README goes thin (#10) #16
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge!16
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "hermes/10-readme-goes-thin"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
The README stops being the junk drawer and becomes a front door. The numbered
Conventions list and the detail that had grown into it are gone; the detail
already lives in
docs/(issue #8). Scope isREADME.mdonly.Evidence
handling, PRE rehearsal and Actions notes;
grep -nEi 'convention|phase 1|no CI|private' README.mdmatched 6 lines.After: 71-line README; the same grep matches 0 lines. 44 insertions, 86 deletions.
Acceptance checks run against the branch:
grep -nE '^\s*[0-9]+\.\s'→ none.AGENTS.md,LICENSEand external tool sites — nothing intodocs/yet.docs/sections carried over from #8: Requirements/Env/Running/Overview/Contributing/License all present.Out-of-diff, run at merge time: the forge repository description was updated via
the API to the new tagline, in English, and read back:
Merge Danger
Door: two-way — README-only change,
git revertwalks it back.Blast Radius: repo landing page. No tofu or ansible behaviour changes.
@ -6,0 +7,4 @@its own git service — repositories, issues, pull requests and CI — instead ofdepending on a public one, and doubles as the worked example of the three-layerpattern (Guest, Edge, service) that the other sites copy. Part of thehomelab-blueprint plan (https://github.com/atthepit/homelab-blueprint).Remove mention of blueprint plan
@ -16,0 +15,4 @@token for it.- [OpenTofu](https://opentofu.org/) `>= 1.8`.- [Ansible](https://docs.ansible.com/) on the machine that runs the playbook.- An admin account on the Edge (NPM), with `sshd` disabled in its LXC and theWould it be possible to move the sshd requirement to ansible config? out of scope for this PR, just curious
@ -52,3 +42,2 @@cd tofu/npm && set -a && source .env && set +a && tofu plan -var-file=forgejo.tfvars# ALWAYS: source .env (tofu does not read .env on its own) and -var-file=forgejo.tfvars# (without it, the required variables fail the plan instead of proposing destroys).# Review the plan in full, then:You mention plan review here but not for guest
@ -76,3 +58,1 @@committed on main so a rehearsal needs no variable re-add — a bare variablecreates nothing, its only consumer is the parked `tofu/pre.tf`.) To run arehearsal:## Before you touch anythingLet's change this section to
For agentsor something similar@ -93,2 +63,3 @@## Contributing## Actions (Forgejo runner on the guest)Work on a branch and open a pull request for Pedro to review — nothing goesChange Pedro for
a humanAddressed all five in
29d5b46:sshdrequirement to ansible config? (out of scope, answering anyway): in principle yes, but it needs the NPM appliance to become a managed host, which it is not today. This repo reaches NPM only through its API (tofu/npm/, proxy hosts + streams); Ansible targets the Forgejo Guest only (inventories/prod/hosts). Doing it "in ansible" would mean adding annpmhost to the inventory plus a small role/play that runssystemctl disable --now sshthere. Two wrinkles worth noting before anyone does: (1) ordering — Ansible reaches that host over SSH, so the disable happens from inside the very session it removes, and any later config drift to NPM would need another path in (the API, or re-enabling sshd); (2) the router rule and the NPM UI are still manual, so this would move one of three steps, not all of them. Worth its own issue if you want it.tofu plan, thentofu applyunder a "Review the plan in full, then:" line — and the prose below now reads "Review the plan in full before every apply, both layers."## Before you touch anything→## For agents.a human": Contributing now reads "open a pull request for a human to review — nothing goes directly tomain. A pull request merges without required approvals."29d5b4635ato636df594b4