Record successful public Gitea SSH authentication

This commit is contained in:
Fabio Scotto di Santolo
2026-10-02 10:19:23 +02:00
parent dd33a4f55d
commit 309d64b4ed
4 changed files with 19 additions and 15 deletions

View File

@@ -328,13 +328,15 @@ successfully. The first monthly scrub remains a runtime check.
and Syncthing remained active, the pool was healthy, and the normal Gitea run changed nothing. and Syncthing remained active, the pool was healthy, and the normal Gitea run changed nothing.
The old host account and data on Prometheus remain preserved; the old Atlas Quadlet and its The old host account and data on Prometheus remain preserved; the old Atlas Quadlet and its
parent-dataset traverse ACL were removed. A subsequent normal run changed nothing. parent-dataset traverse ACL were removed. A subsequent normal run changed nothing.
- [ ] Complete public SSH/2222 and representative authenticated HTTPS/SSH clone/push validation. - [x] Validate public Gitea SSH/2222 and an authenticated read from Ikaros. After the VPS
Prometheus' TCP/2222 socket and firewalld rule are active and the local proxy presents the firewall was opened on 2026-10-02, TCP/2222 connected, the public ED25519 host-key
matching Atlas host key, but Ikaros' external TCP connection timed out and no SYN reached fingerprint matched Atlas, Gitea authenticated `fscotto` using the `ikaros` key, and
Prometheus `eth0` during the test. Investigate upstream/provider filtering; do not claim the `git ls-remote` returned HEAD for `fscotto/infra.git` over public SSH.
approved simultaneous HTTPS+SSH cutover complete. The secondary NPM hostname - [ ] Validate a representative authenticated SSH push and HTTPS write/login before declaring
`git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had no generated NPM config file. the full cutover complete. Do not push to an existing repository merely as a test. The
Do not restart the stale source Gitea after Atlas has accepted writes. secondary NPM hostname `git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had
no generated NPM config file at the previous inspection. Do not restart the stale source
Gitea after Atlas has accepted writes.
- [ ] Design and deploy Nextcloud as another explicitly temporary Atlas service before Uranus. Give it - [ ] Design and deploy Nextcloud as another explicitly temporary Atlas service before Uranus. Give it
separate persistent application, database, and cache storage; keep credentials in Vault; publish it only separate persistent application, database, and cache storage; keep credentials in Vault; publish it only
through NPM over the Prometheus--Aegis gateway; and define backup, upgrade, and eventual Uranus-migration through NPM over the Prometheus--Aegis gateway; and define backup, upgrade, and eventual Uranus-migration

View File

@@ -326,8 +326,8 @@ La migrazione Gitea da Prometheus ad Atlas è descritta in
[`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). Gitea usa un Quadlet rootless [`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). Gitea usa un Quadlet rootless
di `admin` su un dataset dedicato; l'immagine derivata mantiene UID/GID 1000 ma chiama l'utente di `admin` su un dataset dedicato; l'immagine derivata mantiene UID/GID 1000 ma chiama l'utente
interno `gitea`. NPM resta su Prometheus e l'HTTPS pubblico primario serve Atlas. L'SSH pubblico interno `gitea`. NPM resta su Prometheus e l'HTTPS pubblico primario serve Atlas. L'SSH pubblico
su TCP/2222 non era ancora raggiungibile dall'esterno il 2026-10-02; non considerare completo su TCP/2222 autentica la chiave `ikaros` e un `git ls-remote` è riuscito; restano da provare
il cutover HTTPS+SSH finché non sono validati clone/push autenticati. I dati sorgente restano push autenticato e scrittura via HTTPS prima di considerare completo il cutover. I dati sorgente restano
conservati su Prometheus senza avviarne il vecchio container. conservati su Prometheus senza avviarne il vecchio container.
Validare il gateway con: Validare il gateway con:

View File

@@ -302,9 +302,8 @@ The Gitea move from Prometheus to Atlas is tracked in
[`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). The final consistent copy runs in [`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). The final consistent copy runs in
Atlas' dedicated dataset under `admin`'s rootless user Quadlet. Its pinned derived image uses an Atlas' dedicated dataset under `admin`'s rootless user Quadlet. Its pinned derived image uses an
internal Unix user named `gitea` (UID/GID 1000), while clone URLs keep `git@`. NPM remains on Prometheus and the primary internal Unix user named `gitea` (UID/GID 1000), while clone URLs keep `git@`. NPM remains on Prometheus and the primary
public HTTPS route serves Atlas. The public SSH/2222 socket works locally on Prometheus, but an public HTTPS route serves Atlas. Public SSH/2222 now authenticates the `ikaros` key and serves
external connection did not reach its interface on 2026-10-02; check upstream filtering before read-only `git ls-remote`; authenticated push and HTTPS writes remain untested. The old Gitea data remains on Prometheus, but its container
declaring the HTTPS+SSH cutover complete. The old Gitea data remains on Prometheus, but its container
is absent from the desired stack. is absent from the desired stack.
The separate `wireguard_overlay` role manages `wg0` between Prometheus (`10.0.0.1`) and Aegis The separate `wireguard_overlay` role manages `wg0` between Prometheus (`10.0.0.1`) and Aegis

View File

@@ -141,9 +141,12 @@ and had no generated NPM config file at the time of inspection.
Prometheus' public TCP/2222 socket proxies to Atlas without changing admin Prometheus' public TCP/2222 socket proxies to Atlas without changing admin
SSH/22. The local socket presents the preserved Gitea ED25519 host key, but SSH/22. The local socket presents the preserved Gitea ED25519 host key, but
an external TCP/2222 connection from Ikaros timed out. During the test no SYN an external TCP/2222 connection from Ikaros initially timed out. During that
reached Prometheus `eth0`; its socket and firewalld port were active. Check test no SYN reached Prometheus `eth0`; its socket and firewalld port were active.
upstream/provider filtering before declaring public SSH complete. Do not After the VPS firewall was opened later on 2026-10-02, the public port connected,
its ED25519 host-key fingerprint matched Atlas, Gitea authenticated the `ikaros`
key as `fscotto`, and a public SSH `git ls-remote` for `fscotto/infra.git`
returned HEAD. Authenticated push and HTTPS write/login remain untested. Do not
restart the stale source after public HTTPS has accepted target writes. restart the stale source after public HTTPS has accepted target writes.
The Prometheus export timer resumed with NPM-only paths. A recursive ZFS The Prometheus export timer resumed with NPM-only paths. A recursive ZFS