Repository navigation
Conversation
This was referenced Oct 5, 2026
Owner
Author
Qualification status — 2026-10-06Current exact head after a no-source-change synchronize is Control-plane diagnosis:
Therefore the blocker remains Dev Plane repository activation/webhook registration, above Required next evidence is operator-side |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Add a clean, CI-only Woodpecker + Dagger validation path to Dev Plane without coupling it to the forge/Gitea feature stack.
This branch is based directly on
mainand changes only three additive CI files. It is intended to become the reusable CI substrate that #149-#153 and other stacked work can qualify against once the repository is activated in Woodpecker and the operator-owned Dagger Engine is deployed.Authority model
Woodpecker checks
git rev-parse HEAD == CI_COMMIT_SHAbefore invoking Dagger, so a successful pipeline is evidence for the exact forge-selected revision.Security boundary
PR-controlled workflow code does not receive
/var/run/docker.sockand contains no host volume mounts. The workflow explicitly fails if the host Docker socket is visible.The Dagger Engine endpoint must be injected by the Woodpecker control plane through
_EXPERIMENTAL_DAGGER_RUNNER_HOST. Nulang Cloud #827 defines the operator-owned engine on the dedicated CI node and exposes it only through the privatewoodpecker-ci-executionnetwork.The privileged engine is therefore contained by the dedicated/disposable CI host/VM rather than by a repository-controlled step container. It must not be colocated with tenant or production Firecracker workloads.
Dagger contract
.dagger/ci/verify.dagpreserves the repository CI contract:make lint-gomake testmake buildgit diff --checkover the committed PR range (or latest main commit)The Go 1.26.8 Linux/amd64 archive is SHA-256 verified before extraction.
Woodpecker adapter
.woodpecker/dagger.yml:pool: bootstrap-ci;Why this supersedes the direction of #136
#136 established the right owned Woodpecker fallback, but duplicates the GitHub workflow command sequencing directly inside Woodpecker. This PR keeps Woodpecker thin and moves toolchain/environment orchestration behind Dagger so local execution and future schedulers can use the same verification contract.
Do not close #136 until this lane receives real Woodpecker execution evidence.
Dependencies
Qualification sequence
dporkka/dev-planeusing the mergedensure-repository.shoperator helper;ci/woodpecker/pr/daggerstatus (or the workflow's generated equivalent) for the exact head;This PR remains draft until a real
bootstrap-ciWoodpecker job executes Dagger on its exact head. GitHub Actions jobs that fail withrunner_id=0and no executed steps remain non-authoritative infrastructure failures.