Compare commits

..
Author SHA1 Message Date
not 1c9eeccacc Merge branch 'main' into feat/186-otel-endpoint
CI / k8s (pull_request) Successful in 11s
CI / lint (pull_request) Successful in 2m3s
CI / build (pull_request) Successful in 1m24s
CI / docs (pull_request) Successful in 58s
CI / unit (pull_request) Successful in 1m27s
CI / frontend (pull_request) Successful in 2m29s
CI / mutation (pull_request) Successful in 5m32s
CI / verify-stack (pull_request) Skipped
2026-09-28 13:29:43 +00:00
not b444e0c680 ci(docs): build the MkDocs site with --strict in CI (refs #173) (#189)
CI / k8s (push) Successful in 10s
CI / build (push) Successful in 1m22s
CI / lint (push) Successful in 2m5s
CI / docs (push) Successful in 1m1s
CI / unit (push) Successful in 1m29s
CI / frontend (push) Successful in 2m31s
Deploy to Talos / deploy (push) Successful in 2m36s
CI / mutation (push) Successful in 5m9s
CI / verify-stack (push) Canceled after 8m47s
refs #173. This is the minimum step from the issue: the site is now **built** in CI, not **published**. Publishing still needs an ADR (Gitea has no built-in Pages) or a CLAUDE.md §12 correction, so the issue stays open.

- `make docs`: creates a throwaway `.venv-docs`, installs pinned `mkdocs==1.6.1` and `mkdocs-material==9.7.7`, then runs `mkdocs build --strict`. The target is also added to `make ci`.
- New `docs` job in `ci.yaml` (`setup-python@v5`, then `make docs`).
- Red, then green: the first commit fails on a link from `runbooks/ci.md` to a file outside `docs/`; the second turns that link into plain code.

**Dependency (§13):** mkdocs and mkdocs-material were already the site's declared toolchain (`mkdocs.yml`) but were never installed anywhere. They give a strict link/nav/theme check. Replacing them means writing our own Markdown link checker, and `check-docs-nav.py` already covers only the nav half. Risk: Material warns that MkDocs 2.0 drops its plugin/theme system, so both are pinned exactly. No ADR, since this adds no new decision beyond what `mkdocs.yml` already assumes.

Verified locally: `make docs` → `Documentation built in 0.87 seconds`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #189
2026-09-28 13:25:40 +00:00
not f3e10c6642 Merge branch 'main' into feat/186-otel-endpoint
CI / k8s (pull_request) Successful in 11s
CI / lint (pull_request) Successful in 1m52s
CI / build (pull_request) Successful in 1m17s
CI / unit (pull_request) Successful in 1m41s
CI / frontend (pull_request) Successful in 2m43s
CI / mutation (pull_request) Successful in 5m10s
CI / verify-stack (pull_request) Skipped
2026-09-28 13:03:21 +00:00
not 733ba71173 fix(acl): keep the integration tests out of Stryker's solution (closes #174) (#188)
CI / k8s (push) Successful in 10s
CI / lint (push) Successful in 1m53s
CI / build (push) Successful in 1m22s
CI / unit (push) Successful in 1m35s
CI / frontend (push) Successful in 2m46s
Deploy to Talos / deploy (push) Successful in 2m37s
CI / mutation (push) Successful in 4m56s
CI / verify-stack (push) Canceled after 9m56s
closes #174

Took fix option 3, cut down: removed `Acl.IntegrationTests` from `services/acl/Acl.slnx`. Only Stryker reads that file. `make build`, `make lint` and `make unit` use the root `register-referentie.slnx`, and `Dockerfile.integration` targets the csproj directly, so nothing else changes. A comment in the slnx and a note in `docs/runbooks/ci.md` explain why the project is left out.

**Verified locally** (`cd services/acl && dotnet stryker`):
- `Number of tests found: 86` (was 94); the `8 tests are failing` warning is gone.
- Final score **90.45 %**, the same as before. Tests that fail their initial run were never used to kill mutants, so the number was not depressed, only unverified. Re-baselined from this clean run: `break: 90` stays (§5, never lower).

No test-first commit: this changes build config only. The check is the Stryker initial-run log above.

🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #188
2026-09-28 12:56:10 +00:00
notandClaude Opus 5.5 86381d7059 feat(k8s): make the OTLP trace endpoint a chart value (refs #186)
CI / lint (pull_request) Successful in 1m46s
CI / k8s (pull_request) Successful in 10s
CI / build (pull_request) Successful in 1m53s
CI / unit (pull_request) Successful in 2m3s
CI / frontend (pull_request) Successful in 2m22s
CI / mutation (pull_request) Successful in 5m32s
CI / verify-stack (pull_request) Skipped
otelEndpoint defaults to the chart's own tempo; deploy overrides it from the
OTEL_ENDPOINT repo variable, so the labs cluster can ship traces to the
monitoring stack's Tempo instead of failing every export.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-28 14:31:48 +02:00
not 1489f68796 docs(arch): ADR-0035 — publish the stack through the existing labs Caddy (closes #177) (#185)
CI / k8s (push) Successful in 8s
CI / build (push) Successful in 1m43s
CI / lint (push) Successful in 2m1s
CI / unit (push) Successful in 1m41s
CI / frontend (push) Successful in 2m28s
Deploy to Talos / deploy (push) Successful in 2m26s
CI / mutation (push) Successful in 4m58s
CI / verify-stack (push) Canceled after 7m18s
## What & why

ADR-0035 records the decision issue #177 asked for, which went the other way from its proposal. The stack is published through the **existing labs Caddy** over a reverse SSH tunnel, not through an in-cluster Caddy edge. The deciding facts: the Talos hypervisor sits behind office NAT with no inbound path, and the labs Caddy already holds 80/443 and the `*.labs.respellion.tech` wildcard certificate.

The ADR covers the chain (Caddy → `openssh-server` → tunnel → NodePorts), `keycloakUrl` / `big.keycloakUrl`, `KC_PROXY_HEADERS`, the optional demo OTP autofill, the alternatives (including the closed PR #178), and the costs: routing outside the cluster, two SSH hops, a single issuer string, public demo portals, and 401s after a Keycloak restart.

- `docs/architecture/adr-0035-public-access-through-the-labs-caddy.md` (new)
- `mkdocs.yml`: nav entry (`check-docs-nav.py` passes)
- `docs/runbooks/kubernetes-talos.md`: links the ADR from "Publishing through the labs Caddy"

Closes #177

## Definition of Done

- [x] Linked Gitea issue (above).
- [x] Conventional Commit referencing the issue.
- [ ] CI green
- [x] ADR added in `docs/architecture/`.

## Notes for reviewers

- The number 0035 was used in the unmerged #178 for the in-cluster ADR. That ADR never reached `main`, so the number is free there.
- Implementation PRs: #179, #180, #181. Related CI fixes: #183, #184.

🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #185
2026-09-28 12:30:11 +00:00
7 changed files with 48 additions and 8 deletions
+11
View File
@@ -98,6 +98,17 @@ jobs:
[ -n "${GITHUB_STEP_SUMMARY:-}" ] || exit 0
python3 infra/trx-summary.py TestResults >> "$GITHUB_STEP_SUMMARY"
# The docs site must build with --strict (#173). setup-python so `make docs` can
# create its venv regardless of what the runner image ships.
docs:
runs-on: ubuntu-latest
steps:
- uses: https://github.com/actions/checkout@v4
- uses: https://github.com/actions/setup-python@v5
with:
python-version: '3.12'
- run: make docs
# Frontend (Nx/Angular) lane: install with pnpm, then Nx lint + test + build.
frontend:
runs-on: ubuntu-latest
+4 -1
View File
@@ -34,6 +34,9 @@ jobs:
# `true` fills in the medewerker OTP step for the public demo (chart value
# demo.otpAutofill). The fixture secret is committed: demo only.
OTP_AUTOFILL: ${{ vars.OTP_AUTOFILL }}
# Tempo for the services' traces, e.g. http://tempo.monitoring.svc:4317 (the
# cluster monitoring stack, Infra repo). Empty = the chart default.
OTEL_ENDPOINT: ${{ vars.OTEL_ENDPOINT }}
steps:
- uses: https://github.com/actions/checkout@v4
@@ -100,7 +103,7 @@ jobs:
make k8s-reseed \
TALOS_HOST=${TALOS_HOST:-localhost} \
K8S_REGISTRY=${TALOS_VM_IP:-192.168.122.173}:30500 \
K8S_SET="${KEYCLOAK_URL:+--set keycloakUrl=$KEYCLOAK_URL} --set demo.otpAutofill=${OTP_AUTOFILL:-false}"
K8S_SET="${KEYCLOAK_URL:+--set keycloakUrl=$KEYCLOAK_URL} --set demo.otpAutofill=${OTP_AUTOFILL:-false}${OTEL_ENDPOINT:+ --set otelEndpoint=$OTEL_ENDPOINT}"
# `dev` is a mutable tag and helm sees an unchanged pod template, so the
# new images only land on a restart (pullPolicy is already Always).
+4
View File
@@ -61,3 +61,7 @@ __pycache__/
TestResults/
test-output/
tests/e2e/playwright-report.json
# MkDocs build (`make docs`)
.venv-docs/
site/
+11 -2
View File
@@ -43,11 +43,11 @@ export DOCKER_HOST := unix://$(PODMAN_SOCK)
endif
endif
.PHONY: ci lint build unit mutation frontend integration verify verify-up verify-acl verify-nrc verify-projection verify-bff verify-domain verify-observability verify-tracing verify-metrics verify-objecttypen verify-objecten verify-registerrecord verify-objecten-notifications verify-notifications smoke up down local verify-local local-down changelog openzaak-up openzaak-smoke openzaak-seed openzaak-down stack-up stack-smoke stack-down keycloak-up keycloak-smoke keycloak-down flowable-up flowable-smoke flowable-down k8s-lint k8s-drift k8s-registry k8s-images k8s-seed k8s-up k8s-reseed k8s-portals k8s-down k8s-purge help
.PHONY: ci lint build unit mutation frontend docs integration verify verify-up verify-acl verify-nrc verify-projection verify-bff verify-domain verify-observability verify-tracing verify-metrics verify-objecttypen verify-objecten verify-registerrecord verify-objecten-notifications verify-notifications smoke up down local verify-local local-down changelog openzaak-up openzaak-smoke openzaak-seed openzaak-down stack-up stack-smoke stack-down keycloak-up keycloak-smoke keycloak-down flowable-up flowable-smoke flowable-down k8s-lint k8s-drift k8s-registry k8s-images k8s-seed k8s-up k8s-reseed k8s-portals k8s-down k8s-purge help
## ci: run the full pipeline — lint, build, unit, mutation, frontend, verify (mirrors Gitea Actions)
## `verify` is the live-stack stage (full stack up once → ACL + notification checks).
ci: lint build unit mutation frontend verify
ci: lint build unit mutation frontend docs verify
## frontend: install deps and run the Nx lint/test/build for the portals (pnpm + Node required)
# Tests run in their own phase, ahead of the build. The @angular/build:unit-test
@@ -81,6 +81,15 @@ unit:
python3 infra/test_playwright_summary.py
python3 infra/test_portal_caddyfiles.py
## docs: build the MkDocs site with --strict (a broken link or nav entry fails)
# Pinned in a throwaway venv: Material 9.7 is the last line on MkDocs 1.x, and MkDocs
# 2.0 drops the plugin/theme system this site relies on. Publishing is a separate
# decision (#173); this only proves the site builds.
docs:
python3 -m venv .venv-docs
.venv-docs/bin/pip install --quiet mkdocs==1.6.1 mkdocs-material==9.7.7
