Restore repository-scoped image publishers after runner migration #675
Labels
No labels
burndown-2026-06
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#675
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Incident
The completed scoped-runner migration retired every global
deploy:hostregistration after canarying onlycoilyco-bridge/deployandcoilyco-gaming/sirens-discord-ops. A canonical workflow inventory across all 29 active repositories found twelve repositories selectingruns-on: deploy. Ten image publishers therefore have no eligible runner, including the Eco application publisher.Outcome
coilyco-bridge/deployas the sole runner with Kubernetes deployment identity.REGISTRY_TOKEN, andFORGEJO_EGRESS_PROXY, without a Kubernetes service-account token, AWS credentials, home-network values, or private-source read credentials.deployworkflow label during the compatibility migration.Publisher roster
Related: #653, #658, #665, coilyco-gaming/eco-app#142.
Rollout checkpoint: commits
6b8e3bdand4f272e3are on canonical main. Ten missing exact-repository registration tokens are stored in SSM through newline-free file sources. Flux created all publisher resources and every ExternalSecret reports SecretSynced. Live verification found kai-server at its kubelet 110-pod ceiling. Six publisher pods scheduled and four remain Pending with Too many pods. The tracked k3s-config role now owns the systemd start wrapper and raises max-pods to 180 while publisher idle memory requests are reduced. Repository render and full pre-commit pass. Remaining attended action: ward exec ansible-sync apply tags=k3s-config hosts=kai-server ask_pass. After the restart, Ops must verify node pod capacity, all eleven publisher StatefulSets, repository runner visibility, and the Eco workflow before closing this issue.Live rollout update: kai-server now reports pod capacity 180, all eleven repository-scoped publisher runners and the scoped deploy runner are
Running 2/2, and Ops restarted all twelve after their ExternalSecrets refreshed the rotated registry credential.Eco verification run 143 passed test, frontend, and
build-image. Docker authentication and immutable app-image publication are restored. The four downstream mod publishers fail later inside eco-app because Ward is invoked from an extracted temporary directory without a reachable repository config. coilyco-gaming/eco-app#167 owns that repository fix.Keep this issue open until eco-app#167 lands and a full Eco publish run returns green. The original scheduling and registry-credential blockers are cleared.
Evidence: https://forgejo.coilysiren.me/coilyco-gaming/eco-app/actions/runs/143
Closing verification is complete.
The scheduling, registration, registry authentication, and downstream publication blockers are cleared. Evidence: https://forgejo.coilysiren.me/coilyco-gaming/eco-app/actions/runs/148