8b71d0db8e794e2efaaabe70bed31e9c25cf8e84
Two fixes from the vm4006 rollout (docs/plan/16-git-in-docker-builds.md): Rootless daemons map the host user to container root, so running the build container as --user <host-uid> put it into the subuid range and it could not even create .gradle in a fresh worktree (legacy only worked because its ownership-repair chown had accidentally moved build/ and .gradle/ into subuid ownership in its reused primary checkout). The container now always runs as --user 0: the unprivileged host user under rootless, real root under rootful where the ownership repair still applies; under rootless it degenerates to 0:0. Git now works inside build containers: the primary .git is mounted read-only with .git/gittally/ masked by an empty tmpfs (git.token and the control token stay unreachable, the workspace bind resurfaces only the build's own worktree) and the worktree admin dir mounted read-write for index-refreshing commands. Verified on vm4006: git log/status succeed, the machine config is invisible, ref writes fail on the read-only mount. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
GitTally
Lightweight, declarative and highly opinionated software build system (CI/CD).
Documentation
- docs/configuration.md — configuration reference
- docs/bootstrapping.md — initializing a repository with
init - docs/deployment.md — running GitTally as a systemd service behind a reverse proxy
- docs/migration-from-legacy.md — migrating from the legacy bash script
Legacy Script
legacy/gitTally (bash) is deprecated and kept only as a behavioral reference for the rewrite.
Do not use it for new installations; see docs/migration-from-legacy.md.
Developer Setup
Source .envrc to add tools/ to your PATH, or install direnv to have this done automatically on cd:
source .envrc
Common tasks:
./gradlew build # compile and run all checks
./gradlew test # run tests
./gradlew ktlintFormat # auto-format Kotlin sources
./gradlew ktlintCheck # check formatting (also runs as part of build)
adr-status # show all architecture decisions at a glance
direnv
direnv sources .envrc automatically whenever you enter the repository and unloads it when you leave.
# Ubuntu
sudo apt install direnv
# add to ~/.bashrc or ~/.zshrc
eval "$(direnv hook bash)" # or: eval "$(direnv hook zsh)"
Trust the project's .envrc once per clone:
direnv allow
Tools (tools/)
| Command | Description |
|---|---|
adr-status |
List all Architecture Decision Records with their status and decision summary |
Architecture Decision Records
Major technical decisions are documented as ADRs in docs/adrs/.
adr-status # show all decisions at a glance
New ADRs follow the template at docs/adrs/0000-00-00.adr-template.md.
Languages
Kotlin
87%
HTML
4.6%
Shell
4.2%
JavaScript
3%
CSS
1.2%