Thermograph monorepo: graded-climate API + SSR frontend + infra, domain-specific containerized deploys
Find a file
Emi Griffith fd12ad6740
All checks were successful
PR build (required check) / changes (pull_request) Successful in 14s
secrets-guard / encrypted (pull_request) Successful in 10s
shell-lint / shellcheck (pull_request) Successful in 11s
PR build (required check) / build-backend (pull_request) Has been skipped
PR build (required check) / build-frontend (pull_request) Has been skipped
PR build (required check) / validate-observability (pull_request) Has been skipped
PR build (required check) / gate (pull_request) Successful in 2s
branching: the merge methods the orchestrator is told to use
Forgejo now allows only squash and fast-forward-only, so the three method= calls
in this file named styles the API rejects: rebase for feat->dev, and merge
commits for both promotions. An orchestrator following them gets a 405.

The fast-forward paragraph said adopting ff-only 'needs a one-time
reconciliation of the protected branches, which is the owner's decision'. That
decision was taken and the reconciliation done — the trees were already
identical, so it carried no content. release subset-of main subset-of dev now
holds and promotions land the branches on the same SHA. The paragraph keeps the
structural explanation, since it is what makes the failure mode recognisable,
and now points at reconciliation as the remedy.
2026-08-01 17:50:12 -07:00
.claude branching: the merge methods the orchestrator is told to use 2026-08-01 17:50:12 -07:00
.forgejo/workflows flow: squash into dev, fast-forward the promotions (#165) 2026-08-02 00:15:42 +00:00
backend registry: move the registry host to dev.jinemi.com, MCP to mcp.jinemi.com 2026-08-01 16:06:22 -07:00
docs/onboarding registry: move the registry host to dev.jinemi.com, MCP to mcp.jinemi.com 2026-08-01 16:06:22 -07:00
frontend registry: move the registry host to dev.jinemi.com, MCP to mcp.jinemi.com 2026-08-01 16:06:22 -07:00
infra registry: move the registry host to dev.jinemi.com, MCP to mcp.jinemi.com 2026-08-01 16:06:22 -07:00
observability registry: move the registry host to dev.jinemi.com, MCP to mcp.jinemi.com 2026-08-01 16:06:22 -07:00
.gitignore gitignore: ignore .claude/settings.local.json 2026-08-01 09:16:06 -07:00
CLAUDE.md flow: squash into dev, fast-forward the promotions (#165) 2026-08-02 00:15:42 +00:00
CUTOVER-NOTES.md registry: move the registry host to dev.jinemi.com, MCP to mcp.jinemi.com 2026-08-01 16:06:22 -07:00
Makefile make: add root install/up/down for the local stack 2026-08-01 13:14:32 -07:00
README.md registry: move image and repo references to the Jinemi namespace 2026-08-01 09:25:02 -07:00

thermograph

The Thermograph monorepo — the split repos reunified (2026-07-22) with full history via subtree merges, while keeping everything the split was actually for: per-domain images, per-domain deploys, and an async FE/BE contract.

Domains

Dir What CI
backend/ FastAPI graded-climate API, accounts, notifications (Discord bot, push, mail), data pipeline build-push → image jinemi/thermograph/backend; deploy
frontend/ Public client: static JS/CSS + SSR pages same build-push / deploy workflows, matrixed by domain; image jinemi/thermograph/frontend
infra/ Compose (dev, on vps1) + two Swarm stacks co-resident on vps2 (beta, prod), deploy scripts, terraform, SOPS secrets vault, ops cron infra-sync (host checkout + secrets render), secrets-guard, ops-cron
observability/ Loki + Grafana + Alloy stack observability-validate

thermograph-docs deliberately stays its own repo (ADRs + runbooks, no build artifacts, different change cadence).

New here?

docs/onboarding/ is the developer onboarding path: orientation, verified local-setup recipes, a per-domain deep dive, the cross-service contracts that break silently, the release flow, and a list of which docs in this repo are currently stale.

How CI stays decoupled

Every workflow in .forgejo/workflows/ is path-filtered to its domain: a push touching only frontend/** builds/deploys nothing else. Images stay separate (jinemi/thermograph/backend, jinemi/thermograph/frontend, each tagged sha-<12hex>), deploys stay per-service (infra/deploy/deploy.sh SERVICE=backend|frontend|all), and the API version contract (GET /api/version, PAYLOAD_VER) still lets FE and BE ship out of lockstep. The one intentionally coupled piece is pr-build.yml: a single always-running gate required check that builds only the domains a PR touches (a path-filtered required check would deadlock auto-merge).

Branch model (unchanged from the split era): PRs → dev, main → beta, release → prod. Infra isn't environment-staged the same way app images are: beta's and prod's checkouts (both on vps2) track main; dev's checkout (on vps1) tracks dev itself, since it's the one environment that isn't a rehearsal for something downstream.

Before pointing anything live at this repo, read CUTOVER-NOTES.md.