feat: publish classifications from Forgejo

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
This commit is contained in:
tegwick 2026-09-01 01:39:39 +02:00
parent 738d407bb7
commit fd624021ec
12 changed files with 2000 additions and 47 deletions

View file

@ -102,7 +102,7 @@ accepted as one current generation. Evidence:
```task
id: RMGR-WP-0013-T05
status: wait
status: progress
priority: medium
state_hub_task_id: "9dbdbcfc-f485-50fb-92b1-3e084563d276"
```
@ -110,11 +110,14 @@ state_hub_task_id: "9dbdbcfc-f485-50fb-92b1-3e084563d276"
Package the publisher runtime, document registry bootstrap and refresh, record
evidence, and hand the concrete endpoint/configuration to HUB-WP-0006-T06.
Implementation and operating documentation are complete. Deployment remains
waiting on an explicit placement/network owner: the public Core Hub cluster
cannot read the host-local Repo Manager checkout registry, and mounting a broad
home directory or reintroducing State Hub as the live classification source is
not an acceptable implicit choice.
**Update (2026-09-01):** placement is resolved to the `railiance01` Core Hub
cluster. The publisher now uses a committed stable UUID-to-Forgejo registry,
reads each classification at the exact default-branch commit, and has a
digest-pinned, private ClusterIP deployment with constrained Forgejo HTTPS
egress. Live anonymous conformance accepts 114 public repositories and reports
the nine private `rapp-*` repositories as errors. Final admission therefore
waits only for a dedicated `read:repository` Forgejo token; reusing the
operator/admin PAT or another workload's token is explicitly disallowed.
## Acceptance