ba5ffd76f92f3c5f50b81aa9f0fe9faf7dd49357
Phase 10 (P03) ships: - .coreci.yml validate pipeline: gosec, govulncheck (offline mode), gitleaks in order; gitleaks baseline suppresses the v0.1 historical .env leak - scripts/security_scan.sh wrapper for local dev - .gitleaks.toml with cert PEM allowlist (REQ-039) - .gitleaks-baseline.json (REQ-029) - .golangci.yml unified config (REQ-040) with gosec severity=high so G101 (hardcoded credentials) is a build-breaker - .githooks/pre-commit gitleaks gate (skip if not installed) - docs/security-scanning.md operator doc - Makefile test-race + security-scan targets (REQ-031) - scripts/release.sh now passes --repo coreci/orca to tea (P01 audit fix; was missing in v0.2.1) Coverage: - REQ-014 gosec+govulncheck in CI - REQ-027 govulncheck offline mode - REQ-029 gitleaks baseline for pre-existing .env - REQ-031 go test -race in CI - REQ-039 .gitleaks.toml with cert PEM allowlist - REQ-040 .golangci.yml unified config ---ci--- project: orca phase: 10 milestone: v0.2 status: ship version: v0.2.3 requirements: covered: [REQ-014, REQ-027, REQ-029, REQ-031, REQ-039, REQ-040] partial: [] ---/ci---
Orca
Offline/CLI-first orchestration engine inspired by HashiCorp Nomad, far simpler than Kubernetes.
Status
v0.1: Foundation — see .ciagent/ROADMAP.md for the 6-phase plan.
Pillars
- Simplicity — single binary, minimal dependencies
- AI-first — CLI designed for both humans and AI agents
- Offline-first — no cloud dependencies
- CLI-first — primary interface is the command line
- Security before features — NFRs ship before new functionality
- Bug fixes before features — stability is paramount
- NFRs before features — observability and auditability first
Quickstart
# Build
make build
# Run
./bin/orca version
./bin/orca --help
# Initialize local state
./bin/orca init
Subcommands
| Command | Description | Status |
|---|---|---|
orca version |
Print version info | ✅ Phase 1 |
orca init |
Initialize local orca state | ✅ Phase 1 (stub) |
orca status |
Show orca daemon status | ✅ Phase 1 (stub) |
orca node |
Node management (join, leave, list) |
Phase 2 |
orca job |
Job management (run, list, stop, logs) |
Phase 3 |
Development
make build # Build binary to ./bin/orca
make test # Run tests with race detection
make lint # Run golangci-lint
make fmt # Format code
make release # Build + create Gitea release (Phase 6)
Architecture
See .ciagent/ARCHITECTURE.md for full architecture details.
License
MIT — see LICENSE.
Releases
91
Languages
Go
94.7%
Shell
4.9%
Makefile
0.3%