Compare commits

..
Author SHA1 Message Date
Jørgen StensrudandClaude Fable 5.1 46eab199ee Add forte-cli public device-code Keycloak client
/ test (pull_request) Successful in 7s
Add a shared public client `forte-cli` to the `forte` realm so downloaded
skills (forte-drop first) can do RFC 8628 device-code login through the
Auth Sidecar. Today no client in the realm has the device grant enabled,
so the flow cannot start.

Client (inline in forte-realm.json, imported verbatim by keycloak-config-cli):
- publicClient: true, standardFlowEnabled: false,
  directAccessGrantsEnabled: false
- attributes: oauth2.device.authorization.grant.enabled=true
- no secret, no redirectUris/webOrigins, no k8s.secret.sync

It has to go in the realm JSON because the self-service registrar
hardcodes publicClient:false/standardFlowEnabled:true and drops
attributes. Also add forte-cli to the cleanup CronJob's protected list
(belt-and-braces; it does not match the UUID pattern anyway).

Additive only: gitea/grafana/argocd and all other realm settings are
unchanged. Keycloak is deployed only via the upc-dev overlay, which
inherits base values, so this lands on id.forteapps.net.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QciXev3MtCxo3eomcfrDRW
2026-09-03 09:56:31 +02:00
gitea_admin b616e59231 Increase min age for keycloak client cleanup
/ test (push) Successful in 13s
increase to 15 days min age
2026-09-03 07:26:30 +00:00
danijel.simeunovic 705c010806 Mute deployment notifications
/ test (push) Successful in 9s
2026-08-25 12:34:33 +00:00
29624e845d fix(forte-drop-pg-backup): set MC_CONFIG_DIR so backups can upload (#23)
/ test (push) Successful in 10s
The nightly Postgres backup CronJob has been **failing every run** — no backups exist in `s3://drops/_pgbackups/`.

**Cause:** the upload container runs as uid 65532 (`runAsNonRoot`). `mc` defaults its config to `$HOME/.mc` = `/.mc` and dies with `mkdir /.mc: permission denied` on the non-writable root fs — before any upload.

**Fix:** set `MC_CONFIG_DIR=/work/.mc` (the shared emptyDir, writable via `fsGroup: 65532`). The `pg_dump` initContainer already succeeds; this lets the upload step actually run.

Validated: `kubectl kustomize` renders clean; env present on the upload container.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Sten <sten@Sten-sin-MacBook-Pro.local>
Reviewed-on: #23
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Jørgen Stensrud <jorgen.stensrud@fortedigital.com>
Co-committed-by: Jørgen Stensrud <jorgen.stensrud@fortedigital.com>
2026-08-25 09:44:02 +00:00
danijel.simeunovic 4712eb4804 wayfinder instructions
/ test (push) Successful in 8s
2026-08-01 12:10:50 +02:00
danijel.simeunovic 2696044a02 docs
/ test (push) Successful in 8s
2026-08-01 12:07:26 +02:00
danijel.simeunovic b0c0074f7f Merge branch 'main' of https://git.forteapps.net/Forte/launchpad
/ test (push) Successful in 8s
2026-07-02 15:27:25 +02:00
danijel.simeunovic 7f4a0bccf1 notify mail 2026-07-02 15:27:16 +02:00
jorgen.stensrud 52c752caba feat(auth-sidecar): inject AUTH_OIDC_ALLOWED_RETURN_HOSTS (#25)
/ test (push) Successful in 9s
2026-07-02 13:17:57 +00:00
danijel.simeunovic af1e94d85d review
/ test (push) Successful in 9s
2026-07-02 12:25:11 +02:00
jorgen.stensrudanddanijel.simeunovic df35cd0630 feat(auth-sidecar): inject AUTH_OIDC_COOKIE_DOMAIN (#24)
/ test (push) Successful in 10s
Adds AUTH_OIDC_COOKIE_DOMAIN to the injected OIDC sidecar, from the `policies.forteapps.io/auth-oidc-cookie-domain` annotation. Empty when unset = host-only = unchanged for every app. Pairs with forte-helm + auth-sidecar#23. Safe to merge anytime (opt-in).

