docs(domain): dev/ci Vault + glossary for CI credentials (ADR 0002) #11
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-tracker!11
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "docs/ci-credentials"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Records the credential decision for the test Suite: a dev/ci Vault beside the dev/ci Inventory, and the prod Vault moved out of the playbook-adjacent
group_vars/so a test run never loads it.Evidence
Before: a vault auto-loaded from playbook-adjacent
group_vars/hard-fails a vault-less run.After: inventory-adjacent placement loads only for its own Inventory.
(Rehearsed locally on ansible-core 2.21.3 against a throwaway tree; the prod layout and the dev/ci layout both resolve.)
Merge Danger
Door: two-way
The change is docs-only - an ADR, glossary terms, and README wording. Reverting the branch restores the old wording; nothing reads these files at runtime.
Blast Radius: docs
It records a decision the execution effort will implement (the actual vault move and the two-vault layout are code, still to come). No runtime path changes here.
Code review — two axes
Fixed point:
main(2cc9500) ...docs/ci-credentials(c444035) — 1 commit, 3 files (GLOSSARY.md +22, README.md +3/-1, docs/adr/0002-...md +37 new).Spec source: Vikunja INFRATRACK-8 ("Decide CI secrets and the run's least-privilege credentials") + its resolution comment (map INFRATRACK-2).
The two axes are reported separately and not reranked against each other.
Standards
Documented standards
GLOSSARY.md(### Credentials)_Avoid_list; subheading grouping and 1–2 sentence definitions comply withGLOSSARY-FORMAT.md. No hard breach.GLOSSARY-FORMAT.md): "vault" appears three ways in one glossary —Vault,Prod Vault(Title Case) vsdev/ci vault(lower). Thedev/ci vault_Avoid_list names "ci vault", yet the canonical term keeps the slash. Pick one casing/form.docs/adr/0002-...md(new)# {Short title},status: accepted, sequential0002-slug.md, named Considered/Consequences sections (ADR-FORMAT.md); indocs/adr/perdocs/agents/domain.md.ADR-FORMAT.md): the opening is 3 sentences, but a second full paragraph ("The prod Vault moves from…") precedesConsidered:; it is neither a labelled optional section nor inside the 3-sentence body. Fold it in or label it.Prod Vault.Terminology — ADR and README use
Suite,Guest,Inventory,dev/ci vault,Prod Vaultconsistently withGLOSSARY.md(satisfiesdomain.md"Use the glossary's vocabulary"). No avoid-list synonyms leaked.README.md(+3/-1)vikunja/service/inventories/prod/group_vars/vikunja/vault.yml, but line ~108's command still readsansible-vault edit group_vars/vikunja/vault.yml, and line ~89 still says "The vault password lives in the root.env" (singular), while the ADR describes two vaults, each with its own password.Baseline smells (all judgement calls)
dev/ci vaultvsProd Vaultare sibling concepts named in different registers.Not applicable: the PR body (
prskill format) is not in this docs diff; tooling-enforced checks skipped.Spec
The ADR/glossary/README record the decision's core (dev/ci vault split, forced move + reason, glossary terms, README path) but omit several spec-required elements.
(a) Missing / partial
packages:readonly); fallback: make the image public." ADR says only "a fresh registry token" — nopackages:read, no public-image fallback, and the unproven runner-credentials fact is not recorded.ansible-playbook -i <dev/ci inventory> ... --vault-password-file <dev/ci pass>— no prod secret, no-e." ADR records the rationale against-ebut never states the command; how secrets are "kept out of logs" is not addressed at all.vault_vikunja_db_password,_service_secret,_account_passwordsincl.pit,_smtp_passwordmove into the dev/ci vault … the others are placeholders." ADR mentions only the empty SMTP password; the other three moving as placeholders is unstated.(b) Scope creep
pull_requestfrom a fork sees an empty secrets map, which this single-user instance does not hit today." Not part of the recorded decision.(c) Looks implemented, but wrong
vikunja/service/inventories/prod/group_vars/vikunja/vault.yml, yet the edit example 28 lines below still readsansible-vault edit group_vars/vikunja/vault.yml— stale, contradicts the path the diff just changed.The glossary terms (Vault, Prod Vault, dev/ci vault, CI secret) and the forced-move justification are faithful.
