Migrate the standalone k3s image registry inventory to Forgejo OCI #653
Labels
No labels
burndown-2026-06
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#653
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Outcome
Migrate every supported image from the standalone kai-server k3s registry to Forgejo OCI, update every producer and consumer to use the same Forgejo image authority, then retire the standalone registry after a verified rollback window.
The application publisher and the k3s consumer must use the same immutable Forgejo image reference. The migration must remove the separate raw push endpoint, the
kai-registry.localpull alias, and the DinD insecure-registry exception from steady state.Live evidence
The 2026-07-27 read-only cluster inventory established:
registrynamespace is active.The old registry stays available until every supported workload has moved and the operator confirms the retained rollback set.
Active image inventory
atlas-coilyco-bridge/atlaspublishes it.coilyco-bridge/deploy/services/atlasconsumes it.bluesky-mcp-coilyco-flight-deck/bluesky-mcppublishes it.deploy/services/bluesky-mcpconsumes it.coilysiren-backend- deprecated. Deploy source retired incoilyco-bridge/deploy@6ae879e. Ops removes the live workload only after the data-retention decision in coilysiren/inbox#277. No Forgejo package is created.coilysiren-eco-app-coilyco-gaming/eco-apppublishes it. The Eco App and Discord worker Deployments both consume it.factory-game-v3-coilyco-gaming/factory-game-v3publishes it.deploy/services/factory-gameconsumes it.forgejo-runner-deploy- infrastructure builds it. The Forgejo deploy-runner StatefulSet consumes it.galaxy-gen-coilyco-gaming/galaxy-genowns the source.deploy/services/galaxy-genbuilds and consumes it.lunch-money-mcp-coilyco-flight-deck/lunch-money-k8spublishes it.deploy/services/lunch-money-mcpconsumes it.node-stats-mcp-coilyco-flight-deck/node-stats-mcppublishes it.deploy/services/node-stats-mcpconsumes it.playwright-mcp- Microsoft publishes the upstream image.deploy/services/playwright-mcpowns the trusted mirror and consumes it.reddit-mcp-coilyco-flight-deck/reddit-mcppublishes it.deploy/services/reddit-mcpconsumes it.steam-mcp-coilyco-gaming/steam-opspublishes it.deploy/services/steam-mcpconsumes it.ward-mcp-coilyco-flight-deck/ward-mcppublishes one shared runtime. The AWS SSM, Discord, Forgejo, Glama, SigNoZ, SkillsMP, and Trello MCP Deployments consume it.website-coilysiren/websitepublishes it.deploy/services/websiteconsumes it.Legacy or unreferenced catalog inventory
agent-proxy- Agent Proxy already publishes to and pulls from Forgejo OCI on ser8. The operator confirms no rollback reference still needs the standalone copy before deleting it.coilysiren-galaxy-gen- this is the retired predecessor of the currentgalaxy-genimage. The operator confirms no rollback reference before deleting it.probe- this is a synthetic registry verification artifact. The operator deletes it after the migration verification no longer needs it.repo-recall-api- no active kai-server controller references it. The owning role identifies whether the product is supported, retained only for rollback, or retired before migration or deletion.Target contract
forgejo.coilysiren.me/<owner>/<image>:<immutable-source-tag>.kubernetes.io/dockerconfigjsonSecret and names it throughimagePullSecrets.Migration sequence
Acceptance
kai-registry.localor the standalone NodePort authority.Related risks
The migration owner must account for those risks rather than treating a successful small-image push as proof that every publisher shape is ready.
Codex, via advisor surface
Authorized legacy-image cleanup
Kai explicitly authorized deletion of these four standalone-registry repositories on 2026-07-27:
agent-proxycoilysiren-galaxy-genproberepo-recall-apiPre-delete evidence:
probeis synthetic and reproducible. Only registry verification documentation names it.The ops-role operator may delete every manifest and tag belonging to these four repositories. The operator must not delete the registry Deployment, Service, PVC, shared blobs still referenced by retained images, or any other catalog entry.
After deletion, the operator verifies that the four names no longer have retrievable manifests, retained workloads remain Ready, and the remaining registry catalog is unchanged except for these targets. The operator records the result here.
This advisor session performed the read-only retirement audit but did not mutate the live registry because the advisor role does not hold the live-operations mutation surface.
Codex, via advisor surface
Cross-repository authority is now coilysiren/inbox#276.
This issue remains the infrastructure child and the canonical live inventory, migration sequencing, registry-retirement, rollback, and data-retention record.
The child graph also exposed one inventory correction:
coilyco-flight-deck/backendis absent from Forgejo even though the active image and deploy metadata still name it. coilysiren/inbox#277 owns restoring, rehoming, or explicitly retiring that source before the backend migration can complete.Engineer checkpoint: reusable Forgejo OCI contract landed
Canonical main now contains commit
da0c2f0(docs: establish Forgejo OCI application image contract).The checkpoint establishes:
forgejo.coilysiren.me/<owner>/<image>:<full-source-sha>as the sole target application-image authority.kubernetes.io/dockerconfigjsonSecrets through ExternalSecret.Evidence:
ward exec pre-commitpassed every repository and catalog hook before the fast-forward push.This completes sequence item 1's repository prerequisite. It does not close infrastructure#653. Publisher migrations, deploy-runner migration, live zero-reference evidence, rollback and retention decisions, and registry retirement remain.
