reforge-seed hardcoded approvals_whitelist_username to security-lead,
so seeded stack repos ignored the module option that the working repo
already respected. The package now bakes REFORGE_REQUIRED_APPROVERS in
from the option (space-separated, standalone default unchanged) and the
seed script builds the protection payload from it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Lifecycle step 6 had no tooling: a run's issues, reviews and charter
deliverables stayed inside the root-owned sqlite archive. reforge-harvest
walks every repo in the org and writes per-repo markdown (issues with
comments, PRs with reviews and inline comments), raw API JSON, an INDEX,
and a source-stripped tree of the charter repo (GAMEPLAN.md, CONTRACTS.md).
Read-only on the forge; re-runnable at any point.
Docs: step 6 now names the command and states that harvest is not
optional — run #1 sat unharvested for three months with two Critical
findings live in deployed forks.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The forgejo-sandbox / reforge harness, lifted out of the machine config
into a host-agnostic, generic engine anyone can consume with Nix.
Two layers:
- engine (this repo) — nixosModules.reforge stands up the sandbox forge,
provisions role accounts + tokens, enforces branch protection, and puts
the reforge-* CLI + forgejo-mcp on PATH. Carries no project specifics.
- run config — per-project manifest/charter/agenda/issues an adopter fills
in; scaffold one with the `reforge` flake template.
Portability fixes vs the in-config version:
- forgejo-mcp resolved from $REFORGE_MCP_BIN or PATH, never a named host
(kills the nixosConfigurations.omni hardcode).
- all instance data + paths parameterized via REFORGE_* env, baked into the
reforge-scripts wrappers from module options (configDir, agentsDir,
refsDir, org, port, tokenOwner, ...).
- option namespace neutral (reforge.* not omni.packs.*); settings policies
carry no absolute /etc/nixos paths.
- role briefs + orchestrator playbook genericized: all project specifics
point at the charter; refs corpus optional.
Validated: nix flake check (eval) + builds of forgejo-mcp, reforge-scripts,
and a module-eval check.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>