Restore native Forgejo CI and primary hosting #110
Open
adam
wants to merge 3 commits from
codex/forgejo-primary-hosting into main
pull from: codex/forgejo-primary-hosting
merge into: kaiba:main
kaiba:main
kaiba:codex/autonomous-appliance-updates
kaiba:codex/pages-deployment-gate
kaiba:codex/ci-backlog-recovery
kaiba:codex/production-provisioning-plan
kaiba:codex/task1-storage-public-review
kaiba:codex/retain-firmware-build-notices
kaiba:codex/raspberry-pi-firmware-notices
kaiba:codex/task1-recovered-staging-bindings
kaiba:codex/task1-reviewed-witnesses
kaiba:codex/task1-native-staging-manifest
kaiba:codex/effective-trust-observation
kaiba:codex/pilot-trust-continuation
kaiba:codex/offline-qualification-evidence
kaiba:codex/spiffe-roadmap
kaiba:codex/hydra-pr-manual
kaiba:codex/hydra-github-ci
kaiba:codex/hydra-on-ace
kaiba:codex/pilot-listener-readiness
kaiba:codex/pilot-host-system-path
kaiba:codex/pilot-serving-handoff
kaiba:codex/pilot-access-checks
kaiba:codex/pilot-host-deployment
kaiba:codex/pilot-authority-transition
kaiba:codex/pilot-ssh-dispatch
kaiba:codex/pilot-device-host-hook
kaiba:codex/mako-enrollment-hooks
kaiba:codex/pilot-enrollment-runner
kaiba:codex/pilot-enrollment-reports
kaiba:codex/select-arm64-heavy-checks
kaiba:codex/recovered-credential-renewal
kaiba:codex/pilot-recovery-installation
kaiba:codex/pilot-recovery-proof
kaiba:codex/pilot-renewal-history
kaiba:codex/pilot-renewal-client
kaiba:codex/pilot-device-diagnostics
kaiba:codex/pilot-credential-lifecycle
kaiba:codex/pilot-enrollment
kaiba:codex/ci-runtime-source-isolation
kaiba:codex/signer-test-timeout
kaiba:codex/ace-mako-pilot
kaiba:codex/malak-cli-enrollment
kaiba:codex/protected-enrollment-state
kaiba:codex/ace-adoption-plan
kaiba:codex/device-enrollment-client
kaiba:codex/guided-station-campaign
kaiba:codex/copied-storage-failure-metadata
kaiba:codex/copied-storage-comparison
kaiba:codex/provisioning-record-export
kaiba:codex/enrollment-handoff
kaiba:codex/feasibility-status
kaiba:codex/remaining-lock-observation
kaiba:codex/lock-clear-readback
kaiba:codex/development-signing-compat
kaiba:codex/signing-response-lengths
kaiba:codex/device-secret-response-diagnostics
kaiba:codex/firmware-rejection-observer
kaiba:codex/device-secret-lock-checks
kaiba:codex/hmac-lock-observation
kaiba:codex/offline-storage-observation
kaiba:codex/offline-storage-development
kaiba:codex/remote-luks-development
kaiba:codex/hmac-evidence-assessment
kaiba:codex/device-secret-hmac-diagnostics
kaiba:codex/device-secret-development
kaiba:codex/device-secret-failure-diagnostics
kaiba:codex/device-secret-usb-identity
kaiba:codex/per-device-boot-root-plan
kaiba:codex/firmware-crypto-locks
kaiba:codex/signing-failure-diagnostics
kaiba:codex/device-secret-native-export
kaiba:codex/device-secret-execution-packet
kaiba:codex/device-secret-target-harness
kaiba:codex/hmac-feasibility-runner
kaiba:codex/native-verity-evidence
kaiba:codex/read-only-slot-metadata
kaiba:codex/native-offline-positive-evidence
kaiba:codex/native-offline-handoff-main
kaiba:codex/native-offline-candidate
kaiba:codex/device-secret-feasibility
kaiba:codex/native-offline-handoff
kaiba:codex/station-read-only-status
kaiba:codex/implementation-staging
kaiba:codex/documentation-cleanup
kaiba:codex/fleet-admission-policy
kaiba:scope-rework
kaiba:codex/native-staging-export
kaiba:codex/public-root-payload-key-scan
kaiba:codex/rpi5-verifier-public-inputs-20260915
kaiba:codex/rpi5-campaign-preparation
kaiba:codex/rpi5-verifier-signing-handoff
kaiba:codex/rpi5-prephysical-validation
kaiba:codex/rpi5-recovery-preparation
kaiba:codex/rpi5-campaign-sandbox
kaiba:codex/gpt-test-feedback
kaiba:codex/gpt-metadata-captures
kaiba:codex/first-physical-baseline
kaiba:codex/release-candidate-ci
kaiba:codex/scope-build-inputs
kaiba:codex/development-checks
kaiba:codex/scope-pi-jemalloc-overlay
kaiba:codex/rpi5-stable-campaign-provisioner-final
kaiba:codex/rpi5-stable-verifier-campaign
kaiba:codex/fix-arm64-tcg-boot-timeout
kaiba:codex/rpi5-initramfs-verifier
kaiba:codex/goals-rework
No reviewers
Labels
Clear labels
bug
Something isn't working
documentation
Improvements or additions to documentation
duplicate
This issue or pull request already exists
enhancement
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
invalid
This doesn't seem right
question
Further information is requested
wontfix
This will not be worked on
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-provisioning!110
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/forgejo-primary-hosting"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Restore project validation on Forgejo using the existing pinned inputs and full native workflow gates. Jobs run in fresh repository-scoped ephemeral VMs; deployment and cache publishing credentials stay outside the guests. Owned source fetches retain the same revisions.
The ARM runner passed live private checkout, scoped Nix fetching, artifact upload with independent stored-content hashing, anonymous denial, and a dependent job in a second fresh VM. Native x86 and full project workflow results are required before changing the protected merge gate. Main tips and administrator push/merge blocks remain unchanged.
GitHub workflows remain as historical records. Go module identities and historical provenance links are preserved. Host fixture checks do not establish deployed-host acceptance; production physical provisioning remains separately gated.
Retains the ten-job native ARM Hydra gate, validates exact task attempts with pagination, and checks every expected derivation against the immutable evaluation. Public CI does not replace the private historical NVMe campaign result.
Stage Forgejo primary hostingto Restore native Forgejo CI and primary hostingView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.