All checks were successful
PR build (required check) / changes (pull_request) Successful in 6s
secrets-guard / encrypted (pull_request) Successful in 4s
shell-lint / shellcheck (pull_request) Successful in 6s
PR build (required check) / validate-observability (pull_request) Successful in 20s
PR build (required check) / build-frontend (pull_request) Successful in 37s
PR build (required check) / build-backend (pull_request) Successful in 51s
PR build (required check) / gate (pull_request) Successful in 1s
Repos moved to the Jinemi org; the container packages did not follow, since
Forgejo does not transfer packages with a repo. The deploy path still resolved
`emi/thermograph/*` — a user_redirect to admin_emi — while build-push.yml
derives its push path from ${github.repository}, now jinemi/thermograph. The
next backend or frontend build would have published somewhere no deploy looks.
Point the image paths at jinemi/thermograph/* (lowercase: OCI references admit
no uppercase, which is why build-push.yml already pipes through tr), the clone
URLs at Jinemi/thermograph, and the registry logins at admin_emi — the account
that actually owns the tokens, rather than the redirect.
The live tags and both ci-runner tags were copied into the Jinemi namespace
first, so the switch has something to pull. thermograph-infra,
thermograph-observability and the retired */app packages stay under admin_emi;
they did not move.
44 lines
2.4 KiB
Markdown
44 lines
2.4 KiB
Markdown
# thermograph
|
|
|
|
The Thermograph monorepo — the split repos reunified (2026-07-22) with full
|
|
history via subtree merges, while keeping everything the split was actually
|
|
for: **per-domain images, per-domain deploys, and an async FE/BE contract**.
|
|
|
|
## Domains
|
|
|
|
| Dir | What | CI |
|
|
|---|---|---|
|
|
| `backend/` | FastAPI graded-climate API, accounts, notifications (Discord bot, push, mail), data pipeline | `build-push` → image `jinemi/thermograph/backend`; `deploy` |
|
|
| `frontend/` | Public client: static JS/CSS + SSR pages | same `build-push` / `deploy` workflows, matrixed by domain; image `jinemi/thermograph/frontend` |
|
|
| `infra/` | Compose (dev, on vps1) + two Swarm stacks co-resident on vps2 (beta, prod), deploy scripts, terraform, SOPS secrets vault, ops cron | `infra-sync` (host checkout + secrets render), `secrets-guard`, `ops-cron` |
|
|
| `observability/` | Loki + Grafana + Alloy stack | `observability-validate` |
|
|
|
|
`thermograph-docs` deliberately **stays its own repo** (ADRs + runbooks, no
|
|
build artifacts, different change cadence).
|
|
|
|
## New here?
|
|
|
|
[`docs/onboarding/`](docs/onboarding/README.md) is the developer onboarding
|
|
path: orientation, verified local-setup recipes, a per-domain deep dive, the
|
|
cross-service contracts that break silently, the release flow, and a list of
|
|
which docs in this repo are currently stale.
|
|
|
|
## How CI stays decoupled
|
|
|
|
Every workflow in `.forgejo/workflows/` is **path-filtered to its domain**: a
|
|
push touching only `frontend/**` builds/deploys nothing else. Images stay
|
|
separate (`jinemi/thermograph/backend`, `jinemi/thermograph/frontend`, each tagged
|
|
`sha-<12hex>`), deploys stay per-service (`infra/deploy/deploy.sh
|
|
SERVICE=backend|frontend|all`), and the API version contract
|
|
(`GET /api/version`, `PAYLOAD_VER`) still lets FE and BE ship out of lockstep.
|
|
The one intentionally *coupled* piece is `pr-build.yml`: a single always-running
|
|
`gate` required check that builds only the domains a PR touches (a
|
|
path-filtered required check would deadlock auto-merge).
|
|
|
|
Branch model (unchanged from the split era): PRs → `dev`, `main` → beta,
|
|
`release` → prod. Infra isn't environment-staged the same way app images are:
|
|
beta's and prod's checkouts (both on vps2) track `main`; dev's checkout (on
|
|
vps1) tracks `dev` itself, since it's the one environment that isn't a
|
|
rehearsal for something downstream.
|
|
|
|
**Before pointing anything live at this repo, read `CUTOVER-NOTES.md`.**
|