Compare commits
26 Commits
ops/seleni
...
4319cc2b51
| Author | SHA1 | Date | |
|---|---|---|---|
| 4319cc2b51 | |||
|
|
2bf339ce51 | ||
|
|
5bdedfc5ae | ||
|
|
0307ae16ae | ||
|
|
6c18f69cf2 | ||
|
|
47e2256556 | ||
|
|
9d77f8ba0e | ||
|
|
2f4be19c85 | ||
|
|
2a62c40990 | ||
|
|
7be98e5efc | ||
|
|
a65b356c9d | ||
|
|
08c17ef1b4 | ||
|
|
06f2f002b7 | ||
|
|
7ac4a8b4b7 | ||
|
|
90f2a86819 | ||
|
|
cbdefb2b23 | ||
|
|
1c36fe3a0a | ||
|
|
2b420ce8a4 | ||
|
|
5cbc1a06b1 | ||
|
|
9e7ee39b3a | ||
|
|
ae030a5f33 | ||
| bc8c35896f | |||
|
|
2cc91b6df0 | ||
| 0d2090fe81 | |||
|
|
bc3548e715 | ||
| 74333cc26b |
2
.gitattributes
vendored
Normal file
2
.gitattributes
vendored
Normal file
@@ -0,0 +1,2 @@
|
|||||||
|
/.gitattributes text eol=lf
|
||||||
|
*.sh text eol=lf
|
||||||
10
README.md
10
README.md
@@ -116,6 +116,16 @@ dotnet test tests/bluejay-infra-lint/BluejayInfraLint.Tests.csproj -c Release
|
|||||||
|
|
||||||
That test project sweeps `bluejay-infra/apps/**` plus the canonical sibling `FlowerCore.*\\k8s` manifests that share the same workspace. Matching `conftest.dev` policy files live under `tests/bluejay-infra-lint/conftest.dev/` for environments that also have `conftest` or `opa`.
|
That test project sweeps `bluejay-infra/apps/**` plus the canonical sibling `FlowerCore.*\\k8s` manifests that share the same workspace. Matching `conftest.dev` policy files live under `tests/bluejay-infra-lint/conftest.dev/` for environments that also have `conftest` or `opa`.
|
||||||
|
|
||||||
|
## Non-K8s Pi Artifacts
|
||||||
|
|
||||||
|
Some `apps/*` directories are deployment artifact bundles consumed by Puppet
|
||||||
|
instead of Kubernetes workloads. `apps/fc-signage-pi-player/` carries the
|
||||||
|
Chromium signage Pi player, `apps/fc-divoom-dm-pi-device/` carries the additive
|
||||||
|
edge2 Divoom-as-DeviceManagement-device profile/Hiera contract, and
|
||||||
|
`apps/fc-divoom-tv-pi/` carries the Divoom TV Pi HDMI systemd/Puppet shape.
|
||||||
|
These bundles intentionally avoid Deployment, IngressRoute, Certificate, and
|
||||||
|
OnePasswordItem resources.
|
||||||
|
|
||||||
## References
|
## References
|
||||||
|
|
||||||
- OpenVox noc1 durability runbook: `docs/runbooks/openvoxserver-quadlet-durability.md`
|
- OpenVox noc1 durability runbook: `docs/runbooks/openvoxserver-quadlet-durability.md`
|
||||||
|
|||||||
45
apps/fc-divoom-dm-pi-device/README.md
Normal file
45
apps/fc-divoom-dm-pi-device/README.md
Normal file
@@ -0,0 +1,45 @@
|
|||||||
|
# FlowerCore Divoom DM Pi Device
|
||||||
|
|
||||||
|
Source-controlled Puppet/Hiera deployment contract for registering the edge2
|
||||||
|
Divoom MiniToo panel as a FlowerCore DeviceManagement-managed Pi device.
|
||||||
|
|
||||||
|
This is not a Kubernetes application. The live panel remains the existing
|
||||||
|
edge2 `flowercore-divoom.service` managed by `FlowerCore.Puppet`
|
||||||
|
`profile::pi::service::divoom`, with the .NET payload deployed out of band
|
||||||
|
and `/opt/flowercore/divoom/data` plus the Bluetooth shell wrappers preserved.
|
||||||
|
Because edge2 is already Hiera-driven through `profile::pi::service::apps`,
|
||||||
|
the deploy home is additive `profile::pi::service` data/profile source, not
|
||||||
|
`profile::edge::service::apps` and not an ArgoCD/K8s app.
|
||||||
|
|
||||||
|
## Scope
|
||||||
|
|
||||||
|
- Stage DeviceManagement registration metadata for the edge2 Divoom MiniToo.
|
||||||
|
- Stage a separate, disabled-by-default DM Agent executor unit for privileged
|
||||||
|
Bluetooth operations once the DM-RPC lane lands.
|
||||||
|
- Keep `flowercore-divoom.service` and `flowercore-divoom-bt.service`
|
||||||
|
untouched: no service replacement, no restart subscription, no K8s surface.
|
||||||
|
- Preserve the current wrapper contract:
|
||||||
|
`/opt/flowercore/divoom/bt-link.sh`,
|
||||||
|
`/opt/flowercore/divoom/bt-reset.sh`, and
|
||||||
|
`/opt/flowercore/divoom/audio-link.sh`.
|
||||||
|
- Keep FM radio disabled and require visible render proof; device-info echo is
|
||||||
|
not render proof.
|
||||||
|
|
||||||
|
## Artifact Map
|
||||||
|
|
||||||
|
| Path | Use |
|
||||||
|
| --- | --- |
|
||||||
|
| `hiera/edge2-divoom-dm-device.overlay.yaml` | Additive Hiera overlay for edge2. Merge into the existing node YAML without removing `fc-pimanager` or `fc-divoom`. |
|
||||||
|
| `puppet/profile/pi/service/divoom_dm_device.pp` | Puppet profile shape to vendor into `FlowerCore.Puppet` after the DM-RPC executor binary exists. |
|
||||||
|
| `puppet/templates/divoom-device-registration.json.epp` | DM device registration metadata rendered on edge2. |
|
||||||
|
| `puppet/templates/flowercore-divoom-dm-agent.service.epp` | Separate DM Agent systemd unit. Defaults are stopped and disabled until a later cutover. |
|
||||||
|
|
||||||
|
## Rollout Notes
|
||||||
|
|
||||||
|
1. Land these artifacts in bluejay-infra as the deploy contract.
|
||||||
|
2. Vendor the Puppet profile and EPP templates into `FlowerCore.Puppet`.
|
||||||
|
3. Merge the Hiera overlay into `data/nodes/edge2.iamworkin.lan.yaml`.
|
||||||
|
4. Run Puppet in noop first, preferably with a node-local validation directory
|
||||||
|
under `~/.fcv` rather than `/tmp`.
|
||||||
|
5. Only enable the DM Agent service after the DeviceManagement BT executor has
|
||||||
|
landed and passed operator-eyeball render proof.
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
---
|
||||||
|
# Merge into FlowerCore.Puppet data/nodes/edge2.iamworkin.lan.yaml.
|
||||||
|
# Additive overlay only: keep the existing fc-pimanager version/tarball entry,
|
||||||
|
# keep fc-divoom enabled, and do not move Divoom into Kubernetes.
|
||||||
|
|
||||||
|
profile::pi::service::apps:
|
||||||
|
fc-pimanager:
|
||||||
|
binary: 'FlowerCore.PiManager.Web'
|
||||||
|
install_dir: '/opt/fc-pimanager'
|
||||||
|
port: 5000
|
||||||
|
environment: 'edge2'
|
||||||
|
version: '2026.05.28.1646'
|
||||||
|
tarball_source: 'puppet:///modules/profile/pi/builds/fc-pimanager.tar.gz'
|
||||||
|
fc-divoom:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
profile::pi::service::divoom_dm_device::ensure: 'present'
|
||||||
|
profile::pi::service::divoom_dm_device::service_enabled: false
|
||||||
|
profile::pi::service::divoom_dm_device::service_ensure: 'stopped'
|
||||||
|
profile::pi::service::divoom_dm_device::device_id: 'edge2-divoom-minitoo'
|
||||||
|
profile::pi::service::divoom_dm_device::display_name: 'edge2 Divoom MiniToo'
|
||||||
|
profile::pi::service::divoom_dm_device::host_fqdn: 'edge2.iamworkin.lan'
|
||||||
|
profile::pi::service::divoom_dm_device::dm_web_url: 'https://devicemgmt.iamworkin.lan'
|
||||||
|
profile::pi::service::divoom_dm_device::divoom_install_dir: '/opt/flowercore/divoom'
|
||||||
|
profile::pi::service::divoom_dm_device::agent_install_dir: '/opt/flowercore/devicemanagement-agent'
|
||||||
|
profile::pi::service::divoom_dm_device::bt_candidate_channels:
|
||||||
|
- '1'
|
||||||
|
- '10'
|
||||||
|
profile::pi::service::divoom_dm_device::default_bt_channel: '1'
|
||||||
|
profile::pi::service::divoom_dm_device::a2dp_default_state: 'off'
