Go to file
chrisfu 500c9b1317 fix(installer): env-contamination guard against shell-context / config mismatch
Filed in response to the 2026-04-28 14:00 UTC backup outage. An
`install.sh --mode k3d` run with the shell pointed at GKE silently
overwrote the GKE cluster's GCS-backed ObjectStore + ScheduledBackup
with k3d-mode defaults; Garage filled up and CNPG backups failed for
hours before the next manual check. The class of bug is "config says
target cluster A, shell context says target cluster B, installer
proceeds against B without warning."

New shared bash helper at etc/preflight_kubecontext.sh with two
functions:

  - verify_kubecontext_matches_config <cfg-path>
      Strict gate. Reads [Global] APP_CLUSTER_KUBECONTEXT from the
      config and exits 1 if `kubectl config current-context` differs.
      Skipped silently when the config has no baked APP_CLUSTER_KUBECONTEXT
      (e.g. fresh k3d.cfg) or when there's no live current-context.

  - print_kubecontext_notice
      Informational. Prints what's about to be inherited so the user
      can abort before the TUI launches if it looks wrong. Never fails.

Wiring:

  - deploy.sh sources the helper and calls the strict gate against
    ${PROLE_DEPLOY_CFG:-conf/gke.cfg} before invoking Python.
    Unattended path -> hard refusal on mismatch.

  - install.sh sources the helper and calls the informational notice
    (gated on not-`--min`) right after entering the local-checkout
    branch. The TUI is interactive, so the strict mode-aware gate is
    a follow-up once the welcome screen records a mode in
    state.inputs.

Bypass for deliberate cross-cluster maintenance:
    KNOE_SKIP_KUBECONTEXT_GUARD=true ./deploy.sh

End-to-end verified:
  - deploy.sh with current=cnpg-0, gke.cfg=app-0   -> exit 1, clear msg
  - deploy.sh with KNOE_SKIP_...=true              -> bypasses, prints
                                                     "skipping check"
  - install.sh --min                               -> notice skipped
  - install.sh (no flag) and install.sh --silent   -> notice printed

