Rules find a home; source comments go self-contained (#9) #15
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge!15
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "hermes/9-rules-find-a-home"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #7. Implements #9.
Summary
The rules move to the agent context file; the comments that leaned on them learn to stand alone.
"Version pins live in one place" is not carried over — it is self-evident from the role defaults.
Evidence
grep -rniE 'convention ?[0-9]|README|AGENTS\.md' ansible tofu-> 2 hits (defaults/main.yml:2,ansible.cfg:7), plus 3 in the ADR.After: the same command over
ansible/andtofu/-> 0 hits.tofu fmt -checkandtofu validate(Guest stack) pass; the role YAML parses; neither.tflogic,.ymllogic nor any.j2template was touched.Merge Danger
Door: two-way — four docs/comment files;
git reverton the merge restores the previous text.Blast Radius: none at runtime. The tofu stacks and the ansible role are byte-identical in behaviour; only comments and agent-facing docs changed.
@ -2,6 +2,27 @@Infra repo: OpenTofu + Ansible that provisions and maintains Forgejo and Nginx Proxy Manager (NPM) on the Pit hosts.## Standing rulesI don't like this naming. This implies the actions that we're taking here. A new reader doesn't need to know that these used to be rules in a readme with more rules and these are the last "standing rules". Naming should be something that simply implies that these are rules to follow by agents in this repo/project.
@ -1,5 +1,5 @@---# Version pins (convention 4): one place for the service, one for its runner.# Version pins: one place for the service, one for its runner.Everithing after the
:needs to go. It's implementation details that would need to grow if the list of pinned versions grow in the future@ -16,3 +16,2 @@`uses: actions/checkout@v5` resolves without touching GitHub.- **Runner binary pinned** next to the Forgejo pin in role defaults(convention 4), downloaded checksum-first like the service binary itself.- **Runner binary pinned** next to the Forgejo pin in role defaults,Again a lot of implementation detail. ADRs should be documents that discuss architecture, not implementation. Just stating that the version needs to be pinned is enough
@ -49,3 +47,1 @@download, fetched checksum-first) are third-party software mirrors, not theoperator's own public IP or DDNS name — the convention's actual target. Bothare public by design, and both hosts live in role defaults rather than being- **Public mirrors are not our addresses.** `data.forgejo.org` (theI don't think this section even belongs to the ADR. Again too much implementation detail
Comments addressed in
38320ca(the API rejected inline replies on this instance, so this is one comment instead of four).## Standing rulesname (r150): renamed to## Rules. You are right, "standing" was a leftover from the list it used to sit in.# Version pins.- **Runner binary pinned** in role defaults.forgejo_actions_mirrorandforgejo_runner_download_host— where someone changing a host actually looks. Say the word if you want that trimmed too.Net effect across the two commits: no numbered-convention reference and no README/AGENTS pointer survives under
ansible/ortofu/; the ADR is down from 70 to 57 lines, decisions only.tofu fmt -checkclean, role YAML parses, no behaviour touched.