|
||||||
|
profile::pi::service::divoom_dm_device::fm_radio_enabled: false
|
||||||
|
profile::pi::service::divoom_dm_device::visible_render_proof_required: true
|
||||||
@@ -0,0 +1,140 @@
|
|||||||
|
# Drop into FlowerCore.Puppet site-modules/profile/manifests/pi/service/divoom_dm_device.pp.
|
||||||
|
# This profile is additive to profile::pi::service::divoom. It must not manage,
|
||||||
|
# restart, replace, or subscribe the existing flowercore-divoom.service.
|
||||||
|
class profile::pi::service::divoom_dm_device (
|
||||||
|
Enum['present', 'absent'] $ensure = 'present',
|
||||||
|
Boolean $service_enabled = false,
|
||||||
|
Enum['running', 'stopped'] $service_ensure = 'stopped',
|
||||||
|
String $service_name = 'flowercore-divoom-dm-agent',
|
||||||
|
String $device_id = 'edge2-divoom-minitoo',
|
||||||
|
String $display_name = 'edge2 Divoom MiniToo',
|
||||||
|
String $host_fqdn = 'edge2.iamworkin.lan',
|
||||||
|
String $dm_web_url = 'https://devicemgmt.iamworkin.lan',
|
||||||
|
String $divoom_install_dir = '/opt/flowercore/divoom',
|
||||||
|
String $agent_install_dir = '/opt/flowercore/devicemanagement-agent',
|
||||||
|
String $agent_binary = 'FlowerCore.DeviceManagement.Agent',
|
||||||
|
Array[String] $bt_candidate_channels = ['1', '10'],
|
||||||
|
String $default_bt_channel = '1',
|
||||||
|
Enum['on', 'off'] $a2dp_default_state = 'off',
|
||||||
|
Boolean $fm_radio_enabled = false,
|
||||||
|
Boolean $visible_render_proof_required = true,
|
||||||
|
) {
|
||||||
|
include profile::workstation::safe_account_exclusion
|
||||||
|
|
||||||
|
$safe_account = $profile::workstation::safe_account_exclusion::safe_account
|
||||||
|
$config_dir = '/etc/flowercore/device-management/devices'
|
||||||
|
$state_dir = '/var/lib/flowercore/divoom-dm-agent'
|
||||||
|
$log_dir = '/var/log/flowercore/divoom-dm-agent'
|
||||||
|
$registration_path = "${config_dir}/${device_id}.json"
|
||||||
|
$agent_binary_path = "${agent_install_dir}/${agent_binary}"
|
||||||
|
$bt_channels_json = inline_template('[<%= @bt_candidate_channels.map { |c| "\"#{c}\"" }.join(", ") %>]')
|
||||||
|
|
||||||
|
if $safe_account {
|
||||||
|
notify { 'fc-divoom-dm-device safe-account exclusion':
|
||||||
|
message => 'SAFE-ACCOUNT-EXCLUSION: Divoom DM Pi device profile refused to apply on operator workstation',
|
||||||
|
}
|
||||||
|
|
||||||
|
if $facts['os']['family'] != 'windows' {
|
||||||
|
ensure_resource('file', '/var/log/flowercore-audit', {
|
||||||
|
'ensure' => 'directory',
|
||||||
|
'owner' => 'root',
|
||||||
|
'group' => 'root',
|
||||||
|
'mode' => '0755',
|
||||||
|
})
|
||||||
|
|
||||||
|
file { '/var/log/flowercore-audit/safe-account-noop-fc-divoom-dm-device.log':
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644',
|
||||||
|
content => "noop: divoom dm pi device profile refused to apply on safe-account host\n",
|
||||||
|
require => File['/var/log/flowercore-audit'],
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} elsif $ensure == 'absent' {
|
||||||
|
service { $service_name:
|
||||||
|
ensure => stopped,
|
||||||
|
enable => false,
|
||||||
|
}
|
||||||
|
|
||||||
|
file { [
|
||||||
|
"/etc/systemd/system/${service_name}.service",
|
||||||
|
$registration_path,
|
||||||
|
]:
|
||||||
|
ensure => absent,
|
||||||
|
}
|
||||||
|
|
||||||
|
exec { 'fc-divoom-dm-agent-systemd-reload':
|
||||||
|
command => '/usr/bin/systemctl daemon-reload',
|
||||||
|
refreshonly => true,
|
||||||
|
path => ['/usr/bin', '/bin'],
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
case $facts['os']['family'] {
|
||||||
|
'Debian': {}
|
||||||
|
default: { fail("profile::pi::service::divoom_dm_device only supports Debian-family OS, got ${facts['os']['family']}") }
|
||||||
|
}
|
||||||
|
|
||||||
|
file { [$config_dir, $state_dir, $log_dir]:
|
||||||
|
ensure => directory,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0755',
|
||||||
|
}
|
||||||
|
|
||||||
|
file { $registration_path:
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644',
|
||||||
|
content => epp('profile/pi/fc_divoom_dm/divoom-device-registration.json.epp', {
|
||||||
|
'device_id' => $device_id,
|
||||||
|
'display_name' => $display_name,
|
||||||
|
'host_fqdn' => $host_fqdn,
|
||||||
|
'divoom_install_dir' => $divoom_install_dir,
|
||||||
|
'bt_channels_json' => $bt_channels_json,
|
||||||
|
'default_bt_channel' => $default_bt_channel,
|
||||||
|
'a2dp_default_state' => $a2dp_default_state,
|
||||||
|
'fm_radio_enabled' => $fm_radio_enabled,
|
||||||
|
'visible_render_proof_required' => $visible_render_proof_required,
|
||||||
|
}),
|
||||||
|
require => File[$config_dir],
|
||||||
|
}
|
||||||
|
|
||||||
|
file { "/etc/systemd/system/${service_name}.service":
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644',
|
||||||
|
content => epp('profile/pi/fc_divoom_dm/flowercore-divoom-dm-agent.service.epp', {
|
||||||
|
'service_name' => $service_name,
|
||||||
|
'device_id' => $device_id,
|
||||||
|
'dm_web_url' => $dm_web_url,
|
||||||
|
'registration_path' => $registration_path,
|
||||||
|
'divoom_install_dir' => $divoom_install_dir,
|
||||||
|
'agent_install_dir' => $agent_install_dir,
|
||||||
|
'agent_binary_path' => $agent_binary_path,
|
||||||
|
'state_dir' => $state_dir,
|
||||||
|
'log_dir' => $log_dir,
|
||||||
|
}),
|
||||||
|
notify => Exec['fc-divoom-dm-agent-systemd-reload'],
|
||||||
|
require => File[$registration_path],
|
||||||
|
}
|
||||||
|
|
||||||
|
exec { 'fc-divoom-dm-agent-systemd-reload':
|
||||||
|
command => '/usr/bin/systemctl daemon-reload',
|
||||||
|
refreshonly => true,
|
||||||
|
path => ['/usr/bin', '/bin'],
|
||||||
|
}
|
||||||
|
|
||||||
|
service { $service_name:
|
||||||
|
ensure => $service_ensure,
|
||||||
|
enable => $service_enabled,
|
||||||
|
require => [
|
||||||
|
File["/etc/systemd/system/${service_name}.service"],
|
||||||
|
File[$registration_path],
|
||||||
|
Exec['fc-divoom-dm-agent-systemd-reload'],
|
||||||
|
],
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
{
|
||||||
|
"deviceId": "<%= $device_id %>",
|
||||||
|
"displayName": "<%= $display_name %>",
|
||||||
|
"hostFqdn": "<%= $host_fqdn %>",
|
||||||
|
"kind": "DivoomMiniToo",
|
||||||
|
"managedBy": "FlowerCore.DeviceManagement",
|
||||||
|
"executionMode": "Pi",
|
||||||
|
"transport": {
|
||||||
|
"kind": "BluetoothSerial",
|
||||||
|
"candidateChannels": <%= $bt_channels_json %>,
|
||||||
|
"defaultChannel": "<%= $default_bt_channel %>",
|
||||||
|
"deviceInfoIsRenderProof": false,