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Reviewed-on: #24
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
2026-06-30 06:59:37 +00:00
danijel.simeunovic 04b3a210fe shared-prompts
/ test (push) Successful in 8s
2026-06-29 17:02:50 +02:00
danijel.simeunovic 330c25f241 model
/ test (push) Successful in 8s
2026-06-29 16:47:51 +02:00
jorgen.stensrud 3a23451802 feat(forte-drop): issuer dnsZones for *.drop.forteapps.net (subdomain-per-drop) (#22)
/ test (push) Successful in 12s
2026-06-26 11:38:30 +00:00
31 changed files with 319 additions and 309 deletions
+4 -1
View File
@@ -23,7 +23,7 @@ jobs:
REVIEW__INLINE_COMMENT_FALLBACK: "false" REVIEW__INLINE_COMMENT_FALLBACK: "false"
# LLM configuration # LLM configuration
LLM__PROVIDER: CLAUDE LLM__PROVIDER: CLAUDE
LLM__META__MODEL: claude-sonnet-4-20250514 LLM__META__MODEL: claude-3-opus
LLM__META__MAX_TOKENS: "4096" LLM__META__MAX_TOKENS: "4096"
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }} LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
@@ -36,6 +36,9 @@ jobs:
fetch-depth: 0 fetch-depth: 0
token: ${{ secrets.AI_REVIEW_TOKEN }} token: ${{ secrets.AI_REVIEW_TOKEN }}
- name: Update submodules to remote
run: git submodule update --remote --merge
- name: Run inline review - name: Run inline review
uses: docker://nikitafilonov/ai-review:v0.64.0 uses: docker://nikitafilonov/ai-review:v0.64.0
with: with:
+2
View File
@@ -1,3 +1,5 @@
[submodule "shared-prompts"] [submodule "shared-prompts"]
path = shared-prompts path = shared-prompts
url = https://git.forteapps.net/Forte/ai-review-prompts.git url = https://git.forteapps.net/Forte/ai-review-prompts.git
branch = main
+103
View File
@@ -1,3 +1,64 @@
# =============================================================================
# UpCloud Workload Cluster
# =============================================================================
# A lean UCS cluster for running application workloads. No managed data
# services — those live on the platform cluster. ArgoCD (on the platform
# cluster) deploys apps to this cluster via the app-of-apps pattern.
#
# Platform components deployed by deploy-workload.sh:
# nginx-ingress, cert-manager, external-dns, external-secrets, alloy
#
# Usage:
# tofu init && tofu plan && tofu apply
# ./sync-tofu-outputs.sh --env upcloud-workload
# ./deploy-workload.sh --env upcloud-workload
# =============================================================================
variable "prefix" {
description = "Prefix for resource names"
type = string
default = "clst-workload"
}
variable "zone" {
description = "UpCloud zone"
type = string
default = "no-svg1"
}
variable "node_plan" {
description = "UpCloud server plan for worker nodes"
type = string
default = "2xCPU-4GB"
}
variable "node_count" {
description = "Number of worker nodes"
type = number
default = 2
}
variable "network_cidr" {
description = "CIDR block for the private network"
type = string
default = "10.110.0.0/24"
}
variable "control_plane_ip_filter" {
description = "CIDRs allowed to access the K8s API"
type = list(string)
default = ["0.0.0.0/0"]
}
variable "tags" {
description = "Labels to apply to resources"
type = map(string)
default = {
Environment = "workload"
ManagedBy = "tofu"
}
}
module "cluster" { module "cluster" {
source = "../modules/cluster" source = "../modules/cluster"
@@ -15,3 +76,45 @@ module "cluster" {
ManagedBy = "tofu" ManagedBy = "tofu"
} }
} }
# ─── Networking ───────────────────────────────────────────────────────
resource "upcloud_router" "kubernetes" {
name = "${var.prefix}-workload-router"
}
resource "upcloud_gateway" "kubernetes" {
name = "${var.prefix}-workload-gateway"
zone = var.zone
features = ["nat"]
router {
id = upcloud_router.kubernetes.id
}
}
resource "upcloud_network" "kubernetes" {
name = "${var.prefix}-workload-network"
zone = var.zone
router = upcloud_router.kubernetes.id
ip_network {
address = var.network_cidr
dhcp = true
dhcp_default_route = true
family = "IPv4"
gateway = cidrhost(var.network_cidr, 1)
}
depends_on = [upcloud_gateway.kubernetes]
}
# ─── Kubernetes Cluster ───────────────────────────────────────────────
resource "upcloud_kubernetes_cluster" "main-prod" {
name = "${var.prefix}-workload"
zone = var.zone
network = upcloud_network.kubernetes.id
control_plane_ip_filter = var.control_plane_ip_filter
private_node_groups = true
}
+6 -49
View File
@@ -5,56 +5,9 @@ SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
TOFU_ROOT="$(dirname "$SCRIPT_DIR")" TOFU_ROOT="$(dirname "$SCRIPT_DIR")"
PROJECT_ROOT="$(dirname "$TOFU_ROOT")" PROJECT_ROOT="$(dirname "$TOFU_ROOT")"
usage() { CLUSTER="${1:?Usage: $0 <cluster> (e.g., aks-dev, eks-prod)}"
cat <<EOF
Usage: $0 <cluster> --envtype <dev|prod|workload>
Fetch (or reuse) a kubeconfig for the given cluster.
Platform is read from the cluster prefix (<platform>-...).