Codex, via engineer surface
Publisher checkpoint blocked at live package authorization
Website source commit
8466f5areached the trusted deploy runner, builtforgejo.coilysiren.me/coilysiren/website:8466f5acf84b2f12e78157cf8530d174f76d8bf8, then Forgejo rejected the push withunauthorized: reqPackageAccessin https://forgejo.coilysiren.me/coilysiren/website/actions/runs/137.Local source validation is green. The agent did not rerun or probe CI. The required Ops action and exact return evidence now live in interactive issue infrastructure#654.
Node Stats and Reddit source publishers are also landed, but their queued workflows and all immutable-manifest handoffs remain gated on the same write-authority checkpoint.
Codex, via engineer surface
Consumer checkpoint: the agent pushed deploy branch
issue-239-forgejo-ociatd7e3245.All named source publishers now target private Forgejo OCI at full source SHAs. The deploy branch pins those exact authorities, adds read-only pull credentials, owns the Playwright digest mirror, removes legacy consumer paths, and passes offline Kubernetes, workflow, shell, documentation, and secret-scan validation.
The agent did not land deploy main or touch live workloads. infrastructure#654 remains the package-write and manifest-proof wall. inbox#277 remains the backend ownership wall. The old registry stays a gated rollback edge until Ops proves the migrated workloads and zero legacy pulls.
Deploy-runner repository checkpoint
Remote branch
issue-653-deploy-runner-ocinow carries the final-publisher handoff ata3e4814.ab7f2afchanges only the main-only publisher. The existing deploy runner buildsforgejo.coilysiren.me/coilyco-flight-deck/forgejo-runner-deploy:ab7f2af13c507c456470f1d76bb6aad7bc1e28da, pushes no moving tag, and requires remote manifest inspection.a3e4814is the dependent consumer commit. It pins both runner containers to that exact image, adds the separate read-only package pull Secret, and removes the deploy runner's legacy pull and insecure-registry path.ward exec pre-commitpasses every repository, documentation, runner-contract, registry-bridge, and offline secret-scan hook.The two commits remain off
mainby design. infrastructure#654 must restore package-write authority before the publisher commit can land and prove its manifest. The consumer commit must not land until that proof exists. The agent opened no PR, reran no CI, and changed no live runner.Codex, via engineer surface
Registry-source retirement checkpoint
Dependent remote branch
issue-653-registry-retirementnow ends at7d0f9c5.After the deploy-runner handoff commits, this commit removes the standalone
registry:2manifest, k3s mirror role and sync wiring, all remaining DinD insecure-registry exceptions, obsolete registry backup scope, and active rollback-bridge documentation. It replaces the old mirror-presence hook with a Forgejo-authority guard that fails if the retired workload, role, endpoint, alias, or runner exception returns.ward exec pre-commitpasses every repository, runner-contract, Forgejo-authority, documentation, catalog, and offline secret-scan hook.The branch remains off
main. It is source cleanup for the post-retirement state, not authorization to delete live resources. Ops must first prove every migrated workload, return a live zero-reference inventory, complete the rollback window, record the registry data-retention disposition, and remove the live edge, workload, mirror config, and storage through the authorized operator surface.Codex, via engineer surface
Registry inventory correction:
coilysiren-backendis deprecated, not a supported Forgejo OCI migration target. Kai is archiving the GitHub source, and the engineer discarded the unpublished publisher recovery.Treat the backend as an explicit retirement item. Deploy source removal is in progress. Ops must inventory the running workload and decide retention for Postgres, PVCs, backups, namespace, and rollback images before removal. The infrastructure retirement branch intentionally keeps backend backup coverage until that decision is recorded.
Backend repository retirement is now source-complete. GitHub is archived and deploy main
6ae879econtains no backend surface. The active cluster item is now an Ops retirement target, not a Forgejo OCI publisher. Keep backup coverage until inbox#277 records the Postgres, PVC, backup, namespace, and rollback-image disposition.Backend image deletion now has a dedicated destructive Ops gate: #655. It covers only the retired
coilysiren-backendrepository in the standalone registry. Whole-registry retirement and PVC deletion remain in infrastructure#653.Node Stats, the final protected application consumer exception, has completed its Forgejo OCI cutover.
forgejo.coilysiren.me/coilyco-flight-deck/node-stats-mcp:9e486430f44f35edc39277e6b3c9d956c5abf415coilyco-bridge/deploy@1b119f5309607f54146030734d11af7f3f07cf08The umbrella remains open. Registry retirement still needs the separate deploy-runner/backend work, zero-consumer fleet proof, the four legacy-entry dispositions, and the operator-reviewed rollback/data-retention decision. kai-server filesystem pressure is currently below warning at 78.6%, but only about 7.3 GB below the 80% threshold, so infrastructure#624 remains relevant during retirement work.