diff --git a/AGENTS.md b/AGENTS.md index f642760..64d0e62 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -328,13 +328,15 @@ successfully. The first monthly scrub remains a runtime check. and Syncthing remained active, the pool was healthy, and the normal Gitea run changed nothing. The old host account and data on Prometheus remain preserved; the old Atlas Quadlet and its parent-dataset traverse ACL were removed. A subsequent normal run changed nothing. -- [ ] Complete public SSH/2222 and representative authenticated HTTPS/SSH clone/push validation. - Prometheus' TCP/2222 socket and firewalld rule are active and the local proxy presents the - matching Atlas host key, but Ikaros' external TCP connection timed out and no SYN reached - Prometheus `eth0` during the test. Investigate upstream/provider filtering; do not claim the - approved simultaneous HTTPS+SSH cutover complete. The secondary NPM hostname - `git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had no generated NPM config file. - Do not restart the stale source Gitea after Atlas has accepted writes. +- [x] Validate public Gitea SSH/2222 and an authenticated read from Ikaros. After the VPS + firewall was opened on 2026-10-02, TCP/2222 connected, the public ED25519 host-key + fingerprint matched Atlas, Gitea authenticated `fscotto` using the `ikaros` key, and + `git ls-remote` returned HEAD for `fscotto/infra.git` over public SSH. +- [ ] Validate a representative authenticated SSH push and HTTPS write/login before declaring + the full cutover complete. Do not push to an existing repository merely as a test. The + secondary NPM hostname `git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had + no generated NPM config file at the previous inspection. Do not restart the stale source + Gitea after Atlas has accepted writes. - [ ] Design and deploy Nextcloud as another explicitly temporary Atlas service before Uranus. Give it separate persistent application, database, and cache storage; keep credentials in Vault; publish it only through NPM over the Prometheus--Aegis gateway; and define backup, upgrade, and eventual Uranus-migration diff --git a/README.it.md b/README.it.md index 7882b90..52c5a93 100644 --- a/README.it.md +++ b/README.it.md @@ -326,8 +326,8 @@ La migrazione Gitea da Prometheus ad Atlas è descritta in [`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). Gitea usa un Quadlet rootless di `admin` su un dataset dedicato; l'immagine derivata mantiene UID/GID 1000 ma chiama l'utente interno `gitea`. NPM resta su Prometheus e l'HTTPS pubblico primario serve Atlas. L'SSH pubblico -su TCP/2222 non era ancora raggiungibile dall'esterno il 2026-10-02; non considerare completo -il cutover HTTPS+SSH finché non sono validati clone/push autenticati. I dati sorgente restano +su TCP/2222 autentica la chiave `ikaros` e un `git ls-remote` è riuscito; restano da provare +push autenticato e scrittura via HTTPS prima di considerare completo il cutover. I dati sorgente restano conservati su Prometheus senza avviarne il vecchio container. Validare il gateway con: diff --git a/README.md b/README.md index e39ad93..fe6d169 100644 --- a/README.md +++ b/README.md @@ -302,9 +302,8 @@ The Gitea move from Prometheus to Atlas is tracked in [`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). The final consistent copy runs in Atlas' dedicated dataset under `admin`'s rootless user Quadlet. Its pinned derived image uses an internal Unix user named `gitea` (UID/GID 1000), while clone URLs keep `git@`. NPM remains on Prometheus and the primary -public HTTPS route serves Atlas. The public SSH/2222 socket works locally on Prometheus, but an -external connection did not reach its interface on 2026-10-02; check upstream filtering before -declaring the HTTPS+SSH cutover complete. The old Gitea data remains on Prometheus, but its container +public HTTPS route serves Atlas. Public SSH/2222 now authenticates the `ikaros` key and serves +read-only `git ls-remote`; authenticated push and HTTPS writes remain untested. The old Gitea data remains on Prometheus, but its container is absent from the desired stack. The separate `wireguard_overlay` role manages `wg0` between Prometheus (`10.0.0.1`) and Aegis diff --git a/docs/atlas-gitea-migration.md b/docs/atlas-gitea-migration.md index fcbf53e..4ba4f8b 100644 --- a/docs/atlas-gitea-migration.md +++ b/docs/atlas-gitea-migration.md @@ -141,9 +141,12 @@ and had no generated NPM config file at the time of inspection. Prometheus' public TCP/2222 socket proxies to Atlas without changing admin SSH/22. The local socket presents the preserved Gitea ED25519 host key, but -an external TCP/2222 connection from Ikaros timed out. During the test no SYN -reached Prometheus `eth0`; its socket and firewalld port were active. Check -upstream/provider filtering before declaring public SSH complete. Do not +an external TCP/2222 connection from Ikaros initially timed out. During that +test no SYN reached Prometheus `eth0`; its socket and firewalld port were active. +After the VPS firewall was opened later on 2026-10-02, the public port connected, +its ED25519 host-key fingerprint matched Atlas, Gitea authenticated the `ikaros` +key as `fscotto`, and a public SSH `git ls-remote` for `fscotto/infra.git` +returned HEAD. Authenticated push and HTTPS write/login remain untested. Do not restart the stale source after public HTTPS has accepted target writes. The Prometheus export timer resumed with NPM-only paths. A recursive ZFS