Env type must be supplied explicitly — it is no longer inferred
from the cluster name, so names like 'upc-forte-group' work.
Examples:
$0 aks-dev --envtype dev
$0 upc-forte-group --envtype prod
$0 eks-workload --envtype workload
EOF
exit "${1:-0}"
}
CLUSTER=""
ENVTYPE=""
while [[ $# -gt 0 ]]; do
case "$1" in
--envtype) ENVTYPE="${2:-}"; shift 2 ;;
--envtype=*) ENVTYPE="${1#*=}"; shift ;;
-h|--help) usage 0 ;;
-*) echo "Unknown option: $1"; usage 1 ;;
*)
if [[ -z "$CLUSTER" ]]; then
CLUSTER="$1"; shift
else
echo "Error: unexpected argument '$1'"; usage 1
fi
;;
esac
done
[[ -z "$CLUSTER" ]] && { echo "Error: <cluster> argument required"; usage 1; }
[[ -z "$ENVTYPE" ]] && { echo "Error: --envtype <dev|prod|workload> required"; usage 1; }
case "$ENVTYPE" in
dev|prod|workload) ;;
*) echo "Error: invalid --envtype '$ENVTYPE'. Expected: dev, prod, workload"; exit 1 ;;
esac
PLATFORM="${CLUSTER%%-*}" PLATFORM="${CLUSTER%%-*}"
ENV="$ENVTYPE" ENV="${CLUSTER#*-}"
case "$PLATFORM" in
aks|eks|gke|upc) ;;
*) echo "Error: unknown platform '$PLATFORM'. Expected: aks, eks, gke, upc"; exit 1 ;;
esac
KUBECONFIG_FILE="$PROJECT_ROOT/private/$CLUSTER/kubeconfig" KUBECONFIG_FILE="$PROJECT_ROOT/private/$CLUSTER/kubeconfig"
@@ -100,6 +53,10 @@ else
CLUSTER_ID=$(tofu output -raw cluster_id 2>/dev/null || echo "${UPCLOUD_CLUSTER_ID:-}") CLUSTER_ID=$(tofu output -raw cluster_id 2>/dev/null || echo "${UPCLOUD_CLUSTER_ID:-}")
upctl kubernetes config "$CLUSTER_ID" > "$KUBECONFIG_FILE" upctl kubernetes config "$CLUSTER_ID" > "$KUBECONFIG_FILE"
;; ;;
*)
echo "Error: unknown platform '$PLATFORM'"
exit 1
;;
esac esac
chmod 600 "$KUBECONFIG_FILE" chmod 600 "$KUBECONFIG_FILE"
+11 -28
View File
@@ -8,33 +8,25 @@ PROJECT_ROOT="$(dirname "$TOFU_ROOT")"
# ─── Usage ──────────────────────────────────────────────────────────── # ─── Usage ────────────────────────────────────────────────────────────
usage() { usage() {
cat <<EOF cat <<EOF
Usage: $0 <cluster> --envtype <dev|prod|workload> [options] Usage: $0 <cluster> [options]
Provision a Kubernetes cluster using OpenTofu. Provision a Kubernetes cluster using OpenTofu.
Cluster name is opaque — platform is read from its prefix Mirrors bootstrap.sh convention: cluster = <platform>-<env>
(<platform>-...), env is taken from --envtype.
Platforms (inferred from cluster prefix): Clusters: aks-dev | aks-prod | eks-dev | eks-prod
aks | eks | gke | upc gke-dev | gke-prod | upc-dev | upc-prod
<platform>-workload (for workload clusters)
Env types (required via --envtype):
dev Platform cluster, development
prod Platform cluster, production
workload Lean cluster for application workloads (no managed data
services — those run on the platform cluster)
Options: Options:
--envtype <type> dev | prod | workload (required)
--plan Plan only, don't apply --plan Plan only, don't apply
--destroy Destroy the cluster (use teardown-cluster.sh instead) --destroy Destroy the cluster (use teardown-cluster.sh instead)
--auto Skip confirmation prompts --auto Skip confirmation prompts
-h, --help Show this help -h, --help Show this help
Examples: Examples:
$0 aks-dev --envtype dev $0 aks-dev
$0 eks-prod --envtype prod --plan $0 eks-prod --plan
$0 upc-forte-group --envtype prod --auto $0 upc-dev --auto
$0 upc-workload --envtype workload
Prerequisites: Prerequisites:
- tofu, kubectl, helm installed - tofu, kubectl, helm installed
@@ -49,7 +41,6 @@ EOF
# ─── Parse arguments ────────────────────────────────────────────────── # ─── Parse arguments ──────────────────────────────────────────────────
CLUSTER="" CLUSTER=""
ENVTYPE=""
PLAN_ONLY=false PLAN_ONLY=false
DESTROY=false DESTROY=false
AUTO_APPROVE=false AUTO_APPROVE=false
@@ -59,8 +50,6 @@ while [[ $# -gt 0 ]]; do
--plan) PLAN_ONLY=true; shift ;; --plan) PLAN_ONLY=true; shift ;;
--destroy) DESTROY=true; shift ;; --destroy) DESTROY=true; shift ;;
--auto) AUTO_APPROVE=true; shift ;; --auto) AUTO_APPROVE=true; shift ;;
--envtype) ENVTYPE="${2:-}"; shift 2 ;;
