Migrate to Forgejo: remove all CI, update URLs, honest docs #1

Merged
amethyst merged 11 commits from migration/kill-actions into main 2026-10-11 04:16:12 +00:00
Owner

Migrates the repository off GitHub to self-hosted Forgejo after the gokooteam suspension (2026-10-10). The server runs git hosting and onxd only: no Actions, no runners, no review bots.

What changes

  • All 26 CI workflows deleted (24 .github/workflows, 2 .forgejo/workflows).
  • GitHub URLs migrated to git.on-x.live/amethyst/the-open-network-x (/src/branch/main/ paths). site.py rewrites them at build time, and check fails if any GitHub link or API call remains.
  • Deploy scripts use the Forgejo API. site-pull-deploy.sh no longer has a CI gate; the review process is the gate.
  • SECURITY.md: private reports go by email to admin@on-x.live.
  • Review process defined once in CONTRIBUTING.md#review-process: Claude three-lens review, half-weight self-check, point system (critical = NO-GO, 50 points = NO-GO), push authorization, Amethyst merges.
  • Inert GitHub config removed: .coderabbit.yaml, CODEOWNERS, dependabot, labeler, actionlint, zizmor, rulesets, apply-branch-protection.sh. The branch-protection guide is rewritten for Forgejo.
  • Site: PR cards link to their merge commits on Forgejo, and the heavy compare API call is dropped from the live widget.
  • docs/MIGRATION-forgejo.md records what was removed, what replaces it, and what was lost (PR pages, releases, tag v0.2.1, pr59/pr60).

Checks (run locally)

site.py check, check-doc-links.py, check-spec-citations.py and version.py check all pass on e3d3bd9.

Not in this PR (server and owner side)

  • Runner to-x deleted. Still to do: set [actions] ENABLED = false in app.ini.
  • Enable [cors] for https://on-x.live, or the site's live widget stays on the snapshot.
  • pr59 (critical consensus safety fix) is still unmerged.
  • claude-review.py and push-auth.sh are not in the repo.

🤖 Generated with Claude Code

Migrates the repository off GitHub to self-hosted Forgejo after the `gokooteam` suspension (2026-10-10). The server runs git hosting and `onxd` only: no Actions, no runners, no review bots. ## What changes - **All 26 CI workflows deleted** (24 `.github/workflows`, 2 `.forgejo/workflows`). - **GitHub URLs migrated** to `git.on-x.live/amethyst/the-open-network-x` (`/src/branch/main/` paths). `site.py` rewrites them at build time, and `check` fails if any GitHub link or API call remains. - **Deploy scripts** use the Forgejo API. `site-pull-deploy.sh` no longer has a CI gate; the review process is the gate. - **SECURITY.md**: private reports go by email to `admin@on-x.live`. - **Review process** defined once in `CONTRIBUTING.md#review-process`: Claude three-lens review, half-weight self-check, point system (critical = NO-GO, 50 points = NO-GO), push authorization, Amethyst merges. - **Inert GitHub config removed**: `.coderabbit.yaml`, CODEOWNERS, dependabot, labeler, actionlint, zizmor, rulesets, `apply-branch-protection.sh`. The branch-protection guide is rewritten for Forgejo. - **Site**: PR cards link to their merge commits on Forgejo, and the heavy compare API call is dropped from the live widget. - **`docs/MIGRATION-forgejo.md`** records what was removed, what replaces it, and what was lost (PR pages, releases, tag `v0.2.1`, `pr59`/`pr60`). ## Checks (run locally) `site.py check`, `check-doc-links.py`, `check-spec-citations.py` and `version.py check` all pass on `e3d3bd9`. ## Not in this PR (server and owner side) - Runner `to-x` deleted. Still to do: set `[actions] ENABLED = false` in `app.ini`. - Enable `[cors]` for `https://on-x.live`, or the site's live widget stays on the snapshot. - `pr59` (critical consensus safety fix) is still unmerged. - `claude-review.py` and `push-auth.sh` are not in the repo. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
- Delete .forgejo/workflows/ (no CI on the server)
- Delete .github/workflows/ (24 GitHub workflows, inert on Forgejo)
- Update all github.com/gokooteam URLs to git.on-x.live/amethyst
- Remove CI badges from README (no CI means no badges)
- Update CONTRIBUTING, hosting guide, site README for new check process
- Add docs/MIGRATION-forgejo.md explaining the move
- Rebuild site with Forgejo URLs

