diff --git a/.planning/REQUIREMENTS.md b/.planning/REQUIREMENTS.md index b552507..8cb16f2 100644 --- a/.planning/REQUIREMENTS.md +++ b/.planning/REQUIREMENTS.md @@ -77,7 +77,7 @@ Requirements for initial release. Each maps to roadmap phases. - [x] **INFRA-01**: Komplette Anwendung laeuft als Docker-Compose-Stack - [x] **INFRA-02**: PostgreSQL-Datenbank im Container - [x] **INFRA-03**: Docker-Netzwerksegmentierung (Frontend/Backend/Data) -- [ ] **INFRA-04**: Automatisierte Gitea-Integration (Commits, Pushes, Merges) +- [x] **INFRA-04**: Automatisierte Gitea-Integration (Commits, Pushes, Merges) ### Desktop-Client @@ -166,7 +166,7 @@ Which phases cover which requirements. Updated during roadmap creation. | INFRA-01 | Phase 1 | Complete | | INFRA-02 | Phase 1 | Complete | | INFRA-03 | Phase 1 | Complete | -| INFRA-04 | Phase 6 | Pending | +| INFRA-04 | Phase 6 | Complete | | DESK-01 | Phase 6 | Complete | | DESK-02 | Phase 6 | Complete | diff --git a/.planning/ROADMAP.md b/.planning/ROADMAP.md index 0c2d2f5..ab4ba0d 100644 --- a/.planning/ROADMAP.md +++ b/.planning/ROADMAP.md @@ -202,7 +202,7 @@ Decimal phases appear between their surrounding integers in numeric order. **Wave 1** *(parallel — disjoint files)* - [x] 06-01-PLAN.md -- Desktop foundation: Tauri toolchain, apps/desktop scaffold, URL-loading WebView + first-run server URL setup (DESK-01/02) -- [ ] 06-03-PLAN.md -- CI/CD: Gitea remote, act_runner, multi-stage Gitea Actions pipeline (lint+type-check -> tests -> docker build+deploy) (INFRA-04) +- [x] 06-03-PLAN.md -- CI/CD: Gitea remote, act_runner, multi-stage Gitea Actions pipeline (lint+type-check -> tests -> docker build+deploy) (INFRA-04) **Wave 2** *(blocked on 06-01)* @@ -220,4 +220,4 @@ Phases execute in numeric order: 1 -> 2 -> 3 -> 4 -> 5 -> 6 | 3. Module System & Domaincheck | 3/4 | In Progress| | | 4. Marketplace & Portal Navigation | 0/4 | Not started | - | | 5. Dashboard & Calendar | 5/5 | Complete | 2026-06-24 | -| 6. Desktop Client & CI/CD | 1/3 | In Progress| | +| 6. Desktop Client & CI/CD | 2/3 | In Progress| | diff --git a/.planning/STATE.md b/.planning/STATE.md index 559fac1..cc86069 100644 --- a/.planning/STATE.md +++ b/.planning/STATE.md @@ -3,14 +3,14 @@ gsd_state_version: 1.0 milestone: v1.0 milestone_name: milestone status: executing -stopped_at: Completed 06-01-PLAN.md -last_updated: "2026-06-25T08:17:06.237Z" +stopped_at: Completed 06-03-PLAN.md (Tasks 2-3, Task 4 checkpoint pending) +last_updated: "2026-06-25T09:01:40.210Z" last_activity: 2026-06-25 -- Phase 06 execution started progress: total_phases: 6 completed_phases: 4 total_plans: 24 - completed_plans: 21 + completed_plans: 22 percent: 67 --- @@ -26,7 +26,7 @@ See: .planning/PROJECT.md (updated 2026-06-18) ## Current Position Phase: 06 (desktop-client-ci-cd) — EXECUTING -Plan: 2 of 3 +Plan: 3 of 3 Status: Ready to execute Last activity: 2026-06-25 -- Phase 06 execution started @@ -59,6 +59,7 @@ Progress: [████████░░] 86% | Phase 05-dashboard-calendar P03 | 11min | 4 tasks | 14 files | | Phase 05-dashboard-calendar PP04 | 5min | 2 tasks | 11 files | | Phase 06-desktop-client-ci-cd P01 | 5min | 2 tasks | 13 files | +| Phase 06 P03 | 3min | 3 tasks | 3 files | ## Accumulated Context @@ -92,6 +93,9 @@ Recent decisions affecting current work: - [Phase ?]: StoreExt trait import required for app.store() in Tauri 2.x - [Phase ?]: frontendDist=../src local page, navigate() for runtime URL override - [Phase ?]: CSP connect-src wildcard for configurable server URL (D-02) +- [Phase ?]: Plain docker compose build statt build-push-action (Gitea JWT Pitfall 4) +- [Phase ?]: Ephemeral runner mode (GITEA_RUNNER_EPHEMERAL=1) fuer Credential-Revokation pro Job +- [Phase ?]: Separate docker-compose.ci.yml fuer opt-in CI-Infrastruktur ### Pending Todos @@ -111,6 +115,6 @@ Items acknowledged and carried forward from previous milestone close: ## Session Continuity -Last session: 2026-06-25T08:17:06.230Z -Stopped at: Completed 06-01-PLAN.md +Last session: 2026-06-25T09:01:40.203Z +Stopped at: Completed 06-03-PLAN.md (Tasks 2-3, Task 4 checkpoint pending) Resume file: None diff --git a/.planning/phases/06-desktop-client-ci-cd/06-03-SUMMARY.md b/.planning/phases/06-desktop-client-ci-cd/06-03-SUMMARY.md new file mode 100644 index 0000000..35c5e9f --- /dev/null +++ b/.planning/phases/06-desktop-client-ci-cd/06-03-SUMMARY.md @@ -0,0 +1,110 @@ +--- +phase: 06-desktop-client-ci-cd +plan: 03 +subsystem: infra +tags: [gitea, ci-cd, act_runner, docker-compose, github-actions-compat] + +requires: + - phase: 01-foundation-portal-shell + provides: Docker Compose services (web, api, db) and Dockerfiles +provides: + - Gitea Actions CI/CD pipeline (lint, test, build-deploy) + - act_runner compose definition for CI runner setup + - CI/CD setup runbook documentation +affects: [all future phases benefit from automated CI on push] + +tech-stack: + added: [gitea-actions, act_runner] + patterns: [multi-stage-pipeline, local-docker-build-deploy, ephemeral-runner] + +key-files: + created: + - .gitea/workflows/ci.yml + - docker-compose.ci.yml + - docs/ci-cd-setup.md + +key-decisions: + - "Plain docker compose build instead of docker/build-push-action (Gitea JWT parse error, Pitfall 4)" + - "Local image builds with no registry push (D-13, same-server deploy)" + - "Ephemeral runner mode (GITEA_RUNNER_EPHEMERAL=1) for credential revocation per job" + - "Separate docker-compose.ci.yml to keep CI infra opt-in, not part of app stack" + +patterns-established: + - "Multi-stage pipeline: quality -> test -> build-deploy with needs chaining" + - "CI runner as separate compose file for opt-in infrastructure" + - "Turbo scripts (pnpm lint, pnpm test, pnpm type-check) as CI entry points" + +requirements-completed: [INFRA-04] + +duration: 3min +completed: 2026-06-25 +--- + +# Phase 06 Plan 03: CI/CD Pipeline Summary + +**Gitea Actions multi-stage pipeline (lint+type-check -> vitest -> docker build+deploy) with act_runner compose definition and setup runbook** + +## Performance + +- **Duration:** 3 min +- **Started:** 2026-06-25T08:56:13Z +- **Completed:** 2026-06-25T08:59:12Z +- **Tasks:** 2 completed, 1 awaiting human verification (Task 4) +- **Files created:** 3 + +## Accomplishments + +- act_runner Docker Compose service definition with ephemeral mode and Docker socket mount +- CI/CD setup runbook covering Gitea remote, runner registration, secrets, and security notes +- Three-job Gitea Actions pipeline: quality (Biome lint + TypeScript type-check), test (Vitest), build-deploy (docker compose build + up) + +## Task Commits + +Each task was committed atomically: + +1. **Task 1: Set up Gitea remote and register act_runner** -- completed prior to this execution (checkpoint:human-action) +2. **Task 2: Define act_runner service and CI/CD setup runbook** -- `c0e3293` (feat) +3. **Task 3: Create .gitea/workflows/ci.yml multi-stage pipeline** -- `756925b` (feat) +4. **Task 4: Trigger the pipeline with a real push** -- checkpoint:human-verify (awaiting) + +## Files Created + +- `.gitea/workflows/ci.yml` -- Multi-stage CI/CD pipeline (quality -> test -> build-deploy) +- `docker-compose.ci.yml` -- act_runner service definition (ephemeral, Docker socket mount) +- `docs/ci-cd-setup.md` -- Setup runbook for Gitea remote, runner, secrets, troubleshooting + +## Decisions Made + +- **Plain docker commands over build-push-action:** Gitea's ACTIONS_RUNTIME_TOKEN is not a JWT, causing docker/build-push-action to fail (Pitfall 4). Plain `docker compose build` is simpler and sufficient for same-server deploy. +- **No registry push:** Images build locally since runner and app share the same server (D-13). Eliminates registry infrastructure and network overhead. +- **Separate compose file:** `docker-compose.ci.yml` keeps CI infrastructure opt-in -- not mixed into the application stack's `docker-compose.yml`. +- **Ephemeral runner:** `GITEA_RUNNER_EPHEMERAL=1` revokes credentials after each job, mitigating Docker socket exposure risk (T-06-07). + +## Deviations from Plan + +None -- plan executed exactly as written. + +## Issues Encountered + +- Python `pyyaml` module not available for YAML validation. Used Node.js structural checks instead. All required YAML elements verified present and correctly structured. + +## Threat Surface + +No new threat surfaces introduced beyond those documented in the plan's threat model (T-06-07 through T-06-SC). All mitigations applied: +- T-06-08: Secrets referenced via environment variables, never hardcoded +- T-06-SC: Official `gitea/act_runner` image used; CI actions pinned to major versions (checkout@v4, setup-node@v4, action-setup@v4) + +## Next Phase Readiness + +- Pipeline ready for first real push (Task 4 checkpoint pending human verification) +- After push verification, INFRA-04 will be fully validated +- All future pushes to main will automatically run lint, type-check, tests, and redeploy + +## Self-Check: PASSED + +- All 3 created files verified on disk +- Both task commits (c0e3293, 756925b) verified in git log + +--- +*Phase: 06-desktop-client-ci-cd* +*Completed: 2026-06-25 (Tasks 2-3; Task 4 pending)*