2026-03-10T17:42:57Z - 2026-09-10T17:42:57Z

Overview

68 active pull requests
69 active issues
Excluding merges, 2 authors have pushed 5 commits to main and 237 commits to all branches. On main, 2 files have changed and there have been 6 additions and 4 deletions.

4 releases published by 2 users

Published 0.3.1 2026-07-25 10:32:17 +00:00

Published 0.3.0 0.3.0 2026-07-21 18:06:51 +00:00

Published 0.2.0 0.2.0 2026-07-19 23:04:21 +00:00

Published 0.1.0 0.1.0 2026-07-19 18:03:35 +00:00

68 pull requests merged by 5 users

Merged #140 fix: refuse a PATH without /usr/sbin, before the token prompt 2026-08-02 07:57:52 +00:00

Merged #146 fix: slim ubuntu-latest default; install shellcheck in ci.yml (#144) 2026-08-01 23:23:41 +00:00

Merged #137 test: cli.sh reads fixtures, not the host it happens to run on 2026-07-31 21:24:04 +00:00

Merged #132 docs: README install quick start names the Forgejo channel (RIG_HOST) 2026-07-31 21:17:59 +00:00

Merged #130 feat(drill): a forgejo-runner lifecycle leg beside the GitHub one 2026-07-31 20:56:18 +00:00

Merged #134 fix(forgejo-runner): 'active' is not proof the runner is fetching 2026-07-31 20:55:19 +00:00

Merged #138 fix(forgejo-runner): the cache server can start 2026-07-31 20:35:33 +00:00

Merged #128 fix: align Ceremony actors with Forgejo 2026-07-30 22:57:19 +00:00

Merged #114 feat: install channel is forge-agnostic (RIG_HOST / BOX_HOST) 2026-07-30 17:00:21 +00:00

Merged #113 fix: rig's ceremony CI guards resolve on Forgejo 2026-07-29 13:37:34 +00:00

Merged #110 feat: Forgejo-native CI — a ci-box tenant and a forgejo-runner command family 2026-07-28 19:58:37 +00:00

Merged #101 release: 0.3.0 2026-07-21 18:06:51 +00:00

Merged #104 refactor: one drill record per version, in drills/ 2026-07-21 17:41:34 +00:00

Merged #102 feat: CI refuses a release PR with no drill record 2026-07-21 16:23:34 +00:00

Merged #100 docs(changelog): one line per entry, and a pass over the whole file 2026-07-21 14:44:03 +00:00

Merged #93 fix: don't read a missing /run/sshd as a broken sshd config 2026-07-21 13:07:35 +00:00

Merged #99 fix: catch a deleted or duplicated release heading in CHANGELOG.md 2026-07-20 23:36:37 +00:00

Merged #97 fix(labels): sweep on labeled so the handoff is immediate 2026-07-20 20:32:44 +00:00

Merged #94 docs(contributing): document the blocker axis and merge-next ownership 2026-07-20 19:27:32 +00:00

Merged #91 docs: align README quick start with main 2026-07-20 18:41:13 +00:00

Merged #90 refactor(labels): split PR labels into state and blocker axes 2026-07-20 18:30:07 +00:00

Merged #88 fix(labels): state:needs-human means a human could merge it right now 2026-07-20 17:02:57 +00:00

Merged #84 feat: /etc/rig/manifest — which rig converged this machine, and when 2026-07-20 13:06:01 +00:00

Merged #74 feat: rig platform — what is this machine, computed not stored 2026-07-20 12:46:00 +00:00

Merged #81 test: pin the at-risk gate's floor at one operator 2026-07-20 12:36:55 +00:00

Merged #73 fix: gate 'users apply' on an empty file that would revoke everyone 2026-07-20 12:36:36 +00:00

Merged #82 test: widen the read-guard sweep to bin/ and to plain-statement reads 2026-07-20 12:24:24 +00:00

Merged #72 fix: uninstall_confirm swallows Ctrl-D — the abort was silent 2026-07-20 12:23:51 +00:00

Merged #71 fix: lint .github/scripts with dotglob, and assert the sweep is total 2026-07-20 12:16:57 +00:00

Merged #83 feat(users)!: --class human|server becomes --root-door closed|open 2026-07-20 12:05:47 +00:00

Merged #80 feat(bootstrap)!: box tenant roles carry a -box suffix 2026-07-20 12:05:25 +00:00