Doc updates:
  - CLAUDE.md §"Env-contamination warning" rewritten to describe the
    live guard (was a forward-looking TODO).
  - CLAUDE.md drift table row R4 removed; "Closed 2026-05-01" line added.
  - docs/TODO.md queue item #1 archived to Done; R4 dropped from the
    reality-vs-intent table. Queue numbering retained (no #1 placeholder)
    so the docs/plans/junie/<NN>-...md filenames still match.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-01 16:14:30 -07:00
.idea/runConfigurations docs: update README; IntelliJ run config picks up Python 3.14 SDK 2026-04-27 14:47:27 -07:00
authority refactor(authority): rebrand package org.prole → dev.knoe; raise test coverage to 50% 2026-04-30 22:42:53 -07:00
conf Phase 1: OIDC provider integration and GKE auth deployment 2026-04-28 12:22:45 -07:00
demo feat(oauth): add Google OIDC/OAuth2 Proxy support for Studio and Grafana. Add Google OIDC configuration for Grafana in gke.cfg, introduce oauth2-proxy templates and configurations for Supabase Studio, update Helm values/templates for authenticated Studio access, and add ingress/service manifests for Postgres TCP and Prole services. 2026-04-28 11:27:34 -07:00
deploy Phase 1: OIDC provider integration and GKE auth deployment 2026-04-28 12:22:45 -07:00
docs fix(installer): env-contamination guard against shell-context / config mismatch 2026-05-01 16:14:30 -07:00
etc fix(installer): env-contamination guard against shell-context / config mismatch 2026-05-01 16:14:30 -07:00
gitea Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
img Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
infrastructure infrastructure: restore ansible configuration and refactor samba_dns for internal zone - Restored the 'infrastructure' directory and root-level 'ansible.sh', 'ansible.cfg' scripts. - Refactored 'samba_dns' role to dynamically handle 'prole.org' and 'internal.prole.org' DNS zones. - Switched 'samba-tool' commands to use machine account authentication (-P) in 'samba_dns' and 'samba_reverse_dns'. - Updated AD DC inventory variables to use 127.0.0.1 and correct admin principal. - Added tags to 'samba_dns' tasks for better target execution. - Updated IDE project configuration for knoe-db. 2026-04-28 00:05:03 -07:00
k3s feat(oauth): add Google OIDC/OAuth2 Proxy support for Studio and Grafana. Add Google OIDC configuration for Grafana in gke.cfg, introduce oauth2-proxy templates and configurations for Supabase Studio, update Helm values/templates for authenticated Studio access, and add ingress/service manifests for Postgres TCP and Prole services. 2026-04-28 11:27:34 -07:00
k8s feat(oauth): add Google OIDC/OAuth2 Proxy support for Studio and Grafana. Add Google OIDC configuration for Grafana in gke.cfg, introduce oauth2-proxy templates and configurations for Supabase Studio, update Helm values/templates for authenticated Studio access, and add ingress/service manifests for Postgres TCP and Prole services. 2026-04-28 11:27:34 -07:00
knoe fix(test): extract field.replace to variable before f-string in cloudnative_pg.py 2026-04-30 16:03:38 -07:00
knoe-db chore: purge dead credentials and harden .gitignore 2026-04-27 13:33:29 -07:00
mock_val Migrate Ansible-based scripts and documentation to 1Password integration. Removed deprecated and redundant Ansible vault workflows, added 1Password CLI handling for secrets management, and updated tests to reflect the change. 2026-04-22 20:54:13 -07:00
modes Harden prod deploy namespace/context routing and vault password handling 2026-04-10 00:43:07 -07:00
scan Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
scripts Migrate Ansible-based scripts and documentation to 1Password integration. Removed deprecated and redundant Ansible vault workflows, added 1Password CLI handling for secrets management, and updated tests to reflect the change. 2026-04-22 20:54:13 -07:00
src Remove prole-db-manager; simplify deployment via prole-authority; fix pg18 downgrade & cluster name 2026-03-01 20:40:44 -08:00
supabase feat(oauth): add Google OIDC/OAuth2 Proxy support for Studio and Grafana. Add Google OIDC configuration for Grafana in gke.cfg, introduce oauth2-proxy templates and configurations for Supabase Studio, update Helm values/templates for authenticated Studio access, and add ingress/service manifests for Postgres TCP and Prole services. 2026-04-28 11:27:34 -07:00
tests test(infra): move T1.4 test to test_hostnossl_precedence.py; conftest is fixtures-only 2026-04-30 16:08:19 -07:00
tmp chore(k3s): script and hostprobe updates, temp maintenance scripts 2026-04-27 14:47:27 -07:00
.coveragerc feat(installer): improve UI and add test coverage for core features 2026-01-08 21:51:30 -08:00
.gitignore chore: purge dead credentials and harden .gitignore 2026-04-27 13:33:29 -07:00
.gitlab-ci.yml feat: GitLab deployment pipeline — operator fix, CI config, and namespace isolation 2026-04-01 15:26:39 -07:00
AGENTS.md Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
