code.stanford.edu / iac/cloud-framework / commits
| SHA | Message | Author | Date | Stats |
|---|---|---|---|---|
| c5abaf48 | chore(changelog): backfill update-downstream-tag fix under 1.4.4 | xuwang <x****g@g****m> | about 1 month ago | |
| b60c47a4 |
docs: add GCP-AUTH.md (GCP_LOGIN_METHOD, GOOGLE_APPLICATION_CREDENTIALS, CI s...
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | about 1 month ago | |
| 78cb41be | Release v1.4.4 | xuwang <x****g@g****m> | about 1 month ago | |
| 7dfdb830 |
update-downstream-tag.sh: accept env TAG_FILE (2-arg) form
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | about 1 month ago | |
| 4dc16631 |
refactor(skills): move crashloop-reporter to skills/gcp as gke-crashloop-repo...
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| 15c9bac5 |
refactor(skills): move crashloop-reporter to skills/gcp as gke-crashloop-repo...
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| 2ccb1147 | merge Merge branch 'add-crashloop-reporter-skill' into 'main' | Xu Wang <x****g@s****u> | about 2 months ago | |
| 1344be71 | Add otica-crashloop-reporter skill (cluster-wide CrashLoopBackOff -> Slack) | Xueshan Feng <x****g@s****u> | about 2 months ago | |
| f020efdf | Release v1.4.3 | xuwang <x****g@g****m> | about 2 months ago | |
| ec611484 |
feat(gke.mk): replace kubescape with gke-security-posture-enable/disable targets
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| b7c4c951 | Release v1.4.2 | xuwang <x****g@g****m> | about 2 months ago | |
| 37c9ae49 |
feat(gke.mk): add upgrade-kubescape and uninstall-kubescape targets
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| e55cd778 |
fix(render.sh): make vault-kv format field optional, default to text
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| 9e6a3238 | Update makefiles/kube.mk, fix the kc-delete-sec help message | xuwang <x****g@g****m> | about 2 months ago | |
| 8f555bb8 |
skills/otica-migrate-docker: document DOWNSTREAM_REPO SSH URL requirement
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| d8d96b43 |
skills/otica-migrate-tf: gcp-login on tf-init is GCP-platform-only
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| c4ee21e4 |
skills: document vault-login prereq placement for kube and TF repos
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| 1fc707c8 |
feat(skills/otica-migrate): tools.txt, cert-manager gate, encryption_key, SQL...
Co-authored-by: Claude Sonnet 4.6 <n****y@a****m> |
xuwang <x****g@g****m> | about 2 months ago | |
| 8d8ef1e3 | merge Merge commit '8f76d9d' | xuwang <x****g@g****m> | 2 months ago | |
| 8f76d9d8 | Update scripts/renovate-init.sh, write a minimal starter config with the reco... | xuwang <x****g@g****m> | 2 months ago | |
| 5e651dd0 |
otica-migrate-kube: rule for rendering vault-bearing properties into Secret/C...
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 5afd19eb |
docs(gitlab-release): point to docker-toolchain as the onboarded example
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 16081185 | Release v1.4.1 | xuwang <x****g@g****m> | 2 months ago | |
| 2eafbe03 |
feat(release): GITLAB_TOKEN auth, RELEASE_BRANCH auto-detect; uppercase docs
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 05432660 | Release v1.4.0 | xuwang <x****g@g****m> | 2 months ago | |
| e22eaae5 |
feat(release): generalize release module for any GitLab repo
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| a24ae0f4 |
fix(gcp-login): drop GSA_NAME assertion in workload-identity login
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| ff2306a8 | Update scripts/otica-upgrade-check.sh, ref to release notes in help message | xuwang <x****g@g****m> | 2 months ago | |
| a7a07852 | Release v1.3.0 | xuwang <x****g@g****m> | 2 months ago | |
| 2e5b1599 |
docs(renovate): pin CI-template include examples to v1.3.0
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| bcd99ffb |
docs(renovate): fix example module link (gitlab-renovate-bot -> gitlab-sa-user)
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| fc5e4dd6 |
refactor(renovate): drop in-tree bot management; identity is provisioned out-...
