Skip to content

feat(recipes): add recipe contract v3 - #65

Merged
NovusEdge merged 49 commits into
mainfrom
feat/recipe-contract-v3
Sep 5, 2026
Merged

NovusEdge merged 49 commits into
mainfrom
feat/recipe-contract-v3

Conversation

@NovusEdge

@NovusEdge NovusEdge commented Sep 5, 2026 •

Copy link
Copy Markdown
Owner

What changed

Add typed recipe parameters, separate private secret storage, declared outputs,
and health checks across SSH/cloud-init provisioning, CLI status/logs/wait,
the TUI parameter form, bundled recipes, and annotated samples.

Includes regression coverage for SSH argument joining, quoted output read-back,
and the Alpine XFCE X-server setup fix also tracked in #66.

Why

Recipe configuration and health are now explicit contracts instead of manual
script edits. Preserve schema2 recipes, the existing recipes name list, and
JSON contract2 with additive recipe-detail fields.

Tests run

  • At 26c52dc: go build ./... && go test ./... && golangci-lint run ./...
    passed once; lint reported 0 issues.
  • At 26c52dc: Debian 13 cloud check passed once, including cloud-init,
    parameter delivery, child-process secret export, transient-secret removal,
    output discovery, parameter-triggered SSH re-apply, health, public-reader
    redaction, and private seed permissions.
  • At 305a1dd: Alpine disk e2e passed once after restoring X-server setup.
    The run verified the installed ext4 root, XFCE, udev, Xorg/libinput, Docker
    and redaction-fixture outputs, healthy wait, secret masking in apply/log/status
    readers, and the parameter-change dry-run assertion.

The unit gate and Debian check were not repeated after the Alpine-only fix.
Earlier validation at a02cd93 included vet, tidy, formatting, Just lint,
ShellCheck, and Python MCP tests (131 passed, 4 existing warnings). The last
race run passed at c698919; no race refresh was run in this follow-up.
A fresh whole-branch review remains pending; all three earlier chunk reviews
were approved.

Live output

Debian 13 cloud check (26c52dc, exit 0):

cloud-e2e-1213786 reached reachable (14347ms)
cloud-e2e-1213786 reached healthy (203ms)
updated cloud-e2e-1213786: [params]
cloud-e2e-1213786 is running; this takes effect at next start
cloud-e2e-1213786 reached healthy (265ms)
PASS: Debian13 cloud params, child secret export, outputs, health, redaction, and private seed modes

Alpine disk e2e (305a1dd, exit 0):

=== assert: Xorg drives input through libinput (mouse clickable) ===

PASS: e2e-1231512 reached a clickable xfce desktop with no manual steps

=== assert: docker recipe contract ===
updated e2e-1231512: [recipes params]
e2e-1231512 is running; this takes effect at next start
e2e-1231512 reached healthy (744ms)

=== assert: non-secret param reruns ===
updated e2e-1231512: [params]
e2e-1231512 is running; this takes effect at next start
stopping e2e-1231512...
e2e-1231512 stopped
e2e-1231512 deleted

Test guests used isolated data roots, headless VNC, 2048 MiB RAM, and 2 CPUs.
Both successful guests were stopped and deleted; runner logs are retained
locally. No existing user VM or daemon was changed.

OS matrix

  • Alpine disk, XFCE plus Docker and synthetic secret: passed at 305a1dd.
  • Debian 13 cloud, including SSH re-apply output read-back: passed at 26c52dc.
  • Other guest variants and live Tailscale authentication: not tested.

Docs

CLI and JSON references, canonical annotated samples, and cloud secret-storage
notes updated. Host secret-bearing seed files remain owner-only; guest
transient delivery is removed after recipe commands. No host-seed deletion or
disk-detach behavior is promised.

Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Cover explicit schema compatibility, schema-2 v3 blocks, and health timeout presence. Assert SaveSecrets preserves an empty recipe entry in its caller-owned map.

Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
@NovusEdge NovusEdge added enhancement New feature needs-live-boot Cannot be verified by agents; needs a real Alpine boot tui Terminal UI: layout, styling, interaction recipes bundled or index recipes labels Sep 5, 2026
@NovusEdge NovusEdge self-assigned this Sep 5, 2026
@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
PR #48 merged install-alpine.sh into install.sh and dropped its setup-xorg-base call. Alpine's xfce4 metapackage does not depend on xorg-server or xinit, so tty1 looped on 'startx: not found' and the e2e libinput assert failed.

Signed-off-by: NovusEdge <novusedge0@gmail.com>
@NovusEdge
NovusEdge marked this pull request as ready for review September 5, 2026 09:26
@NovusEdge
NovusEdge merged commit 752eac7 into main Sep 5, 2026
5 of 6 checks passed
@NovusEdge NovusEdge mentioned this pull request Sep 5, 2026
4 tasks done
@NovusEdge
NovusEdge deleted the feat/recipe-contract-v3 branch September 5, 2026 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature needs-live-boot Cannot be verified by agents; needs a real Alpine boot recipes bundled or index recipes tui Terminal UI: layout, styling, interaction

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant