--- id: overview title: "Overview" description: "See the real Corp v1 service architecture: people and Discord, Hermes Agent, Gitea, CI, Pages, Harbor, Argo CD, and Gondor MicroK8s." --- import Drawio from '@theme/Drawio'; import architectureDiagram from '!!raw-loader!./diagrams/architecture-overview.drawio'; # Overview This is the **deployed service architecture around Corp v1 today**. It is different from the [Operating Model](/architecture-high-level/operating-model/): the operating model explains how work moves; this page shows which services perform and preserve that work. ## Services in the current setup | Service | Current role in Corp v1 | |---|---| | **Discord** | Human interaction surface: one `corp-v1-board` governance channel and seven focused sessions per project. | | **Hermes Agent** | The executing AI agent. It loads channel and engineering skills, uses connected tools, changes repositories, observes CI and runtime state, and reports evidence. It is not placed inside the Kubernetes cluster in this model. | | **Penpot** | Current UI/UX design workspace for journeys, information architecture, prototypes, accessibility review, and implementation handoff. | | **Gitea** | Durable source and collaboration system for the Board portal, project documentation, application source, adopted skills, branches, pull requests, decisions, and GitOps repositories. | | **Gitea Actions** | Self-hosted validation and publication. Exact-head runs are part of delivery evidence. | | **LEGO Cloud Pages** | Publishes the Board and project Docusaurus portals through the `pages` workload. The current `0500-pages` Argo CD application is `Synced / Healthy`. | | **Harbor** | Stores immutable application images. The current `0200-harbor` Argo CD application is `Synced / Healthy`. | | **Argo CD** | Reconciles GitOps desired state into Gondor v1. The current AeroSim application is `Synced / Healthy`; a project is not shown as deployed merely because a repository exists. | | **Gondor v1 MicroK8s** | Three-node Kubernetes runtime: Osgiliath plus two Minas Tirith workers. It currently hosts Pages and approved application workloads. | | **Access edge** | Cloudflare and Osgiliath Nginx route public traffic. Pages uses `pages-oauth2-proxy`, with Keycloak providing the observed sign-in boundary. | ## Documentation delivery path 1. Hermes or a human contributor changes an editable source in Gitea. 2. Gitea Actions validates the exact commit and builds Docusaurus. 3. The Pages publication workload serves the built route. 4. Protected readers pass through the access boundary. 5. Hermes verifies distinctive content through the authorized Pages service path before claiming completion. ## Application delivery path 1. Project source and GitOps desired state are reviewed in Gitea. 2. Gitea Actions validates the exact commit and publishes an immutable image to Harbor when credentials and policy gates are satisfied. 3. Argo CD reconciles approved desired state into the target MicroK8s namespace. 4. Runtime pod readiness, image identity, service route, and user-visible behavior are read back. Penpot evidence enters this flow through reviewed links and project documentation; it does not replace versioned requirements, ADRs, code, or release evidence. ## Boundaries of truth Discord and agent sessions coordinate work, but they are not the only durable record. Approved decisions, current architecture, source, adopted skills, and delivery evidence are persisted in Gitea-backed documentation. CI success proves validation; deployed readback proves publication or runtime behavior. The two are required together when delivery is claimed.