--envtype=*) ENVTYPE="${1#*=}"; shift ;;
-h|--help) usage 0 ;; -h|--help) usage 0 ;;
-*) echo "Unknown option: $1"; usage 1 ;; -*) echo "Unknown option: $1"; usage 1 ;;
*) *)
@@ -76,16 +65,10 @@ while [[ $# -gt 0 ]]; do
done done
[[ -z "$CLUSTER" ]] && { echo "Error: <cluster> argument required"; usage 1; } [[ -z "$CLUSTER" ]] && { echo "Error: <cluster> argument required"; usage 1; }
[[ -z "$ENVTYPE" ]] && { echo "Error: --envtype <dev|prod|workload> required"; usage 1; }
case "$ENVTYPE" in # ─── Map cluster → platform + env ────────────────────────────────────
dev|prod|workload) ;; PLATFORM="${CLUSTER%%-*}" # aks-dev → aks
*) echo "Error: invalid --envtype '$ENVTYPE'. Expected: dev, prod, workload"; exit 1 ;; ENV="${CLUSTER#*-}" # aks-dev → dev
esac
# ─── Resolve platform + env ───────────────────────────────────────────
PLATFORM="${CLUSTER%%-*}" # cluster prefix → platform (e.g. upc-forte-group → upc)
ENV="$ENVTYPE" # env comes from --envtype, not the cluster name
case "$PLATFORM" in case "$PLATFORM" in
aks|eks|gke|upc) ;; aks|eks|gke|upc) ;;
-32
View File
@@ -1,32 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: monitoring
annotations:
argocd.argoproj.io/sync-wave: "-1"
---
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: infrastructure-apps
namespace: argocd
labels:
app.kubernetes.io/name: infrastructure-apps
app.kubernetes.io/part-of: platform
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
project: default
source:
repoURL: ssh://git@git.forteapps.net:2222/Forte/launchpad.git
targetRevision: HEAD
path: infra/overlays/upc-forte-group
destination:
server: https://kubernetes.default.svc
namespace: default
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
-3
View File
@@ -15,9 +15,6 @@ metadata:
namespace: argocd namespace: argocd
annotations: annotations:
argocd.argoproj.io/sync-wave: "1" argocd.argoproj.io/sync-wave: "1"
notifications.argoproj.io/subscribe.on-sync-succeeded.slack: ""
notifications.argoproj.io/subscribe.on-sync-failed.slack: ""
notifications.argoproj.io/subscribe.on-degraded.slack: ""
labels: labels:
app.kubernetes.io/name: dot-ai-stack app.kubernetes.io/name: dot-ai-stack
app.kubernetes.io/part-of: apps app.kubernetes.io/part-of: apps
@@ -1,6 +1,8 @@
apiVersion: kustomize.config.k8s.io/v1beta1 apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- ../../base/mcp10x - dot-ai-stack
- ../../base/ts-mcp - mcp10x
- musicman
- ts-mcp
- argo-mcp
@@ -77,6 +77,12 @@ spec:
mc rm --recursive --force --older-than 30d "obj/${S3_BUCKET}/_pgbackups/" || true mc rm --recursive --force --older-than 30d "obj/${S3_BUCKET}/_pgbackups/" || true
echo "backup retention pass complete" echo "backup retention pass complete"
env: env:
# mc writes its config under $MC_CONFIG_DIR; point it at the shared
# emptyDir (writable by uid 65532 via fsGroup). Without this it tries
# to mkdir /.mc on the read-only-to-nonroot root fs -> "mkdir /.mc:
# permission denied" and every run fails before uploading.
- name: MC_CONFIG_DIR
value: "/work/.mc"
- name: S3_ENDPOINT - name: S3_ENDPOINT
valueFrom: valueFrom:
secretKeyRef: { name: forte-drop-secrets, key: S3_ENDPOINT } secretKeyRef: { name: forte-drop-secrets, key: S3_ENDPOINT }
+6 -12
View File
@@ -1,19 +1,13 @@
apiVersion: kustomize.config.k8s.io/v1beta1 apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- ../../base/musicman - ../../base
- ../../base/dot-ai-stack
- ../../base/argo-mcp
- forte-drop-postgresql - forte-drop-postgresql
- forte-drop - forte-drop
- forte-drop-mcp - forte-drop-mcp
patches: # No patches needed — base apps already default to "upc-dev" value paths
# dot-ai-stack: swap upc-dev → upc-forte-group # (upc-dev is the default/base cluster).
- target: # forte-drop (postgres + web + mcp) and dbunk-demo are upc-dev-only apps — their
kind: Application # values hardcode upc-dev hosts (drop.forteapps.net etc.) and must not sync to
name: dot-ai-stack # upc-prod, so they live here in the overlay rather than in apps/base/.
