The reviewed PR stack is now merged into main, so an open draft PR #19 is no longer proof that the reviewed code is what runs. The mandatory release.exact-lineage-is-running check now requires the merged terminal state instead: PR #19 closed with merged=true, base main, the existing feature ref, and the exact reviewed head, plus a new merge-ancestry step that proves the reviewed head is an ancestor of the pinned origin/main via git merge-base --is-ancestor. An open PR, a PR closed without merging, a mismatched head, or a head that is not a proven ancestor of main still fails closed; an undecidable ancestry probe is NOT_RUN. The recorded pre-merge base SHA is no longer compared against current main. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
titan-iac
Flux-managed Kubernetes desired-state config for bstein.dev.
Canonical source URL:
ssh://git@scm.bstein.dev:2242/atlas/titan-iac.git
Scope
This repo contains cluster configuration consumed by Flux:
- platform/infrastructure manifests
- service manifests and kustomizations
- operational scripts for render/reconcile workflows
Apply model
I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.
Description
Languages
Python
74%
JavaScript
10.2%
Shell
6.2%
TypeScript
3.9%
Go
2.1%
Other
3.4%