thermograph/README.md
Emi Griffith 759789f0c6 registry: use admin_emi as the canonical image and repo namespace
The deploy path defaulted to emi/thermograph/{backend,frontend} and logged in
to the registry as `emi`. Neither is a real account: `emi` is a user_redirect
to admin_emi, left from renaming that account. Every package, repo and access
token belongs to admin_emi, and build-push.yml already publishes to
${github.repository}/<domain> — that is, admin_emi/thermograph/*.

Point the deploy-side defaults, the registry logins and the clone URLs at
admin_emi so nothing resolves through the redirect.
2026-07-30 20:53:26 -07:00

44 lines
2.4 KiB
Markdown

# thermograph
The Thermograph monorepo — the split repos reunified (2026-07-22) with full
history via subtree merges, while keeping everything the split was actually
for: **per-domain images, per-domain deploys, and an async FE/BE contract**.
## Domains
| Dir | What | CI |
|---|---|---|
| `backend/` | FastAPI graded-climate API, accounts, notifications (Discord bot, push, mail), data pipeline | `build-push` → image `admin_emi/thermograph/backend`; `deploy` |
| `frontend/` | Public client: static JS/CSS + SSR pages | same `build-push` / `deploy` workflows, matrixed by domain; image `admin_emi/thermograph/frontend` |
| `infra/` | Compose (dev, on vps1) + two Swarm stacks co-resident on vps2 (beta, prod), deploy scripts, terraform, SOPS secrets vault, ops cron | `infra-sync` (host checkout + secrets render), `secrets-guard`, `ops-cron` |
| `observability/` | Loki + Grafana + Alloy stack | `observability-validate` |
`thermograph-docs` deliberately **stays its own repo** (ADRs + runbooks, no
build artifacts, different change cadence).
## New here?
[`docs/onboarding/`](docs/onboarding/README.md) is the developer onboarding
path: orientation, verified local-setup recipes, a per-domain deep dive, the
cross-service contracts that break silently, the release flow, and a list of
which docs in this repo are currently stale.
## How CI stays decoupled
Every workflow in `.forgejo/workflows/` is **path-filtered to its domain**: a
push touching only `frontend/**` builds/deploys nothing else. Images stay
separate (`admin_emi/thermograph/backend`, `admin_emi/thermograph/frontend`, each tagged
`sha-<12hex>`), deploys stay per-service (`infra/deploy/deploy.sh
SERVICE=backend|frontend|all`), and the API version contract
(`GET /api/version`, `PAYLOAD_VER`) still lets FE and BE ship out of lockstep.
The one intentionally *coupled* piece is `pr-build.yml`: a single always-running
`gate` required check that builds only the domains a PR touches (a
path-filtered required check would deadlock auto-merge).
Branch model (unchanged from the split era): PRs → `dev`, `main` → beta,
`release` → prod. Infra isn't environment-staged the same way app images are:
beta's and prod's checkouts (both on vps2) track `main`; dev's checkout (on
vps1) tracks `dev` itself, since it's the one environment that isn't a
rehearsal for something downstream.
**Before pointing anything live at this repo, read `CUTOVER-NOTES.md`.**