|
All checks were successful
PR build (required check) / changes (pull_request) Successful in 9s
shell-lint / shellcheck (pull_request) Successful in 8s
secrets-guard / encrypted (pull_request) Successful in 9s
PR build (required check) / build-frontend (pull_request) Has been skipped
PR build (required check) / validate-observability (pull_request) Successful in 16s
PR build (required check) / build-backend (pull_request) Successful in 53s
PR build (required check) / gate (pull_request) Successful in 3s
The RETURN trap added in the previous commit leaked out of the function and killed every deploy on a SOPS-configured host. A RETURN trap set inside a SOURCED function is not function-scoped: it persists in the caller's shell after the function returns, and a RETURN trap also fires when a `.`/source completes. deploy.sh sources /etc/thermograph.env six lines after calling render_thermograph_secrets, which re-fired the trap at top level where `tmp` -- function-local -- is unset. Under deploy.sh's `set -u` that is fatal, and silent: that line already sends stderr to /dev/null, so the deploy rendered secrets and then died with no diagnostic before pulling or rolling anything. Replaced with explicit `rm -f "$tmp"` on each exit path, plus a comment recording why the tidier-looking trap is wrong here so it doesn't come back. The original defect the trap was meant to fix stays fixed: the decrypt-failure path removes the plaintext temp file before returning 1. The write section now captures its status in `rc` and cleans up once, rather than ending on `rm` -- as the last command it was masking a failed in-place `cat` write to status 0, so a half-written /etc/thermograph.env would have deployed as if it succeeded. Verified in a container against the real call pattern (strict-mode caller, source lib, call, then source the rendered env): success path returns 0 and the caller survives the subsequent source; decrypt-failure path aborts the caller with no /etc/thermograph.env written; both leave zero temp files. |
||
|---|---|---|
| .forgejo/workflows | ||
| backend | ||
| frontend | ||
| infra | ||
| observability | ||
| CLAUDE.md | ||
| CUTOVER-NOTES.md | ||
| README.md | ||
thermograph
The Thermograph monorepo — the split repos reunified (2026-07-22) with full history via subtree merges, while keeping everything the split was actually for: per-domain images, per-domain deploys, and an async FE/BE contract.
Domains
| Dir | What | CI |
|---|---|---|
backend/ |
FastAPI graded-climate API, accounts, notifications (Discord bot, push, mail), data pipeline | backend-build-push → image emi/thermograph/backend; backend-deploy[-prod|-dev] |
frontend/ |
Public client: static JS/CSS + SSR pages | frontend-* mirrors of the above; image emi/thermograph/frontend |
infra/ |
Compose, deploy scripts, terraform, SOPS secrets vault, ops cron | infra-sync (host checkout + secrets render), secrets-guard, ops-cron |
observability/ |
Loki + Grafana + Alloy stack | observability-validate |
thermograph-docs deliberately stays its own repo (ADRs + runbooks, no
build artifacts, different change cadence).
How CI stays decoupled
Every workflow in .forgejo/workflows/ is path-filtered to its domain: a
push touching only frontend/** builds/deploys nothing else. Images stay
separate (emi/thermograph/backend, emi/thermograph/frontend, each tagged
sha-<12hex>), deploys stay per-service (infra/deploy/deploy.sh SERVICE=backend|frontend|all), and the API version contract
(GET /api/version, PAYLOAD_VER) still lets FE and BE ship out of lockstep.
The one intentionally coupled piece is pr-build.yml: a single always-running
gate required check that builds only the domains a PR touches (a
path-filtered required check would deadlock auto-merge).
Branch model (unchanged from the split era): PRs → dev, main → beta,
release → prod; infra tracked via main on all hosts.
Before pointing anything live at this repo, read CUTOVER-NOTES.md.