Compare commits

..
Author SHA1 Message Date
not 1c9eeccacc Merge branch 'main' into feat/186-otel-endpoint
CI / k8s (pull_request) Successful in 11s
CI / lint (pull_request) Successful in 2m3s
CI / build (pull_request) Successful in 1m24s
CI / docs (pull_request) Successful in 58s
CI / unit (pull_request) Successful in 1m27s
CI / frontend (pull_request) Successful in 2m29s
CI / mutation (pull_request) Successful in 5m32s
CI / verify-stack (pull_request) Skipped
2026-09-28 13:29:43 +00:00
not b444e0c680 ci(docs): build the MkDocs site with --strict in CI (refs #173) (#189)
CI / k8s (push) Successful in 10s
CI / build (push) Successful in 1m22s
CI / lint (push) Successful in 2m5s
CI / docs (push) Successful in 1m1s
CI / unit (push) Successful in 1m29s
CI / frontend (push) Successful in 2m31s
Deploy to Talos / deploy (push) Successful in 2m36s
CI / mutation (push) Successful in 5m9s
CI / verify-stack (push) Canceled after 8m47s
refs #173. This is the minimum step from the issue: the site is now **built** in CI, not **published**. Publishing still needs an ADR (Gitea has no built-in Pages) or a CLAUDE.md §12 correction, so the issue stays open.

- `make docs`: creates a throwaway `.venv-docs`, installs pinned `mkdocs==1.6.1` and `mkdocs-material==9.7.7`, then runs `mkdocs build --strict`. The target is also added to `make ci`.
- New `docs` job in `ci.yaml` (`setup-python@v5`, then `make docs`).
- Red, then green: the first commit fails on a link from `runbooks/ci.md` to a file outside `docs/`; the second turns that link into plain code.

**Dependency (§13):** mkdocs and mkdocs-material were already the site's declared toolchain (`mkdocs.yml`) but were never installed anywhere. They give a strict link/nav/theme check. Replacing them means writing our own Markdown link checker, and `check-docs-nav.py` already covers only the nav half. Risk: Material warns that MkDocs 2.0 drops its plugin/theme system, so both are pinned exactly. No ADR, since this adds no new decision beyond what `mkdocs.yml` already assumes.

Verified locally: `make docs` → `Documentation built in 0.87 seconds`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #189
2026-09-28 13:25:40 +00:00
not f3e10c6642 Merge branch 'main' into feat/186-otel-endpoint
CI / k8s (pull_request) Successful in 11s
CI / lint (pull_request) Successful in 1m52s
CI / build (pull_request) Successful in 1m17s
CI / unit (pull_request) Successful in 1m41s
CI / frontend (pull_request) Successful in 2m43s
CI / mutation (pull_request) Successful in 5m10s
CI / verify-stack (pull_request) Skipped
2026-09-28 13:03:21 +00:00
notandClaude Opus 5.5 86381d7059 feat(k8s): make the OTLP trace endpoint a chart value (refs #186)
CI / lint (pull_request) Successful in 1m46s
CI / k8s (pull_request) Successful in 10s
CI / build (pull_request) Successful in 1m53s
CI / unit (pull_request) Successful in 2m3s
CI / frontend (pull_request) Successful in 2m22s
CI / mutation (pull_request) Successful in 5m32s
CI / verify-stack (pull_request) Skipped
otelEndpoint defaults to the chart's own tempo; deploy overrides it from the
OTEL_ENDPOINT repo variable, so the labs cluster can ship traces to the
monitoring stack's Tempo instead of failing every export.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-28 14:31:48 +02:00
2 changed files with 14 additions and 4 deletions
+4 -1
View File
@@ -34,6 +34,9 @@ jobs:
# `true` fills in the medewerker OTP step for the public demo (chart value
# demo.otpAutofill). The fixture secret is committed: demo only.
OTP_AUTOFILL: ${{ vars.OTP_AUTOFILL }}
# Tempo for the services' traces, e.g. http://tempo.monitoring.svc:4317 (the
# cluster monitoring stack, Infra repo). Empty = the chart default.
OTEL_ENDPOINT: ${{ vars.OTEL_ENDPOINT }}
steps:
- uses: https://github.com/actions/checkout@v4
@@ -100,7 +103,7 @@ jobs:
make k8s-reseed \
TALOS_HOST=${TALOS_HOST:-localhost} \
K8S_REGISTRY=${TALOS_VM_IP:-192.168.122.173}:30500 \
K8S_SET="${KEYCLOAK_URL:+--set keycloakUrl=$KEYCLOAK_URL} --set demo.otpAutofill=${OTP_AUTOFILL:-false}"
K8S_SET="${KEYCLOAK_URL:+--set keycloakUrl=$KEYCLOAK_URL} --set demo.otpAutofill=${OTP_AUTOFILL:-false}${OTEL_ENDPOINT:+ --set otelEndpoint=$OTEL_ENDPOINT}"
# `dev` is a mutable tag and helm sees an unchanged pod template, so the
# new images only land on a restart (pullPolicy is already Always).
+10 -3
View File
@@ -30,6 +30,12 @@ host: 192.168.122.100
# portals' authority (runbook, "Publishing through the labs Caddy").
keycloakUrl: ""
# Where the .NET services send traces (OTLP gRPC). The default is the chart's own
# `tempo` workload (off by default, like compose). Point it at a Tempo outside the
# release, e.g. the cluster monitoring stack's http://tempo.monitoring.svc:4317 —
# with no Tempo at all, every export fails and is counted as a .NET exception.
otelEndpoint: http://tempo:4317
demo:
# Fill in and submit the medewerker OTP step from the fixture secret, so a public
# demo shows MFA enforced without an authenticator: makes the big-demo theme
@@ -160,10 +166,11 @@ envGroups:
NOTIFICATIONS_DISABLED: "false"
RUN_SETUP_CONFIG: "true"
# Traces for the .NET services. Always set, like compose: the exporter fails
# harmlessly when Tempo is absent (services/*/Program.cs).
# Traces for the .NET services. Always set, like compose. With no Tempo behind
# `otelEndpoint` the exporter fails quietly but throws on every batch, which
# shows up as HttpRequestException/SocketException in dotnet_exceptions_total.
otel:
OTEL_EXPORTER_OTLP_ENDPOINT: http://tempo:4317
OTEL_EXPORTER_OTLP_ENDPOINT: '{{ .Values.otelEndpoint }}'
OTEL_EXPORTER_OTLP_PROTOCOL: grpc
# ── Workloads ──────────────────────────────────────────────────────────────────