已合并
MVP-09: provision isolated Yandex Cloud dev environment #16
urandon创建于 7月31日
MVP-09: provision isolated Yandex Cloud dev environment #16
已合并
urandon创建于 7月31日
urandon
urandon成员
7月31日

Outcome

Provision the harness-neutral, scale-to-zero Yandex Cloud development environment tracked by #12 and aligned with architecture #1.

What changed

  • added pinned Terraform modules for an isolated folder, resource-scoped IAM, YDB Serverless, Object Storage, YMQ queues and DLQs, Container Registry, KMS/Lockbox, Cloud Logging, private Serverless Containers, timer/YMQ triggers, managed DNS/certificate, and blue/green API Gateway routing;
  • added bounded HTTP trigger entrypoints for the reconciler, Telegram sender, and worker runtime;
  • added a strict Yandex YMQ event adapter where 2xx acknowledges a trigger batch and failures remain owned by YMQ retry/redrive;
  • added a fenced YDB deployment-lock wrapper and saved-plan-only apply/destroy procedures;
  • added folder-first Billing Budget verification, secret payload streaming outside Terraform state, immutable image publication, private/public smoke checks, and Telegram webhook setup;
  • documented first deployment, cloud/local verification boundaries, canary promotion, rollback, external alert obligations, and protected destroy;
  • updated README and CI to reflect the serverless, frontend-neutral and harness-neutral architecture and to build all four runtime images.

Safety boundaries

  • public documentation and issue research are in English;
  • Telegram and subscription secrets never enter Terraform state, argv, images, or repository files;
  • billable resources remain behind an externally verified folder-scoped budget gate;
  • YDB, KMS, Lockbox, and the certificate default to deletion protection; the artifact bucket is not force-deleted;
  • cloud apply accepts exactly one reviewed saved plan under the deployment lock;
  • no real cloud deployment is claimed in this MR; cloud acceptance requires credentials and the runbook checks after merge/review.

Verification

  • make ci
  • make test after the final trigger parser hardening
  • make terraform-ci TERRAFORM=/tmp/sessionless-terraform-bin/terraform
  • Terraform 1.15.5 / Yandex provider 0.220.0: both bootstrap and cloud-dev roots initialized and validated
  • sh -n scripts/cloud-*.sh
  • git diff --check

Docker is unavailable on the development workstation. The mirrored GitHub Actions Runtime images job is therefore the required image-build gate for commit 527bd34.

Closes #12 after green CI and the separately recorded cloud-dev acceptance run.

likedislike
Pull Request已成功合入, 合并人@urandon
(感谢 urandon 的贡献)
urandonurandon成员
7月31日 关联了issue:Design the Sessionless system architecture,[MVP-09] Provision the isolated Yandex Cloud dev environment with Terraform
urandon
urandon成员
7月31日 评论:

CI result

GitHub Actions run #30634841746 completed successfully for the exact MR head 527bd34f9b0bcde6ddb5c9282e8680114004af22.

All five gates are green: Go verification, Terraform environments, YDB integration, the full local multi-service/restart suite, and all four runtime image builds. The GitCode → GitHub push mirror was triggered and verified through gitcode-mcp.

likedislike
urandonurandon成员
7月31日 合入了pull request,合并节点 SHA:8ec76b33e25f835a83480e4ce0af28100a97c93a