Merged #79 feat(bootstrap)!: machine roles carry a -server suffix; staging-server restored 2026-07-20 12:05:07 +00:00

Merged #69 release: 0.2.0 2026-07-19 23:04:22 +00:00

Merged #67 fix(release): re-arm the changelog heading, and guard it against VERSION (#66) 2026-07-19 21:06:49 +00:00

Merged #59 fix(bootstrap): refuse a users file that names no users 2026-07-19 19:46:12 +00:00

Merged #54 feat!: bootstrap takes the users file 2026-07-19 19:17:45 +00:00

Merged #53 feat: users apply grants the box tier, not just the socket 2026-07-19 19:12:10 +00:00

Merged #55 fix: dropping the box role revokes through box, not behind its back 2026-07-19 19:08:00 +00:00

Merged #60 fix(users): the host= marker gates the box role, not the incus group 2026-07-19 19:02:12 +00:00

Merged #46 release: 0.1.0 2026-07-19 18:03:35 +00:00

Merged #48 feat: merging a release-labeled PR is the release 2026-07-19 17:12:10 +00:00

Merged #45 fix: the release suite accepts the ceremony's own tree 2026-07-19 14:22:15 +00:00

Merged #43 fix: headless credential prompts refuse loudly, naming their variable 2026-07-19 13:00:48 +00:00

Merged #41 install: derive $HOME from getent when the environment has none (#39) 2026-07-18 23:53:21 +00:00

Merged #40 feat: release flow — CHANGELOG, release.yml, and a tag-resolving installer (#32) 2026-07-18 22:17:13 +00:00

Merged #37 feat(bootstrap): box tenant roles — claude, codex, grok, staging (#31) 2026-07-18 20:32:13 +00:00

Merged #38 fix: base the human auto-request on this handoff, not review history 2026-07-18 20:31:51 +00:00

Merged #36 feat(install): versioned installs and a real uninstall — box#79's layout, ported (#35) 2026-07-18 20:18:05 +00:00

Merged #34 feat: label automation — state reconciler, path-scoped labeler, and CONTRIBUTING 2026-07-18 20:02:56 +00:00

Merged #33 docs: LABELS.md — the label taxonomy (states, stale/blocked, scopes) 2026-07-18 18:20:07 +00:00

Merged #30 users: finish #17 — close-root proves the door (sudo -n, per-user sshd -T), @root key seeding, runner row owned 2026-07-18 17:39:35 +00:00

Merged #29 feat: the #12/#25 remnants — README class table + box rename, unpinned-install note, box effective check, coolify marker warnings 2026-07-18 17:36:33 +00:00

Merged #28 feat(bootstrap): host-class machines install box + run setup-host (#12, #25) 2026-07-18 00:25:20 +00:00

Merged #23 feat(bootstrap): staging role — host archetype for box-minted staging VMs 2026-07-17 21:24:53 +00:00

Merged #27 Machine traits + fleet users: class/host/join presets and rig users apply/status/close-root (#26 + #24) 2026-07-17 21:24:51 +00:00

Merged #18 feat(db): bring ad-hoc dump/restore on-box as rig db (Closes #15) 2026-07-17 15:55:17 +00:00

Merged #20 bootstrap: infer the tailnet tag from the pre-auth key — verify the tag granted, not the one requested 2026-07-17 15:47:12 +00:00

Merged #14 fix(runner): install refuses a box registered to another repo 2026-07-13 20:00:46 +00:00

Merged #11 feat(runner): status, remove, and repoint — the runner lifecycle verbs 2026-07-13 13:33:11 +00:00

Merged #10 fix(coolify): validate the dump bindings, and stop printing $EDITOR 2026-07-12 19:59:21 +00:00

Merged #9 feat(coolify): install the control-plane dump as a systemd timer 2026-07-12 19:16:53 +00:00

Merged #7 fix(bootstrap): converge the tailnet hostname on an already-joined box 2026-07-12 17:00:32 +00:00

Merged #6 fix(bootstrap): sshd hardening never applied on cloud images 2026-07-12 15:31:35 +00:00

Merged #5 fix: source /etc/os-release in a subshell — it clobbers $VERSION 2026-07-11 19:39:32 +00:00

Merged #4 feat: runner follow-ups — bootstrap role + latest-version resolution 2026-07-11 18:46:57 +00:00

