fix(vloer): default the chart and image builds to public registries #213

Merged
ryangr0 merged 3 commits from ryangr0/replace/191-portable-chart into development 2026-10-04 08:39:43 +00:00 AGit
Owner

Replaces #191 (fix(vloer): default the chart and image builds to public registries) after the Ploeg separation in #206. Its Ploeg part is ploeg-hq/ploeg#52; this PR moves Unfold's pin to that branch and carries the rest.

Carried over from the original: check that homelab-cluster's Vloer HelmRelease sets its own image repository and registry before merging, because Vloer's chart now defaults to ghcr.io/webgrip/de-vloer and the Dockerfiles to dhi.io. The original's Ploeg caveat (Homelab Roadmap VIK-1826) now applies to adopting the ploeg-hq chart instead.

Commits

  • cab20c8b build(ploeg): pin ploeg-hq/ploeg#52 to make the chart portable
  • f08bc68d fix(vloer): default the chart and image builds to public registries (from 3fa37ead76)
  • 30310434 build: keep Renovate off Vloer's chart image tag at its ghcr.io default (from d48e3ce377)

Merge order

  1. #206, the cutover. Until it merges, this PR's diff also shows the cutover commits it is stacked on.
  2. ploeg-hq/ploeg#52.
  3. Move the pin in this PR's build(ploeg) commit to the merge commit on Ploeg's main, then merge. Until then the ploeg-pin check is red by design: it requires the pinned commit on Ploeg's main.

Verification (local, at 30310434 with Ploeg b066bc49)

  • mise run verify with the result cache, as a pull request runs it: all gates passed. That includes the Ploeg group (its own scripts/verify.sh at the pin), Vloer, the extension, the demo replay check, integration (managed qualification) and docs.
  • Ploeg side: GitHub CI passed on ploeg-hq/ploeg#52.

What happened to each commit of #191

Commit Subject Here
d48e3ce377 fix(ploeg): make the chart install on a cluster outside the homelab Ploeg part ported to ploeg-hq/ploeg#52; Unfold part re-applied as 30310434 ("build: keep Renovate off Vloer's chart image tag at its ghcr.io default")
3fa37ead76 fix(vloer): default the chart and image builds to public registries Unfold part re-applied as f08bc68d

The original had no reviews or comments. Its checks were red because development itself failed at mise install --locked; #206 fixes that lock. No earlier check result carries over.

Original description of #191

The chart pulled de-vloer and de-vloer-agent from Harbor and the
Dockerfiles pulled their hardened base through Harbor's proxy. The chart
now defaults to the ghcr.io release copies and the Dockerfiles to dhi.io;
CI and the release workflow still pass REGISTRY_DHI explicitly. The chart
README lists the images and the services live mode needs.

DO NOT MERGE before the homelab-cluster Ploeg HelmRelease sets the overrides in Homelab Roadmap ticket 'ploeg: set explicit chart values before portable defaults' (image.repository, nodeSelectors, database/webhook secrets, executor.litellm baseUrl/adminUrl). Without them the homelab render fails or switches ploegd to GHCR, where rc.33/rc.34 are missing. With them the homelab render is byte-identical (checked). Fresh install on kind reached Ready for both charts in 38 s. Ploeg's GHCR publish for rc.33/rc.34 is missing (separate ticket).

Verified with mise run verify on the pinned toolchain (all gates passed).

