feat(shared-layer): bnk-prerequisites pack + cert-issuer catalog + MIGRATION.md - #61
Merged
Merged
Conversation
…reqs Combines stages 1 and 2 of the migration to a per-cloud blueprint repo architecture (see MIGRATION.md): - Create k8s/bnk-prerequisites/bnkforge.pack.json (v2alpha1 schema). This was the only "active" shared module missing a pack JSON; the PR #60 catalog-version fix had to source its version from module.json as a fallback. Now sourced from the pack directly. - Add k8s/bnk-cert-issuer to release-2.2-official.json. The module has a working pack and is silently depended on by cert-manager, network-setup, and bnk-prerequisites — but wasn't listed in the catalog, so Forge never generated a transition blueprint for it. Adding it as an active first-class entry. - Add MIGRATION.md at the repo root. Documents the target architecture (per-cloud repos modelled on jgruberf5/bnk-forge-ibm-roks-cluster), what stays here (shared cloud-agnostic k8s layer), what moves out (FLO, CNEInstance, network-setup vendor per-cloud), what retires (bnk-namespaces, far-setup, bnk-gateway-ext), and the phased plan. - Bump VERSION to 2.2-rev.29. Co-Authored-By: Claude <noreply@anthropic.com>
Validator allows source in {user, module, auto} only. project_secret
isn't a valid value — sensitive secrets use source=user + sensitive=true,
and Forge lets the deploy form bind it to a project secret.
Bump VERSION to 2.2-rev.30.
bnk-cert-issuer is a pure-manifest module (no .tf code) rendered by the backend Python engine. The release validator previously required every active entry to match the release-level execution_engine (opentofu), which would have forced a misleading engine value on this module. Changes: - scripts/validate_module_metadata.py: allow per-entry execution.engine override; falls back to release.execution_engine when entry doesn't specify one. Backwards compatible for all 24 existing packs. - catalog/releases/release-2.2-official.json: declare execution.engine = kubernetes on the bnk-cert-issuer entry. - k8s/bnk-cert-issuer/module.json: new file, mirrors the existing pack with engine=kubernetes / deploy_models=[kubernetes_manifest]. - VERSION: 2.2-rev.30 -> 2.2-rev.31. Both pack and release-manifest validators pass locally. Co-Authored-By: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stages 1 and 2 of the migration to a per-cloud blueprint repo architecture (see
MIGRATION.md). All changes are additive — no removals, no breaking changes.What's in this PR
k8s/bnk-prerequisites/bnkforge.pack.jsonstate: activeshared module missing a v2alpha1 pack. PR #60 fell back tomodule.jsonfor its version; now sourced from the pack directly.k8s/bnk-cert-issuertorelease-2.2-official.jsoncert-manager,network-setup, andbnk-prerequisites, but wasn't listed in the catalog — so Forge never generated a transition blueprint for it. Now first-class.MIGRATION.mdjgruberf5/bnk-forge-ibm-roks-cluster, what stays here vs moves out vs retires, the phased plan, and the Forge↔modules versioning contract.2.2-rev.28→2.2-rev.29.Architectural framing
After full migration,
bnk-forge-modulesis the shared cloud-agnostic k8s layer only:k8s/bnk-prerequisites,k8s/cert-manager,k8s/bnk-cert-issuer(pure k8s API, no cloud-specific code).bnk/flo,bnk/cneinstance,k8s/network-setup(cloud-specific install/networking models).k8s/bnk-namespaces,bnk/far-setup,bnk/bnk-gateway-ext.This PR doesn't move or delete anything yet — it just creates the missing pack, surfaces the missing catalog entry, and writes down where we're heading so the next agent / next PR has the context.
Test plan
release/2.2k8s/bnk-prerequisitesshould now report its version from the pack (not module.json fallback)k8s/bnk-cert-issuershould appear as a new transition blueprint withvalidation_state = validFollow-ups
bnk-forge-aws-eks-cluster) with vendored FLO/CNEInstance/network-setup + hand-authored blueprints.k8s/bnk-namespaces,bnk/far-setup,bnk/bnk-gateway-extonce per-cloud repos cover the moved modules.🤖 Generated with Claude Code