution inside the CICD validation image.
### New enforcement scripts
- Added `scripts/check-dockerfile-boundaries.sh`:
- Ensures deployable Dockerfiles do **not** reference CICD image paths (`cicd-base`, `CICD_BASE_IMAGE`, `Dockerfile.cicd*`, etc.).
- Ensures deployable Dockerfiles do **not** include disallowed CI-only tooling tokens.
- Enforces runtime base expectations:
- Backend: `python:3.14-slim`
- Frontend production target: `nginx:alpine`
- Added `scripts/verify-deployable-image-purity.sh`:
- Baseline binary checks for disallowed tooling.
- Backend-specific deep checks:
- Python module import probes for disallowed CI/dev modules.
- `pip show` package metadata checks for disallowed CI/dev packages.
- Frontend-specific deep checks:
- OS package metadata checks (`apk`/`dpkg` when available) for disallowed runtime leaks.
- Directory-based checks for development package trees (`node_modules`, `.venv`, `site-packages`, `dist-packages` in sensitive paths).
## Documentation updates
- Updated `docs/DEVELOPMENT.md`:
- Clarifies runtime-vs-validation enforcement and where checks run.
- Notes purity checks include binaries and metadata artifacts.
- Updated `docs/CICD_MULTI_STAGE_BUILD.md`:
- Adds explicit “Runtime Boundary Enforcement” section.
- Documents metadata-level purity probes.
- Updated `docs/DEPLOYABLE_RUNTIME_CONTRACT.md`:
- Replaces future-only language with current enforcement hooks.
- Documents binary + metadata-level purity enforcement.
## Acceptance Criteria Mapping
1. **Deployable backend/frontend image paths do not require CI-only tool installation**
- Enforced by:
- `scripts/check-dockerfile-boundaries.sh`
- `scripts/verify-deployable-image-purity.sh`
- `docker-build-main.yaml` pre-publish gates
2. **Checks and tests execute in dedicated validation environment(s)**
- Reinforced by:
- `cicd-checks.yaml` boundary-check job running in CICD validation image
- Existing check/test workflow usage of CICD image
3. **Workflow docs identify runtime vs validation concerns**
- Addressed via updates to:
- `docs/DEVELOPMENT.md`
- `docs/CICD_MULTI_STAGE_BUILD.md`
- `docs/DEPLOYABLE_RUNTIME_CONTRACT.md`
## Scope / Non-Goals
- Included:
- Structural separation enforcement
- Workflow-level guardrails
- Documentation clarity and traceability
- Not included:
- Full staging deployment wiring
- Security policy redesign
## Notes for Reviewers
- Main enforcement path is in `docker-build-main.yaml` before CICD image publish.
- New scripts are intentionally fail-fast and policy-oriented.
- Existing deployable Dockerfiles currently satisfy the new gates.
Co-authored-by: copilotcoder <copilotcoder@darkhelm.org >
Reviewed-on: #69
2026-06-22 12:45:20 -04:00
9b742a5a6d
feature/pp-58-runtime-image-contract ( #68 )
...
CICD Start / Sanity and Base Decision (push) Successful in 18s
Renovate Dependency Updates / Renovate Dependencies (push) Failing after 7m19s
## Summary
This PR tightens repository quality enforcement around markdown and documentation. It adds `markdownlint` to the `cicd-checks` workflow, expands pre-commit coverage so markdown files are checked repo-wide, and cleans up the PP-58 documentation set to keep it aligned with the new policy.
## What changed
- Added a `Markdownlint Check` entry to `.gitea/workflows/cicd-checks.yaml`
- Added `markdownlint` to pre-commit and widened prettier coverage to include markdown files across the repo
- Updated `README.md` to satisfy markdownlint line-length rules
- Normalized the PP-58 documentation set:
- `docs/DEPLOYABLE_RUNTIME_CONTRACT.md`
- `docs/adr/ADR003-deployable_runtime_image_contract.md`
- `docs/DEVELOPMENT.md`
- `docs/CICD_MULTI_STAGE_BUILD.md`
- `docs/CICD_TROUBLESHOOTING_GUIDE.md`
- `docs/SECURE_DOCKER_CICD.md`
## Validation
- `pre-commit run markdownlint --files README.md docs/DEPLOYABLE_RUNTIME_CONTRACT.md`
- `pre-commit run prettier --files README.md docs/DEPLOYABLE_RUNTIME_CONTRACT.md`
- Workflow YAML validation returned no errors
## Notes
This change does not alter application runtime behavior. It only strengthens CI and documentation quality enforcement.
