Skip to content

feat(shared-layer): bnk-prerequisites pack + cert-issuer catalog + MIGRATION.md - #61

Merged
JLCode-tech merged 3 commits into
release/2.2from
feat/shared-layer-scope-2.2
May 13, 2026
Merged

JLCode-tech merged 3 commits into
release/2.2from
feat/shared-layer-scope-2.2

Conversation

@JLCode-tech

Copy link
Copy Markdown
Owner

Summary

Stages 1 and 2 of the migration to a per-cloud blueprint repo architecture (see MIGRATION.md). All changes are additive — no removals, no breaking changes.

What's in this PR

Change Why
Create k8s/bnk-prerequisites/bnkforge.pack.json The only state: active shared module missing a v2alpha1 pack. PR #60 fell back to module.json for its version; now sourced from the pack directly.
Add k8s/bnk-cert-issuer to release-2.2-official.json The module has a working pack and is depended on by cert-manager, network-setup, and bnk-prerequisites, but wasn't listed in the catalog — so Forge never generated a transition blueprint for it. Now first-class.
Add MIGRATION.md Documents the target architecture: per-cloud repos modelled on jgruberf5/bnk-forge-ibm-roks-cluster, what stays here vs moves out vs retires, the phased plan, and the Forge↔modules versioning contract.
Bump VERSION 2.2-rev.28 → 2.2-rev.29.

Architectural framing

After full migration, bnk-forge-modules is the shared cloud-agnostic k8s layer only:

  • Stays here: k8s/bnk-prerequisites, k8s/cert-manager, k8s/bnk-cert-issuer (pure k8s API, no cloud-specific code).
  • Moves to per-cloud repos: bnk/flo, bnk/cneinstance, k8s/network-setup (cloud-specific install/networking models).
  • Retires in Phase 4: k8s/bnk-namespaces, bnk/far-setup, bnk/bnk-gateway-ext.

This PR doesn't move or delete anything yet — it just creates the missing pack, surfaces the missing catalog entry, and writes down where we're heading so the next agent / next PR has the context.

Test plan

  • Merge to release/2.2
  • Forge sync — k8s/bnk-prerequisites should now report its version from the pack (not module.json fallback)
  • Forge sync — k8s/bnk-cert-issuer should appear as a new transition blueprint with validation_state = valid
  • No regressions on the 8 previously-fixed blueprints from PR chore(catalog): add version field to release-2.2 modules #60

Follow-ups

  • Phase 3: scaffold first per-cloud repo (bnk-forge-aws-eks-cluster) with vendored FLO/CNEInstance/network-setup + hand-authored blueprints.
  • Phase 4: retire k8s/bnk-namespaces, bnk/far-setup, bnk/bnk-gateway-ext once per-cloud repos cover the moved modules.

🤖 Generated with Claude Code

JLCode-tech and others added 3 commits May 13, 2026 17:16
…reqs

Combines stages 1 and 2 of the migration to a per-cloud blueprint
repo architecture (see MIGRATION.md):

- Create k8s/bnk-prerequisites/bnkforge.pack.json (v2alpha1 schema).
  This was the only "active" shared module missing a pack JSON; the
  PR #60 catalog-version fix had to source its version from module.json
  as a fallback. Now sourced from the pack directly.

- Add k8s/bnk-cert-issuer to release-2.2-official.json. The module has
  a working pack and is silently depended on by cert-manager,
  network-setup, and bnk-prerequisites — but wasn't listed in the
  catalog, so Forge never generated a transition blueprint for it.
  Adding it as an active first-class entry.

- Add MIGRATION.md at the repo root. Documents the target architecture
  (per-cloud repos modelled on jgruberf5/bnk-forge-ibm-roks-cluster),
  what stays here (shared cloud-agnostic k8s layer), what moves out
  (FLO, CNEInstance, network-setup vendor per-cloud), what retires
  (bnk-namespaces, far-setup, bnk-gateway-ext), and the phased plan.

- Bump VERSION to 2.2-rev.29.

Co-Authored-By: Claude <noreply@anthropic.com>
Validator allows source in {user, module, auto} only. project_secret
isn't a valid value — sensitive secrets use source=user + sensitive=true,
and Forge lets the deploy form bind it to a project secret.

Bump VERSION to 2.2-rev.30.
bnk-cert-issuer is a pure-manifest module (no .tf code) rendered by the
backend Python engine. The release validator previously required every
active entry to match the release-level execution_engine (opentofu),
which would have forced a misleading engine value on this module.

Changes:
- scripts/validate_module_metadata.py: allow per-entry execution.engine
  override; falls back to release.execution_engine when entry doesn't
  specify one. Backwards compatible for all 24 existing packs.
- catalog/releases/release-2.2-official.json: declare
  execution.engine = kubernetes on the bnk-cert-issuer entry.
- k8s/bnk-cert-issuer/module.json: new file, mirrors the existing pack
  with engine=kubernetes / deploy_models=[kubernetes_manifest].
- VERSION: 2.2-rev.30 -> 2.2-rev.31.

Both pack and release-manifest validators pass locally.

Co-Authored-By: Claude <noreply@anthropic.com>
@JLCode-tech
JLCode-tech merged commit 894c3e4 into release/2.2 May 13, 2026
2 checks passed
@JLCode-tech
JLCode-tech deleted the feat/shared-layer-scope-2.2 branch May 13, 2026 22:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant