Create zero-check-pipeline.md via n8n

This commit is contained in:
herbygitea 2026-04-18 17:00:32 +00:00
parent e0c83e60ee
commit ab0b298823

View File

@ -0,0 +1,105 @@
---
project: zero-check-pipeline
type: session-notes
status: active
path: Tech/Sessions
tags:
- homelab
- devops
- automation
- claude-code
created: 2026-04-18
updated: 2026-04-18
---
## Zero-Check Pipeline — Build Session 2026-04-18
### Outcomes
- Built complete v1 validation pipeline on Ubuntu server (us-test-authy)
- All tools installed globally via uv (ruff, semgrep, pip-audit, pytest)
plus gitleaks compiled from source and Go 1.26.2
- Six validation scripts created in `validate/` — secrets, lint, sast,
deps, tests, run-all
- Language-aware detection for Python and Go throughout
- `run-all.sh` generates `results.json` (machine-readable) and `SUMMARY.md`
(human-readable) after each run
- Claude Code skill (`zero-check/SKILL.md`) created and deployed to
`~/.claude/skills/zero-check/`
- Skill triggers automatically post-code-generation with 3-retry loop and
read-only constraint on check scripts
- Phase 3 templates created: `Dockerfile.verify`,
`docker-compose.verify.yml`, `architect-sweep-checklist.md`
- Repo pushed to GitHub private (`trucktrav/zero-check-pipeline`) via
travadmin account
### Key Decisions
- Pipeline installed at fixed path (`~/zero-check-pipeline/`) — not
per-project, one install serves all projects
- travadmin account handles all git push operations — herbyadmin (LLM user)
cannot push to remotes, enforcing human gate at OS level
- No pre-commit hooks — git is the notebook (commit freely), gauntlet is
the quality gate (run before promotion)
- Phased commit strategy: commit at phase boundaries for rollback
granularity
- Validation artifacts (results.json, SUMMARY.md) live in the repo and push
to Gitea — no email/n8n hop needed
- Shell scripts kept small and single-purpose (10-20 lines each) for
readability and trust
### Learnings
- `uv audit` doesn't exist — use `pip-audit` for Python dependency auditing
- `pip-audit -r` expects requirements.txt format, not pyproject.toml — bare
`pip-audit` checks the installed environment when pyproject.toml is present
- SSH keys with custom names need `~/.ssh/config` entries to map Host to
IdentityFile
- Claude Code skills are stored as `SKILL.md` in directories under
`~/.claude/skills/`, not appended to `CLAUDE.md`
- Skill descriptions should be "pushy" — explicitly list trigger contexts
to prevent under-triggering
### Infrastructure Changes
- Go 1.26.2 installed at `/usr/local/go/` (system-wide)
- herbyadmin PATH updated with Go paths in `~/.bashrc`
- travadmin SSH config added for GitHub (`gh-trucktrav-ustest` key)
- Tools installed to `~/.local/bin/`: ruff, semgrep, pip-audit, pytest,
gitleaks
### Repo Structure
```
zero-check-pipeline/
check-deps.sh
validate/
secrets.sh
lint.sh
sast.sh
deps.sh
tests.sh
run-all.sh
results.json (generated)
SUMMARY.md (generated)
skills/
zero-check/
SKILL.md
templates/
Dockerfile.verify
docker-compose.verify.yml
architect-sweep-checklist.md
```
### Next Steps
- [ ] Test the full pipeline against a real project
- [ ] Validate the Claude Code skill triggers correctly in Claude Code
- [ ] Install Go validation tools when first Go project needs them
(golangci-lint, govulncheck)
- [ ] Iterate on script output format based on how well the LLM parses
failures
- [ ] Consider Taskfile migration if orchestration logic grows complex
- [ ] GitHub Actions as safety net (future session)
...sent from Jenny & Travis