Co-authored-by: copilotcoder <copilotcoder@darkhelm.org >
Reviewed-on: #68
2026-06-19 17:00:57 -04:00
d02039a22e
Backend runtime upgraded to Python 3.14 with exact dependency pinning ( #57 )
...
CICD Start / Sanity and Base Decision (push) Successful in 18s
Runner Canary / Canary Heavy (ubuntu-act-8gb) (push) Has been skipped
Runner Canary / Canary Heavy (ubuntu-act-4gb) (push) Has been skipped
Runner Canary / Canary Burst (ubuntu-act (push) Failing after 11m10s
Runner Canary / Canary (ubuntu-latest) (push) Failing after 12m39s
Runner Canary / Canary (ubuntu-act) (push) Failing after 12m42s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
## Summary
Upgrades backend runtime baseline and dependency management for issue #10 .
### Changes
1. **Python Baseline**: Updated from 3.13 to 3.14
- Updated `backend/pyproject.toml` requires-python constraint
- Updated `backend/pyrightconfig.json` pythonVersion
- Updated all Dockerfile and CI references
2. **Dependency Pinning**: Switched to exact version pins in `backend/pyproject.toml`
- All dev and runtime dependencies now use `==` instead of `>=`
- `fastapi==0.120.2`, `uvicorn==0.38.0`
- ruff, pyright, pytest suite pinned to current resolved versions
- Regenerated `backend/uv.lock` under Python 3.14
3. **Startup Compatibility Guard** (TDD via RED→GREEN)
- New `compatibility_status()` function evaluates runtime and pinned deps
- Startup raises `RuntimeError` if policy fails
- Implemented via FastAPI lifespan (non-deprecated) handler
4. **Compatibility Status Endpoint**
- New `GET /compatibility` returns policy status, runtime version, and package checks
- Shares single source of truth with startup validation
5. **Integration Tests**
- Added failing-then-passing tests for startup guard and endpoint behavior
- 100% coverage maintained
6. **Direnv Configuration**
- Added `UV_PYTHON="3.14"` pin to repo `.envrc`
- Ensures direnv creates/recreates venv with correct Python version
### Validation
- ✅ ruff format/check
- ✅ pyright strict (0 errors)
- ✅ pytest: 8 passed, 100% coverage (>=95 gate)
- ✅ pydoclint: pass
- ✅ xdoctest: pass
### Notes
- SQLAlchemy/SQLModel introduction deferred to next pass per scope
- Compatibility logic currently validates fastapi/uvicorn pins (runtime deps)
- Ready for container build validation and Renovate bot testing
Co-authored-by: copilotcoder <copilotcoder@darkhelm.org >
Reviewed-on: #57
Co-authored-by: Cliff Hill <xlorep@darkhelm.org >
Co-committed-by: Cliff Hill <xlorep@darkhelm.org >
2026-06-18 11:19:24 -04:00
570bc83295
Making it more resiliant to network problems, fixing playright
...
Tests / Build and Push CICD Complete Image (push) Failing after 4m6s
Tests / TSDoc Lint Check (push) Has been skipped
Tests / Backend Tests (push) Has been skipped
Tests / Frontend Tests (push) Has been skipped
Tests / Integration Tests (push) Has been skipped
Tests / End-to-End Tests (push) Has been skipped
Tests / Trailing Whitespace Check (push) Has been skipped
Tests / End of File Check (push) Has been skipped
Tests / YAML Syntax Check (push) Has been skipped
Tests / Backend Doctests (push) Has been skipped
Tests / TOML Syntax Check (push) Has been skipped
Tests / Mixed Line Ending Check (push) Has been skipped
Tests / TOML Formatting Check (push) Has been skipped
Tests / Ruff Linting (push) Has been skipped
Tests / Pyright Type Check (push) Has been skipped
Tests / Darglint Docstring Check (push) Has been skipped
Tests / No Docstring Types Check (push) Has been skipped
Tests / ESLint Check (push) Has been skipped
Tests / Prettier Format Check (push) Has been skipped
Tests / Ruff Format Check (push) Has been skipped
Tests / TypeScript Type Check (push) Has been skipped
Tests / Build and Push CICD Base Image (push) Successful in 3m27s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-11-01 10:47:02 -04:00
c5660e547a
Trying to make e2e be truly non-interactive and headless.