patch: |
- op: replace
path: /spec/sources/0/helm/valueFiles/1
value: $values/infra/values/upc-dev/dot-ai-stack-values.yaml
+10
View File
@@ -2,3 +2,13 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- ../../base - ../../base
patches:
# dot-ai-stack: swap upc-dev → upc-prod
- target:
kind: Application
name: dot-ai-stack
patch: |
- op: replace
path: /spec/sources/0/helm/valueFiles/1
value: $values/infra/values/upc-prod/dot-ai-stack-values.yaml
+1 -1
View File
@@ -3,7 +3,7 @@
# in case of $'\r': command not found error, run command below first # in case of $'\r': command not found error, run command below first
# sed -i 's/\r$//' ./bootstrap.sh # sed -i 's/\r$//' ./bootstrap.sh
CLUSTER="${1:?Usage: ./bootstrap.sh <cluster> # e.g. upc-dev, upc-prod, upc-forte-group, aks-dev, eks-prod, gke-dev — must match clusters/<cluster>.yaml}" CLUSTER="${1:?Usage: ./bootstrap.sh <cluster> (upc-dev|upc-prod|aks-dev|aks-prod|eks-dev|eks-prod|gke-dev|gke-prod)}"
echo "running $0 for cluster: ${CLUSTER}..." echo "running $0 for cluster: ${CLUSTER}..."
+18 -4
View File
@@ -24,8 +24,15 @@ spec:
name: azuredns-config name: azuredns-config
key: client-secret key: client-secret
selector: selector:
dnsNames: # NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames
- '*.forteapps.net' # matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally
# named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones
# instead suffix-matches the zone apex AND every subdomain at any depth, so this single
# entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net,
# drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this
# Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail
# to match fall through to the http01 solver below.
dnsZones:
- 'forteapps.net' - 'forteapps.net'
# HTTP-01 fallback for non-wildcard certificates # HTTP-01 fallback for non-wildcard certificates
- http01: - http01:
@@ -58,8 +65,15 @@ spec:
name: azuredns-config name: azuredns-config
key: client-secret key: client-secret
selector: selector:
dnsNames: # NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames
- '*.forteapps.net' # matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally
# named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones
# instead suffix-matches the zone apex AND every subdomain at any depth, so this single
# entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net,
# drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this
# Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail
# to match fall through to the http01 solver below.
dnsZones:
- 'forteapps.net' - 'forteapps.net'
# HTTP-01 fallback for non-wildcard certificates # HTTP-01 fallback for non-wildcard certificates
- http01: - http01:
@@ -233,6 +233,10 @@ spec:
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}" value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
- name: AUTH_OIDC_SCOPES - name: AUTH_OIDC_SCOPES
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}" value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
- name: AUTH_OIDC_COOKIE_DOMAIN
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}"
- name: AUTH_OIDC_ALLOWED_RETURN_HOSTS
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-allowed-return-hosts\" || '' }}"
- name: AUTH_PUBLIC_PATHS - name: AUTH_PUBLIC_PATHS
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}" value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