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 1f372ca0 |
docs(renovate): document Terraform-provisioned bot via Vault token path
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| aff5ae4f |
refactor(renovate): route renovate-bot API calls through gitlab.sh helpers
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 2868d0d9 |
fix(renovate): bot operator token honors RENOVATE_BOT_ADMIN_TOKEN over ambient
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 32cce66f |
feat(renovate): default bot to Maintainer; RENOVATE_BOT_NAME for multiple bots
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 0089d522 |
feat(renovate): renovate-bot-rotate — atomic token rotation
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 21f751c1 |
refactor(renovate): one RENOVATE_TOKEN_VAULT_PATH for both write and read
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 26170bd7 |
feat(renovate): add RENOVATE_TOKEN_VAULT_PATH to the token resolution chain
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| b393242f |
feat(renovate): sa-create can store the bot token in Vault
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 7883a91f |
feat(renovate): cross-group service-account bot (sa-create + add-groups)
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 87d8a2c7 |
feat(renovate): optional dedicated bot identity (create/list/revoke/ci-set)
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 6986c242 |
docs(renovate): document onboarding / requireConfig options and the three models
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 1dea9202 |
feat(renovate): renovate-admin-update — build admin repo list from repos.txt
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| c362da58 |
feat(renovate): root-controlled admin scans via RENOVATE_ADMIN_CONFIG
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| dd5353fa |
fix(renovate): normalize endpoint scheme; add RENOVATE_TOKEN_FILE for multi-s...
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 5248d486 |
fix(renovate): derive endpoint from remote host; scrub internal RENOVATE_* env
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| a8de2699 |
renovate: add dependency-update module, scripts, CI template, docs
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 9347bc59 |
Factor iap-authz into gke-iap-authz.sh with IAP_MEMBERS validation
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| e557c951 |
doc(gke-iap-auth): correct Google sign-in screen description
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| ea8ee0b5 |
fix(upgrade-check): put update-otica hint on one line
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
Xueshan Feng <x****g@s****u> | 2 months ago | |
| 13ee993e |
fix(upgrade-check): fold CHANGELOG link into the review line
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
Xueshan Feng <x****g@s****u> | 2 months ago | |
| e76e787c |
fix(update): land branch refs on the remote head
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
Xueshan Feng <x****g@s****u> | 2 months ago | |
| 47eb20c8 |
fix(upgrade-check): link to CHANGELOG instead of release page
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
Xueshan Feng <x****g@s****u> | 2 months ago | |
| f49119f3 |
fix(upgrade-check): hourly fetch throttle and release notes link
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
Xueshan Feng <x****g@s****u> | 2 months ago | |
| b34fe873 |
validate: guard against orphaned Changelog: trailers
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 6f90303c | Release v1.2.1 | xuwang <x****g@g****m> | 2 months ago | |
| 0ef5beb7 |
doc(gke-iap-auth): add identity propagation + sign-in experience sections
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 46c0b211 |
Add gke-iap-authz.mk: per-app GKE IAP authorization
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 027f9cae |
docs(readme): rename Examples to Example Consumer Repos
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 1fa0f072 |
docs(readme): remove outdated Framework Structure section
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| b1a9ebfc |
docs(readme): trim Framework Structure tree and drop CI Runner Images section
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 7d239b65 |
terraform: keep TF_CLI_CONFIG_FILE defined but unexport it when online
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 88df2ade |
terraform.mk: make tf-init resilient to provider-registry outages
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 13f157b0 |
docs(changelog): update preamble off removed OTICA_VERSION pin