|
||||||
|
"visibleRenderProofRequired": <%= $visible_render_proof_required %>
|
||||||
|
},
|
||||||
|
"paths": {
|
||||||
|
"divoomInstallDir": "<%= $divoom_install_dir %>",
|
||||||
|
"btLink": "<%= $divoom_install_dir %>/bt-link.sh",
|
||||||
|
"btReset": "<%= $divoom_install_dir %>/bt-reset.sh",
|
||||||
|
"audioLink": "<%= $divoom_install_dir %>/audio-link.sh"
|
||||||
|
},
|
||||||
|
"capabilities": {
|
||||||
|
"supportsBluetoothSerial": true,
|
||||||
|
"supportsBtChannelRedetect": true,
|
||||||
|
"supportsBtHardReset": true,
|
||||||
|
"supportsBtAudioProfileSwitch": true,
|
||||||
|
"a2dpDefaultState": "<%= $a2dp_default_state %>",
|
||||||
|
"fmRadioEnabled": <%= $fm_radio_enabled %>
|
||||||
|
},
|
||||||
|
"safety": {
|
||||||
|
"preserveExistingService": "flowercore-divoom.service",
|
||||||
|
"preserveDataDirectory": "<%= $divoom_install_dir %>/data",
|
||||||
|
"doNotEnableFmRadio": true
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=FlowerCore Divoom DM Agent Bluetooth executor
|
||||||
|
Documentation=https://github.com/astoltz/FlowerCore.Notes/blob/master/docs/standards/divoom-tv-hdmi-multitarget-render-substrate.md
|
||||||
|
Wants=network-online.target
|
||||||
|
After=network-online.target bluetooth.service
|
||||||
|
Requires=bluetooth.service
|
||||||
|
ConditionPathExists=<%= $agent_binary_path %>
|
||||||
|
ConditionPathExists=<%= $registration_path %>
|
||||||
|
ConditionPathExists=<%= $divoom_install_dir %>/bt-link.sh
|
||||||
|
ConditionPathExists=<%= $divoom_install_dir %>/bt-reset.sh
|
||||||
|
ConditionPathExists=<%= $divoom_install_dir %>/audio-link.sh
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
User=stoltz
|
||||||
|
Group=stoltz
|
||||||
|
WorkingDirectory=<%= $agent_install_dir %>
|
||||||
|
Environment=DOTNET_CLI_TELEMETRY_OPTOUT=1
|
||||||
|
Environment=FLOWERCORE_DM_DEVICE_REGISTRATION=<%= $registration_path %>
|
||||||
|
Environment=Divoom__Bluetooth__DeviceInfoIsRenderProof=false
|
||||||
|
Environment=Divoom__Bluetooth__VisibleRenderProofRequired=true
|
||||||
|
Environment=Divoom__Bluetooth__A2dpDefaultState=off
|
||||||
|
ExecStart=<%= $agent_binary_path %> --mode=Pi --device-id=<%= $device_id %> --dm-web-url=<%= $dm_web_url %> --registration=<%= $registration_path %>
|
||||||
|
Restart=on-failure
|
||||||
|
RestartSec=10s
|
||||||
|
StartLimitBurst=3
|
||||||
|
StartLimitIntervalSec=300s
|
||||||
|
SupplementaryGroups=bluetooth audio dialout
|
||||||
|
NoNewPrivileges=true
|
||||||
|
PrivateTmp=true
|
||||||
|
ProtectSystem=strict
|
||||||
|
ProtectHome=true
|
||||||
|
ReadWritePaths=<%= $state_dir %> <%= $log_dir %>
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
44
apps/fc-divoom-tv-pi/README.md
Normal file
44
apps/fc-divoom-tv-pi/README.md
Normal file
@@ -0,0 +1,44 @@
|
|||||||
|
# FlowerCore Divoom TV Pi HDMI
|
||||||
|
|
||||||
|
Source-controlled deploy shape for the native `FlowerCore.Divoom.Tv`
|
||||||
|
Avalonia HDMI renderer on a Raspberry Pi connected to a TV.
|
||||||
|
|
||||||
|
This is a Puppet/systemd appliance bundle, not a Kubernetes application. It
|
||||||
|
mirrors the existing `fc-signage-pi-player` pattern: bluejay-infra carries the
|
||||||
|
systemd units, scripts, Hiera shape, and Puppet profile source that
|
||||||
|
`FlowerCore.Puppet` vendors and installs.
|
||||||
|
|
||||||
|
## Scope
|
||||||
|
|
||||||
|
- Launch the future `FlowerCore.Divoom.Tv` linux-arm64 self-contained payload
|
||||||
|
from `/opt/flowercore/divoom-tv/FlowerCore.Divoom.Tv`.
|
||||||
|
- Prefer `cage` as the Wayland fullscreen compositor, with direct app launch as
|
||||||
|
a fallback for development images.
|
||||||
|
- Restart the app after HDMI hotplug with a 2 second DRM settle delay.
|
||||||
|
- Keep all runtime state local: `/var/lib/fc-divoom-tv` and
|
||||||
|
`/var/log/fc-divoom-tv`.
|
||||||
|
- Avoid CDN/runtime fetches; the app renders the in-house Divoom scene catalog
|
||||||
|
locally.
|
||||||
|
|
||||||
|
## Artifact Map
|
||||||
|
|
||||||
|
| Path | Use |
|
||||||
|
| --- | --- |
|
||||||
|
| `systemd/flowercore-divoom-tv.service` | Fullscreen Avalonia HDMI app service. |
|
||||||
|
| `systemd/flowercore-divoom-tv-hdmi.service` | HDMI hotplug responder service. |
|
||||||
|
| `systemd/99-flowercore-divoom-tv-hdmi.rules` | DRM udev hotplug rule. |
|
||||||
|
| `scripts/flowercore-divoom-tv-prelaunch.sh` | Preflight checks and local directory creation. |
|
||||||
|
| `scripts/flowercore-divoom-tv-launch.sh` | Cage-first fullscreen launcher. |
|
||||||
|
| `scripts/flowercore-divoom-tv-hdmi-respond.sh` | Hotplug settle and restart script. |
|
||||||
|
| `puppet/profile/pi/service/divoom_tv.pp` | Puppet profile shape to vendor into `FlowerCore.Puppet`. |
|
||||||
|
| `hiera/example-divoom-tv-pi.iamworkin.lan.yaml` | Example node Hiera for a Divoom TV Pi. |
|
||||||
|
|
||||||
|
## Rollout Notes
|
||||||
|
|
||||||
|
1. Build `FlowerCore.Divoom.Tv` with `dotnet.exe publish -c Release -r linux-arm64 --self-contained`.
|
||||||
|
2. Stage the payload to `/opt/flowercore/divoom-tv/` through the standard noc1
|
||||||
|
jump path and avoid `/tmp` for unprivileged Pi scratch.
|
||||||
|
3. Vendor the profile and static files into `FlowerCore.Puppet`.
|
||||||
|
4. Run Puppet noop, then apply on the target Pi.
|
||||||
|
5. Prove deployment with `systemctl is-active flowercore-divoom-tv.service`,
|
||||||
|
journal lines showing frames presented, and a visible HDMI display check.
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
# Example node data for a dedicated Pi -> HDMI -> TV Divoom renderer.
|
||||||
|
# Copy into FlowerCore.Puppet data/nodes/<hostname>.iamworkin.lan.yaml only
|
||||||
|
# after the Pi has a static DHCP/DNS entry and the linux-arm64 payload exists.
|
||||||
|
|
||||||
|
facts:
|
||||||
|
role: pi_prototype
|
||||||
|
|
||||||
|
profile::motd::role: 'Divoom TV HDMI Renderer'
|
||||||
|
|
||||||
|
profile::pi::service::divoom_tv::ensure: 'present'
|
||||||
|
profile::pi::service::divoom_tv::service_enabled: true
|
||||||
|
profile::pi::service::divoom_tv::service_ensure: 'running'
|
||||||
|
profile::pi::service::divoom_tv::install_dir: '/opt/flowercore/divoom-tv'
|
||||||
|
profile::pi::service::divoom_tv::state_dir: '/var/lib/fc-divoom-tv'
|
||||||
|
profile::pi::service::divoom_tv::log_dir: '/var/log/fc-divoom-tv'
|
||||||
|
profile::pi::service::divoom_tv::presentation_mode: 'PillarboxSquare'
|
||||||
|
profile::pi::service::divoom_tv::startup_scene: 'bluejay-clock'
