Personal infrastructure and tooling repository.
# Install all tools
just configure
# Lint and format check
just validate
# Auto-fix formatting
just fix- Tools are managed via mise; see
mise.tomlfor the tool list. - Tasks are defined in
justfile; usejustto list available commands. - GitHub Actions workflows are linted with zizmor.
- Dockerfiles are linted with hadolint.
- Infrastructure is managed with OpenTofu.
Two images are maintained:
| Image | Base | Purpose |
|---|---|---|
base-ci |
fedora:44 |
CI runner with mise pre-installed |
spacelift-runner |
spacelift/runner-terraform + 1password/op |
Spacelift stack runner with 1Password CLI |
Images are tagged with both latest and the full git SHA, and pushed to
ghcr.io/nikitabarskov/<target> on merge to main.
# Lint a Dockerfile
cd container-images && just validate <target>
# Build both platforms locally (no push)
cd container-images && just build <target>
# Build + push (CI path)
cd container-images && just ci <target>- Images must build for
linux/amd64andlinux/arm64. - Pin base image digests (
@sha256:...) — do not use floating tags. - Lint Dockerfiles with
hadolintbefore committing.
OpenTofu manages cloud resources (Cloudflare, GitHub, GitLab, Spacelift,
1Password). Plans run via
Spacelift; apply is not
run locally.
cd infrastructure/opentofu
# Install tools and init (no backend)
just configure
# Format check + validate
just validate
# Auto-format
just fix
# Local preview via Spacelift CLI
just plan- Requires a
.envfile withCLOUDFLARE_API_TOKEN="op://<1password-reference>". - Run
op run -- just <cmd>to inject secrets from 1Password when needed. - Backend is disabled for local runs (
tofu init -backend=false).
| Workflow | Trigger | What it does |
|---|---|---|
ci.yaml |
push/PR on relevant paths | Orchestrator: runs path-filter, fans out to container-images and infrastructure-opentofu reusable workflows |
container-images.yaml |
called by ci.yaml |
Builds (PR) or builds+pushes (main) the target image |
infrastructure-opentofu.yaml |
called by ci.yaml |
Runs mise install && just ci inside base-ci container |
- The
setupjob usesdorny/paths-filterto determine which jobs actually run; only changed paths trigger downstream jobs (unless shared files likemise.tomlchanged, which triggers all). - All workflow actions are pinned by SHA.
- Workflows are linted with
zizmor; runjust validatefrom the repo root.
- Always run
mise lock --platform linux-x64 --platform macos-arm64after updating tool versions to keep the lock file consistent across platforms.