Files
homelab/.gitea/EDU_HANDOFF.md
T
forust f767f3ce1a
ci / Compose (push) Skipped
ci / Workflows (push) Skipped
ci / Shell (push) Skipped
ci / Formatting (push) Skipped
ci / Kubernetes (push) Skipped
ci / Compose (pull_request) Successful in 11s
ci / Shell (pull_request) Successful in 15s
ci / Python and tests (push) Skipped
ci / YAML (push) Skipped
ci / Dockerfiles (push) Skipped
ci / Workflows (pull_request) Successful in 6s
ci / Formatting (pull_request) Successful in 16s
ci / Python and tests (pull_request) Successful in 6s
ci / YAML (pull_request) Successful in 7s
ci / Dockerfiles (pull_request) Successful in 5s
ci / build (pull_request) Skipped
ci / Kubernetes (pull_request) Successful in 6s
ci / image-plan (pull_request) Skipped
ci / Image (${{ matrix.name }}) (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 9s
docs: update EDU handoff status
2026-10-07 10:25:17 +02:00

4.9 KiB

EDU ownership handoff

Current status

EDU PR #1 merged at 2026-10-07 08:04:30 UTC. Main release 5094952464ce315130839303985fd04d721bc1f2 passed CI run 1585 and deploy run 1586. The workstation checkout /srv/edu-master is at that SHA. The release changed the application image digests:

  • Session keeper: sha256:1e59473bd40fe4c22622017d808a8927a68788275fe073dc23d718c44b2fd5dd
  • Webinar checker: sha256:987d9bf0770272766523ea5b94c7f3f849175d737551d46591ae55e058cf9f12

The live workloads remain healthy in context Default, namespace edu-master. Both health and live probes return 200. Redis AUTH passes, session TTL is 1178 seconds, the delivery backlog is zero, all nine EDU alert rules are healthy, and the scrape target is UP. The unauthorized-pod Redis check passed. The Redis PVC UID and Secret UID and values, including the Fernet key, match their pre-release state.

The homelab EDU active marker was present after the EDU deployment. It was moved to the private snapshot as homelab-k8s-active.marker while holding /tmp/homelab-apply.lock. The homelab checkout at /srv/homelab is at 5f9354b and has the tracked marker deletion. Its deploy preflight blocks a dirty checkout until this removal is reconciled. Preserve private ignored configuration when syncing that checkout.

The remaining homelab change is PR #105, branch feat/edu-handoff-matrix, based on codex/ci-visible-checks. Its eight protected checks passed. Renovate runs 1587 and 1588 passed. Image publishing was skipped for the PR. The EDU runtime changes are in PR #3 from fix/handoff-runtime to main; CI run 1589 is in progress. Those runtime changes have not been released.

Approval gate and next steps

PR #99 must merge before PR #105 can target main. A merge attempt for PR #99 returned HTTP 405 because it needs one approval; the protected branch has required_approvals=1 and whitelist approval is enabled. This approval gate prevents the remaining transfer steps.

After the required approval:

  1. Merge PR #99.
  2. Retarget PR #105 to main. Complete CI and review, then approve and merge it.
  3. Under the homelab apply lock, sync /srv/homelab to the merged removal. Preserve private ignored configuration and keep the active marker removed. Confirm the deploy preflight is clean.
  4. Merge the EDU runtime PR after its CI and review pass. The main-push CI run must complete successfully before its exact SHA can deploy.
  5. Verify the new release SHA, image digests, workload health, Redis AUTH and TTL, backlog, PVC and Secret identity, and monitoring. Record the results in the EDU PR.

AUTODEPLOY=false is explicitly configured. The EDU repository path and port secrets are confirmed, and EDU_KUBE_CONTEXT=Default is configured as a repository variable. Keep deployment and registry credentials outside Git. Never run both homelab and EDU deployment paths at the same time.

Change summary

The homelab PR removes the EDU subtree, deployment and image selection, rollback and verification cases, route probes, Renovate references, and external-image exceptions. It adds a serial dynamic matrix for the three homelab images. Each job builds an image or reuses a matching immutable digest. The final job checks all image results and publishes full-SHA tags and the existing release artifact only after they pass. PRs do not publish images. The protected check names from PR #99 are preserved. PR #100's service-metrics work is independent of this handoff.

The EDU runtime PR adds the Playwright service manifest, reconciles Redis storage and Secret reload annotations, and adds pre-apply Redis backup and identity checks. It verifies application endpoints, Redis AUTH, session TTL, metrics, and all nine vmalert rules. Rollback checks workload and application health and reports when manual recovery is needed. Its deployment guard rejects an unexpected or dirty checkout and refuses deployment while either legacy homelab EDU marker exists.

Rollback and limits

The private snapshot is /home/forust/.local/state/edu-master-deploy/handoff-20261007T080838Z on the workstation. It contains the pre-handoff Redis RDB and recovery data. RDB checksum verification confirmed twelve keys. Keep the snapshot outside Git. For an EDU release failure, restore the saved Kubernetes resources and inspect application health. The rollback does not automatically restore the Redis RDB; restore old Redis data only when recovery requires it.

For an ownership rollback, stop EDU deployment triggers first, restore the reviewed homelab source and marker, then reapply recorded immutable image digests. Verify both workload and application health. Never delete or recreate the Redis PVC.

The initial EDU release and the homelab marker move are complete. PR #99 approval and merge, PR #105 retarget and merge, homelab checkout reconciliation, EDU runtime PR merge, and release of those runtime changes remain pending. Synthetic Telegram delivery and Alertmanager-to-Telegram notification were not tested.