|
||||||
|
profile::pi::service::divoom_tv::reduced_motion: false
|
||||||
149
apps/fc-divoom-tv-pi/puppet/profile/pi/service/divoom_tv.pp
Normal file
149
apps/fc-divoom-tv-pi/puppet/profile/pi/service/divoom_tv.pp
Normal file
@@ -0,0 +1,149 @@
|
|||||||
|
# Drop into FlowerCore.Puppet site-modules/profile/manifests/pi/service/divoom_tv.pp.
|
||||||
|
# Static files come from profile/pi/fc_divoom_tv/ after this bluejay-infra
|
||||||
|
# bundle is vendored into the Puppet control repo.
|
||||||
|
class profile::pi::service::divoom_tv (
|
||||||
|
Enum['present', 'absent'] $ensure = 'present',
|
||||||
|
Boolean $service_enabled = false,
|
||||||
|
Enum['running', 'stopped'] $service_ensure = 'stopped',
|
||||||
|
String $service_name = 'flowercore-divoom-tv',
|
||||||
|
String $user = 'fc-divoom-tv',
|
||||||
|
String $group = 'fc-divoom-tv',
|
||||||
|
String $install_dir = '/opt/flowercore/divoom-tv',
|
||||||
|
String $state_dir = '/var/lib/fc-divoom-tv',
|
||||||
|
String $log_dir = '/var/log/fc-divoom-tv',
|
||||||
|
String $presentation_mode = 'PillarboxSquare',
|
||||||
|
String $startup_scene = 'bluejay-clock',
|
||||||
|
Boolean $reduced_motion = false,
|
||||||
|
) {
|
||||||
|
include profile::workstation::safe_account_exclusion
|
||||||
|
|
||||||
|
$safe_account = $profile::workstation::safe_account_exclusion::safe_account
|
||||||
|
|
||||||
|
if $safe_account {
|
||||||
|
notify { 'fc-divoom-tv safe-account exclusion':
|
||||||
|
message => 'SAFE-ACCOUNT-EXCLUSION: Divoom TV Pi profile refused to apply on operator workstation',
|
||||||
|
}
|
||||||
|
} elsif $ensure == 'absent' {
|
||||||
|
service { $service_name:
|
||||||
|
ensure => stopped,
|
||||||
|
enable => false,
|
||||||
|
}
|
||||||
|
|
||||||
|
file { [
|
||||||
|
"/etc/systemd/system/${service_name}.service",
|
||||||
|
"/etc/systemd/system/${service_name}-hdmi.service",
|
||||||
|
'/etc/udev/rules.d/99-flowercore-divoom-tv-hdmi.rules',
|
||||||
|
'/usr/local/bin/flowercore-divoom-tv-prelaunch.sh',
|
||||||
|
'/usr/local/bin/flowercore-divoom-tv-launch.sh',
|
||||||
|
'/usr/local/bin/flowercore-divoom-tv-hdmi-respond.sh',
|
||||||
|
'/etc/flowercore/divoom-tv.env',
|
||||||
|
]:
|
||||||
|
ensure => absent,
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
case $facts['os']['family'] {
|
||||||
|
'Debian': {}
|
||||||
|
default: { fail("profile::pi::service::divoom_tv only supports Debian-family OS, got ${facts['os']['family']}") }
|
||||||
|
}
|
||||||
|
|
||||||
|
package { ['cage', 'libgbm1', 'libdrm2', 'libxkbcommon0', 'fonts-dejavu-core']:
|
||||||
|
ensure => installed,
|
||||||
|
}
|
||||||
|
|
||||||
|
group { $group:
|
||||||
|
ensure => present,
|
||||||
|
system => true,
|
||||||
|
}
|
||||||
|
|
||||||
|
user { $user:
|
||||||
|
ensure => present,
|
||||||
|
system => true,
|
||||||
|
gid => $group,
|
||||||
|
home => $state_dir,
|
||||||
|
managehome => false,
|
||||||
|
shell => '/usr/sbin/nologin',
|
||||||
|
require => Group[$group],
|
||||||
|
}
|
||||||
|
|
||||||
|
file { [$install_dir, $state_dir, $log_dir, '/etc/flowercore']:
|
||||||
|
ensure => directory,
|
||||||
|
owner => $user,
|
||||||
|
group => $group,
|
||||||
|
mode => '0755',
|
||||||
|
}
|
||||||
|
|
||||||
|
file { '/etc/flowercore/divoom-tv.env':
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644',
|
||||||
|
content => "FC_DIVOOM_TV_PRESENTATION_MODE=${presentation_mode}\nFC_DIVOOM_TV_START_SCENE=${startup_scene}\nFC_DIVOOM_TV_REDUCED_MOTION=${reduced_motion}\n",
|
||||||
|
require => File['/etc/flowercore'],
|
||||||
|
}
|
||||||
|
|
||||||
|
$script_map = {
|
||||||
|
'/usr/local/bin/flowercore-divoom-tv-prelaunch.sh' => 'profile/pi/fc_divoom_tv/flowercore-divoom-tv-prelaunch.sh',
|
||||||
|
'/usr/local/bin/flowercore-divoom-tv-launch.sh' => 'profile/pi/fc_divoom_tv/flowercore-divoom-tv-launch.sh',
|
||||||
|
'/usr/local/bin/flowercore-divoom-tv-hdmi-respond.sh' => 'profile/pi/fc_divoom_tv/flowercore-divoom-tv-hdmi-respond.sh',
|
||||||
|
}
|
||||||
|
|
||||||
|
$script_map.each |$dest, $src| {
|
||||||
|
file { $dest:
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0755',
|
||||||
|
source => "puppet:///modules/${src}",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$unit_map = {
|
||||||
|
"/etc/systemd/system/${service_name}.service" => 'profile/pi/fc_divoom_tv/flowercore-divoom-tv.service',
|
||||||
|
"/etc/systemd/system/${service_name}-hdmi.service" => 'profile/pi/fc_divoom_tv/flowercore-divoom-tv-hdmi.service',
|
||||||
|
}
|
||||||
|
|
||||||
|
$unit_map.each |$dest, $src| {
|
||||||
|
file { $dest:
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644',
|
||||||
|
source => "puppet:///modules/${src}",
|
||||||
|
notify => Exec['fc-divoom-tv-systemd-reload'],
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
file { '/etc/udev/rules.d/99-flowercore-divoom-tv-hdmi.rules':
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644',
|
||||||
|
source => 'puppet:///modules/profile/pi/fc_divoom_tv/99-flowercore-divoom-tv-hdmi.rules',
|
||||||
|
notify => Exec['fc-divoom-tv-udev-reload'],
|
||||||
|
}
|
||||||
|
|
||||||
|
exec { 'fc-divoom-tv-systemd-reload':
|
||||||
|
command => '/usr/bin/systemctl daemon-reload',
|
||||||
|
refreshonly => true,
|
||||||
|
path => ['/usr/bin', '/bin'],
|
||||||
|
}
|
||||||
|
|
||||||
|
exec { 'fc-divoom-tv-udev-reload':
|
||||||
|
command => '/usr/bin/udevadm control --reload-rules',
|
||||||
|
refreshonly => true,
|
||||||
|
path => ['/usr/bin', '/bin'],
|
||||||
|
}
|
||||||
|
|
||||||
|
service { $service_name:
|
||||||
|
ensure => $service_ensure,
|
||||||
|
enable => $service_enabled,
|
||||||
|
require => [
|
||||||
|
File["/etc/systemd/system/${service_name}.service"],
|
||||||
|
File['/etc/flowercore/divoom-tv.env'],
|
||||||
|
File['/usr/local/bin/flowercore-divoom-tv-prelaunch.sh'],
|
||||||
|
File['/usr/local/bin/flowercore-divoom-tv-launch.sh'],
|
||||||
|
Exec['fc-divoom-tv-systemd-reload'],
|
||||||
|
],
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
sleep 2
|
||||||
|
systemctl restart flowercore-divoom-tv.service
|
||||||
25
apps/fc-divoom-tv-pi/scripts/flowercore-divoom-tv-launch.sh
Normal file
25
apps/fc-divoom-tv-pi/scripts/flowercore-divoom-tv-launch.sh
Normal file
@@ -0,0 +1,25 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
APP_BIN="${FC_DIVOOM_TV_BIN:-/opt/flowercore/divoom-tv/FlowerCore.Divoom.Tv}"
|
||||||
|
STATE_DIR="${FC_DIVOOM_TV_STATE_DIR:-/var/lib/fc-divoom-tv}"
|
||||||
|
LOG_DIR="${FC_DIVOOM_TV_LOG_DIR:-/var/log/fc-divoom-tv}"
|
||||||
|
PRESENTATION_MODE="${FC_DIVOOM_TV_PRESENTATION_MODE:-PillarboxSquare}"
|
||||||
|
START_SCENE="${FC_DIVOOM_TV_START_SCENE:-bluejay-clock}"
|
||||||
|
REDUCED_MOTION="${FC_DIVOOM_TV_REDUCED_MOTION:-false}"
|
||||||
|
|
||||||
|
COMMON_ARGS=(
|
||||||
|
"--target=hdmi"
|
||||||
|
"--presentation-mode=${PRESENTATION_MODE}"
|
||||||
|
"--startup-scene=${START_SCENE}"
|
||||||
|
"--reduced-motion=${REDUCED_MOTION}"
|
||||||
|
"--state-dir=${STATE_DIR}"
|
||||||
|
"--log-dir=${LOG_DIR}"
|
||||||
|
)
|
||||||
|
|
||||||
|
if command -v cage >/dev/null 2>&1; then
|
||||||
|
exec cage -- "${APP_BIN}" "${COMMON_ARGS[@]}" "$@"
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "[$(date -Is)] cage not found; launching FlowerCore.Divoom.Tv directly" >&2
|
||||||
|
exec "${APP_BIN}" "${COMMON_ARGS[@]}" "$@"
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
APP_BIN="${FC_DIVOOM_TV_BIN:-/opt/flowercore/divoom-tv/FlowerCore.Divoom.Tv}"
|
||||||
|
STATE_DIR="${FC_DIVOOM_TV_STATE_DIR:-/var/lib/fc-divoom-tv}"
|
||||||
|
LOG_DIR="${FC_DIVOOM_TV_LOG_DIR:-/var/log/fc-divoom-tv}"
|
||||||
|
|
||||||
|
mkdir -p "${STATE_DIR}" "${LOG_DIR}"
|
||||||
|
|
||||||
|
if [[ ! -x "${APP_BIN}" ]]; then
|
||||||
|
echo "[$(date -Is)] missing executable ${APP_BIN}" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ -d /sys/class/drm ]] && ! find /sys/class/drm -maxdepth 1 -name 'card*-HDMI-A-*' -print -quit | grep -q .; then
|
||||||
|
echo "[$(date -Is)] no HDMI connector visible yet; continuing so the app can wait for display" >&2
|
||||||
|
fi
|
||||||
|
|
||||||
|
if command -v cage >/dev/null 2>&1; then
|
||||||
|
echo "[$(date -Is)] cage available for fullscreen Wayland launch"
