Using Zyvor Fabric in DevOps
Fabric is the control plane. FluxVM is the VM engine. Pipelines should treat them as one stack.
Git / CI → zyvor-fabricd :9095 → fluxvm :7788 → KVM guests
/health /readyz /healthz /readyz
Probe contract
| Service | Liveness | Readiness |
|---|---|---|
| Fabric | GET /health | GET /readyz (ok, store, fluxvm) |
| FluxVM | GET /healthz | GET /readyz (ok, optional kvm / dataplane) |
/readyz is what load balancers and kubectl probes must use. Fabric is not ready if FluxVM /readyz is 503.
Canonical JSON: contracts/fabric-fluxvm-readyz.json.
Environment promotion
- PR — contract unit tests + Catch-up coverage job +
scripts/test-devops-gate.sh+ proven-infra suites. - Lab —
./scripts/ship sus@HOST(FluxVM + Fabric + readiness). Full lab pack:scripts/test-lab-verify.sh. Optional catch-up verify:scripts/feat-catchup-verify.sh. - Prod — snapshot (
scripts/upgrade-rollback.sh snapshot) →FABRIC_ADMIN_PASSWORD=… ./scripts/ship sus@HOST --prod→ keep snapshot.
A push to main also deploys the lab host from GitHub Actions
(.github/workflows/lab-deploy.yml).
The job runs ./scripts/deploy-remote.sh 80.79.5.173 sus --quick --e2e --verify-apis
and authenticates with the LAB_DEPLOY_KEY repository secret (an ed25519 key
for sus, not a personal key). You can start the same job with
workflow_dispatch. It stops zyvor-fabricd for the remote rebuild, so it
does not run on pull requests.
Pair FluxVM upgrades with fluxvm scripts/upgrade-snapshot.sh on the same change window.
Lab HTTPS
Lab zyvor-fabricd usually serves HTTPS with a self-signed cert.
scripts/devops-gate.sh uses curl -k and, when FABRIC_URL is unset, probes
https://127.0.0.1:9095 then http://127.0.0.1:9095.
fabricctl does the same for its default server: with no --server,
ZYVOR_FABRIC_URL or FABRIC_URL it uses https://localhost:9095 when that
port answers a plain-HTTP request the way a TLS listener does, and
http://localhost:9095 otherwise (the Docker config serves plain HTTP). An
explicit server is used as given.
# Super-easy stack ship (FluxVM + Fabric + readiness)
./scripts/ship sus@HOST
# Full post-deploy lab gate (stdin closed for nested tools)
./scripts/test-lab-verify.sh
# Production readiness only (read-only; requires real token — no Admin@321 fallback)
FABRIC_URL=https://127.0.0.1:9095 FLUXVM_URL=http://127.0.0.1:7788 \
FABRIC_TOKEN=… ./scripts/test-production-readiness.sh
# Live probe only
unset FABRIC_URL
FLUXVM_URL=http://127.0.0.1:7788 ./scripts/devops-gate.sh
# or:
ZYVOR_DEVOPS_LIVE=1 ./scripts/test-devops-gate.sh
Security and format scans in CI
- Trivy (
.github/workflows/security.yml) scans the tree for vulnerabilities and secrets at HIGH and CRITICAL.trivy-secret.yamlat the repo root is Trivy's secret config; it allows only the fakeghp_…tokens inagent-runtime/src/memory.rs(the memory redaction tests need a token-shaped value). Every other path is still scanned. Add a new allow rule there only for a test fixture, with apathlimited to that file. - CodeQL reports to the repository's code-scanning page. A false positive is dismissed there
with a written reason (for example the operator-set path in
agent-runtime/src/audit.rs); a real one gets a code fix and a test. - Fabric Doctor (
.github/workflows/fabric-doctor.yml) runsgofmt -l ./cmd ./internalintools/fabric-doctor; rungofmt -won the listed files before pushing.
Source of truth (pick one)
- GitOps:
examples/devops/gitops+ operator - Terraform:
examples/devops/terraform - CLI:
fabricctl apply -f examples/devops/apply-vm.yaml
Do not mix writers on the same VM name.
Secrets
ZYVOR_FABRICD_ADMIN_PASSWORD,ZYVOR_FABRICD_JWT_SECRET- CI user token (
FABRIC_TOKEN) driver.fluxvm_tokenwhen FluxVM auth is on