How the platform behind our projects works.
One monorepo holds the applications, the infrastructure that runs them, the pipelines that ship them and the guardrails that keep agents honest. Here is how the pieces fit.
One build graph for every language.
vitruvian-core is a Bazel workspace on Bzlmod with Aspect rulesets. Go, TypeScript, Python, Kotlin and Swift build and test from the same graph, mostly on hermetic, version-pinned toolchains, so a green build on a laptop means the same thing as a green build in CI.
- One version per dependency per ecosystem, enforced across the repo.
- Gazelle generates BUILD files from source, so the graph follows the code.
- A presubmit planner tests only what a change can affect.
- Remote cache and execution are available, never required.
- Every tool is a
bazel runtarget, so agents and people use the same entry points.
Everything as code. No click-ops.
Cloud projects, deploy identities, DNS and even this repository's own GitHub settings are Pulumi programs written in Go. The homelab cluster reconciles from git through Argo CD. If it is not in a commit, it does not exist.
- Pulumi in Go for Google Cloud, GitHub and Cloudflare, applied only by CI.
- Argo CD app-of-apps for the K3s platform: Cilium, Envoy Gateway, Zitadel, CloudNativePG, MinIO.
- Observability as code: Prometheus, Thanos, Grafana, Loki, Tempo and OpenTelemetry.
- An enterprise GCP foundation built from our own Pulumi library.
Keyless deploys, through one gate.
Every change lands through the merge queue, which tests it against the latest main. Deploys authenticate with Workload Identity Federation, so there are no service-account keys to leak, and each app deploys into its own project behind its own GitHub Environment.
- Squash-only main behind a merge queue. Agents do not push to main or merge around the queue; the maintainer's break-glass raises an alert.
- Per-app GCP projects and deploy identities, scoped to one service each.
- Post-merge verification: work is not done until the pipelines on main are green.
- Secrets never in git: Secret Manager at runtime, sealed-secrets in the cluster.
Edit once, mirror out.
The monorepo is the single source of truth. Copybara exports each project to its own public repository on every merge, one way. Outside contributions come back as labelled pull requests that are imported for review here, so history never forks.
- Ten standalone repositories kept in sync automatically.
- release-please versions each component from its conventional commits; CLIs install from our Homebrew tap.
- This website is one of them: edited in the monorepo, published by its mirror.
AI agents as accountable teammates.
A team of specialist agents (build, infrastructure, cluster operations, application code, testing, security, documentation) works in the repo every day. Each acts under its own GitHub App, follows the same rules as a person, and is stopped by guardrails when it tries a shortcut.
- One GitHub App per agent, so authorship and approvals are real.
- One-hour installation tokens minted on demand; private keys stay in the vault.
- A shared, vendor-neutral AGENTS.md read by every coding tool we use.
- Guardrails from real incidents, each with a test that proves it fires.