ansible_min.cfg infrastructure: restore ansible configuration and refactor samba_dns for internal zone - Restored the 'infrastructure' directory and root-level 'ansible.sh', 'ansible.cfg' scripts. - Refactored 'samba_dns' role to dynamically handle 'prole.org' and 'internal.prole.org' DNS zones. - Switched 'samba-tool' commands to use machine account authentication (-P) in 'samba_dns' and 'samba_reverse_dns'. - Updated AD DC inventory variables to use 127.0.0.1 and correct admin principal. - Added tags to 'samba_dns' tasks for better target execution. - Updated IDE project configuration for knoe-db. 2026-04-28 00:05:03 -07:00
ansible.cfg infrastructure: restore ansible configuration and refactor samba_dns for internal zone - Restored the 'infrastructure' directory and root-level 'ansible.sh', 'ansible.cfg' scripts. - Refactored 'samba_dns' role to dynamically handle 'prole.org' and 'internal.prole.org' DNS zones. - Switched 'samba-tool' commands to use machine account authentication (-P) in 'samba_dns' and 'samba_reverse_dns'. - Updated AD DC inventory variables to use 127.0.0.1 and correct admin principal. - Added tags to 'samba_dns' tasks for better target execution. - Updated IDE project configuration for knoe-db. 2026-04-28 00:05:03 -07:00
ansible.sh infrastructure: restore ansible configuration and refactor samba_dns for internal zone - Restored the 'infrastructure' directory and root-level 'ansible.sh', 'ansible.cfg' scripts. - Refactored 'samba_dns' role to dynamically handle 'prole.org' and 'internal.prole.org' DNS zones. - Switched 'samba-tool' commands to use machine account authentication (-P) in 'samba_dns' and 'samba_reverse_dns'. - Updated AD DC inventory variables to use 127.0.0.1 and correct admin principal. - Added tags to 'samba_dns' tasks for better target execution. - Updated IDE project configuration for knoe-db. 2026-04-28 00:05:03 -07:00
BUILD.md Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
CLAUDE.md fix(installer): env-contamination guard against shell-context / config mismatch 2026-05-01 16:14:30 -07:00
config.py Migrate Ansible-based scripts and documentation to 1Password integration. Removed deprecated and redundant Ansible vault workflows, added 1Password CLI handling for secrets management, and updated tests to reflect the change. 2026-04-22 20:54:13 -07:00
config.sh Add GCP ncurses TUI to knoe/config.py and config.sh launcher 2026-03-31 23:15:54 -07:00
deploy.sh fix(installer): env-contamination guard against shell-context / config mismatch 2026-05-01 16:14:30 -07:00
env.sh Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
Executing Fix Kong OOM crash: increase memory limit to 1Gi, mount ConfigMap to subdirectory 2026-02-22 01:02:00 -08:00
install.sh fix(installer): env-contamination guard against shell-context / config mismatch 2026-05-01 16:14:30 -07:00
knoe-db.iml Merge remote-tracking branch 'knoe/main' 2026-04-28 00:05:40 -07:00
knoe.iml Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
knoe.sh Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
knoe.spec Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
LICENSE Initial commit 2025-07-12 18:02:40 -07:00
Makefile Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
pom.xml chore(build): Maven version and authority module updates 2026-04-27 14:47:27 -07:00
pyproject.toml Phase 0: test pipeline foundation — pyproject.toml, IntelliJ run configs, coverage fix, welcome mode selector 2026-04-27 14:44:46 -07:00
qodana.yaml Installer refactor: k3d cluster lifecycle, kubeconfig handling, UI polish & cleanup - Fix KUBECONFIG not generated for dev/k3d clusters by merging k3d kubeconfig in _script_env_for_namespace() and after cluster creation - Fix Add/Delete button macOS black focus ring with highlightbackground/highlightthickness styling - Refactor milestones, actions, controller, deploy pipeline, and env helpers - Simplify prole.cfg and port-mapping.cfg defaults - Improve archive_garage_backup.py and init_cloudnative_pg.sh - Remove unused img/LOADING_GIF_README.md and img/generate_loading_gif.py - Add qodana.yaml for static analysis configuration 2026-02-20 01:28:52 -08:00
README.md docs: update README; IntelliJ run config picks up Python 3.14 SDK 2026-04-27 14:47:27 -07:00
requirements-test.txt Phase 0: test pipeline foundation — pyproject.toml, IntelliJ run configs, coverage fix, welcome mode selector 2026-04-27 14:44:46 -07:00
requirements.txt Update Prole-DB and improve Supabase integration 2026-02-01 23:56:25 -08:00
run_with_coverage.sh Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
status.py Complete rebranding from prole to knoe and fix macOS application identity. Bulk renamed 'prole' to 'knoe' across code, scripts, and manifests. Updated Makefile with 'knoe', 'build', and 'start' targets. Implemented macOS Application Bundle (.app) support for correct identity. Fixed macOS 'Python' process name to 'Knoe.DB Installer' via Objective-C bridge. Standardized application name to 'Knoe.DB Installer' across all interfaces. 2026-04-22 15:08:35 -07:00
supabase.sh Configure Silent Install Test with unique logging and shared run configuration 2026-02-02 16:13:15 -08:00
update.sh Migrate Ansible-based scripts and documentation to 1Password integration. Removed deprecated and redundant Ansible vault workflows, added 1Password CLI handling for secrets management, and updated tests to reflect the change. 2026-04-22 20:54:13 -07:00