|
||||||
|
else
|
||||||
|
echo "[$(date -Is)] cage not installed; direct launch fallback will be used" >&2
|
||||||
|
fi
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
# Settle DRM for 2s before restarting the fullscreen Avalonia renderer.
|
||||||
|
SUBSYSTEM=="drm", KERNEL=="card?-HDMI-A-?", ACTION=="change", RUN+="/usr/bin/systemctl start flowercore-divoom-tv-hdmi.service"
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=FlowerCore Divoom TV HDMI hotplug responder
|
||||||
|
DefaultDependencies=no
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
ExecStart=/usr/local/bin/flowercore-divoom-tv-hdmi-respond.sh
|
||||||
40
apps/fc-divoom-tv-pi/systemd/flowercore-divoom-tv.service
Normal file
40
apps/fc-divoom-tv-pi/systemd/flowercore-divoom-tv.service
Normal file
@@ -0,0 +1,40 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=FlowerCore Divoom TV HDMI Renderer (Avalonia fullscreen)
|
||||||
|
Documentation=https://github.com/astoltz/FlowerCore.Notes/blob/master/docs/standards/divoom-tv-hdmi-multitarget-render-substrate.md
|
||||||
|
Wants=network-online.target
|
||||||
|
After=network-online.target systemd-user-sessions.service
|
||||||
|
ConditionPathExists=/opt/flowercore/divoom-tv/FlowerCore.Divoom.Tv
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
User=fc-divoom-tv
|
||||||
|
Group=fc-divoom-tv
|
||||||
|
WorkingDirectory=/opt/flowercore/divoom-tv
|
||||||
|
EnvironmentFile=-/etc/flowercore/divoom-tv.env
|
||||||
|
Environment=DOTNET_CLI_TELEMETRY_OPTOUT=1
|
||||||
|
Environment=XDG_RUNTIME_DIR=/run/fc-divoom-tv
|
||||||
|
RuntimeDirectory=fc-divoom-tv
|
||||||
|
RuntimeDirectoryMode=0700
|
||||||
|
ExecStartPre=/usr/local/bin/flowercore-divoom-tv-prelaunch.sh
|
||||||
|
ExecStart=/usr/local/bin/flowercore-divoom-tv-launch.sh
|
||||||
|
Restart=always
|
||||||
|
RestartSec=10s
|
||||||
|
StartLimitBurst=5
|
||||||
|
StartLimitIntervalSec=300s
|
||||||
|
MemoryMax=2G
|
||||||
|
MemoryHigh=1500M
|
||||||
|
PrivateTmp=true
|
||||||
|
NoNewPrivileges=true
|
||||||
|
ProtectSystem=strict
|
||||||
|
ProtectHome=true
|
||||||
|
ReadWritePaths=/var/lib/fc-divoom-tv /var/log/fc-divoom-tv /run/fc-divoom-tv
|
||||||
|
TTYPath=/dev/tty1
|
||||||
|
StandardInput=tty
|
||||||
|
StandardOutput=journal
|
||||||
|
StandardError=journal
|
||||||
|
TTYReset=yes
|
||||||
|
TTYVHangup=yes
|
||||||
|
TTYVTDisallocate=yes
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=graphical.target
|
||||||
@@ -532,7 +532,7 @@ spec:
|
|||||||
fsGroupChangePolicy: OnRootMismatch
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
containers:
|
containers:
|
||||||
- name: web
|
- name: web
|
||||||
image: localhost/fc-ttsreader-web:v20260518-sprint36-demo-finish-b132cbf
|
image: localhost/fc-ttsreader-web:v20260603-s54cx14-pr29-live
|
||||||
imagePullPolicy: Never
|
imagePullPolicy: Never
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 5217
|
- containerPort: 5217
|
||||||
@@ -554,6 +554,8 @@ spec:
|
|||||||
value: "/data/chapter-context.db"
|
value: "/data/chapter-context.db"
|
||||||
- name: TtsReader__Jobs__Root
|
- name: TtsReader__Jobs__Root
|
||||||
value: "/data/jobs"
|
value: "/data/jobs"
|
||||||
|
- name: TtsReader__Export__LocalCasRoot
|
||||||
|
value: "/data/bundles/cas"
|
||||||
- name: TtsReader__Piper__Host
|
- name: TtsReader__Piper__Host
|
||||||
value: "10.0.57.17"
|
value: "10.0.57.17"
|
||||||
- name: TtsReader__Piper__Port
|
- name: TtsReader__Piper__Port
|
||||||
|
|||||||
@@ -58,7 +58,7 @@ spec:
|
|||||||
nodeName: rke2-server
|
nodeName: rke2-server
|
||||||
containers:
|
containers:
|
||||||
- name: web
|
- name: web
|
||||||
image: localhost/fc-updater-web:v20260509-4162dca-authgate
|
image: localhost/fc-updater-web:v202605310029-7974fc4
|
||||||
imagePullPolicy: Never
|
imagePullPolicy: Never
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
@@ -88,6 +88,8 @@ spec:
|
|||||||
value: Faith AI Mike Edition
|
value: Faith AI Mike Edition
|
||||||
- name: FlowerCore__Updater__PublicShares__Links__0__Description
|
- name: FlowerCore__Updater__PublicShares__Links__0__Description
|
||||||
value: Private release link for Mike's Faith AI bundle.
|
value: Private release link for Mike's Faith AI bundle.
|
||||||
|
- name: FlowerCore__Audit__Sinks__Loki__Enabled
|
||||||
|
value: "false"
|
||||||
- name: FlowerCore__Updater__Auth__Bootstrap__Enabled
|
- name: FlowerCore__Updater__Auth__Bootstrap__Enabled
|
||||||
value: "true"
|
value: "true"
|
||||||
- name: FlowerCore__Updater__Auth__Bootstrap__Username
|
- name: FlowerCore__Updater__Auth__Bootstrap__Username
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -46,7 +46,7 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: intranet-web
|
- name: intranet-web
|
||||||
image: localhost/fc-intranet-web:v20260508-brochure-w1
|
image: localhost/fc-intranet-web:v20260531-ttsreader-bridge
|
||||||
imagePullPolicy: Never
|
imagePullPolicy: Never
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 5300
|
- containerPort: 5300
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ metadata:
|
|||||||
role: github-actions-runner
|
role: github-actions-runner
|
||||||
flowercore.io/managed-by: bluejay-infra
|
flowercore.io/managed-by: bluejay-infra
|
||||||
spec:
|
spec:
|
||||||
runStrategy: Always
|
runStrategy: Halted
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
|
|||||||
@@ -207,20 +207,13 @@ spec:
|
|||||||
- port: 993
|
- port: 993
|
||||||
targetPort: 993
|
targetPort: 993
|
||||||
name: imaps
|
name: imaps
|
||||||
---
|
# --- mail-tls Certificate REMOVED 2026-06-01 ---
|
||||||
# TLS Certificate via cert-manager
|
# mail-tls is now managed OUTSIDE cert-manager: issued from step-ca's JWK 'admin'
|
||||||
apiVersion: cert-manager.io/v1
|
# provisioner and auto-renewed by a systemd timer on noc1 (step ca renew), which
|
||||||
kind: Certificate
|
# writes the mail-tls secret directly. step-ca-acme only has an HTTP-01 (Traefik)
|
||||||
metadata:
