You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Define Git-authored desired state for fleet controllers and capacity #32
Make reviewed Git configuration the authoritative desired state for worker-controller machines, while keeping credentials, addresses, and runtime state outside Git.
A new or existing Linux Docker host must be able to converge from a pinned configuration revision with one repository-owned Bash command. Application repositories describe jobs and shards; infrastructure configuration alone controls available worker capacity.
Public contract
Define a versioned, implementation-independent configuration model using fictional values such as example-org, example-repo, and example-ci-01.
The model must cover:
logical runner pools, routing labels, runner-group policy, and allowed repositories;
a pool-level capacity budget;
controller instances with unique logical IDs, assigned pool, enabled/drained state, minimum and maximum runners, and per-runner resource limits;
validation that aggregate enabled controller capacity cannot exceed its pool budget;
lifecycle channel or pinned engine revision;
no host addresses, VM IDs, credentials, private keys, tokens, or secret values.
Application workflows must not cap parallelism according to fleet size. They should submit all independent jobs; controllers and private infrastructure policy provide the capacity. Document only narrowly scoped exceptions for a real external-service concurrency limit.
Installer and convergence
Extend the host-installer work in #21 so an operator can run a command equivalent to:
The same command must support a fresh VM or bare-metal host and safe adoption of an existing controller. It must validate the pinned desired state, render host-local runtime configuration, preserve root-owned secrets, drain before disruptive changes, create or verify a recoverable checkpoint, install maintenance timers, verify health, detect drift, and emit a redacted final report.
The target host must perform the work directly. OpenClaw or another agent may run the command but is not a required component. GitHub approval steps must remain phone-friendly as described in #27.
Set-and-forget operation
Specify how a host detects and applies reviewed desired-state changes without following an unreviewed moving branch. If automatic convergence reads a private configuration repository, use a narrowly scoped identity with read-only contents permission for that repository. Never expose that identity to runner jobs.
A failed validation, drain, checkpoint, upgrade, or health check must leave or restore the last known-good controller.
Host retirement
Document a drain-and-retire workflow. Once legacy project-specific runners are no longer referenced by CI, promotion, or deployment, they should be unregistered, have scoped fleet-owned resources removed, have credentials revoked, and then be deleted or repurposed according to the operator's declared policy. No application workflow should require edits when one generic controller is replaced.
Acceptance
Public schema/specification and fictional examples exist.
The public configuration template implements the same version.
The installer consumes a pinned desired-state revision and supports existing-host adoption.
Ownership handoff: PR #33 is OPEN and mergeable at 61b9728eda98c70db93f2254c2dc5a955a1774b7. The public schema-v3 desired-state contract, strict validation/rendering, and transactional controller install/adopt/upgrade/rollback/uninstall lifecycle are implemented. The exact head passed Build without registering a runner and isolated Docker validation of both images, runner tools, scoped dry-run cleanup, and secret scanning. Codex reviewed the final head and opened four new unresolved P2 threads; those findings are not yet reacted to or fixed, so the PR must not merge as-is. Private delivery-configuration work remains local and incomplete. No live controller, runner, runner-group, or settings mutation occurred, and the downstream consumer application cutover has not started. PR #33 and issue #32 should now be owned by the ci-fleet project manager. This handoff task closed or merged neither the issue nor the PR.
Goal
Make reviewed Git configuration the authoritative desired state for worker-controller machines, while keeping credentials, addresses, and runtime state outside Git.
A new or existing Linux Docker host must be able to converge from a pinned configuration revision with one repository-owned Bash command. Application repositories describe jobs and shards; infrastructure configuration alone controls available worker capacity.
Public contract
Define a versioned, implementation-independent configuration model using fictional values such as
example-org,example-repo, andexample-ci-01.The model must cover:
Application workflows must not cap parallelism according to fleet size. They should submit all independent jobs; controllers and private infrastructure policy provide the capacity. Document only narrowly scoped exceptions for a real external-service concurrency limit.
Installer and convergence
Extend the host-installer work in #21 so an operator can run a command equivalent to:
Required modes:
--check--install--adopt--upgrade--rollback--uninstallThe same command must support a fresh VM or bare-metal host and safe adoption of an existing controller. It must validate the pinned desired state, render host-local runtime configuration, preserve root-owned secrets, drain before disruptive changes, create or verify a recoverable checkpoint, install maintenance timers, verify health, detect drift, and emit a redacted final report.
The target host must perform the work directly. OpenClaw or another agent may run the command but is not a required component. GitHub approval steps must remain phone-friendly as described in #27.
Set-and-forget operation
Specify how a host detects and applies reviewed desired-state changes without following an unreviewed moving branch. If automatic convergence reads a private configuration repository, use a narrowly scoped identity with read-only contents permission for that repository. Never expose that identity to runner jobs.
A failed validation, drain, checkpoint, upgrade, or health check must leave or restore the last known-good controller.
Host retirement
Document a drain-and-retire workflow. Once legacy project-specific runners are no longer referenced by CI, promotion, or deployment, they should be unregistered, have scoped fleet-owned resources removed, have credentials revoked, and then be deleted or repurposed according to the operator's declared policy. No application workflow should require edits when one generic controller is replaced.
Acceptance