- name: AUTH_OIDC_COOKIE_SECRET - name: AUTH_OIDC_COOKIE_SECRET
-12
View File
@@ -1,12 +0,0 @@
# Cluster config reference — values must match the corresponding overlay files.
# Read by bootstrap.sh at install time; NOT auto-propagated to ArgoCD value files.
clusterName: prod-fd-no-svg1 # → infra/values/upc-forte-group/argocd-values.yaml (notifications.context.clusterName)
domain: fortedigital.com # → infra/values/base/gitea-values.yaml, renovate-values.yaml, keycloak-values.yaml (subdomains)
argocdDomain: argocd.127.0.0.1.nip.io # → infra/values/upc-forte-group/argocd-values.yaml (global.domain)
grafanaDomain: grafana.fortedigital.com # → infra/values/upc-forte-group/grafana-values.yaml (ingress.hosts)
keycloakDomain: id.fortedigital.com # → infra/values/upc-forte-group/keycloak-values.yaml (ingress.hostname)
dotaiDomain: kubemcp.fortedigital.com # → infra/values/upc-forte-group/dot-ai-stack-values.yaml (dot-ai.ingress.host)
dotaiUiDomain: kubemcpui.fortedigital.com # → infra/values/upc-forte-group/dot-ai-stack-values.yaml (dot-ai-ui.ingress.host)
letsencryptEmail: danijel.simeunovic@fortedigital.com # → cluster-resources/letsencrypt-issuer.yaml (spec.acme.email)
trustedIPs: "172.16.1.0/24" # → infra/values/upc-forte-group/traefik-values.yaml (ports.*.trustedIPs)
cloudProvider: upcloud # → determines overlay directory and cloud-specific LB/storage annotations
+6
View File
@@ -1469,6 +1469,12 @@ ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret | | `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret | | `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
#### Public CLI Client (Device-Code Login)
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
### Retrieving Secrets for External Deployments ### Retrieving Secrets for External Deployments
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster: The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
+2 -2
View File
@@ -1326,7 +1326,7 @@ storage:
- Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`) - Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`)
- Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient) - Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient)
- Agent mode: disabled (one-shot review, no multi-turn reasoning) - Agent mode: disabled (one-shot review, no multi-turn reasoning)
- LLM: Claude Sonnet (`claude-sonnet-4-20250514`) - LLM: Claude Sonnet (`claude-3-opus`)
**Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`): **Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`):
``` ```
@@ -1344,7 +1344,7 @@ shared-prompts/
```yaml ```yaml
llm: llm:
provider: CLAUDE provider: CLAUDE
model: claude-sonnet-4-20250514 model: claude-3-opus
vcs: vcs:
provider: GITEA provider: GITEA
review: review:
+36
View File
@@ -0,0 +1,36 @@
# Domain Docs
How the engineering skills should consume this repo's domain documentation when exploring the codebase.
## Before exploring, read these
- **`CONTEXT.md`** at the repo root, or
- **`CONTEXT-MAP.md`** at the repo root if it exists — it points at one `CONTEXT.md` per context. Read each one relevant to the topic.
- **`docs/adr/`** — read ADRs that touch the area you're about to work in. In multi-context repos, also check `src/<context>/docs/adr/` for context-scoped decisions.
If any of these files don't exist, **proceed silently**. Don't flag their absence; don't suggest creating them upfront. The `/domain-modeling` skill (reached via `/grill-with-docs` and `/improve-codebase-architecture`) creates them lazily when terms or decisions actually get resolved.
## File structure
Single-context repo (most repos):
```
/
├── CONTEXT.md
├── docs/adr/
│ ├── 0001-event-sourced-orders.md
│ └── 0002-postgres-for-write-model.md
└── src/
```
## Use the glossary's vocabulary
When your output names a domain concept (in an issue title, a refactor proposal, a hypothesis, a test name), use the term as defined in `CONTEXT.md`. Don't drift to synonyms the glossary explicitly avoids.
If the concept you need isn't in the glossary yet, that's a signal — either you're inventing language the project doesn't use (reconsider) or there's a real gap (note it for `/domain-modeling`).
## Flag ADR conflicts
If your output contradicts an existing ADR, surface it explicitly rather than silently overriding:
> _Contradicts ADR-0007 (event-sourced orders) — but worth reopening because…_
+39
View File
@@ -0,0 +1,39 @@
# Issue tracker: Gitea
Issues for this repo live in Gitea at `git.forteapps.net/Forte/launchpad`. Use the Gitea API or `tea` CLI.
## Conventions
- **Create an issue**: `tea issue create --title "..." --description "..."`
or via API: `curl -X POST "https://git.forteapps.net/api/v1/repos/Forte/launchpad/issues" -H "Authorization: token $GITEA_TOKEN" -H "Content-Type: application/json" -d '{"title":"...","body":"..."}'`
- **Read an issue**: `tea issue view <number>` or API `GET /api/v1/repos/Forte/launchpad/issues/<number>`
- **List issues**: `tea issue list` or API `GET /api/v1/repos/Forte/launchpad/issues?state=open`
- **Comment on an issue**: `tea issue comment <number> "..."` or API `POST /api/v1/repos/Forte/launchpad/issues/<number>/comments`
- **Apply labels**: API `POST /api/v1/repos/Forte/launchpad/issues/<number>/labels` with `{"labels": [<label_id>]}`
- **Close**: API `PATCH /api/v1/repos/Forte/launchpad/issues/<number>` with `{"state": "closed"}`
Infer the repo from `git remote -v`.
## Pull requests as a triage surface
**PRs as a request surface: no.**
## When a skill says "publish to the issue tracker"
Create a Gitea issue.
## When a skill says "fetch the relevant ticket"
Fetch the issue via API or `tea issue view <number>`.
## Wayfinding operations
Used by `/wayfinder`. The **map** is a single issue with **child** issues as tickets.
- **Map**: a single issue labelled `wayfinder:map`, holding the Destination / Notes / Decisions-so-far / Fog body.
