Static analysis findings never fail a build, so nothing has ever pulled them into triage. There are 139 open on Ariadne alone, each already naming its file, line and rule - better-located evidence than the console text the code-repair flow usually mines. Scoped deliberately narrow to start: one project, one proposal per hourly sweep, and only findings SonarQube itself estimates at 20 minutes or less. Effort is the filter rather than severity because it is the closest proxy for the single anchored change the patch validator can actually check. The 64-open-proposal ceiling still applies on top, so the queue cannot grow while nobody is draining it. Hotspots are not in the type list and cannot be: SonarQube models them as needing human review, this instance's quality gate fails on exactly that condition, and an automation that resolved them would be marking them reviewed without review. The token comes from Vault. Ariadne's maintenance role was granted read on kv/data/atlas/quality/sonarqube-oidc, which it did not previously have. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
titan-iac
Flux-managed Kubernetes desired-state config for bstein.dev.
Canonical source URL:
ssh://git@scm.bstein.dev:2242/bstein/titan-iac.git
Scope
This repo contains cluster configuration consumed by Flux:
- platform/infrastructure manifests
- service manifests and kustomizations
- operational scripts for render/reconcile workflows
Apply model
I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.
Description
Languages
Python
60.2%
Shell
30.6%
Mermaid
6.8%
HCL
1.2%
Groovy
0.5%
Other
0.7%