|
# solver, but mail.iamworkin.lan must resolve to the dedicated MetalLB IP 10.0.56.202
|
||||||
name: mail-tls
|
# (SMTP/IMAP), so HTTP-01 cannot validate. Do NOT re-add a cert-manager Certificate
|
||||||
namespace: mail
|
# here unless a DNS-01 solver is deployed for step-ca-acme.
|
||||||
spec:
|
|
||||||
secretName: mail-tls
|
|
||||||
issuerRef:
|
|
||||||
name: step-ca-acme
|
|
||||||
kind: ClusterIssuer
|
|
||||||
dnsNames:
|
|
||||||
- mail.iamworkin.lan
|
|
||||||
---
|
---
|
||||||
# Traefik IngressRoute - Webmail placeholder
|
# Traefik IngressRoute - Webmail placeholder
|
||||||
apiVersion: traefik.io/v1alpha1
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
|||||||
@@ -479,11 +479,11 @@ data:
|
|||||||
- "https://gitea.iamworkin.lan/"
|
- "https://gitea.iamworkin.lan/"
|
||||||
- "https://argocd.iamworkin.lan/"
|
- "https://argocd.iamworkin.lan/"
|
||||||
- "https://intranet.iamworkin.lan/"
|
- "https://intranet.iamworkin.lan/"
|
||||||
- "https://signage.iamworkin.lan/"
|
- "https://signage.iamworkin.lan/healthz" # root 401 auth-gated 2026-06-01; /healthz anon 200
|
||||||
- "https://kiosk.iamworkin.lan/"
|
- "https://kiosk.iamworkin.lan/"
|
||||||
- "https://media.iamworkin.lan/"
|
- "https://media.iamworkin.lan/"
|
||||||
- "https://mysql.iamworkin.lan/"
|
- "https://mysql.iamworkin.lan/healthz" # root 401 auth-gated 2026-06-01; /healthz anon 200
|
||||||
- "https://php.iamworkin.lan/"
|
- "https://php.iamworkin.lan/healthz" # root 401 auth-gated 2026-06-01; /healthz anon 200
|
||||||
- "https://zabbix.iamworkin.lan/"
|
- "https://zabbix.iamworkin.lan/"
|
||||||
- "https://desktop.iamworkin.lan/"
|
- "https://desktop.iamworkin.lan/"
|
||||||
- "https://print.iamworkin.lan/"
|
- "https://print.iamworkin.lan/"
|
||||||
|
|||||||
206
tests/bluejay-infra-lint/DivoomPiDeployArtifactTests.cs
Normal file
206
tests/bluejay-infra-lint/DivoomPiDeployArtifactTests.cs
Normal file
@@ -0,0 +1,206 @@
|
|||||||
|
using FluentAssertions;
|
||||||
|
using Xunit;
|
||||||
|
|
||||||
|
namespace BluejayInfraLint.Tests;
|
||||||
|
|
||||||
|
[Trait("Category", "Unit")]
|
||||||
|
public sealed class DivoomPiDeployArtifactTests
|
||||||
|
{
|
||||||
|
private static readonly string Root = FindRepoRoot();
|
||||||
|
private static readonly string DmRoot = Path.Combine(Root, "apps", "fc-divoom-dm-pi-device");
|
||||||
|
private static readonly string TvRoot = Path.Combine(Root, "apps", "fc-divoom-tv-pi");
|
||||||
|
|
||||||
|
public static TheoryData<string> DmRequiredArtifacts => new()
|
||||||
|
{
|
||||||
|
"README.md",
|
||||||
|
"hiera/edge2-divoom-dm-device.overlay.yaml",
|
||||||
|
"puppet/profile/pi/service/divoom_dm_device.pp",
|
||||||
|
"puppet/templates/divoom-device-registration.json.epp",
|
||||||
|
"puppet/templates/flowercore-divoom-dm-agent.service.epp",
|
||||||
|
};
|
||||||
|
|
||||||
|
public static TheoryData<string> TvRequiredArtifacts => new()
|
||||||
|
{
|
||||||
|
"README.md",
|
||||||
|
"hiera/example-divoom-tv-pi.iamworkin.lan.yaml",
|
||||||
|
"puppet/profile/pi/service/divoom_tv.pp",
|
||||||
|
"systemd/flowercore-divoom-tv.service",
|
||||||
|
"systemd/flowercore-divoom-tv-hdmi.service",
|
||||||
|
"systemd/99-flowercore-divoom-tv-hdmi.rules",
|
||||||
|
"scripts/flowercore-divoom-tv-prelaunch.sh",
|
||||||
|
"scripts/flowercore-divoom-tv-launch.sh",
|
||||||
|
"scripts/flowercore-divoom-tv-hdmi-respond.sh",
|
||||||
|
};
|
||||||
|
|
||||||
|
[Theory]
|
||||||
|
[MemberData(nameof(DmRequiredArtifacts))]
|
||||||
|
public void DmDeviceArtifacts_ArePresent(string relativePath)
|
||||||
|
{
|
||||||
|
File.Exists(Path.Combine(DmRoot, relativePath.Replace('/', Path.DirectorySeparatorChar))).Should().BeTrue(relativePath);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Theory]
|
||||||
|
[MemberData(nameof(TvRequiredArtifacts))]
|
||||||
|
public void TvPiArtifacts_ArePresent(string relativePath)
|
||||||
|
{
|
||||||
|
File.Exists(Path.Combine(TvRoot, relativePath.Replace('/', Path.DirectorySeparatorChar))).Should().BeTrue(relativePath);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DmDeviceReadme_DeclaresPuppetSystemdNotKubernetes()
|
||||||
|
{
|
||||||
|
var readme = ReadDm("README.md");
|
||||||
|
|
||||||
|
readme.Should().Contain("not a Kubernetes application");
|
||||||
|
readme.Should().Contain("profile::pi::service::divoom");
|
||||||
|
readme.Should().Contain("no K8s surface");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DmHieraOverlay_PreservesExistingEdge2DivoomService()
|
||||||
|
{
|
||||||
|
var hiera = ReadDm("hiera/edge2-divoom-dm-device.overlay.yaml");
|
||||||
|
|
||||||
|
hiera.Should().Contain("fc-pimanager:");
|
||||||
|
hiera.Should().Contain("fc-divoom:");
|
||||||
|
hiera.Should().Contain("enabled: true");
|
||||||
|
hiera.Should().Contain("profile::pi::service::divoom_dm_device::service_enabled: false");
|
||||||
|
hiera.Should().Contain("profile::pi::service::divoom_dm_device::service_ensure: 'stopped'");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DmPuppetProfile_DefaultsToStoppedDisabledService()
|
||||||
|
{
|
||||||
|
var profile = ReadDm("puppet/profile/pi/service/divoom_dm_device.pp");
|
||||||
|
|
||||||
|
profile.Should().Contain("Boolean $service_enabled = false");
|
||||||
|
profile.Should().Contain("Enum['running', 'stopped'] $service_ensure = 'stopped'");
|
||||||
|
profile.Should().Contain("service { $service_name:");
|
||||||
|
profile.Should().Contain("ensure => $service_ensure");
|
||||||
|
profile.Should().Contain("enable => $service_enabled");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DmPuppetProfile_DoesNotManageLiveDivoomWebUnit()
|
||||||
|
{
|
||||||
|
var profile = ReadDm("puppet/profile/pi/service/divoom_dm_device.pp");
|
||||||
|
|
||||||
|
profile.Should().NotContain("Service['flowercore-divoom.service']");
|
||||||
|
profile.Should().NotContain("service { 'flowercore-divoom.service'");
|
||||||
|
profile.Should().NotContain("notify => Service");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DmAgentUnit_IsSeparateAndGatedByExistingWrappers()
|
||||||
|
{
|
||||||
|
var unit = ReadDm("puppet/templates/flowercore-divoom-dm-agent.service.epp");
|
||||||
|
|
||||||
|
unit.Should().Contain("ConditionPathExists=<%= $divoom_install_dir %>/bt-link.sh");
|
||||||
|
unit.Should().Contain("ConditionPathExists=<%= $divoom_install_dir %>/bt-reset.sh");
|
||||||
|
unit.Should().Contain("ConditionPathExists=<%= $divoom_install_dir %>/audio-link.sh");
|
||||||
|
unit.Should().Contain("ExecStart=<%= $agent_binary_path %> --mode=Pi");
|
||||||
|
unit.Should().NotContain("flowercore-divoom.service");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DmRegistration_CarriesRenderProofAndSafetyPolicy()
|
||||||
|
{
|
||||||
|
var registration = ReadDm("puppet/templates/divoom-device-registration.json.epp");
|
||||||
|
|
||||||
|
registration.Should().Contain("\"candidateChannels\": <%= $bt_channels_json %>");
|
||||||
|
registration.Should().Contain("\"deviceInfoIsRenderProof\": false");
|
||||||
|
registration.Should().Contain("\"visibleRenderProofRequired\": <%= $visible_render_proof_required %>");
|
||||||
|
registration.Should().Contain("\"preserveExistingService\": \"flowercore-divoom.service\"");
|
||||||
|
registration.Should().Contain("\"doNotEnableFmRadio\": true");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void TvService_UsesAvaloniaHdmiSafetyGates()
|
