Open the repository in its devcontainer. It provides Go, Task, golangci-lint, actionlint,
hadolint, Node, Helm, kubectl and k3d, at the versions CI uses.
task # list every task
task test # Go race tests, short fuzz runs, and Node tests for the browser helper
task lint # go vet, golangci-lint, actionlint, hadolint
task test-e2e # a real API server trusting a real Dex; see docs/testing.md
task verify # the local gate: the same checks CI runs in separate jobs- The service contract is docs/design.md. A change to a route's behavior changes that document in the same pull request.
- Kubernetes decides access. krm-foyer adds no access rules of its own; see docs/application-scope.md before proposing one.
- The browser never receives a bearer token, and the service never falls back to its own service account for a user's request.
- Preserve Kubernetes semantics: status codes,
Statuserrors, patch types and concurrency preconditions pass through unchanged. Never replay a mutation. - No application-specific endpoints. Domain logic belongs in the domain's operator and admission, not here. See docs/bff-choice.md.
- krm-foyer's own pages are server-rendered and have no JavaScript build. See docs/frontend.md.
Commit messages follow Conventional Commits, because
release-please reads them to cut versions: fix: is a patch, feat: a minor and feat!:
a breaking change. Before 1.0 a breaking change bumps the minor version.
Pushes to main keep a release pull request up to date. Merging it tags the release, and
the image ghcr.io/configbutler/krm-foyer:<version> is published once CI has passed on
that commit.
- Format with
task fmt(gofmt and goimports). - Comments explain constraints and non-obvious choices, not what the next line does.
- Test the guarantee a change promises, not only the happy path. Security boundaries need tests that try to get past them.