Ticket: https://vikunja.webgrip.dev/tasks/1758

🤖 Generated with Claude Code

🤖 Generated with Claude Code

Replaces #191 (fix(vloer): default the chart and image builds to public registries) after the Ploeg separation in #206. Its Ploeg part is [ploeg-hq/ploeg#52](https://github.com/ploeg-hq/ploeg/pull/52); this PR moves Unfold's pin to that branch and carries the rest. **Carried over from the original:** check that homelab-cluster's Vloer HelmRelease sets its own image repository and registry before merging, because Vloer's chart now defaults to `ghcr.io/webgrip/de-vloer` and the Dockerfiles to `dhi.io`. The original's Ploeg caveat (Homelab Roadmap VIK-1826) now applies to adopting the ploeg-hq chart instead. ## Commits - `cab20c8b` build(ploeg): pin ploeg-hq/ploeg#52 to make the chart portable - `f08bc68d` fix(vloer): default the chart and image builds to public registries (from `3fa37ead76`) - `30310434` build: keep Renovate off Vloer's chart image tag at its ghcr.io default (from `d48e3ce377`) ## Merge order 1. #206, the cutover. Until it merges, this PR's diff also shows the cutover commits it is stacked on. 2. [ploeg-hq/ploeg#52](https://github.com/ploeg-hq/ploeg/pull/52). 3. Move the pin in this PR's `build(ploeg)` commit to the merge commit on Ploeg's `main`, then merge. Until then the `ploeg-pin` check is red by design: it requires the pinned commit on Ploeg's `main`. ## Verification (local, at `30310434` with Ploeg `b066bc49`) - `mise run verify` with the result cache, as a pull request runs it: all gates passed. That includes the Ploeg group (its own `scripts/verify.sh` at the pin), Vloer, the extension, the demo replay check, integration (managed qualification) and docs. - Ploeg side: GitHub CI passed on [ploeg-hq/ploeg#52](https://github.com/ploeg-hq/ploeg/pull/52). ## What happened to each commit of #191 | Commit | Subject | Here | | --- | --- | --- | | `d48e3ce377` | fix(ploeg): make the chart install on a cluster outside the homelab | Ploeg part ported to ploeg-hq/ploeg#52; Unfold part re-applied as `30310434` ("build: keep Renovate off Vloer's chart image tag at its ghcr.io default") | | `3fa37ead76` | fix(vloer): default the chart and image builds to public registries | Unfold part re-applied as `f08bc68d` | The original had no reviews or comments. Its checks were red because `development` itself failed at `mise install --locked`; #206 fixes that lock. No earlier check result carries over. <details><summary>Original description of #191</summary> The chart pulled de-vloer and de-vloer-agent from Harbor and the Dockerfiles pulled their hardened base through Harbor's proxy. The chart now defaults to the ghcr.io release copies and the Dockerfiles to dhi.io; CI and the release workflow still pass REGISTRY_DHI explicitly. The chart README lists the images and the services live mode needs. DO NOT MERGE before the homelab-cluster Ploeg HelmRelease sets the overrides in Homelab Roadmap ticket 'ploeg: set explicit chart values before portable defaults' (image.repository, nodeSelectors, database/webhook secrets, executor.litellm baseUrl/adminUrl). Without them the homelab render fails or switches ploegd to GHCR, where rc.33/rc.34 are missing. With them the homelab render is byte-identical (checked). Fresh install on kind reached Ready for both charts in 38 s. Ploeg's GHCR publish for rc.33/rc.34 is missing (separate ticket). Verified with `mise run verify` on the pinned toolchain (all gates passed). Ticket: https://vikunja.webgrip.dev/tasks/1758 🤖 Generated with [Claude Code](https://claude.com/claude-code) </details> 🤖 Generated with [Claude Code](https://claude.com/claude-code)
711a4814 moved uv to 0.12.22 in mise.toml but left the lockfile at
0.12.21. mise-action runs `mise install --locked`, which refuses a
version the lockfile does not hold, so the checks job has failed before
any gate since that commit, on development and on every pull request.

`mise lock uv` (mise 2026.9.18) records 0.12.22 for all seven platforms.
The openspec lock files it deletes under .mise/locks are kept.

Refs: https://github.com/webgrip/unfold/issues/2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace the vendored apps/ploeg tree with a gitlink to
https://github.com/ploeg-hq/ploeg.git at v0.1.0
(87f8dc45a0ea768c6ab95196d8b99d481df10c65), which was extracted from
this repository at 9c1d53f.

- mise run setup, the verify, docs and demo checkouts and the TechDocs
  prepare commands initialise the submodule.
- scripts/ploeg-pin.mjs refuses vendored source, another repository and
  an uninitialised or modified checkout. The ploeg-pin job also requires
  the pinned commit on Ploeg's main, and the release waits for it.
- verify runs Ploeg's own scripts/verify.sh at the pin and compiles the
  unified demo helper, which now imports github.com/ploeg-hq/ploeg.
- The docs build still renders Ploeg's pinned pages, but no longer
  regenerates or validates Ploeg's configuration reference, domain pages
  or decision ledger, and it links Ploeg's source files on GitHub at the
  pinned commit. The combined glossary keeps a decision that a pinned
  model cites by URL instead of mangling it into a relative path.
- Renovate ignores apps/ploeg, drops the Go overlay and leaves the pin
  to people. CI no longer builds the ploegd image context.

Refs: https://github.com/webgrip/unfold/issues/2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Unfold's train now versions Vloer only; github.com/ploeg-hq/ploeg
versions and publishes Ploeg with GitHub Actions.