...
Tests / Mixed Line Ending Check (push) Has been cancelled
Tests / Darglint Docstring Check (push) Has been cancelled
Tests / Frontend Tests (push) Has been cancelled
Tests / End of File Check (push) Has been cancelled
Tests / Build and Push CICD Image (push) Has started running
Tests / YAML Syntax Check (push) Has been cancelled
Tests / TOML Formatting Check (push) Has been cancelled
Tests / Ruff Linting (push) Has been cancelled
Tests / Ruff Format Check (push) Has been cancelled
Tests / No Docstring Types Check (push) Has been cancelled
Tests / End-to-End Tests (push) Has been cancelled
Tests / TOML Syntax Check (push) Has been cancelled
Tests / TSDoc Lint Check (push) Has been cancelled
Tests / Trailing Whitespace Check (push) Has been cancelled
Tests / Pyright Type Check (push) Has been cancelled
Tests / ESLint Check (push) Has been cancelled
Tests / Backend Tests (push) Has been cancelled
Tests / Prettier Format Check (push) Has been cancelled
Tests / Integration Tests (push) Has been cancelled
Tests / TypeScript Type Check (push) Has been cancelled
Tests / Backend Doctests (push) Has been cancelled
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-30 22:32:59 -04:00
aee066d611
Fixing the e2e tests (again).
...
Tests / Build and Push CICD Image (push) Successful in 1h18m58s
Tests / YAML Syntax Check (push) Successful in 40s
Tests / TOML Syntax Check (push) Successful in 33s
Tests / Mixed Line Ending Check (push) Successful in 38s
Tests / TOML Formatting Check (push) Successful in 46s
Tests / Ruff Linting (push) Successful in 35s
Tests / Ruff Format Check (push) Successful in 32s
Tests / Pyright Type Check (push) Successful in 48s
Tests / Darglint Docstring Check (push) Successful in 30s
Tests / No Docstring Types Check (push) Successful in 20s
Tests / ESLint Check (push) Successful in 51s
Tests / Prettier Format Check (push) Successful in 30s
Tests / TypeScript Type Check (push) Successful in 1m4s
Tests / TSDoc Lint Check (push) Successful in 59s
Tests / End of File Check (push) Successful in 10m13s
Tests / Backend Tests (push) Successful in 37s
Tests / Backend Doctests (push) Successful in 20s
Tests / Frontend Tests (push) Successful in 1m30s
Tests / Trailing Whitespace Check (push) Successful in 12m47s
Tests / Integration Tests (push) Successful in 10m43s
Tests / End-to-End Tests (push) Has been cancelled
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-30 18:47:47 -04:00
eb8802eea2
Fixing frontend coverage.
...
Tests / Build and Push CICD Image (push) Successful in 46m49s
Tests / YAML Syntax Check (push) Successful in 7m40s
Tests / TOML Syntax Check (push) Successful in 53s
Tests / Mixed Line Ending Check (push) Successful in 54s
Tests / TOML Formatting Check (push) Successful in 52s
Tests / Ruff Linting (push) Successful in 55s
Tests / Ruff Format Check (push) Successful in 59s
Tests / Trailing Whitespace Check (push) Successful in 9m41s
Tests / Pyright Type Check (push) Successful in 1m9s
Tests / No Docstring Types Check (push) Successful in 57s
Tests / Darglint Docstring Check (push) Successful in 1m16s
Tests / ESLint Check (push) Successful in 1m6s
Tests / Prettier Format Check (push) Successful in 1m14s
Tests / TypeScript Type Check (push) Successful in 1m12s
Tests / Backend Tests (push) Successful in 1m3s
Tests / TSDoc Lint Check (push) Successful in 1m37s
Tests / Frontend Tests (push) Successful in 1m23s
Tests / Backend Doctests (push) Successful in 1m7s
Tests / End of File Check (push) Successful in 13m53s
Tests / Integration Tests (push) Successful in 6m23s
Tests / End-to-End Tests (push) Has been cancelled
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-30 14:15:13 -04:00
245169c01e
Fixing jest error.