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| 6ef52043 | Release v1.2.0 | xuwang <x****g@g****m> | 2 months ago | |
| 109d91f6 |
feat(update): roll to latest release by default; drop OTICA_VERSION
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 2 months ago | |
| b05b712d |
chore(makefile): use shared help.mk for the dev repo's own help
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 433c7952 | Release v1.1.2 | xuwang <x****g@g****m> | 3 months ago | |
| 040c6f82 |
fix(upgrade-check): nudge whenever HEAD is not the latest release
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| dac078df | Release v1.1.1 | xuwang <x****g@g****m> | 3 months ago | |
| 0cf75312 |
feat(help): show pinned OTICA_VERSION and checked-out ref in make help
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 36f77996 |
release: render changelog commit refs as compact markdown links
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 0e0467dd |
fix(agentic): keep Closes and Changelog in separate paragraphs so trailers parse
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 571167fc |
fix(release): keep changelog entries on separate lines; flag untrailered commits
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| ec97d0fe | Release v1.1.0 | xuwang <x****g@g****m> | 3 months ago | |
| 1f38ed6a | merge Merge branch 'agent/issue-9' into 'main' | otica-integrator <p****f@n****u> | 3 months ago | |
| c7194fc7 | fix(gl-flow): shift once for valueless issue-list flags |
otica-resolver <p****f@n****u>
Committed by: otica-integrator <p****f@n****u> |
3 months ago | |
| 724b81c4 | feat(gl-set-slack): configure the GitLab for Slack app (per-event channels) |
otica-resolver <p****f@n****u>
Committed by: otica-integrator <p****f@n****u> |
3 months ago | |
| 919979c1 | merge Merge branch 'agent/issue-7' into 'main' | otica-integrator <p****f@n****u> | 3 months ago | |
| 0d11a1c5 |
docs: slim README, fan out detail to docs/, drop stale lists
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 4bc7e872 |
fix(agentic): make agents creates .agentic-logs and records loop launches
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| cc222943 |
feat(agentic): resolver picks up issues assigned to its bot
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 3aaee668 | fix(skill): scope TrimSpace advice to Make-included vault reads |
otica-resolver <p****f@n****u>
Committed by: otica-integrator <p****f@n****u> |
3 months ago | |
| ef96befe | merge Merge branch 'agent/issue-5' into 'main' | otica-integrator <p****f@n****u> | 3 months ago | |
| 09e2c5ed | fix: preserve trailing newline in vault-read.sh output |
otica-resolver <p****f@n****u>
Committed by: otica-integrator <p****f@n****u> |
3 months ago | |
| 5e9c1cc7 | merge Merge branch 'agent/issue-4' into 'main' | otica-integrator <p****f@n****u> | 3 months ago | |
| 7c938615 | merge Merge branch 'agent/issue-6' into 'main' | otica-integrator <p****f@n****u> | 3 months ago | |
| 11db71da | fix: warn when gl-set-slack targets legacy service on a Slack-app repo |
otica-resolver <p****f@n****u>
Committed by: otica-integrator <p****f@n****u> |
3 months ago | |
| 931f8bc8 |
feat(agentic): run loop workers under bypass + per-role deny guardrails
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 2b261789 |
feat(agentic): start agents via `claude --bg`; run from a dedicated clone; docs
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 80de94d8 |
feat(agentic): run multi-identity in `claude agents`; drop tmux launcher
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| c0b4329d |
feat(agentic): bot-token setup, tmux launcher, reviewer claim, issue-close
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 9e6d91f0 | docs: document NONINTERACTIVE escape hatch in confirm.sh |
Xu Wang <x****g@s****u>
Committed by: otica-integrator-test <p****9@n****u> |
3 months ago | |
| a7f2d961 | merge Merge branch 'agent/issue-2' into 'main' | otica-integrator-test <p****9@n****u> | 3 months ago | |
| d41c5395 | merge Merge branch 'feat/agentic-workflow' into 'main' | Xu Wang <x****g@s****u> | 3 months ago | |
| 60923209 | feat(agentic): add issue→fix→review→merge agent workflow | Xu Wang <x****g@s****u> | 3 months ago | |
| af2cec6d |
fix(release): compare HEAD to FETCH_HEAD, not the tracking ref
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| cb76b44b |
fix(release): require local RELEASE_BRANCH in sync with remote
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago | |
| 91be44fd |
docs: correct mirror sync timing (~5 min, not seconds)
Co-authored-by: Claude Opus 4.8 <n****y@a****m> |
xuwang <x****g@g****m> | 3 months ago |