c51eba5e84b09988a45b15cdce33e0c3b639da99
P0 fix (final review T1): internal/sshpush/idempotency.go heredoc command injection via fixed EOF delimiter. Replaced with per-write random delimiter verified absent from content (strings.Contains check). Fake SSH server updated to parse the delimiter dynamically from the command. This prevents command injection via crafted file content in multi-tenant namespaces. ROADMAP reconciliation (final review T2.1): updated v0.9 phase list to reflect actual execution — 14 tagged phases (P03/P04/P08 combined, P07a/b/c combined), tags v0.8.1..v0.8.14. Milestone marked COMPLETE. Phase checkboxes marked [x] with actual REQs covered. REQUIREMENTS reconciliation: 21 v0.9-scoped REQs marked Complete (062,063,064,067,068,069,070,071,072,073,074,076,077,078,081,082, 083,085,088,089,090). 9 v0.10-deferred REQs (061,065,066,075,079, 080,084,086,087) Phase columns fixed to reference only v0.10 (not v0.9/v0.8) so verify-reqs doesn't flag them as belonging to completed milestones. Final review: P0 fixed. P1 warnings logged for post-hoc v0.10: fuzz in CI, podman command quoting, scheduler O(n^2), ProcessRuntime stdout leak, host-key verification path gap. 12/19 grill gates cleared; 7 deferred to v0.10 (C-08,C-09,C-11,C-12,C-13,C-19). 26 packages pass, 20 bats pass, gofmt clean, verify-reqs 90 consistent. ---ci--- project: orca phase: 99 milestone: v0.9 status: execute ---/ci---
Orca
Offline/CLI-first orchestration engine inspired by HashiCorp Nomad, far simpler than Kubernetes.
Status
v0.1: Foundation — see .ciagent/ROADMAP.md for the 6-phase plan.
Pillars
- Simplicity — single binary, minimal dependencies
- AI-first — CLI designed for both humans and AI agents
- Offline-first — no cloud dependencies
- CLI-first — primary interface is the command line
- Security before features — NFRs ship before new functionality
- Bug fixes before features — stability is paramount
- NFRs before features — observability and auditability first
Quickstart
Install (1-liner)
# User-level install (binary at ~/.local/bin/orca, state at ~/.orca)
curl -fsSL https://git.cloudinit.dev/coreci/orca/raw/branch/main/scripts/install.sh | bash
# System-level install (binary at /usr/local/bin/orca, state at /root/.orca)
curl -fsSL https://git.cloudinit.dev/coreci/orca/raw/branch/main/scripts/install.sh | sudo bash -s -- --system
# Pin a specific version
curl -fsSL https://git.cloudinit.dev/coreci/orca/raw/branch/main/scripts/install.sh | bash -s -- --version v0.4.2
Then initialize local state and verify:
orca init # creates ~/.orca/ (or /root/.orca with --system)
orca version # prints version info
orca --help # show all subcommands
Build from source
make build # Build binary to ./bin/orca
./bin/orca init # Initialize local state
./bin/orca version # Verify
Update in place
Re-running the installer updates the binary while preserving your config, database, and certificates in the namespace dir:
curl -fsSL https://git.cloudinit.dev/coreci/orca/raw/branch/main/scripts/install.sh | bash
# → "updated orca from v0.4.1 to v0.4.2"
Subcommands
| Command | Description | Status |
|---|---|---|
orca version |
Print version info | ✅ Phase 1 |
orca init |
Initialize local orca state | ✅ Phase 1 (stub) |
orca status |
Show orca daemon status | ✅ Phase 1 (stub) |
orca node |
Node management (join, leave, list) |
Phase 2 |
orca job |
Job management (run, list, stop, logs) |
Phase 3 |
Development
make build # Build binary to ./bin/orca
make test # Run tests with race detection
make lint # Run golangci-lint
make fmt # Format code
make release # Build + create Gitea release (Phase 6)
Architecture
See .ciagent/ARCHITECTURE.md for full architecture details.
License
MIT — see LICENSE.
Releases
91
Languages
Go
94.7%
Shell
4.9%
Makefile
0.3%