Knoe

Knoe makes it practical to run a Supabase-style platform across air-gapped, edge, and cloud environments.

It packages the core building blocks needed for a modern internal developer platform around PostgreSQL, object storage, secrets, auth, observability, and Kubernetes-native operations — with a bias toward simple deployment, shard-based scale-out, and deterministic ingestion.


Platform badges

Kubernetes K3s K3d GCP Helm Argo CD Docker containerd

PostgreSQL CloudNativePG psql pgvector MariaDB SQLite

Python uv FastAPI Pydantic

Next.js React TypeScript

Supabase GitLab Gitea OpenBao Garage Vector Prometheus Grafana

cert-manager Traefik Kong OIDC Google Workspace Samba AD

1Password OpenTofu Linux Raspberry%20Pi


What Knoe is

Knoe is an infrastructure stack for running a Supabase-like data and application platform across constrained, sovereign, and cloud environments, including:

  • air-gapped networks
  • edge and small-cluster deployments (K3s, K3d)
  • Google Cloud Platform (GCP) deployments
  • sovereign or private data environments
  • disconnected labs and field systems
  • internal platforms where cloud dependencies are undesirable

The design goal is not to mimic Supabase branding or every managed feature exactly.

The design goal is to provide the useful substrate people actually want:

  • PostgreSQL as the center of gravity
  • object storage
  • auth integration
  • secret management
  • ingress and service exposure
  • observability
  • reproducible Kubernetes deployment
  • application and worker services around the database
  • ingestion patterns that are safe, resumable, and idempotent

Core idea

Knoe can run Supabase-style workloads in an air gap, on the edge, or in the cloud.

That means:

  • PostgreSQL remains the system of record, managed as knoe-db within the knoe-system namespace
  • services are deployed on Kubernetes (K3d locally, K3s on-prem, GKE on GCP)
  • auth can come from local identity systems or cloud OIDC where available
  • object storage stays inside the environment
  • secrets stay inside the environment
  • ingestion does not depend on live internet services
  • the stack can be deployed in shards for locality, resilience, and operational simplicity

Main components

Application layer

  • Next.js app for the user-facing platform
  • knoe-agent worker for async and background execution

Data layer

  • knoe-db — CloudNativePG-managed PostgreSQL cluster in the knoe-system namespace
  • PostgreSQL as the primary relational store
  • append-only fact tables for durable ingestion and replay-friendly modeling
  • PostgreSQL COPY for efficient bulk ingest

Deployed add-ons

  • Supabase — self-hosted Supabase stack for auth, realtime, storage, and API gateway
  • ArgoCD — GitOps continuous delivery for the knoe-system cluster
  • Gitea — lightweight self-hosted Git service
  • GitLab — full-featured self-hosted DevOps platform

Storage and secrets

  • Garage for S3-compatible object storage
  • OpenBao for secret storage and secret distribution

Identity

  • Dev auth: Samba AD + IdP
  • Cloud auth: Google Workspace OIDC

Observability

  • Vector for log and event shipping
  • Prometheus / Grafana for metrics and dashboards

Platform operations

  • K3d — local development clusters
  • K3s — on-prem lightweight Kubernetes
  • GCP / GKE — cloud-hosted cluster tier
  • Helm
  • ArgoCD
  • Ansible
  • OpenTofu

Ingestion model

Knoe is designed around deterministic, replayable ingestion.

