Resolve 8 conflicts, uniting #16's daemonless image-release lane with #14's SCM broker + node-audit boundary. Nothing dropped from either side. - quality_coverage.py / test_quality_coverage_helpers.py: take main's dual-metric gate (line+branch enforced per file at minimum_percent); drop #14's now-dead branch_tracked_files/minimum_branch_percent keys. - quality_contract.json: union all lists (managed_modules, lint_paths, coverage_sources, tracked_files, hygiene globs) so #14's scm-broker, git_pack_objects, receive_pack_scan, deadline_http and node_polkit_audit are branch-checked alongside #16's image-builder modules. - Vault auth (vault_k8s_auth_configure.sh): coexist both role sets. Keep #16's hermes-switchyard split + hermes-jenkins-token-seed; keep #14's hermes-scm-broker role. Preserve #14's security property: hermes-agent no longer holds developer-gitea (broker role carries it). - agent-deployment.yaml / stage_runtime_access.py: keep #16's jenkins-image-build-token injection/staging; keep #14's removal of the agent's gitea-token/gitea-username. - Bump vault-k8s-auth-hermes job -9 -> -10 (and its health check + test) so the merged auth config re-applies over any -9 already in-cluster. - flux hermes dependsOn: union jenkins + hermes-scm-broker + observer-rbac. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
titan-iac
Flux-managed Kubernetes desired-state config for bstein.dev.
Canonical source URL:
ssh://git@scm.bstein.dev:2242/atlas/titan-iac.git
Scope
This repo contains cluster configuration consumed by Flux:
- platform/infrastructure manifests
- service manifests and kustomizations
- operational scripts for render/reconcile workflows
Apply model
I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.
Description
Languages
Python
74%
JavaScript
10.2%
Shell
6.2%
TypeScript
3.9%
Go
2.1%
Other
3.4%