Skip to content

ci: make Woodpecker + Dagger the portable validation lane - #156

Draft
dporkka wants to merge 10 commits into
mainfrom
ci/woodpecker-dagger-v1
Draft

dporkka wants to merge 10 commits into
mainfrom
ci/woodpecker-dagger-v1

Conversation

@dporkka

@dporkka dporkka commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Purpose

Add a clean, CI-only Woodpecker + Dagger validation path to Dev Plane without coupling it to the forge/Gitea feature stack.

This branch is based directly on main and changes only three additive CI files. It is intended to become the reusable CI substrate that #149-#153 and other stacked work can qualify against once the repository is activated in Woodpecker and the operator-owned Dagger Engine is deployed.

Authority model

  • Forge selects the immutable source revision.
  • Woodpecker supplies webhook-driven scheduling, exact checkout, status reporting, and owned compute.
  • Operator-owned Dagger Engine supplies the privileged execution substrate outside PR-controlled workflow configuration.
  • Dagger contract supplies the portable pinned execution environment.
  • Make/npm remain the repository verification semantics.

Woodpecker checks git rev-parse HEAD == CI_COMMIT_SHA before invoking Dagger, so a successful pipeline is evidence for the exact forge-selected revision.

Security boundary

PR-controlled workflow code does not receive /var/run/docker.sock and contains no host volume mounts. The workflow explicitly fails if the host Docker socket is visible.

The Dagger Engine endpoint must be injected by the Woodpecker control plane through _EXPERIMENTAL_DAGGER_RUNNER_HOST. Nulang Cloud #827 defines the operator-owned engine on the dedicated CI node and exposes it only through the private woodpecker-ci-execution network.

The privileged engine is therefore contained by the dedicated/disposable CI host/VM rather than by a repository-controlled step container. It must not be colocated with tenant or production Firecracker workloads.

Dagger contract

.dagger/ci/verify.dag preserves the repository CI contract:

  • Node 24
  • Go 1.26.8
  • golangci-lint v2.13.2
  • NATS 2.10 + JetStream during tests
  • make lint-go
  • web lint + typecheck
  • TypeScript SDK typecheck
  • make test
  • web tests
  • make build
  • git diff --check over the committed PR range (or latest main commit)

The Go 1.26.8 Linux/amd64 archive is SHA-256 verified before extraction.

Woodpecker adapter

.woodpecker/dagger.yml:

  • targets pool: bootstrap-ci;
  • verifies the exact checked-out SHA;
  • requires the operator-injected Dagger runner endpoint;
  • refuses a host Docker socket;
  • downloads Dagger CLI v0.20.3 and verifies its release SHA-256 before extraction;
  • invokes the same Dagger contract for pull requests, main pushes, and explicit manual runs.

Why this supersedes the direction of #136

#136 established the right owned Woodpecker fallback, but duplicates the GitHub workflow command sequencing directly inside Woodpecker. This PR keeps Woodpecker thin and moves toolchain/environment orchestration behind Dagger so local execution and future schedulers can use the same verification contract.

Do not close #136 until this lane receives real Woodpecker execution evidence.

Dependencies

  • Nulang Cloud #826 is merged and provides deterministic Dev Plane Woodpecker activation/webhook repair.
  • Nulang Cloud #827 provides the operator-owned Dagger Engine/network required by this workflow.

Qualification sequence

  1. qualify and deploy Nulang Cloud #827 on the dedicated CI host;
  2. activate/repair dporkka/dev-plane using the merged ensure-repository.sh operator helper;
  3. push a no-source-change synchronize commit to this PR;
  4. require a ci/woodpecker/pr/dagger status (or the workflow's generated equivalent) for the exact head;
  5. require the Dagger lane to reach a terminal source-validation result.

This PR remains draft until a real bootstrap-ci Woodpecker job executes Dagger on its exact head. GitHub Actions jobs that fail with runner_id=0 and no executed steps remain non-authoritative infrastructure failures.

dporkka commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Qualification status — 2026-10-06

Current exact head after a no-source-change synchronize is d436e1ee91dd4581b0731253fe36bf4ea266b625.

Control-plane diagnosis:

  • dporkka/nulang-cloud #827 head received a successful Woodpecker control-plane status from ci.adacavo.com, proving the shared Woodpecker server/status path is alive.
  • This PR's prior GitHub Actions run was non-authoritative infrastructure failure: Lint/Test/Build all had runner_id=0, zero steps, and never executed source checks.
  • The new d436e1ee... head currently has no Woodpecker commit status and no GitHub workflow run.

Therefore the blocker remains Dev Plane repository activation/webhook registration, above .woodpecker/dagger.yml and above Dagger execution.

Required next evidence is operator-side deploy/woodpecker/reconcile.sh followed by ensure-repository.sh dporkka/dev-plane with forge remote ID 1261474989, then one more synchronize event. Do not diagnose or modify the Dagger contract until a Woodpecker status appears on the exact head.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant