Commit Graph
3 Commits
Author SHA1 Message Date
Jinwoo-H 544e594800 chore(cloud): sync the relay Terraform root and scripts to the dual-accept identity change
Ports orca-cloud f24f3b4 (#464). The Terraform root is byte-identical to that
commit, including the new github_accepted_repositories variable and
relay-github-workflow-trust.tf, so every relay provider now admits
stablyai/orca alongside stablyai/orca-cloud. The tfvars already name this
repository's cloud- prefixed workflow paths on the stablyai/orca arm.

Ten scripts were three-way merged so the public-repo adaptations survive: the
relayWorkflowFile/relayWorkflowPath/readRelayWorkflow indirection, the census
keys, and the workflow directory depth. The condition renderer keeps the apps
root declared and skips it when the directory is absent, so its expectations
stay a straight copy of the private original. The staging deploy identity's
rendered-length pin keeps the private repository's 797 and derives this copy's
difference from the filename prefix.
2026-09-03 06:40:26 -04:00
Jinwoo-H 88ea4fbc5c chore(cloud): add the 24 relay workflows and the Cloud SQL rollout lease action
Each workflow is copied under a cloud- prefix, runs from cloud/ through a
workflow-level defaults block, and resolves pnpm and the Node cache against
cloud/package.json and cloud/pnpm-lock.yaml. Display names are unchanged
because the recovery chain matches on them; every reusable call, gh dispatch,
and jq run-path check was repointed to the prefixed filenames.

Every job that can start on its own is gated on the repository variable
ORCA_CLOUD_OPERATIONS_ENABLED, so both scheduled triggers and every manual
dispatch skip without running a step until the owner enables them. Reusable
jobs inherit the caller's gate rather than restating it. A new contract test
pins the gate, the three chained display names, and the absence of any
repository secret other than the automatic token.
2026-09-03 06:20:50 -04:00
Jinwoo-H 25e31c931d chore(cloud): add the relay fence broker, ops console, Terraform root, and scripts
Copies the private repository's relay side: the IAM-only fence broker, the
operations console and incident monitor, the relay Terraform root with its
backend configuration and tfvars, and the deploy/capacity/admission/rehome/
monitoring scripts the workflows call, with their contract tests, contracts,
and fixtures.

The foundation and apps Terraform roots and the API and auth services stay
private. Four surfaces that spanned both trees are narrowed to the relay side
rather than left with a dangling read: the infra runner and the root-partition
and workload-identity-condition renderers now declare only the relay root, and
the Cloud SQL rollout census drops the six app workflows that are not here.
2026-09-03 06:20:32 -04:00