Merged #3 feat: runner install — GitHub Actions runner as an unprivileged systemd service 2026-07-11 18:19:00 +00:00

Merged #2 fix: bootstrap installs openssh-server (pristine images lack sshd_config.d) 2026-07-11 10:39:32 +00:00

Merged #1 feat: rig CLI — bootstrap, coolify install, curl installer 2026-07-11 08:34:50 +00:00

59 issues closed from 4 users

Closed #115 Forgejo Actions runner — make rig workflows execute 2026-08-17 23:23:21 +00:00

Closed #133 rig forgejo-runner status reports (active) as health — a poller that has gone quiet looks identical to a working runner 2026-08-17 23:23:07 +00:00

Closed #145 ceremony automation cannot run on Forgejo — the reconcilers are built on gh, which speaks an API Forgejo does not serve 2026-08-17 23:20:50 +00:00

Closed #139 rig admin commands assume /usr/sbin is on PATH — a stock su root shell dies with 'useradd: command not found', after prompting for a token 2026-08-02 07:57:53 +00:00

Closed #144 rig default label maps ubuntu-latest to a slim image that cannot run rig own CI — ci/check fails on shellcheck 2026-08-01 23:51:49 +00:00

Closed #136 test/cli.sh is not hermetic — 13 checks fail on any box that has a Forgejo runner installed 2026-07-31 21:24:06 +00:00

Closed #131 README's install quick start has no Forgejo channel — RIG_HOST shipped in #111 and is documented nowhere 2026-07-31 21:17:59 +00:00

Closed #135 rig-installed Forgejo runners have their cache server disabled — ProtectHome=read-only vs $HOME/.cache 2026-07-31 20:35:34 +00:00

Closed #116 Ceremony on Forgejo — align actors and bootstrap the issue-flow taxonomy 2026-07-30 22:57:20 +00:00

Closed #120 Eight core taxonomy labels are absent — the work queue cannot be expressed and needs-ruling cannot be set 2026-07-30 17:39:08 +00:00

Closed #118 The core label taxonomy is incomplete in this repo — the work-queue labels do not exist 2026-07-30 17:38:47 +00:00

Closed #122 .github/labels.conf's panel= names four accounts that do not exist on this instance 2026-07-30 17:38:18 +00:00

Closed #119 .github/labels.conf names panel and triage identities that do not exist on this instance 2026-07-30 17:37:20 +00:00

Closed #121 No Actions runner has ever served this repo — every check on every commit is permanently pending 2026-07-30 17:36:59 +00:00

Closed #117 No Forgejo Actions runner is attached to this repo — CI, the label reconciler, and the release flow have never run 2026-07-30 17:36:22 +00:00

Closed #125 bootstrap's BOX_MANUAL is not a pasteable command when a host has two candidates 2026-07-30 17:34:07 +00:00

Closed #111 rig's own install channel still hardcodes GitHub (install.sh, bootstrap's box fetch) 2026-07-30 17:00:22 +00:00

Closed #126 Forgejo has no discussions — triage's intake door has no surface on this instance 2026-07-29 21:09:55 +00:00

Closed #112 rig's ceremony actions won't resolve on Forgejo — make the 8 first-party uses: absolute 2026-07-29 13:37:34 +00:00

Closed #109 Forgejo-native CI: a ci-box tenant and a forgejo-runner command family 2026-07-28 19:58:37 +00:00

Closed #92 URGENT: sshd -t failing for a missing /run/sshd is reported as 'sshd rejects the merged config' — bootstrap blocked, stderr discarded 2026-07-21 13:07:36 +00:00

Closed #98 changelog: nothing notices a DELETED release heading — arming is green on a tree that erased a shipped section 2026-07-20 23:36:38 +00:00

Closed #96 labels: sweep on labeled so the handoff is immediate, and let the author set state:needs-human 2026-07-20 20:32:45 +00:00

Closed #89 URGENT: README on main documents unreleased role names — the documented install (0.2.0) rejects every one of them 2026-07-20 18:41:14 +00:00

Closed #87 labels: state:needs-human is sticky and blind to mergeability, and nothing says which PR to merge next 2026-07-20 17:02:58 +00:00

Closed #61 A rig-managed machine records nothing about which rig converged it, or when 2026-07-20 13:06:02 +00:00

