Give every CI step explicit resource requests/limits and the default service
account (matching the pre-commit step), so the k8s woodpecker backend schedules
them with bounded resources.
- build/test/lint/package steps: 512Mi/1cpu requests, 2Gi/2cpu limits
- upload step: lighter 128Mi/100m requests, 512Mi/500m limits
Point the on-tag upload at artifactapi.k8s.syd1.au.unkin.net instead of the
unresolvable artifactapi3 name, matching the host used elsewhere (rpmbuilder,
terragrunt env).
Publish the provider so it can be consumed from terraform-vault: on a tag,
package the linux_amd64 build into a versioned zip and PUT it to the artifactapi
terraform registry, mirroring terraform-provider-artifactapi's release flow.
- Add .woodpecker/release.yml (event: tag) running make package + curl upload to
remotes/terraform-unkin/files/unkin/litellmvaultsecret/