67e5b120e7f190a65a583629afd678b9f9fbc66e
The minimal build-capable CLI decided in RFC 0002's outcome: stdlib-only Go module, one static binary. - engine: RunSpec behind the Engine interface (RFC 0001); the Bwrap engine ports Werkator's hardened invocation — uid-0 mapping, read-only rootfs at /, proc/dev/tmp/root before the user binds so binds below them land inside, mountpoint pre-creation in the rootfs including file mountpoints, and a guard against binds escaping the rootfs. --clearenv gives docker-style clean environments (HOME/PATH set explicitly). - store: images under $WERKDOCK_HOME (default ~/.werkdock), load unpacks via the tar CLI into a tmp dir and renames atomically. - cli: docker-shaped run flags (-v/-e/-w/--rm); refused docker flags (-p, --network, --memory, --cpus, --user, -d) fail loudly with the reason; exit codes follow docker (125 CLI errors, child code through). - doctor: port of werkator-build-prerequisites.sh — userns probe with the three signals, tar/zstd, free space and group-quota headroom via testable df/quota parsers, same PASS/FAIL output. - tests: argv golden test, mountpoint and escape tests, flag refusals, store round trip, doctor parsers — plus real-sandbox integration tests that skip where bwrap or userns are unavailable. Also records in step 21: RFC 0002 levels 2/3 deferred; next goal is sandbox builds of Werkator, Werkbaum, and Werkdock itself. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Werkator
Lightweight, declarative and highly opinionated software build system (CI/CD).
Documentation
- docs/configuration.md — configuration reference
- docs/bootstrapping.md — initializing a repository with
init - docs/deployment.md — running Werkator as a systemd service behind a reverse proxy
Developer Setup
Source .envrc to add tools/ to your PATH, or install direnv to have this done automatically on cd:
source .envrc
Common tasks:
./gradlew build # compile and run all checks
./gradlew test # run tests
./gradlew ktlintFormat # auto-format Kotlin sources
./gradlew ktlintCheck # check formatting (also runs as part of build)
adr-status # show all architecture decisions at a glance
direnv
direnv sources .envrc automatically whenever you enter the repository and unloads it when you leave.
# Ubuntu
sudo apt install direnv
# add to ~/.bashrc or ~/.zshrc
eval "$(direnv hook bash)" # or: eval "$(direnv hook zsh)"
Trust the project's .envrc once per clone:
direnv allow
Tools (tools/)
| Command | Description |
|---|---|
adr-status |
List all Architecture Decision Records with their status and decision summary |
Architecture Decision Records
Major technical decisions are documented as ADRs in docs/adrs/.
adr-status # show all decisions at a glance
New ADRs follow the template at docs/adrs/0000-00-00.adr-template.md.
Languages
Kotlin
87%
HTML
4.6%
Shell
4.2%
JavaScript
3%
CSS
1.2%