Key patterns:

  • SQLite delta cartridges as portable input units
  • append-only fact tables for auditability and recovery
  • PostgreSQL COPY for high-throughput loading
  • queue-driven workers using SKIP LOCKED
  • idempotent ingestion so retries are safe
  • shard-based deployment so data movement stays deliberate and bounded

This makes the platform well suited to environments where data may arrive in batches, be transferred physically, or need careful replay and provenance.


Architecture at a glance

flowchart LR
    subgraph Clients
        U["Users / Operators"]
    end

    subgraph knoe-system ["knoe-system (Kubernetes)"]
        A["Next.js App"]
        W["knoe-agent worker"]
        SB["Supabase\n(auth · realtime · storage · API)"]
        ARGO["ArgoCD\n(GitOps)"]
        GITEA["Gitea\n(Git)"]
        GITLAB["GitLab\n(DevOps)"]
        PG["knoe-db\n(CloudNativePG / PostgreSQL)"]
        OBJ["Garage\n(Object Store)"]
        SEC["OpenBao\n(Secrets)"]
        OBS["Vector / Prometheus / Grafana\n(Observability)"]
        ING["Traefik / Kong\n(Ingress)"]
    end

    subgraph Infra ["Infrastructure"]
        K3D["K3d\n(local dev)"]
        K3S["K3s\n(on-prem)"]
        GCP["GCP / GKE\n(cloud)"]
    end

    subgraph Identity
        AUTH["Samba AD / Google Workspace OIDC"]
    end

    U --> ING
    ING --> A
    ING --> SB
    ING --> ARGO
    ING --> GITEA
    ING --> GITLAB

    A --> PG
    A --> OBJ
    A --> SEC
    A --> AUTH
    W --> PG
    W --> OBJ
    W --> SEC
    SB --> PG
    SB --> OBJ
    SB --> AUTH

    ARGO --> A
    ARGO --> W
    ARGO --> SB
    ARGO --> PG
    ARGO --> OBJ
    ARGO --> SEC

    GITEA --> ARGO
    GITLAB --> ARGO

    K3D & K3S & GCP --> |hosts| knoe-system
    OBS -.-> PG
    OBS -.-> A
    OBS -.-> W

Deployment model

Knoe favors simple, understandable deployment over excessive platform ceremony.

Typical characteristics:

  • Kubernetes-native deployment across K3d (local), K3s (on-prem), and GCP (cloud)
  • lightweight K3s/K3d-friendly footprint
  • HA where it matters
  • shard-oriented layout instead of one giant control surface
  • GitOps-driven operations via ArgoCD, backed by Gitea or GitLab
  • support for small clusters, including Pi-based or edge environments

Use cases

Knoe is a good fit for teams that need:

  • a PostgreSQL-centered application stack inside a disconnected or sovereign environment
  • a self-hosted substrate for Supabase-style internal platforms
  • ingestion from offline or intermittently connected sources
  • reproducible deployment on small Kubernetes clusters (K3s/K3d) or GCP
  • strong control over secrets, storage, and identity boundaries
  • a full GitOps workflow with ArgoCD, Gitea, and GitLab

Project principles

  • Air-gap first
  • Postgres first
  • Simple over ornate
  • Deterministic ingestion
  • Kubernetes-native
  • Shard-friendly
  • Operationally boring where possible

Repository scope

This repository contains the infrastructure and platform materials used to stand up Knoe components, including Kubernetes deployment, database operations (knoe-db in knoe-system), storage, auth, observability, and supporting services.

As the project evolves, this README should stay focused on:

  • what Knoe is
  • why it exists
  • the major building blocks
  • the deployment model
  • the operational philosophy

Detailed setup docs, cluster procedures, and host-specific notes should live in dedicated documents under docs/, ops/, k8s/, or role-specific subdirectories rather than expanding this file indefinitely.


Status

Knoe is an actively evolving platform stack aimed at practical self-hosted, edge, and cloud operation.

Expect the architecture to continue being refined toward:

  • cleaner bootstrapping
  • better shard isolation
  • smoother rejoin/reset behavior for cluster nodes
  • clearer service boundaries
  • improved onboarding and operations documentation

License

Add the project license here.