Closed #64 rig platform: what is this machine, calculated at run time, stored nowhere 2026-07-20 12:46:01 +00:00

Closed #78 A surviving mutant un-gates the single-operator box: AT_RISK -gt 0 is not pinned 2026-07-20 12:36:56 +00:00

Closed #65 users apply cannot tell 'remove everyone' from 'I truncated the file' 2026-07-20 12:36:37 +00:00

Closed #75 The #43 read-guard sweep does not cover bin/rig, which is how #68 slipped through 2026-07-20 12:24:25 +00:00

Closed #68 uninstall_confirm swallows Ctrl-D: the abort is silent, while db.sh one file away gets it right 2026-07-20 12:23:52 +00:00

Closed #70 CI's shellcheck sweep never lints .github/scripts/*.sh — including release-lib.sh, which decides what gets published 2026-07-20 12:16:58 +00:00

Closed #77 users: --class human|server is named for who lives there, but what it decides is the root SSH door 2026-07-20 12:05:48 +00:00

Closed #76 roles: name the family in the role — -server for fleet machines, -box for box tenants 2026-07-20 12:05:08 +00:00

Closed #66 A PR that predates a release merges its Unreleased entry into the released section — silently 2026-07-19 21:06:50 +00:00

Closed #57 An empty users file converges a root-only box as silently as forgetting one 2026-07-19 19:46:13 +00:00

Closed #51 rig bootstrap should take the users file — one command, box ready 2026-07-19 19:17:46 +00:00

Closed #49 users apply grants the incus socket but never the tier — it should call box grant 2026-07-19 19:12:11 +00:00

Closed #50 users apply revokes the incus group behind box revoke's back 2026-07-19 19:08:01 +00:00

Closed #58 A host=no box with an incus group still hands out the bare socket 2026-07-19 19:02:13 +00:00

Closed #52 Rig manifest 2026-07-19 18:01:45 +00:00

Closed #56 Rollback 2026-07-19 17:58:59 +00:00

Closed #47 Merging a release-labeled PR should BE the release — auto-tag + publish on merge (box#96 twin) 2026-07-19 17:12:11 +00:00

Closed #44 test/release.sh demands an Unreleased section — the release PR of the ceremony can never pass CI 2026-07-19 14:22:16 +00:00

Closed #42 Interactive prompts die silently when stdin is not a tty — exit 1, zero output 2026-07-19 13:00:49 +00:00

Closed #39 install.sh dies on unset HOME under set -u — cloud-init runcmd has no HOME 2026-07-18 23:53:22 +00:00

Closed #32 release flow: VERSION, CHANGELOG, tagged releases, and a tag-resolving installer that pins box 2026-07-18 22:18:33 +00:00

Closed #31 rig bootstrap roles for box tenants — claude, codex, grok, staging 2026-07-18 20:32:14 +00:00

Closed #35 versioned installs and a real uninstall — rig's turn (box#79's layout, ported) 2026-07-18 20:18:06 +00:00

Closed #17 bootstrap: create an admin user, and make the root door role-aware — a uniform 'lock root' would cut Coolify off from the fleet 2026-07-18 17:39:36 +00:00

Closed #12 bootstrap: add a dev role — the Incus claudebox host is the one box rig doesn't make 2026-07-18 17:36:34 +00:00

Closed #25 Machine classes: server-class vs host-class as bootstrap's organizing axis 2026-07-18 17:36:34 +00:00

Closed #22 staging bootstrap role: host archetype for box-hosted staging VMs 2026-07-17 21:24:54 +00:00

Closed #24 rig users: declarative operators and roles across the fleet 2026-07-17 21:24:53 +00:00

Closed #26 Machine traits: roles as presets over class/host/join (supersedes #25) 2026-07-17 21:24:52 +00:00

Closed #15 rig db: bring dump/restore on-box (D-278) + close DB/backup interaction gaps 2026-07-17 15:55:18 +00:00

Closed #16 bootstrap: infer the tailnet tag from the pre-auth key — verify the tag control granted, don't assert the one rig requested 2026-07-17 15:47:13 +00:00

Closed #13 runner install: --repo is ignored when a runner is already registered — silently restarts on the OLD repo and reports success 2026-07-13 20:00:47 +00:00

Closed #8 Control-plane backup plumbing belongs in rig, not the runbook (nightly Coolify dump) 2026-07-12 19:16:54 +00:00

10 issues created by 3 users