Thermograph monorepo: graded-climate API + SSR frontend + infra, domain-specific containerized deploys
Find a file
Emi Griffith 151cf37dfa
All checks were successful
PR build (required check) / changes (pull_request) Successful in 7s
secrets-guard / encrypted (pull_request) Successful in 6s
PR build (required check) / build-frontend (pull_request) Has been skipped
PR build (required check) / validate-observability (pull_request) Has been skipped
PR build (required check) / build-backend (pull_request) Successful in 48s
PR build (required check) / gate (pull_request) Successful in 3s
Add ops/dbq.sh: read-only Postgres queries across all environments
Uniform read-only query access to the LAN dev, beta and prod databases, plus a
thermograph_ro role in each to enforce it.

None of the databases are exposed over TCP: each listens only on its private
docker network, and prod's is a Swarm overlay the host cannot route to -- so
ssh -L works for beta but is impossible for prod, and publishing 5432 would mean
new ufw rules and a Swarm endpoint change on production. Running psql inside the
db container works identically everywhere with no ports, tunnels or infra
changes, so dbq.sh does that: local docker exec for dev, ssh for beta/prod. The
prod container is a Swarm task whose name changes each redeploy, so it is
resolved at call time rather than hardcoded.

Queries connect as thermograph_ro (NOSUPERUSER, granted only pg_read_all_data),
so a stray write fails with "permission denied" even against prod; the app's own
superuser role is deliberately unused here. Extra args pass through to psql and
stdin is forwarded.

ops/README.md documents usage and the conventions Iceberg will follow when it
lands as a sibling (env-keyed dispatch, run the engine where the data is
reachable, dedicated read-only identity).
2026-07-23 14:54:20 -07:00
.forgejo/workflows Finish the domain-sha tag keying: three deploy workflows were missed (#6) 2026-07-23 13:58:57 +00:00
backend Merge pull request 'Promote dev -> main (deploy beta): Open-Meteo migration (Phases 0-4)' (#9) from dev into main 2026-07-23 14:58:42 +00:00
frontend Subtree-merge thermograph-frontend origin/dev into frontend/ (two-tier test suite; CI workflow ported to root) 2026-07-22 22:23:50 -07:00
infra Add ops/dbq.sh: read-only Postgres queries across all environments 2026-07-23 14:54:20 -07:00
observability CI: port the split repos' workflows to per-domain path-filtered monorepo pipelines 2026-07-22 22:11:33 -07:00
CLAUDE.md docs: monorepo README, cutover runbook, root agent instructions 2026-07-22 22:11:33 -07:00
CUTOVER-NOTES.md docs: record the 2026-07-22 branch-migration sweep in cutover notes 2026-07-22 22:27:09 -07:00
README.md docs: monorepo README, cutover runbook, root agent instructions 2026-07-22 22:11:33 -07:00

thermograph

The Thermograph monorepo — the split repos reunified (2026-07-22) with full history via subtree merges, while keeping everything the split was actually for: per-domain images, per-domain deploys, and an async FE/BE contract.

Domains

Dir What CI
backend/ FastAPI graded-climate API, accounts, notifications (Discord bot, push, mail), data pipeline backend-build-push → image emi/thermograph/backend; backend-deploy[-prod|-dev]
frontend/ Public client: static JS/CSS + SSR pages frontend-* mirrors of the above; image emi/thermograph/frontend
infra/ Compose, deploy scripts, terraform, SOPS secrets vault, ops cron infra-sync (host checkout + secrets render), secrets-guard, ops-cron
observability/ Loki + Grafana + Alloy stack observability-validate

thermograph-docs deliberately stays its own repo (ADRs + runbooks, no build artifacts, different change cadence).

How CI stays decoupled

Every workflow in .forgejo/workflows/ is path-filtered to its domain: a push touching only frontend/** builds/deploys nothing else. Images stay separate (emi/thermograph/backend, emi/thermograph/frontend, each tagged sha-<12hex>), deploys stay per-service (infra/deploy/deploy.sh SERVICE=backend|frontend|all), and the API version contract (GET /api/version, PAYLOAD_VER) still lets FE and BE ship out of lockstep. The one intentionally coupled piece is pr-build.yml: a single always-running gate required check that builds only the domains a PR touches (a path-filtered required check would deadlock auto-merge).

Branch model (unchanged from the split era): PRs → dev, main → beta, release → prod; infra tracked via main on all hosts.

Before pointing anything live at this repo, read CUTOVER-NOTES.md.