head
Categories:
-
Move project landings into the main site
Publish every registered project’s visitor-facing landing page at /projects/
/ from the main site instead of a dedicated subdomain, and retire the per-project Pages repository, CNAME, and Terraform DNS stage that existed only to serve one page derived from the project README. Each project owns its landing content in projects/
/site/content/ as pure content: no layouts, styles, or build rules. The main site packages those directories into content/projects/ / from the registry in projects/projects.bzl, so membership is declared once. The landing is a short hand-written page for visitors while the README keeps its /docs/projects/ / URL for repository reference documentation, and landing front matter now feeds the statuses, languages, and tags taxonomies. Merge the reusable hugo_landing project into the main site: its shared canvas and accent styles and its landing page rules move into the apex tree, and its landing macro, generated configuration, standalone publisher, and repository-relative rewrite layouts are removed. The theme keeps owning the taxonomy and term layouts, which are richer than the heading-only versions the reusable project carried. Remove the now-unused apex deploy_project.sh and deploy_all.sh landing publishers with it.
Retire the per-project publication and DNS ownership: the project landing targets and the landing deployment command, each landing project’s dnsconfig.json and Terraform root, the build plumbing that served only those stages, and the landing repository and Pages membership in the repository catalog. The apex Terraform root is retained because it also declares VM resources, and no Vault configuration is changed.
Replace the provider-snapshot zone files with generated declaration pages, one per destination view, that project the checked-in declarations and are verified for freshness by the DNS offline check. The DNS linter, both destination pages, the apex site, the skills projection, and the repository quality suite pass, and the whole repository builds.
OpenSpec-Change: projects/alwaldend.com/openspec/changes/consolidate-project-landings-into-apex
LLM-disclaimer: This commit was generated by an LLM.
-
Manage forge resources with hermetic Terraform rules
Centralize organization, repository, and named access configuration in infra/repos. Adopt existing GitHub resources, protect master defaults while retaining Pages publication on pages, and preserve existing repository identities. Manage GitLab one-time imports, the F-Droid metadata fork, and default-branch protections through Vault-backed authentication. Forgejo consumes the same catalog. Ongoing repository synchronization is deferred.
Retire the eleven Bazel rule landing sites through their owning Terraform workflows, removing their DNS records, Pages repositories, and landing configuration. Move all twelve existing standalone rule modules into tools/ and retain their public interfaces and documentation on the main site.
Add tools/rules_terraform with verified provider downloads, packed mirrors in runfiles, and reusable Terraform execution rules. Enforce one version per provider source at an extensible resolution boundary. Migrate every Terraform consumer to thirteen shared provider pins in third_party/terraform. Execution and command maps belong to rules_terraform; consumers explicitly select generic AL wrappers for authentication and Vault injection. Remove tools/terraform and all 43 checked-in Terraform provider locks. Validate installed providers against the declared archives before execution.
Validation covers all fourteen workspace builds, all thirteen standalone test suites, Terraform consumers, offline real-provider regressions, rendered documentation, formatting, and semantic lint. The full root test run has 295 passing tests and one skip; its only failure is the historical secret scan, reduced to four pre-existing synthetic fixture matches. Earlier live imports and the exact landing retirement scope have verified postconditions; the Terraform rules migration uses only offline implementation checks.
OpenSpec-Change: infra/repos/openspec/changes/archive/2026-09-13-adopt-shared-repository-catalog OpenSpec-Change: infra/src/openspec/changes/archive/2026-09-13-retire-bazel-rule-landings OpenSpec-Change: tools/rules_terraform/openspec/changes/archive/2026-09-14-add-hermetic-terraform-rules OpenSpec-Change: tools/rules_terraform/openspec/changes/archive/2026-09-14-correct-terraform-ownership
LLM-disclaimer: This commit was generated by an LLM.
-
Deploy project DNS through Terraform modules
Move DNS ownership into each project’s Terraform state using shared modules. Load dnsconfig.json files at runtime, reject conflicting domain ownership, and render their records as a table. Add missing project AppRoles and scoped DNS policies, and document grouping related Terraform resources in modules.
Deploy all 45 owners sequentially: adopt 155 existing records and create 13 missing OpenHands records. Preserve every pre-existing provider record and verify no-op follow-up plans and DNS answers. Add DNS-scoped plan/show/apply wrappers with a saved-plan guard for roots that also manage services. Allow bounded aggregate path inventories large enough to deliver this migration while retaining truncation refusal in the delivery tool.
Validate runtime ownership, provider imports and preservation with isolated fixtures, Terraform formatting, wrapper builds, repository quality checks, semantic lint, and project documentation/specification builds.
OpenSpec-Change: infra/dns/openspec/changes/archive/2026-09-13-migrate-project-dns-to-terraform
LLM-disclaimer: This commit was generated by an LLM.
-
Fix Android review feedback
Add a shared
androidPluginsversion catalog so both Android apps declare the AGP, Kotlin, Compose, and protobuf plugin versions once, and derive their versions from it instead of duplicating literals per root Gradle file.Align the launcher and ingester app versions with the repository versioning contract: development builds use
0.0.0-devwithversionCode1 in both the Gradle default config and the Bazelmanifest_values.Ignore the whole materialized
.agents/skillsdirectory in Prettier because every entry is either a source-tree symlink or a byte-pinned external archive copy.Apply the ingester’s themed surface background to the main content surface so the status bar area follows the system theme, not a default white surface.
Token: z-ai-glm-flash-latest
LLM-disclaimer: This commit was generated by an LLM.
-
Add spellcheck skill
This commit was generated by an LLM.
-
Restore light and dark site canvases and set the shared accent
The shared Docsy canvas set the same Bootstrap dark palette and the same black page background on
:root,[data-bs-theme="light"], and[data-bs-theme="dark"], so the light/dark toggle changed nothing. The site also rendered Bootstrap’s stock blue instead of its intended accent.Split the shared palette so light mode uses a pure white canvas with the light-mode palette and dark mode uses a pure black canvas with the dark-mode palette, and keep the pre-stylesheet paint and footer on the active mode. Assign
$primaryto#7c3aedbefore Bootstrap compiles, so links, buttons, badges, focus rings, and the dark-mode link tint all derive from one value rather than from a site-local copy.Both files stay in the reusable shell; the apex site consumes them through the existing declared exports and no longer carries the footer’s own blue.
OpenSpec-Change: projects/hugo_landing/openspec/changes/restore-light-dark-canvas-and-accent
LLM-disclaimer: This commit was generated by an LLM.