prole/docs/plans/junie/README.md
chrisfu 2b36add592 docs(plans): file Phase 3 brief — knoe-auth as a pod inside k3d
Phase 1 (host loop) and the Phase 2 OIDC sandbox are shipped; this
brief queues Phase 3 of k3d-mirror-of-GKE: build the knoe-auth image,
k3d-import, run as a pod inside the cluster. Pre-merge smoke loop —
not the daily inner loop.

Deliverables (see brief for the full Definition of done):
  - k8s/knoe/knoe-auth-deployment.yaml         (NEW; sibling of GKE manifest)
  - scripts/k3d-knoe-deploy.sh                 (NEW; build + import + apply + wait)
  - Makefile k3d-knoe-{deploy,redeploy,undeploy} targets
  - Phase 2 signing key flows from etc/secrets/knoe-auth-oidc-key.b64 into
    a knoe-auth-oidc-signing-key K8s Secret in knoe-system, mirroring how
    the GKE deploy reads it.

Index updates:
  docs/plans/junie/README.md           — k3d Phase 3 in Active row
  docs/TODO.md §"In progress"          — promotes the brief to top
  docs/plans/k3d-gke-mirror.md         — banner + §6 Phase 3 entry
                                          flipped from "out of scope"
                                          to "in flight"
2026-05-02 13:15:29 -07:00

4.4 KiB

Junie briefs

Self-contained, single-task briefs for Junie to consume from inside the IntelliJ IDE. Each file is a hand-off — Junie reads the brief cold (no shared chat history), implements the change, and opens an MR.

What lives here vs. ../

The .. parent directory holds architectural plans — multi-section documents covering an initiative's strategy, schema, and component design. They outlive the implementation and become the architectural reference once shipped.

This subdirectory holds work briefs — smaller, more tactical, scoped to a single MR's worth of changes. They reference the master TODO index (../../TODO.md) and contain enough context for Junie to land the change without escalating questions.

Brief shape (convention)

Each brief follows this skeleton:

  1. Why — one or two paragraphs of context, including the trigger event if any (e.g. "the 4/28 14:00 UTC outage").
  2. What changes — concrete file paths, line numbers, before/after where useful. Don't make Junie re-derive the change.
  3. Verification — runnable commands or helm template diffs that confirm the change. Each brief ends with a Definition of done checklist.
  4. Out of scope — explicit fences. The TODO is interconnected; without this section briefs creep.
  5. Commit shape — proposed commit message + structure.

Status tracking

Every brief here corresponds to a numbered item in ../../TODO.md (or has an explicit "doesn't yet exist in TODO" note). When Junie lands a brief:

  1. Move the corresponding item from the TODO ranked queue into the Done section with date + commit ref (or the convention used by the rest of the file).
  2. Don't delete the brief from this directory — it stays as the design record.

Current briefs (as of 2026-05-02)

Active (in flight)

File Tracked at Subject
k3d-knoe-auth-pod-deploy.md TODO §"In progress"; parent ../k3d-gke-mirror.md §6 Phase 3 Phase 3 of k3d-mirror-of-GKE: build the knoe-auth image, k3d image import, run as a pod inside the cluster. Pre-merge smoke loop with make k3d-knoe-{deploy,redeploy,undeploy}.

Shipped (kept as design record)

File Queue # Subject
k3d-knoe-auth-dev-loop.md k3d Phase 1 CNPG + KDC in k3d; make k3d-knoe-{up,pf,down}; --mode k3d flag; etc/krb5.local.conf; smoke script; engineer doc. Shipped 2026-05-02.
02-k3s-prole-rename.md #2 Rename k3s prole-*.yamlknoe-*.yaml (kustomize is broken). Shipped 2026-05-02 (commit fb7e8b7).
06-patch-garage-script-fixes.md #6 Three defects in scripts/patch_garage_cross_cluster.sh. Shipped 2026-05-02 (commits 34a25dd + 5d17325).
07-init-cnpg-gke-sa-wiring.md #7 Wire cnpg-backup-sa into CNPG cluster spec; bump operator to v1.29. Shipped 2026-05-02 (commit c3fae73).
13-podmonitor-manual-management.md #13 Migrate off CNPG-deprecated enablePodMonitor + podMonitorRelabelings. Shipped 2026-05-02 (commit c3fae73).
15-remove-dead-dashboard-consumer.md #15 Remove dead Kong DASHBOARD consumer + basicauth_credentials. Shipped 2026-05-02 (commit c3fae73).
03-image-rename-knoe-authority-to-knoe-auth.md #3 Rename Docker image knoe-authorityknoe-auth; add Dockerfile.app; update 2 manifests. Shipped 2026-05-02.
phase2-oidc-gke-deploy.md Phase 2 GKE Enable OIDC in GKE deployment; Kong /auth route; studioIngress+knoeAuth values defaults. Shipped 2026-05-02.

How a session fires off a batch

The driving session (Claude Code, Cowork+Code, or a human) writes the briefs into this directory and points Junie at one or more of them. Junie reads the brief, implements, runs the verification checklist, opens an MR. Each brief is independent — Junie can take them in any order, or in parallel across separate IDE sessions.

The brief is the contract. If something is unclear, the brief is buggy and should be edited before Junie continues.