...
Tests / Build and Push CICD Image (push) Successful in 24m39s
Tests / Trailing Whitespace Check (push) Successful in 6m14s
Tests / YAML Syntax Check (push) Successful in 57s
Tests / TOML Syntax Check (push) Successful in 51s
Tests / Mixed Line Ending Check (push) Successful in 53s
Tests / TOML Formatting Check (push) Successful in 53s
Tests / Ruff Linting (push) Successful in 59s
Tests / Ruff Format Check (push) Successful in 57s
Tests / Pyright Type Check (push) Successful in 1m16s
Tests / Darglint Docstring Check (push) Successful in 1m2s
Tests / No Docstring Types Check (push) Successful in 1m0s
Tests / ESLint Check (push) Successful in 1m7s
Tests / Prettier Format Check (push) Successful in 56s
Tests / TypeScript Type Check (push) Successful in 1m11s
Tests / TSDoc Lint Check (push) Successful in 1m7s
Tests / Backend Tests (push) Successful in 1m3s
Tests / Frontend Tests (push) Failing after 1m8s
Tests / Integration Tests (push) Has been skipped
Tests / End-to-End Tests (push) Has been skipped
Tests / Backend Doctests (push) Successful in 56s
Tests / End of File Check (push) Successful in 12m30s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-30 12:25:45 -04:00
f410b142c8
Fixing some CICD errors.
...
Tests / Build and Push CICD Image (push) Successful in 24m56s
Tests / Trailing Whitespace Check (push) Successful in 8m47s
Tests / TOML Syntax Check (push) Successful in 1m2s
Tests / Mixed Line Ending Check (push) Successful in 1m3s
Tests / TOML Formatting Check (push) Successful in 1m6s
Tests / Ruff Linting (push) Successful in 1m9s
Tests / Ruff Format Check (push) Successful in 1m8s
Tests / Pyright Type Check (push) Failing after 1m37s
Tests / Darglint Docstring Check (push) Successful in 1m16s
Tests / No Docstring Types Check (push) Successful in 1m3s
Tests / End of File Check (push) Successful in 12m57s
Tests / Prettier Format Check (push) Successful in 1m14s
Tests / YAML Syntax Check (push) Successful in 28s
Tests / ESLint Check (push) Successful in 1m55s
Tests / TypeScript Type Check (push) Successful in 1m34s
Tests / TSDoc Lint Check (push) Successful in 1m54s
Tests / Backend Tests (push) Successful in 46s
Tests / Backend Doctests (push) Successful in 29s
Tests / Frontend Tests (push) Failing after 4m31s
Tests / Integration Tests (push) Has been skipped
Tests / End-to-End Tests (push) Has been skipped
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-30 11:16:45 -04:00
b5170cc39a
Making linters and formatters great.
...
Tests / Build and Push CICD Image (push) Failing after 1h34m10s
Tests / Trailing Whitespace Check (push) Has been skipped
Tests / End of File Check (push) Has been skipped
Tests / Backend Doctests (push) Has been skipped
Tests / YAML Syntax Check (push) Has been skipped
Tests / Integration Tests (push) Has been skipped
Tests / TOML Syntax Check (push) Has been skipped
Tests / Mixed Line Ending Check (push) Has been skipped
Tests / TOML Formatting Check (push) Has been skipped
Tests / Ruff Linting (push) Has been skipped
Tests / Ruff Format Check (push) Has been skipped
Tests / Pyright Type Check (push) Has been skipped
Tests / Darglint Docstring Check (push) Has been skipped
Tests / No Docstring Types Check (push) Has been skipped
Tests / ESLint Check (push) Has been skipped
Tests / Prettier Format Check (push) Has been skipped
Tests / TypeScript Type Check (push) Has been skipped
Tests / TSDoc Lint Check (push) Has been skipped
Tests / Backend Tests (push) Has been skipped
Tests / Frontend Tests (push) Has been skipped
Tests / End-to-End Tests (push) Has been skipped
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-29 08:40:56 -04:00
cde41ddd38
Fix .yarnrc.yml to use global Yarn Berry instead of local.