Summary
ansible-playbookinvocation and how secrets stay out of logs), and the ADR never states it.The docs conform closely to house style yet under-record the decision they exist to capture, and the README edit introduces a contradiction in the file it touched.
Review run via the
code-reviewskill (two parallel axes, aggregated, not reranked).Review addressed —
a37395aFixed point
2cc9500...a37395a(1 commit, 3 files). Every finding, mapped:Standards
Considered:/Consequences:stay labelled.Prod Vaultvsdev/ci vaultunified to glossary terms:Vault(the concept),prod Vault/dev/ci Vault(siblings), the environment qualifier lower to match the already-lowerprod Inventory. Applied across GLOSSARY, ADR, README; the avoided synonyms stay unused.inventories/prod/group_vars/vikunja/vault.yml(wasgroup_vars/vikunja/vault.yml), and the "one secrets file" line now names the second (dev/ci) password instead of implying one. The duplicated-path smell is gone: the only remaininggroup_vars/vikunja/vault.ymlmentions are the corrected full path, twice, consistent.Spec
ansible-playbook -i <dev/ci Inventory> --vault-password-file <dev/ci pass>— no-e, no env var — and how secrets stay out of logs (the password arrives as a file, never on a command line).packages:readonly, with the public-image fallback that drops the credential._db_password,_service_secret,_account_passwordsincl.pit,_smtp_password) recorded as moving into the dev/ci Vault as placeholders, SMTP empty.Verify
make fmt— clean (docs-only; no OpenTofu files touched). No code path reads these files at runtime.docs(domain): dev/ci vault + glossary for CI credentials (ADR 0002)to docs(domain): dev/ci Vault + glossary for CI credentials (ADR 0002)Re-review —
a37395a(fix commita37395aover2cc9500)Two-axis re-review at the new head. Each prior finding verified against the actual file contents, not the fix comment. Both axes now PASS.
Verification:
git diff 2cc9500...a37395a,git show a37395a:...;git ls-files,git grepfor the fork note. 3 files: GLOSSARY.md, README.md, docs/adr/0002-....md.Standards
Prior findings
**prod Vault**/**dev/ci Vault**(GLOSSARY:81/85); README and ADR match. One register (capital V) across all three files.inventories/prod/group_vars/vikunja/vault.yml; the password lines (:91–94) reconciled to "operator keeps one secrets file … dev/ci Vault has its own password".New / residual (all judgement, none hard)
_Avoid_— but it names the root.env, not a Vault; likely fine.packages:read, everyvault_vikunja_*name, the public-image aside, INFRATRACK-21). ADR-FORMAT licenses Consequences for "non-obvious downstream effects" — borderline bloat.domain.mdprefers the defined term.Spec
packages:read+ public-image fallback — RESOLVED. ADR L32–33. (The fallback implies, but does not state, the unproven runner-credentialsrationale.)ansible-playbook -i <dev/ci Inventory> --vault-password-file <dev/ci pass>— no-e, no env var, password arrives as a file, never on a command line.git grepfinds none.Glossary term set required by the spec is complete (Vault, prod Vault, dev/ci Vault, CI secret).
(a) still missing/partial: none substantive — the "image public" fallback is recorded but not labelled as the hedge against the unproven runner-
credentialsfact.(b) unasked-for: none introduced by the fix.
(c) looks wrong: README L93–94 "The dev/ci Vault has its own password, held only in the CI secret store" reads as overreach for local runs (
make test-local, INFRATRACK-10, still open) — the spec is silent on local runs, so no contradiction; flag for INFRATRACK-10.Recommendation: MERGE ✅
inventories/prod/group_vars/vikunja/vault.yml) and assert "prod still decrypts" on ansible-core 2.21.3, butgit ls-filesshows the vault still tracked atvikunja/service/group_vars/vikunja/vault.yml(inventories/prod/holds onlyhosts). This is expected — the PR body says the move is code, "still to come" — so the docs are a forward record of the decision, not a claim aboutmaintoday.Re-review via the
code-reviewskill (two parallel axes, aggregated, not reranked).