feat(binjovi): isolate native BuildKit workers #221

Merged
binjovi-bot merged 2 commits from codex/native-buildkit-infra into trunk 2026-09-03 15:24:56 +00:00
Owner

Adds separate admission and release BuildKit workers on official rootless BuildKit 0.30 with the OCI overlayfs worker. Each worker uses its own 30 GiB zfs-nvme-128k PVC and required node anti-affinity. Adds the OAuth client and scoped credentials for the outbound-only Binjovi agent. The agent deployment remains at zero replicas until the Binjovi release enables it.\n\nChecks: bash tests/binjovi-agent-oauth.sh; bash tests/binjovi-buildkit-cache.sh; kubectl kustomize; server-side dry-run.\n\nRollout order: merge and verify this PR before sean/ory and sean/binjovi. Do not activate sean/binjovi-plans v11 until all three dependencies are live.

Adds separate admission and release BuildKit workers on official rootless BuildKit 0.30 with the OCI overlayfs worker. Each worker uses its own 30 GiB zfs-nvme-128k PVC and required node anti-affinity. Adds the OAuth client and scoped credentials for the outbound-only Binjovi agent. The agent deployment remains at zero replicas until the Binjovi release enables it.\n\nChecks: bash tests/binjovi-agent-oauth.sh; bash tests/binjovi-buildkit-cache.sh; kubectl kustomize; server-side dry-run.\n\nRollout order: merge and verify this PR before sean/ory and sean/binjovi. Do not activate sean/binjovi-plans v11 until all three dependencies are live.
feat(binjovi): isolate native BuildKit workers
Some checks failed
binjovi/ci Binjovi failed the frozen plan
6c338a921e
test(binjovi): run native agent infrastructure guards
All checks were successful
binjovi/ci Binjovi completed the frozen plan
45d16bc7d1
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
sean/seanfarm!221
No description provided.