...
Tests / Build and Push CICD Image (push) Failing after 22m17s
Tests / Trailing Whitespace Check (push) Has been skipped
Tests / End of File Check (push) Has been skipped
Tests / YAML Syntax Check (push) Has been skipped
Tests / TOML Syntax Check (push) Has been skipped
Tests / Mixed Line Ending Check (push) Has been skipped
Tests / TOML Formatting Check (push) Has been skipped
Tests / Ruff Linting (push) Has been skipped
Tests / Ruff Format Check (push) Has been skipped
Tests / Pyright Type Check (push) Has been skipped
Tests / Darglint Docstring Check (push) Has been skipped
Tests / No Docstring Types Check (push) Has been skipped
Tests / ESLint Check (push) Has been skipped
Tests / Prettier Format Check (push) Has been skipped
Tests / TypeScript Type Check (push) Has been skipped
Tests / TSDoc Lint Check (push) Has been skipped
Tests / Backend Tests (push) Has been skipped
Tests / Frontend Tests (push) Has been skipped
Tests / Backend Doctests (push) Has been skipped
Tests / Integration Tests (push) Has been skipped
Tests / End-to-End Tests (push) Has been skipped
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-27 12:36:08 -04:00
8a3aaeafe8
Getting yarn berry working.
...
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-27 12:23:28 -04:00
2590682425
Making yarn work with vue and vite right.
...
Tests / Build and Push CICD Image (push) Failing after 4m47s
Tests / Trailing Whitespace Check (push) Has been skipped
Tests / End of File Check (push) Has been skipped
Tests / YAML Syntax Check (push) Has been skipped
Tests / Darglint Docstring Check (push) Has been skipped
Tests / TOML Syntax Check (push) Has been skipped
Tests / Mixed Line Ending Check (push) Has been skipped
Tests / TOML Formatting Check (push) Has been skipped
Tests / Ruff Linting (push) Has been skipped
Tests / Ruff Format Check (push) Has been skipped
Tests / Pyright Type Check (push) Has been skipped
Tests / No Docstring Types Check (push) Has been skipped
Tests / ESLint Check (push) Has been skipped
Tests / Prettier Format Check (push) Has been skipped
Tests / TypeScript Type Check (push) Has been skipped
Tests / TSDoc Lint Check (push) Has been skipped
Tests / Backend Tests (push) Has been skipped
Tests / Frontend Tests (push) Has been skipped
Tests / Backend Doctests (push) Has been skipped
Tests / Integration Tests (push) Has been skipped
Tests / End-to-End Tests (push) Has been skipped
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-27 11:50:23 -04:00
2c8f424a81
Fixing everything, making the project structure ready for real code.
...
Tests / Frontend Tests (TypeScript + Vue + Yarn Berry) (push) Failing after 7m49s
Tests / Backend Tests (Python 3.13 + uv) (push) Failing after 14m36s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-23 12:58:32 -04:00
8aa8d41e8a
Did some things, made more improvements.
...
CI/CD Pipeline / Backend Tests (Python) (push) Has been cancelled
CI/CD Pipeline / Frontend Tests (TypeScript/Vue) (push) Has been cancelled
CI/CD Pipeline / Integration Tests (push) Has been cancelled
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-19 21:35:02 -04:00
6068faf026
Getting all the things working.
...
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-18 21:33:45 -04:00
4502c92f9b
Making pre-commit powerful again.
...
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-18 21:31:34 -04:00
8ab2e1dd28
Did some things.
...
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-18 21:29:28 -04:00
9c4a8d96bc
Initial commit.
...
Signed-off-by: Cliff Hill <xlorep@darkhelm.org >
2025-10-18 09:14:10 -04:00