|
|
||
|---|---|---|
| .vscode | ||
| cmd | ||
| docs | ||
| internal | ||
| MaidnCLI@cc8fab6832 | ||
| .dockerignore | ||
| .gitignore | ||
| AGENTS.md | ||
| Dockerfile | ||
| go.mod | ||
| go.sum | ||
| How2Auth.md | ||
| main.go | ||
| README.md | ||
Commands
cicd-tool repo initis a legacy GitHub workflow and is not used for new Forgejo/GitOps platform onboarding.cicd-tool bootstrapruns a shorter Forgejo-first wizard, asks for a Forgejo PAT, asks where local repos should be cloned, discovers Proxmox nodes/storage/networks, retries without losing entered answers when discovery fails, shows the latest Talos version, derives the standardized Talos factory URL, schematic, and required extensions automatically from the chosen version, writesterraform.tfvars, stages Talos images on Proxmox, and can execute Terraform, Talos bootstrap, and Flux bootstrapcicd-tool bootstrap --config maidn-bootstrap.yamlskips the wizard and uses the saved configcicd-tool bootstrap init --config <private-config> --organization <new-org> --create-organizationlocks an isolated workspace, initializes Forgejo repositories, then runs the non-destructive bootstrap reconcile lifecycle. Use--mode=rebuild --yesonly for an authorized rebuild.cicd-tool app onboard --config <private-config> --from <app-checkout>is being migrated to central delivery ownership. Do not use the source-owned implementation for new applications; seedocs/architecture/delivery-ownership.md.cicd-tool e2eruns bounded, read-only Flux, ExternalSecret, PipelineRun, preview, and promotion-PR checks with JSON output. Seedocs/e2e.md.
See docs/operations.md for the authorized operating and verification runbook.
See docs/architecture/delivery-ownership.md for the developer and platform
ownership boundary.
App authors: see docs/delivery-feedback.md for preview feedback and the scoped Forgejo token contract.
Forgejo setup
For https://git.pingu.pw you need:
- a user token with repo create/push rights
- an owner target (
Maidnorg by default, or your own user/org) - git/ssh access from the machine running the CLI if you want SSH later
- Flux bootstrap credentials for the repo URL that gets created
Cilium traffic network
Every Talos node needs a second static network for Cilium L2 announcements. It has no gateway; the primary network remains the default route. Configure the matching VLAN and a unique MAC address for each node:
cilium:
trafficInterface: eth1
loadBalancerStart: <first-reserved-address>
loadBalancerEnd: <last-reserved-address>
talos:
nodes:
- networks:
- # Primary management network
- macAddress: <unique-mac>
cidr: <traffic-subnet>
ip: <node-traffic-address>
vlanId: <opnsense-traffic-vlan>