- Create: `POST /api/v1/repos/Forte/launchpad/issues` with `{"title":"...","body":"...","labels":[<wayfinder:map label id>]}`
- **Child ticket**: an issue carrying `Part of #<map>` at the top of its body and a `wayfinder:<type>` label (`research`/`prototype`/`grilling`/`task`). Once claimed, the ticket is assigned to the driving dev.
- **Blocking**: Gitea does not have native issue dependencies. Fall back to a `Blocked by: #<n>, #<n>` line at the top of the child body. A ticket is unblocked when every issue it lists is closed.
- **Frontier query**: list the map's open children — `GET /api/v1/repos/Forte/launchpad/issues?state=open&labels=wayfinder:research,wayfinder:prototype,wayfinder:grilling,wayfinder:task` — then filter to those whose body starts with `Part of #<map>`. Drop any with an open issue in their `Blocked by` line, or with an assignee. First in map order wins.
- **Claim**: `PATCH /api/v1/repos/Forte/launchpad/issues/<n>` with `{"assignees":["<username>"]}` — the session's first write.
- **Resolve**: post the answer as a comment (`POST .../comments`), close the issue (`PATCH` with `{"state":"closed"}`), then append a context pointer (gist + link) to the map's Decisions-so-far by editing the map issue body.
+15
View File
@@ -0,0 +1,15 @@
# Triage Labels
The skills speak in terms of five canonical triage roles. This file maps those roles to the actual label strings used in this repo's issue tracker.
| Label in mattpocock/skills | Label in our tracker | Meaning |
| -------------------------- | -------------------- | ---------------------------------------- |
| `needs-triage` | `needs-triage` | Maintainer needs to evaluate this issue |
| `needs-info` | `needs-info` | Waiting on reporter for more information |
| `ready-for-agent` | `ready-for-agent` | Fully specified, ready for an AFK agent |
| `ready-for-human` | `ready-for-human` | Requires human implementation |
| `wontfix` | `wontfix` | Will not be actioned |
When a skill mentions a role (e.g. "apply the AFK-ready triage label"), use the corresponding label string from this table.
Edit the right-hand column to match whatever vocabulary you actually use.
@@ -28,3 +28,12 @@ resources:
# No patches needed — base already has "upc-dev" paths # No patches needed — base already has "upc-dev" paths
# upc-dev is the default/base cluster # upc-dev is the default/base cluster
patches:
- target:
kind: Application
name: databunker
patch: |
- op: add
path: /spec/sources/0/helm/valueFiles/-
value: $values/infra/values/upc-dev/databunker-values.yaml
@@ -1,61 +0,0 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../../base/cert-manager-application
- ../../base/cluster-resources-application
- ../../base/enterprise-apps
- ../../base/fluent-bit
- ../../base/gitea
- ../../base/gitea-actions
- ../../base/grafana
- ../../base/grafana-dashboards
- ../../base/homepage
- ../../base/karpor
- ../../base/keycloak
- ../../base/kyverno
- ../../base/kyverno-policies
- ../../base/loki
- ../../base/opencost
- ../../base/prometheus
- ../../base/renovate
- ../../base/sealedsecrets
- ../../base/tempo
- ../../base/traefik-application
- ../../base/vault
patches:
# Traefik: swap upc-dev → upc-forte-group
- target:
kind: Application
name: traefik
patch: |
- op: replace
path: /spec/sources/0/helm/valueFiles/1
value: $values/infra/values/upc-forte-group/traefik-values.yaml
# Grafana: swap upc-dev → upc-forte-group
- target:
kind: Application
name: grafana
patch: |
- op: replace
path: /spec/sources/0/helm/valueFiles/1
value: $values/infra/values/upc-forte-group/grafana-values.yaml
# OpenCost: swap upc-dev → upc-forte-group
- target:
kind: Application
name: opencost
patch: |
- op: replace
path: /spec/sources/0/helm/valueFiles/1
value: $values/infra/values/upc-forte-group/opencost-values.yaml
# Gitea: swap upc-dev → upc-forte-group
- target:
kind: Application
name: gitea
patch: |
- op: replace
path: /spec/sources/0/helm/valueFiles/1
value: $values/infra/values/upc-forte-group/gitea-values.yaml
+1 -1
View File
@@ -31,7 +31,7 @@ gitea:
ENABLE_PASSWORD_SIGNIN_FORM: false ENABLE_PASSWORD_SIGNIN_FORM: false
AUTO_WATCH_ON_CHANGES: false AUTO_WATCH_ON_CHANGES: false