Checks run on Gokoo's machine now, not on the server.
Review: Claude (three-lens) + Gokoo self-check + proof-demo gate.
Amethyst merges.
- site.py now rewrites github.com/gokooteam URLs to git.on-x.live
  during build (migrate_host), so index.html is never hand-edited
- BLOB/TREE use Forgejo /src/branch/main/ paths
- repo_links check validates Forgejo URLs
- Historical /pull/N links left alone (GitHub-only)
- site-pull-deploy.sh rewritten for Forgejo API (no more GitHub
  Actions check gate; main is the gate via point-system review)
- check-doc-links.py validates Forgejo /src/branch/main/ URLs
- migrate_host stashes /pull/N links before rewriting (docstring now true)
- CONTRIBUTING check list adds reference-vector and deny/audit commands
- site-pull-deploy.sh: Forgejo nests SHA under commit.id, not sha
- CONTRIBUTING + MIGRATION: add fuzz, multinode, reference-vector,
  deny/audit to the documented check suite
- docs/claude-review-prompt.md added to repo, CONTRIBUTING references it
- ADR-0040 notes versioning workflows removed, checks now manual
- Deploy script honest about procedural (not mechanical) gate
- MIGRATION doc lists honestly-lost scans (fuzz cron, audit cron, secrets)
- hosting.md: deploy script downloads from Forgejo raw, not dead GitHub URL
- site/README.md: deploy docs match the script (no CI gate, procedural review is the gate)
- migrate_host: live-status JS now uses Forgejo API (branch + compare)
- Historical /pull/N URLs restored to github.com (were wrongly rewritten)
- CONTRIBUTING clarifies push-auth.sh is maintainer-held, not in repo
- onx-hosting.sh: REPO and deploy-script URL now Forgejo
- hosting.md: cron always refreshes deploy script (stale-script fix)
- site.py: compare widget uses Forgejo total_commits (not GitHub status)
- MIGRATION: push rule matches CONTRIBUTING (agent pushes w/ auth)
- CONTRIBUTING: honest about what push-auth guarantees (tripwire, not PKI)
- onx-hosting.sh: inline Forgejo URL (FORGEJO not defined on remote host)
- hosting.md: bootstrap downloads onx-hosting.sh from Forgejo
- hosting.md: cron downloads to .new and moves only on success
- Delete GitHub-only config with nothing left to drive it: .coderabbit.yaml,
  CODEOWNERS, dependabot, labeler, actionlint, zizmor, rulesets/, and
  scripts/apply-branch-protection.sh. Rewrite the branch-protection guide
  for Forgejo branch protection.
- site.py: link the site's GitHub PR cards (#1-#5) to their merge commits on
  Forgejo instead of dead PR pages; relabel cards; `check` now fails if
  any GitHub link or API call is left in the page.
- Live widget: drop the Forgejo compare call (returns every commit and file
  in the range per page view; too heavy for the server).
- MIGRATION-forgejo.md: 26 workflows (not 24), point at CONTRIBUTING.md as
  the single definition of the review process, correct the SECURITY.md
  line, and record what was lost (PR pages, releases, v0.2.1 tag, pr59/pr60).
- MILESTONES.md: v0.2.1 release link was a 404 on Forgejo; say what happened.
- Historical notes on review-relay.md, task-chain.md, ADR-0047; conductors'
  score records Forgejo as canonical; scripts/README run-by column; explorer
  provenance comment; drop unused FORGEJO var in onx-hosting.sh.

Checks: site.py check, check-doc-links, check-spec-citations, version check
all pass.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
amethyst deleted branch migration/kill-actions 2026-10-11 04:16:13 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
amethyst/the-open-network-x!1
No description provided.