mhoennigandClaude Fable 5 67e5b120e7 Werkdock skeleton: doctor, load, run over the bwrap engine (Go)
The minimal build-capable CLI decided in RFC 0002's outcome: stdlib-only
Go module, one static binary.

- engine: RunSpec behind the Engine interface (RFC 0001); the Bwrap
  engine ports Werkator's hardened invocation — uid-0 mapping, read-only
  rootfs at /, proc/dev/tmp/root before the user binds so binds below
  them land inside, mountpoint pre-creation in the rootfs including file
  mountpoints, and a guard against binds escaping the rootfs. --clearenv
  gives docker-style clean environments (HOME/PATH set explicitly).
- store: images under $WERKDOCK_HOME (default ~/.werkdock), load
  unpacks via the tar CLI into a tmp dir and renames atomically.
- cli: docker-shaped run flags (-v/-e/-w/--rm); refused docker flags
  (-p, --network, --memory, --cpus, --user, -d) fail loudly with the
  reason; exit codes follow docker (125 CLI errors, child code through).
- doctor: port of werkator-build-prerequisites.sh — userns probe with
  the three signals, tar/zstd, free space and group-quota headroom via
  testable df/quota parsers, same PASS/FAIL output.
- tests: argv golden test, mountpoint and escape tests, flag refusals,
  store round trip, doctor parsers — plus real-sandbox integration
  tests that skip where bwrap or userns are unavailable.

Also records in step 21: RFC 0002 levels 2/3 deferred; next goal is
sandbox builds of Werkator, Werkbaum, and Werkdock itself.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 07:01:21 +02:00
2026-06-09 14:31:35 +02:00
2026-06-09 11:55:23 +02:00
2026-06-09 11:55:23 +02:00
2026-06-09 09:07:47 +02:00

Werkator

Lightweight, declarative and highly opinionated software build system (CI/CD).

Documentation

Developer Setup

Source .envrc to add tools/ to your PATH, or install direnv to have this done automatically on cd:

source .envrc

Common tasks:

./gradlew build          # compile and run all checks
./gradlew test           # run tests
./gradlew ktlintFormat   # auto-format Kotlin sources
./gradlew ktlintCheck    # check formatting (also runs as part of build)

adr-status               # show all architecture decisions at a glance

direnv

direnv sources .envrc automatically whenever you enter the repository and unloads it when you leave.

# Ubuntu
sudo apt install direnv

# add to ~/.bashrc or ~/.zshrc
eval "$(direnv hook bash)"   # or: eval "$(direnv hook zsh)"

Trust the project's .envrc once per clone:

direnv allow

Tools (tools/)

Command Description
adr-status List all Architecture Decision Records with their status and decision summary

Architecture Decision Records

Major technical decisions are documented as ADRs in docs/adrs/.

adr-status   # show all decisions at a glance

New ADRs follow the template at docs/adrs/0000-00-00.adr-template.md.

S
Description
A simple CI app mostly for GitEA and Hostsharing Managed Webserver/Webspace as well as Hostsharing Container Server.
Readme MIT
5 MiB
Languages
Kotlin 87%
HTML 4.6%
Shell 4.2%
JavaScript 3%
CSS 1.2%