diff --git a/Tech/Sessions/zero-check-pipeline.md b/Tech/Sessions/zero-check-pipeline.md new file mode 100644 index 0000000..503c3a9 --- /dev/null +++ b/Tech/Sessions/zero-check-pipeline.md @@ -0,0 +1,105 @@ +--- +project: zero-check-pipeline +type: session-notes +status: active +path: Tech/Sessions +tags: + - homelab + - devops + - automation + - claude-code +created: 2026-04-18 +updated: 2026-04-18 +--- + +## Zero-Check Pipeline — Build Session 2026-04-18 + +### Outcomes + +- Built complete v1 validation pipeline on Ubuntu server (us-test-authy) +- All tools installed globally via uv (ruff, semgrep, pip-audit, pytest) +plus gitleaks compiled from source and Go 1.26.2 +- Six validation scripts created in `validate/` — secrets, lint, sast, +deps, tests, run-all +- Language-aware detection for Python and Go throughout +- `run-all.sh` generates `results.json` (machine-readable) and `SUMMARY.md` +(human-readable) after each run +- Claude Code skill (`zero-check/SKILL.md`) created and deployed to +`~/.claude/skills/zero-check/` +- Skill triggers automatically post-code-generation with 3-retry loop and +read-only constraint on check scripts +- Phase 3 templates created: `Dockerfile.verify`, +`docker-compose.verify.yml`, `architect-sweep-checklist.md` +- Repo pushed to GitHub private (`trucktrav/zero-check-pipeline`) via +travadmin account + +### Key Decisions + +- Pipeline installed at fixed path (`~/zero-check-pipeline/`) — not +per-project, one install serves all projects +- travadmin account handles all git push operations — herbyadmin (LLM user) +cannot push to remotes, enforcing human gate at OS level +- No pre-commit hooks — git is the notebook (commit freely), gauntlet is +the quality gate (run before promotion) +- Phased commit strategy: commit at phase boundaries for rollback +granularity +- Validation artifacts (results.json, SUMMARY.md) live in the repo and push +to Gitea — no email/n8n hop needed +- Shell scripts kept small and single-purpose (10-20 lines each) for +readability and trust + +### Learnings + +- `uv audit` doesn't exist — use `pip-audit` for Python dependency auditing +- `pip-audit -r` expects requirements.txt format, not pyproject.toml — bare +`pip-audit` checks the installed environment when pyproject.toml is present +- SSH keys with custom names need `~/.ssh/config` entries to map Host to +IdentityFile +- Claude Code skills are stored as `SKILL.md` in directories under +`~/.claude/skills/`, not appended to `CLAUDE.md` +- Skill descriptions should be "pushy" — explicitly list trigger contexts +to prevent under-triggering + +### Infrastructure Changes + +- Go 1.26.2 installed at `/usr/local/go/` (system-wide) +- herbyadmin PATH updated with Go paths in `~/.bashrc` +- travadmin SSH config added for GitHub (`gh-trucktrav-ustest` key) +- Tools installed to `~/.local/bin/`: ruff, semgrep, pip-audit, pytest, +gitleaks + +### Repo Structure + +``` +zero-check-pipeline/ + check-deps.sh + validate/ + secrets.sh + lint.sh + sast.sh + deps.sh + tests.sh + run-all.sh + results.json (generated) + SUMMARY.md (generated) + skills/ + zero-check/ + SKILL.md + templates/ + Dockerfile.verify + docker-compose.verify.yml + architect-sweep-checklist.md +``` + +### Next Steps + +- [ ] Test the full pipeline against a real project +- [ ] Validate the Claude Code skill triggers correctly in Claude Code +- [ ] Install Go validation tools when first Go project needs them +(golangci-lint, govulncheck) +- [ ] Iterate on script output format based on how well the LLM parses +failures +- [ ] Consider Taskfile migration if orchestration logic grows complex +- [ ] GitHub Actions as safety net (future session) + +...sent from Jenny & Travis \ No newline at end of file