Skip to content

Latest commit

 

History

History
46 lines (36 loc) · 2.1 KB

File metadata and controls

46 lines (36 loc) · 2.1 KB

Contributing

Prerequisites

Open the repository in its devcontainer. It provides Go, Task, golangci-lint, actionlint, hadolint, Node, Helm, kubectl and k3d, at the versions CI uses.

task          # list every task
task test     # Go race tests, short fuzz runs, and Node tests for the browser helper
task lint     # go vet, golangci-lint, actionlint, hadolint
task test-e2e # a real API server trusting a real Dex; see docs/testing.md
task verify   # the local gate: the same checks CI runs in separate jobs

Design rules

  • The service contract is docs/design.md. A change to a route's behavior changes that document in the same pull request.
  • Kubernetes decides access. krm-foyer adds no access rules of its own; see docs/application-scope.md before proposing one.
  • The browser never receives a bearer token, and the service never falls back to its own service account for a user's request.
  • Preserve Kubernetes semantics: status codes, Status errors, patch types and concurrency preconditions pass through unchanged. Never replay a mutation.
  • No application-specific endpoints. Domain logic belongs in the domain's operator and admission, not here. See docs/bff-choice.md.
  • krm-foyer's own pages are server-rendered and have no JavaScript build. See docs/frontend.md.

Commits and releases

Commit messages follow Conventional Commits, because release-please reads them to cut versions: fix: is a patch, feat: a minor and feat!: a breaking change. Before 1.0 a breaking change bumps the minor version.

Pushes to main keep a release pull request up to date. Merging it tags the release, and the image ghcr.io/configbutler/krm-foyer:<version> is published once CI has passed on that commit.

Style

  • Format with task fmt (gofmt and goimports).
  • Comments explain constraints and non-obvious choices, not what the next line does.
  • Test the guarantee a change promises, not only the happy path. Security boundaries need tests that try to get past them.