Commit graph

8 commits

Author SHA1 Message Date
ff826beb33 Close T06: /health routes to the API again (REUSE-WP-0020)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ci / validate-registry (push) Successful in 1m38s
Helm revision 8. /health returns 200 from uvicorn instead of 404 from the
landing nginx, / still serves the landing page, and make reuse-smoke passes
end to end for the first time.

Also resolves the composed_at observation: it was not a bug, just a build
that predated REUSE-WP-0019-T06. The timestamp now advances per recompose.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 08:17:49 +02:00
0300c5b142 Name the SCOPE-block mistake in compose warnings (REUSE-WP-0020-T03)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
ci / validate-registry (push) Successful in 1m20s
Build and Publish Container Image / build-and-push (push) Successful in 34s
An index row with no id now says whether it looks like a SCOPE.md capability
block, instead of leaving the author to work out why their repo contributes
nothing to the federated index. That confusion is invisible without a
diagnostic: the row is valid YAML, the file parses, and the member just
silently disappears.

Swept all 61 federation sources with --refresh: evidence-binder is the only
affected member. The other ten zero-count repos are genuine empty scaffolds.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 03:23:29 +02:00
9d015d4604 Record T07 done and the SCOPE-block root cause of T03
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 03:22:01 +02:00
2a3fc70172 Record production deploy of main-b035664 (REUSE-WP-0020-T05 done)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
ci / validate-registry (push) Successful in 3m10s
Helm revision 7 on Railiance01. Production now runs a Forgejo image; the Gitea
dependency is gone from both the federation sources and the image reference.
/v1/reuse-events returns 200 for the first time, so REUSE-WP-0019 T04/T05 are
finally live. PVC and all 61 registrations survived.

Also diagnose T06: /health is served correctly by the app (200 in-cluster) but
Traefik routes it to the landing nginx, because router priority is derived from
rule-string length and Path(/health) ties with PathPrefix(/). Raise T06 to
medium — make reuse-smoke is the documented deploy check and it false-negatives.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 00:47:26 +02:00
3b46fd747f Record image pin and remaining apply step (REUSE-WP-0020-T05)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ci / validate-registry (push) Successful in 1m35s
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 00:18:03 +02:00
3aaf961352 Route evidence-binder index fix to its owner (REUSE-WP-0020-T03)
Inspection showed the defect is larger than the missing id that broke compose:
both rows use a non-conforming shape and registry/capabilities/ is empty, so
they are orphans with no backing entry Markdown.

Left to that repo rather than edited here. Reshaping the rows is mechanical,
but assigning maturity vectors is an assessment of their own delivery state.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 00:16:53 +02:00
b035664890 Correct deploy guide for the Gitea registry retirement (REUSE-WP-0020-T05)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ci / validate-registry (push) Successful in 2m44s
Build and Publish Container Image / build-and-push (push) Successful in 49s
The guide described gitea.coulomb.social as the live registry and its manual
build commands still pushed there. CoulombCore is switched off 2026-08-31.

Also record what the registry actually contains: authenticated tags/list shows
latest, main-bca7165, main-f9d957a and no e3ae22e — so the tag pinned in
railiance-apps/helm/reuse-surface-values.yaml cannot be pulled today, making
ImagePullBackOff a present risk on any restart rather than a future one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 00:06:07 +02:00
0c6b1e2538 Harden federated compose against malformed member indexes (REUSE-WP-0020)
Repointing the production hub's 50 Gitea-hosted federation sources to Forgejo
ahead of the 2026-08-31 CoulombCore retirement took /v1/federated to HTTP 500.
One member index (evidence-binder) has capability rows with no `id`, and
compose_federated_index dereferenced item["id"] unguarded. Its Gitea copy was a
stale snapshot returning a non-mapping, so those rows had never been parsed.

A single malformed member index must not take down the whole endpoint. Extract
_read_index_entries(): unparseable YAML, a non-mapping body, an empty file, and
a non-list `capabilities` each degrade to a warning and an empty row list, and
rows without an `id` are skipped individually. A failed source stays listed with
count 0 so it remains visible to operators rather than silently disappearing.

Also fix wall-clock rot in tests/test_plan_check.py, which was already failing
at clean HEAD: three tests pinned the compose date to a literal that has now
aged past STALE_DAYS.

Add workplan REUSE-WP-0020 covering the full cutover.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 00:04:39 +02:00