.venv-docs/bin/mkdocs build --strict
## mutation: run the Stryker.NET ratchet on each service with branching logic (fails below baseline)
# Stryker is pinned as a local dotnet tool (.config/dotnet-tools.json); `tool restore`
# makes `make mutation` work from a fresh clone. Each service owns its config + break
+5 -1
View File
@@ -19,6 +19,7 @@ and CI cannot drift:
| `build` | `make build` → `dotnet build … -c Release` | .NET 10 SDK |
| `unit` | `make unit` → `dotnet test … -c Release --filter "Category!=Integration"` | .NET 10 SDK |
| `frontend` | `make frontend` → Nx lint/test/build for the four portals | pnpm + Node |
| `docs` | `make docs` → `mkdocs build --strict` in a pinned venv (fails on a broken link or nav entry; the site is not published yet, #173) | Python 3 |
| `k8s` | `make k8s-lint` (render + schema-check the Helm chart) → `make k8s-drift` (chart still describes the same stack as `infra/docker-compose.yml`) | pinned `helm` binary + `docker compose` |
| `mutation` | `make mutation` → `dotnet tool restore` → `dotnet stryker` (ACL); uploads the HTML report as an artifact | .NET 10 SDK |
| `verify-stack` | **push to `main` only, skipped on PRs** (#182) — the single live-stack stage — steps: `make verify-up` (full stack up + health, the DoD smoke) → `make verify-acl` (ACL ↔ OpenZaak) → `make verify-nrc` (OpenZaak → NRC delivery) → `make down` | container engine + egress (base images, nuget, `selectielijst.openzaak.nl`) |
@@ -57,9 +58,12 @@ dotnet tool (`.config/dotnet-tools.json`), so it runs identically locally and in
make mutation # dotnet tool restore + dotnet stryker on the ACL
```
Config lives in [`services/acl/stryker-config.json`](../../services/acl/stryker-config.json).
Config lives in `services/acl/stryker-config.json`.
It runs in **solution mode** against `Acl.slnx`, mutating the two projects under test
(`Acl.Application`, `Acl.Infrastructure`); `Acl.Api` has no tests and is skipped.
`Acl.slnx` leaves out `Acl.IntegrationTests`: it needs a live OpenZaak, and Stryker
runs every test project in the solution, so keeping it in makes 8 tests fail in the
initial run (#174).
**Baseline (the ratchet):** the ACL is the first service with branching logic, so it
sets the repo-wide baseline. Observed score **95%**; enforced `break` threshold **90%**
+10 -3
View File
@@ -30,6 +30,12 @@ host: 192.168.122.100
# portals' authority (runbook, "Publishing through the labs Caddy").
keycloakUrl: ""
# Where the .NET services send traces (OTLP gRPC). The default is the chart's own
# `tempo` workload (off by default, like compose). Point it at a Tempo outside the
# release, e.g. the cluster monitoring stack's http://tempo.monitoring.svc:4317 —
# with no Tempo at all, every export fails and is counted as a .NET exception.
otelEndpoint: http://tempo:4317
demo:
# Fill in and submit the medewerker OTP step from the fixture secret, so a public
# demo shows MFA enforced without an authenticator: makes the big-demo theme
@@ -160,10 +166,11 @@ envGroups:
NOTIFICATIONS_DISABLED: "false"
RUN_SETUP_CONFIG: "true"
# Traces for the .NET services. Always set, like compose: the exporter fails
# harmlessly when Tempo is absent (services/*/Program.cs).
# Traces for the .NET services. Always set, like compose. With no Tempo behind
# `otelEndpoint` the exporter fails quietly but throws on every batch, which
# shows up as HttpRequestException/SocketException in dotnet_exceptions_total.
otel:
OTEL_EXPORTER_OTLP_ENDPOINT: http://tempo:4317
OTEL_EXPORTER_OTLP_ENDPOINT: '{{ .Values.otelEndpoint }}'
OTEL_EXPORTER_OTLP_PROTOCOL: grpc
# ── Workloads ──────────────────────────────────────────────────────────────────
+3 -1
View File
@@ -1,7 +1,9 @@
<Solution>
<!-- Stryker-only. Acl.IntegrationTests is left out on purpose: it needs a live
OpenZaak, so in the mutation job it fails its initial run (#174). The root
register-referentie.slnx still builds and lints it. -->
<Project Path="Acl.Api/Acl.Api.csproj" />
<Project Path="Acl.Application/Acl.Application.csproj" />
<Project Path="Acl.Infrastructure/Acl.Infrastructure.csproj" />
<Project Path="Acl.IntegrationTests/Acl.IntegrationTests.csproj" />
<Project Path="Acl.Tests/Acl.Tests.csproj" />
</Solution>