||||||
|
{
|
||||||
|
var unit = ReadTv("systemd/flowercore-divoom-tv.service");
|
||||||
|
|
||||||
|
unit.Should().Contain("ConditionPathExists=/opt/flowercore/divoom-tv/FlowerCore.Divoom.Tv");
|
||||||
|
unit.Should().Contain("Environment=XDG_RUNTIME_DIR=/run/fc-divoom-tv");
|
||||||
|
unit.Should().Contain("RuntimeDirectoryMode=0700");
|
||||||
|
unit.Should().Contain("ExecStartPre=/usr/local/bin/flowercore-divoom-tv-prelaunch.sh");
|
||||||
|
unit.Should().Contain("ExecStart=/usr/local/bin/flowercore-divoom-tv-launch.sh");
|
||||||
|
unit.Should().Contain("MemoryMax=2G");
|
||||||
|
unit.Should().Contain("PrivateTmp=true");
|
||||||
|
unit.Should().NotContain("/tmp");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void TvLauncher_PrefersCageAndFallsBackToDirectLaunch()
|
||||||
|
{
|
||||||
|
var script = ReadTv("scripts/flowercore-divoom-tv-launch.sh");
|
||||||
|
|
||||||
|
script.Should().Contain("command -v cage");
|
||||||
|
script.Should().Contain("exec cage --");
|
||||||
|
script.Should().Contain("launching FlowerCore.Divoom.Tv directly");
|
||||||
|
script.Should().Contain("--target=hdmi");
|
||||||
|
script.Should().Contain("--presentation-mode=${PRESENTATION_MODE}");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void TvHotplugRule_SettlesAndRestartsRenderer()
|
||||||
|
{
|
||||||
|
var rule = ReadTv("systemd/99-flowercore-divoom-tv-hdmi.rules");
|
||||||
|
var responder = ReadTv("scripts/flowercore-divoom-tv-hdmi-respond.sh");
|
||||||
|
|
||||||
|
rule.Should().Contain("KERNEL==\"card?-HDMI-A-?\"");
|
||||||
|
rule.Should().Contain("start flowercore-divoom-tv-hdmi.service");
|
||||||
|
responder.Should().Contain("sleep 2");
|
||||||
|
responder.Should().Contain("systemctl restart flowercore-divoom-tv.service");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void TvPuppetProfile_InstallsCageAndStaticArtifacts()
|
||||||
|
{
|
||||||
|
var profile = ReadTv("puppet/profile/pi/service/divoom_tv.pp");
|
||||||
|
|
||||||
|
profile.Should().Contain("package { ['cage', 'libgbm1', 'libdrm2', 'libxkbcommon0', 'fonts-dejavu-core']");
|
||||||
|
profile.Should().Contain("'profile/pi/fc_divoom_tv/flowercore-divoom-tv.service'");
|
||||||
|
profile.Should().Contain("'profile/pi/fc_divoom_tv/flowercore-divoom-tv-launch.sh'");
|
||||||
|
profile.Should().Contain("profile/pi/fc_divoom_tv/99-flowercore-divoom-tv-hdmi.rules");
|
||||||
|
profile.Should().Contain("Boolean $service_enabled = false");
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void DivoomArtifacts_DoNotAddKubernetesWorkloads()
|
||||||
|
{
|
||||||
|
var allText = Directory.GetFiles(DmRoot, "*", SearchOption.AllDirectories)
|
||||||
|
.Concat(Directory.GetFiles(TvRoot, "*", SearchOption.AllDirectories))
|
||||||
|
.Select(File.ReadAllText);
|
||||||
|
|
||||||
|
foreach (var text in allText)
|
||||||
|
{
|
||||||
|
text.Should().NotContain("kind: Deployment");
|
||||||
|
text.Should().NotContain("kind: IngressRoute");
|
||||||
|
text.Should().NotContain("kind: Certificate");
|
||||||
|
text.Should().NotContain("kind: OnePasswordItem");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string ReadDm(string relativePath)
|
||||||
|
=> File.ReadAllText(Path.Combine(DmRoot, relativePath.Replace('/', Path.DirectorySeparatorChar)));
|
||||||
|
|
||||||
|
private static string ReadTv(string relativePath)
|
||||||
|
=> File.ReadAllText(Path.Combine(TvRoot, relativePath.Replace('/', Path.DirectorySeparatorChar)));
|
||||||
|
|
||||||
|
private static string FindRepoRoot()
|
||||||
|
{
|
||||||
|
var current = new DirectoryInfo(AppContext.BaseDirectory);
|
||||||
|
while (current is not null)
|
||||||
|
{
|
||||||
|
if (Directory.Exists(Path.Combine(current.FullName, "apps"))
|
||||||
|
&& File.Exists(Path.Combine(current.FullName, "README.md")))
|
||||||
|
{
|
||||||
|
return current.FullName;
|
||||||
|
}
|
||||||
|
|
||||||
|
current = current.Parent;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new DirectoryNotFoundException("Could not find bluejay-infra root.");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -67,6 +67,7 @@ public sealed class FleetManifestLintTests
|
|||||||
["github-runner-chat"] = "https://github.com/astoltz/FlowerCore.Chat",
|
["github-runner-chat"] = "https://github.com/astoltz/FlowerCore.Chat",
|
||||||
["github-runner-mysql"] = "https://github.com/astoltz/FlowerCore.MySQL",
|
["github-runner-mysql"] = "https://github.com/astoltz/FlowerCore.MySQL",
|
||||||
["github-runner-kiosk-linux"] = "https://github.com/astoltz/FlowerCore.Kiosk.Linux",
|
["github-runner-kiosk-linux"] = "https://github.com/astoltz/FlowerCore.Kiosk.Linux",
|
||||||
|
["github-runner-updater"] = "https://github.com/astoltz/FlowerCore.Updater",
|
||||||
};
|
};
|
||||||
|
|
||||||
private static readonly HashSet<string> ScaledLinuxRunnerDeployments = new(StringComparer.Ordinal)
|
private static readonly HashSet<string> ScaledLinuxRunnerDeployments = new(StringComparer.Ordinal)
|
||||||
@@ -80,6 +81,7 @@ public sealed class FleetManifestLintTests
|
|||||||
"github-runner-chat",
|
"github-runner-chat",
|
||||||
"github-runner-mysql",
|
"github-runner-mysql",
|
||||||
"github-runner-kiosk-linux",
|
"github-runner-kiosk-linux",
|
||||||
|
"github-runner-updater",
|
||||||
};
|
};
|
||||||
|
|
||||||
private static readonly IReadOnlyDictionary<string, string> WritableRunnerEnv = new Dictionary<string, string>(StringComparer.Ordinal)
|
private static readonly IReadOnlyDictionary<string, string> WritableRunnerEnv = new Dictionary<string, string>(StringComparer.Ordinal)
|
||||||
@@ -234,7 +236,7 @@ public sealed class FleetManifestLintTests
|
|||||||
{
|
{
|
||||||
deployments.Should().ContainKey(expectedRunner.Key);
|
deployments.Should().ContainKey(expectedRunner.Key);
|
||||||
|
|
||||||
var container = deployments[expectedRunner.Key].ContainerMappings().Should().ContainSingle().Subject;
|
var container = deployments[expectedRunner.Key].MainContainerMappings().Should().ContainSingle().Subject;
|
||||||
EnvValue(container, "REPO_URL").Should().Be(expectedRunner.Value);
|
EnvValue(container, "REPO_URL").Should().Be(expectedRunner.Value);
|
||||||
EnvValue(container, "EPHEMERAL").Should().Be("true");
|
EnvValue(container, "EPHEMERAL").Should().Be("true");
|
||||||
EnvValue(container, "LABELS").Should().Be("self-hosted,linux,fc-build-linux");
|
EnvValue(container, "LABELS").Should().Be("self-hosted,linux,fc-build-linux");
|
||||||
@@ -250,7 +252,7 @@ public sealed class FleetManifestLintTests
|
|||||||
{
|
{
|
||||||
foreach (var deployment in GitHubRunnerDeployments().Values)
|
foreach (var deployment in GitHubRunnerDeployments().Values)
|
||||||
{
|
{
|
||||||
var container = deployment.ContainerMappings().Should().ContainSingle().Subject;
|
var container = deployment.MainContainerMappings().Should().ContainSingle().Subject;
|
||||||
|
|
||||||
foreach (var expectedEnv in WritableRunnerEnv)
|
foreach (var expectedEnv in WritableRunnerEnv)
|
||||||
{
|
{
|
||||||
@@ -277,7 +279,10 @@ public sealed class FleetManifestLintTests
|
|||||||
foreach (var deploymentName in ScaledLinuxRunnerDeployments)
|
foreach (var deploymentName in ScaledLinuxRunnerDeployments)
|
||||||
{
|
{
|
||||||
var deployment = deployments[deploymentName];
|
var deployment = deployments[deploymentName];
|
||||||
ReplicaCount(deployment).Should().Be(2);
|
// Scaled runners must have >= 2 replicas (avoid single-pod bottleneck).