AUTO_WATCH_NEW_REPOS: false AUTO_WATCH_NEW_REPOS: false
ENABLE_NOTIFY_MAIL: false ENABLE_NOTIFY_MAIL: true
ENABLE_TIMETRACKING: false ENABLE_TIMETRACKING: false
openid: openid:
+18 -3
View File
@@ -186,6 +186,21 @@ keycloakConfigCli:
} }
} }
] ]
},
{
"clientId": "forte-cli",
"name": "Forte CLI",
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
"enabled": true,
"protocol": "openid-connect",
"standardFlowEnabled": false,
"directAccessGrantsEnabled": false,
"publicClient": true,
"redirectUris": [],
"webOrigins": [],
"attributes": {
"oauth2.device.authorization.grant.enabled": "true"
}
} }
], ],
"browserFlow": "browser-auto-idp", "browserFlow": "browser-auto-idp",
@@ -642,7 +657,7 @@ extraDeploy:
ADMIN_USER="admin" ADMIN_USER="admin"
ADMIN_PASS=$(cat /secrets/admin-password) ADMIN_PASS=$(cat /secrets/admin-password)
DRY_RUN="${DRY_RUN:-true}" DRY_RUN="${DRY_RUN:-true}"
MIN_AGE_DAYS="${MIN_AGE_DAYS:-7}" MIN_AGE_DAYS="${MIN_AGE_DAYS:-14}"
if [ -z "$CLIENT_ID_PATTERN" ]; then if [ -z "$CLIENT_ID_PATTERN" ]; then
CLIENT_ID_PATTERN='^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' CLIENT_ID_PATTERN='^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'
fi fi
@@ -668,7 +683,7 @@ extraDeploy:
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400)) MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
# Hardcoded protected clients (never delete these) # Hardcoded protected clients (never delete these)
PROTECTED_JSON='["gitea","grafana","argocd","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]' PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
echo "Fetching clients from realm '${REALM}'..." echo "Fetching clients from realm '${REALM}'..."
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \ CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
@@ -728,7 +743,7 @@ extraDeploy:
- name: DRY_RUN - name: DRY_RUN
value: "false" value: "false"
- name: MIN_AGE_DAYS - name: MIN_AGE_DAYS
value: "7" value: "15"
volumeMounts: volumeMounts:
- name: keycloak-credentials - name: keycloak-credentials
mountPath: /secrets mountPath: /secrets
@@ -1,5 +0,0 @@
global:
domain: argocd.fortedigital.com
notifications:
context:
clusterName: "prod-fd-no-svg1"
@@ -1,50 +0,0 @@
# UpCloud storage class for Gitea and its embedded PostgreSQL
persistence:
storageClass: upcloud-block-storage-maxiops
postgresql:
primary:
persistence:
storageClass: upcloud-block-storage-maxiops
gitea:
# -- Gitea app.ini configuration
config:
APP_NAME: "Forte Git"
server:
DOMAIN: source.forteapps.net
ROOT_URL: https://source.forteapps.net
SSH_DOMAIN: source.forteapps.net
# -- Ingress via Traefik with Let's Encrypt TLS
ingress:
enabled: true
className: traefik
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
gethomepage.dev/enabled: "true"
gethomepage.dev/name: "Gitea"
gethomepage.dev/description: "Git hosting & CI/CD"
gethomepage.dev/group: "DevOps"
gethomepage.dev/icon: "gitea"
gethomepage.dev/href: "https://source.forteapps.net"
gethomepage.dev/widget.type: "gitea"
gethomepage.dev/widget.url: "https://source.forteapps.net"
gethomepage.dev/widget.key: "{{HOMEPAGE_VAR_GITEA_TOKEN}}"
hosts:
- host: source.forteapps.net
paths:
- path: /
pathType: Prefix
tls:
- secretName: gitea-tls
hosts:
- source.forteapps.net
# -- Git repository storage
persistence:
enabled: true
size: 20Gi
accessModes:
- ReadWriteOnce
@@ -1,3 +0,0 @@
ingress:
hosts:
- grafana.fortedigital.com
@@ -1,2 +0,0 @@
ingress:
hostname: id.forteapps.com
@@ -1,15 +0,0 @@
# UpCloud custom pricing (no native OpenCost integration)
opencost:
exporter:
customPricing:
enabled: true
provider: custom
costModel:
description: "UpCloud 4-node cluster pricing"
CPU: "5.86"
RAM: "1.46"
GPU: "0"
storage: "0.34"
zoneNetworkEgress: "0"
regionNetworkEgress: "0"
internetNetworkEgress: "0"
@@ -1,13 +0,0 @@
service:
annotations: {}
ports:
web:
proxyProtocol:
trustedIPs: "10.0.0.0/16"
forwardedHeaders:
trustedIPs: "10.0.0.0/16"
websecure:
proxyProtocol:
trustedIPs: "10.0.0.0/16"
forwardedHeaders:
trustedIPs: "10.0.0.0/16"
@@ -0,0 +1,8 @@
dot-ai:
ingress:
host: kubemcp.fortedigital.com
webUI:
baseUrl: http://kubemcpui.fortedigital.com
dot-ai-ui:
ingress:
host: kubemcpui.fortedigital.com