- on_release_published.yml drops the Ploeg chart, image, signing and
  distribution jobs. The Vloer publisher is the only one, so it takes
  the GitHub release out of draft itself.
- publish_release.py and publish_chart.py refuse ploeg before any Git,
  network or file access. The Go module export to github.com/webgrip/ploeg
  is gone, including the call that disabled GitHub Actions there.
- release-prepare.mjs and apps/.releaserc.cjs touch only Vloer's chart,
  and a commit scoped ploeg never releases Unfold.
- release-floors.json keeps Ploeg's floor and withdrawn 1.0.0-rc.1, marks
  the component retired after 0.4.0-rc.35, and both loaders refuse a
  train that versions a retired component.
- The release preflight no longer checks registry access for ploegd or
  charts/ploeg.

Refs: https://github.com/webgrip/unfold/issues/2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: record that Unfold pins Ploeg and releases only Vloer
All checks were successful
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 42s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 16s
[Workflow] On Pull Request / checks (pull_request) Successful in 7m8s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
1bca2ac69b
ADR-0019 records the consumer side of the separation approved in
webgrip/unfold#1: Ploeg lives in github.com/ploeg-hq/ploeg, Unfold pins
it as a submodule, and the unfold-v train versions Vloer only. It
supersedes ADR-0004; ADR-0001 and ADR-0018 get dated notes.

README, AGENTS.md, NOTICE, the team-silver skill and the current pages
now say where Ploeg lives, how the pin moves, what Unfold releases and
where Ploeg's artifacts come from.

Refs: https://github.com/webgrip/unfold/issues/2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
build(docs): treat Ploeg's archived history pages as records
All checks were successful
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 24s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 29s
[Workflow] On Pull Request / checks (pull_request) Successful in 2m22s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
3870a8b560
Ploeg's main keeps its pre-separation release history in
docs/history/legacy-changelog.md, a record no current page links. Unfold
renders Ploeg's docs from the pinned commit, so any pin past v0.1.0 failed
the docs build with that page as an orphan. ploeg/history now joins
ploeg/backlog as a record path: kept, marked "not current guidance" and
left out of the nav and search.

Refs: https://github.com/webgrip/unfold/issues/2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Moves apps/ploeg to b066bc49, the head of ploeg-hq/ploeg#52, which is
the Ploeg side of Unfold PR 191. Once that pull request merges, move
the pin to its merge commit on Ploeg's main. Until then the ploeg-pin check
stays red, as it should.

Refs: https://github.com/ploeg-hq/ploeg/pull/52
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The chart pulled de-vloer and de-vloer-agent from Harbor and the
Dockerfiles pulled their hardened base through Harbor's proxy. The chart
now defaults to the ghcr.io release copies and the Dockerfiles to dhi.io;
CI and the release workflow still pass REGISTRY_DHI explicitly. The chart
README lists the images and the services live mode needs.

VIK-1758

Replaces-commit: 3fa37ead76 (#191)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
build: keep Renovate off Vloer's chart image tag at its ghcr.io default
Some checks failed
[Workflow] On Pull Request / ploeg-pin (pull_request) Failing after 53s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 52s
[Workflow] On Pull Request / checks (pull_request) Successful in 7m13s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
3031043462
Vloer's chart now defaults to ghcr.io/webgrip/de-vloer, so the rule that
keeps Renovate from digest-pinning the empty, release-filled tag names that
image. This is the Unfold part of "fix(ploeg): make the chart install on a
cluster outside the homelab" that still applies: its Ploeg rules and its
verify.mjs Helm change moved to ploeg-hq/ploeg#52 with Ploeg's chart.

VIK-1758

Replaces-commit: d48e3ce377 (#191)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 force-pushed ryangr0/replace/191-portable-chart from 3031043462
Some checks failed
[Workflow] On Pull Request / ploeg-pin (pull_request) Failing after 53s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 52s
[Workflow] On Pull Request / checks (pull_request) Successful in 7m13s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
to 4abf12e5ec
Some checks failed
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / ploeg-pin (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
[Workflow] On Pull Request / checks (pull_request) Failing after 6m14s
2026-10-04 07:08:59 +00:00
Compare
ryangr0 force-pushed ryangr0/replace/191-portable-chart from 4abf12e5ec
Some checks failed
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / ploeg-pin (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
[Workflow] On Pull Request / checks (pull_request) Failing after 6m14s
to 4261f449ef
All checks were successful
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 42s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 41s
[Workflow] On Pull Request / checks (pull_request) Successful in 5m39s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
2026-10-04 07:12:40 +00:00
Compare
ryangr0 merged commit 7c24aec610 into development 2026-10-04 08:39:43 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!213
No description provided.