diff --git a/docs/handover.md b/docs/handover.md index 753f511..717fdfa 100644 --- a/docs/handover.md +++ b/docs/handover.md @@ -174,9 +174,17 @@ course, not a position in a window. CI against the target database" is still aspirational. - The fixture-drift CI jobs need `FRONTEND_REPO_TOKEN` to see the sibling repo, and fail rather than pass quietly without it. -- The remote is Gitea. These are GitHub Actions workflows; they do nothing until - a compatible runner exists. Nobody has confirmed a runner exists, so treat - both repositories as having no CI until somebody checks. +- The remote is Gitea and the workflows are GitHub Actions syntax. Gitea Actions + runs them, and a runner now exists: `gitea-runner` (gitea/act_runner v0.6.1) + on the cluster host, registered as `krow-runner` with labels + `ubuntu-latest, ubuntu-22.04` mapped to `node:20-bookworm`. Before that, both + repositories had workflows that had never executed once — the 924 frontend + checks, the whole Go suite, the skip guard and the suite-shrank guard were + all things somebody had to remember to run. + + If a job fails resolving `actions/checkout` or `actions/setup-node`, the + runner needs egress to github.com or a mirror; that is where those actions + come from and Gitea does not host them. - **The application talks to its database in clear text.** `DATABASE_SSLMODE= disable` against `66.116.207.225`, which is a DIFFERENT machine from the cluster host — so credentials and every row cross the network unencrypted.