|
||||||
|
// Individual deployments may be tuned upward per CI activity — see
|
||||||
|
// "runners: right-size replica counts per 14d CI activity (#24)".
|
||||||
|
ReplicaCount(deployment).Should().BeGreaterOrEqualTo(2, $"{deploymentName} is in the scaled set and must run with at least 2 replicas");
|
||||||
|
|
||||||
var volumes = deployment.MappingSequence("spec", "template", "spec", "volumes");
|
var volumes = deployment.MappingSequence("spec", "template", "spec", "volumes");
|
||||||
var claimNames = volumes
|
var claimNames = volumes
|
||||||
@@ -303,6 +308,108 @@ public sealed class FleetManifestLintTests
|
|||||||
.Be("github-runner-nuget-cache");
|
.Be("github-runner-nuget-cache");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void Runners_MustNotPinToOperatorWorkstationHosts()
|
||||||
|
{
|
||||||
|
// CRITICAL SAFETY (operator directive 2026-05-26): BLUEJAY-WS is the
|
||||||
|
// operator's primary workstation — host of the 1Password Connect
|
||||||
|
// bearer token, fcadmin SSH keys to noc1, signing CA private keys,
|
||||||
|
// and source for every FC repo. A self-hosted GitHub Actions runner
|
||||||
|
// there would execute arbitrary PR code with that local access.
|
||||||
|
// Build-side analog of the Sprint 9 NEW safe-account exclusion gate
|
||||||
|
// (Puppet GPO/AppLocker/WDAC/audit-forwarder modules refuse to apply
|
||||||
|
// on BLUEJAY-WS). This lint asserts no GitHub-runner Deployment in
|
||||||
|
// apps/github-runner/ pins to a forbidden operator-workstation host
|
||||||
|
// via nodeName, nodeSelector, nodeAffinity, or tolerations.
|
||||||
|
// Existing legacy `bluejay-ws-sandbox-1` GitHub-registered runner is
|
||||||
|
// out of scope here (it's a runtime registration, not a K8s
|
||||||
|
// Deployment) — see CLAUDE.md "Common Mistakes" entry and
|
||||||
|
// feedback_bluejay_ws_never_public_runner.md.
|
||||||
|
var forbiddenHostPatterns = new[]
|
||||||
|
{
|
||||||
|
"bluejay-ws",
|
||||||
|
"BLUEJAY-WS",
|
||||||
|
"bluejay-ws.iamworkin.lan",
|
||||||
|
"iamworkin-ws",
|
||||||
|
};
|
||||||
|
|
||||||
|
bool ContainsForbidden(string? value) =>
|
||||||
|
!string.IsNullOrWhiteSpace(value)
|
||||||
|
&& forbiddenHostPatterns.Any(pattern => value!.Contains(pattern, StringComparison.OrdinalIgnoreCase));
|
||||||
|
|
||||||
|
var violations = GitHubRunnerDeployments().Values.SelectMany(deployment =>
|
||||||
|
{
|
||||||
|
var local = new List<string>();
|
||||||
|
var podSpec = ManifestNodeExtensions.Mapping(deployment.Root, "spec", "template", "spec");
|
||||||
|
if (podSpec is null)
|
||||||
|
{
|
||||||
|
return local;
|
||||||
|
}
|
||||||
|
|
||||||
|
// nodeName: pins the pod to a specific node by name.
|
||||||
|
var nodeName = ManifestNodeExtensions.Scalar(podSpec, "nodeName");
|
||||||
|
if (ContainsForbidden(nodeName))
|
||||||
|
{
|
||||||
|
local.Add($"{deployment.Name} sets nodeName='{nodeName}' which targets a forbidden operator-workstation host.");
|
||||||
|
}
|
||||||
|
|
||||||
|
// nodeSelector: dict of label → value pinning the pod to nodes
|
||||||
|
// carrying matching labels. Examples that would trip this:
|
||||||
|
// kubernetes.io/hostname: bluejay-ws
|
||||||
|
// flowercore.io/host: bluejay-ws.iamworkin.lan
|
||||||
|
var nodeSelector = ManifestNodeExtensions.Mapping(podSpec, "nodeSelector");
|
||||||
|
if (nodeSelector is not null)
|
||||||
|
{
|
||||||
|
foreach (var entry in nodeSelector.Children)
|
||||||
|
{
|
||||||
|
var key = entry.Key is YamlScalarNode keyScalar ? keyScalar.Value : null;
|
||||||
|
var value = entry.Value is YamlScalarNode valueScalar ? valueScalar.Value : null;
|
||||||
|
if (ContainsForbidden(value))
|
||||||
|
{
|
||||||
|
local.Add($"{deployment.Name} has nodeSelector entry '{key}: {value}' which targets a forbidden operator-workstation host.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// nodeAffinity: matchExpressions over node labels.
|
||||||
|
foreach (var term in ManifestNodeExtensions.MappingSequence(podSpec, "affinity", "nodeAffinity", "requiredDuringSchedulingIgnoredDuringExecution", "nodeSelectorTerms"))
|
||||||
|
{
|
||||||
|
foreach (var expr in ManifestNodeExtensions.MappingSequence(term, "matchExpressions"))
|
||||||
|
{
|
||||||
|
var key = ManifestNodeExtensions.Scalar(expr, "key");
|
||||||
|
foreach (var valueNode in ManifestNodeExtensions.ScalarSequence(expr, "values"))
|
||||||
|
{
|
||||||
|
if (ContainsForbidden(valueNode))
|
||||||
|
{
|
||||||
|
local.Add($"{deployment.Name} has nodeAffinity matchExpression '{key}' value '{valueNode}' which targets a forbidden operator-workstation host.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// tolerations: scheduling onto a tainted operator-workstation
|
||||||
|
// node would let the runner run there. Forbid any toleration
|
||||||
|
// value that names the workstation.
|
||||||
|
foreach (var toleration in ManifestNodeExtensions.MappingSequence(podSpec, "tolerations"))
|
||||||
|
{
|
||||||
|
var key = ManifestNodeExtensions.Scalar(toleration, "key");
|
||||||
|
var value = ManifestNodeExtensions.Scalar(toleration, "value");
|
||||||
|
if (ContainsForbidden(key))
|
||||||
|
{
|
||||||
|
local.Add($"{deployment.Name} has toleration key '{key}' which targets a forbidden operator-workstation host.");
|
||||||
|
}
|
||||||
|
if (ContainsForbidden(value))
|
||||||
|
{
|
||||||
|
local.Add($"{deployment.Name} has toleration value '{value}' which targets a forbidden operator-workstation host.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return local;
|
||||||
|
}).ToList();
|
||||||
|
|
||||||
|
violations.Should().BeEmpty("BLUEJAY-WS / iamworkin-ws must never host a fleet GitHub Actions runner; see CLAUDE.md 'Registering BLUEJAY-WS as a fleet GitHub Actions runner' and feedback_bluejay_ws_never_public_runner.md");
|
||||||
|
}
|
||||||
|
|
||||||
[Fact]
|
[Fact]
|
||||||
public void Monitoring_MustAlertWhenLinuxRunnerDeploymentIsUnavailable()
|
public void Monitoring_MustAlertWhenLinuxRunnerDeploymentIsUnavailable()
|
||||||
{
|
{
|
||||||
@@ -890,6 +997,22 @@ internal sealed record ManifestDocument(
|
|||||||
.ToList();
|
.ToList();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// MainContainerMappings excludes initContainers. Use this when asserting
|
||||||
|
// properties of the primary container (env, image, volumeMounts) where an
|
||||||
|
// initContainer would be a false-positive match — e.g. the GitHub runner
|
||||||
|
// image's `setup-runner-home` initContainer should not count toward the
|
||||||
|
// single-container assertions on the runner deployments.
|
||||||
|
public IReadOnlyList<YamlMappingNode> MainContainerMappings()
|
||||||
|
{
|
||||||
|
var podSpec = PodSpec();
|
||||||
|
if (podSpec is null)
|
||||||
|
{
|
||||||
|
return Array.Empty<YamlMappingNode>();
|
||||||
|
}
|
||||||
|
|
||||||
|
return ManifestNodeExtensions.MappingSequence(podSpec, "containers").ToList();
|
||||||
|
}
|
||||||
|
|
||||||
public IReadOnlyList<ContainerSpec> ContainerSpecs()
|
public IReadOnlyList<ContainerSpec> ContainerSpecs()
|
||||||
{
|
{
|
||||||
return ContainerMappings()
|
return ContainerMappings()
|
||||||
|
|||||||
Reference in New Issue
Block a user