Migrate kaizen distribution to Forgejo
All checks were successful
ci / test (push) Successful in 2m21s
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-08-20 09:43:49 +02:00
parent f027ee5492
commit d4a4560a8d
34 changed files with 324 additions and 195 deletions

View file

@ -1,30 +1,27 @@
# Python Package Release
`kaizen-agentic` publishes as the `kaizen-agentic` Python package on the Coulomb
Gitea PyPI registry. Public [pypi.org](https://pypi.org/) distribution is optional
`kaizen-agentic` publishes as the `kaizen-agentic` Python package on the Forgejo
PyPI registry. Public [pypi.org](https://pypi.org/) distribution is optional
and not required for ecosystem use.
## Install (consumers)
Dependencies such as `pyyaml` resolve from public PyPI. Use Gitea as an extra index:
Dependencies such as `pyyaml` resolve from public PyPI. Use Forgejo as an extra index:
```bash
export GITEA_PACKAGE_USER=<gitea-user>
export GITEA_PACKAGE_TOKEN=<package-token>
pip install kaizen-agentic \
--extra-index-url "https://${GITEA_PACKAGE_USER}:${GITEA_PACKAGE_TOKEN}@gitea.coulomb.social/api/packages/coulomb/pypi/simple/"
--extra-index-url https://forgejo.coulomb.social/api/packages/coulomb/pypi/simple/
```
Global CLI via pipx:
```bash
pipx install kaizen-agentic \
--pip-args="--extra-index-url https://${GITEA_PACKAGE_USER}:${GITEA_PACKAGE_TOKEN}@gitea.coulomb.social/api/packages/coulomb/pypi/simple/"
--pip-args="--extra-index-url https://forgejo.coulomb.social/api/packages/coulomb/pypi/simple/"
```
Do not commit tokenized index URLs. Inject credentials via environment variables or
CI secrets.
Consumer reads are anonymous. Keep publish credentials in Forgejo Actions secrets
or inject them through the environment for a deliberate local release.
## Local Release
@ -37,53 +34,47 @@ make package-check
Publish to the Coulomb organization registry:
```bash
TWINE_USERNAME=<gitea-user> \
TWINE_USERNAME=<forgejo-user> \
TWINE_PASSWORD=<package-token> \
make publish-gitea
make publish-forgejo
```
Package upload endpoint:
```text
https://gitea.coulomb.social/api/packages/coulomb/pypi
https://forgejo.coulomb.social/api/packages/coulomb/pypi
```
Consumer simple index:
```text
https://gitea.coulomb.social/api/packages/coulomb/pypi/simple/
https://forgejo.coulomb.social/api/packages/coulomb/pypi/simple/
```
## Gitea repository secrets (one-time)
## Forgejo repository secrets (one-time)
Configure in Gitea: **Repository → Settings → Actions → Secrets**.
Configure in Forgejo: **Repository → Settings → Actions → Secrets** (or use
organization-level secrets when managed centrally).
| Secret | Value |
|--------|-------|
| `PACKAGE_USER` | `tegwick` — Gitea username that owns the package token |
| `PACKAGE_TOKEN` | Gitea API token named `inter-hub-pkg-rep` (`write:package`) |
| `FORGEJO_PYPI_USER` | Forgejo username that owns the package token |
| `FORGEJO_PYPI_TOKEN` | Forgejo token with package-write permission |
Token custody (OpenBao):
Discover credential ownership before requesting or rotating a token:
```text
platform/data/operators/inter-hub/package-management
→ field: inter-hub-pkg-rep
```bash
warden route find "publish kaizen-agentic to Forgejo PyPI" --json
```
Paste the **plaintext** token into the Gitea secret UI. `inter-hub-pkg-rep` is the
token name in Gitea, not a username.
Gitea rejects secret names prefixed with `GITEA_` — use `PACKAGE_USER` / `PACKAGE_TOKEN`
(not `GITEA_PACKAGE_USER`). Workflows use `runs-on: haskelseed` and native `git clone`
(no GitHub Marketplace actions).
Never commit or copy the token into documentation, workplans, or State Hub.
The publish workflow fails at the upload step when either secret is missing or
invalid. Do not commit tokens to the repository.
**Smoke-test (2026-06-16):** `workflow_dispatch` run #3042 authenticated successfully
(`409 Conflict` on re-upload of `1.1.0` — expected). Root causes of earlier `401`s:
wrong token (`GITEA_API_TOKEN` ≠ package token), wrong username (`inter-hub-pkg-rep`
is a token name), and a stale org-level secret. Build uses `.build-venv` (PEP 668).
**Verified (2026-08-20):** the Forgejo index serves `kaizen-agentic==1.4.0`.
A fresh virtual environment installed it with `--no-cache-dir` and the CLI reported
version `1.4.0`.
Verify secrets without cutting a release:
@ -103,13 +94,13 @@ Before `git tag vX.Y.Z && git push origin vX.Y.Z`:
- [ ] `make release-check` passes (tests, flake8, version consistency, agent parity)
- [ ] `make package-check` builds and validates `dist/*`
- [ ] `CHANGELOG.md` has a dated `[X.Y.Z]` section matching `pyproject.toml`
- [ ] `PACKAGE_USER` and `PACKAGE_TOKEN` secrets are set
- [ ] `FORGEJO_PYPI_USER` and `FORGEJO_PYPI_TOKEN` secrets are set
- [ ] Publish workflow smoke-tested via `workflow_dispatch` (or prior tag release)
- [ ] `make agents-sync-package` run if `agents/` changed since last release
## Gitea Actions Release
## Forgejo Actions Release
The `.gitea/workflows/publish-python-package.yml` workflow publishes on tags
The `.forgejo/workflows/publish-python-package.yml` workflow publishes on tags
matching `v*`.
Example:
@ -135,11 +126,11 @@ A runner that executes a scheduled kaizen agent task (fired by activity-core)
needs:
- **`kaizen-agentic` on PATH** — `pip install kaizen-agentic` (or `pipx install
kaizen-agentic`) using the Gitea PyPI extra index when installing from the
kaizen-agentic`) using the Forgejo PyPI extra index when installing from the
internal registry:
```bash
pip install kaizen-agentic \
--extra-index-url https://gitea.coulomb.social/api/packages/coulomb/pypi/simple/
--extra-index-url https://forgejo.coulomb.social/api/packages/coulomb/pypi/simple/
```
- **Repo checkout reachable** at the `host_paths[<host>]` registered in State
Hub, with a valid `.kaizen/schedule.yml` (`kaizen-agentic schedule validate`).