477b08c9a4091fae7aa61627698e8b5d3f4df23c
Layer-3 security audit during P07 EXECUTE found that .env (containing GITEA_TOKEN) was committed in0cba1aaduring P00 and remained in git history. The pre-P07 .gitignore only excluded .env.local, not .env. This commit: 1. Adds .env to .gitignore alongside .env.local (forward fix — prevents future re-tracking). 2. Documents the pre-existing leak in .ciagent/PHASE7_SECURITY_AUDIT.md with mitigation steps and required human actions (token rotation, history rewrite, access-log audit, CI secret scanning). The backfill script itself (commitde69788) does not leak the secret: it sources .env from disk and never echoes or passes it on the command line. The leak is upstream of P07 and is documented as P0 for the human to remediate out-of-band. ---ci--- project: orca phase: 7 milestone: v0.1 status: execute version: v0.1.7 requirements: covered: [REQ-007] partial: [] ---/ci---
Orca
Offline/CLI-first orchestration engine inspired by HashiCorp Nomad, far simpler than Kubernetes.
Status
v0.1: Foundation — see .ciagent/ROADMAP.md for the 6-phase plan.
Pillars
- Simplicity — single binary, minimal dependencies
- AI-first — CLI designed for both humans and AI agents
- Offline-first — no cloud dependencies
- CLI-first — primary interface is the command line
- Security before features — NFRs ship before new functionality
- Bug fixes before features — stability is paramount
- NFRs before features — observability and auditability first
Quickstart
# Build
make build
# Run
./bin/orca version
./bin/orca --help
# Initialize local state
./bin/orca init
Subcommands
| Command | Description | Status |
|---|---|---|
orca version |
Print version info | ✅ Phase 1 |
orca init |
Initialize local orca state | ✅ Phase 1 (stub) |
orca status |
Show orca daemon status | ✅ Phase 1 (stub) |
orca node |
Node management (join, leave, list) |
Phase 2 |
orca job |
Job management (run, list, stop, logs) |
Phase 3 |
Development
make build # Build binary to ./bin/orca
make test # Run tests with race detection
make lint # Run golangci-lint
make fmt # Format code
make release # Build + create Gitea release (Phase 6)
Architecture
See .ciagent/ARCHITECTURE.md for full architecture details.
License
MIT — see LICENSE.
Releases
91
Languages
Go
94.7%
Shell
4.9%
Makefile
0.3%