Record successful public Gitea SSH authentication

This commit is contained in:
Fabio Scotto di Santolo
2026-10-02 10:19:23 +02:00
parent dd33a4f55d
commit 309d64b4ed
4 changed files with 19 additions and 15 deletions

View File

@@ -328,13 +328,15 @@ successfully. The first monthly scrub remains a runtime check.
and Syncthing remained active, the pool was healthy, and the normal Gitea run changed nothing.
The old host account and data on Prometheus remain preserved; the old Atlas Quadlet and its
parent-dataset traverse ACL were removed. A subsequent normal run changed nothing.
- [ ] Complete public SSH/2222 and representative authenticated HTTPS/SSH clone/push validation.
Prometheus' TCP/2222 socket and firewalld rule are active and the local proxy presents the
matching Atlas host key, but Ikaros' external TCP connection timed out and no SYN reached
Prometheus `eth0` during the test. Investigate upstream/provider filtering; do not claim the
approved simultaneous HTTPS+SSH cutover complete. The secondary NPM hostname
`git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had no generated NPM config file.
Do not restart the stale source Gitea after Atlas has accepted writes.
- [x] Validate public Gitea SSH/2222 and an authenticated read from Ikaros. After the VPS
firewall was opened on 2026-10-02, TCP/2222 connected, the public ED25519 host-key
fingerprint matched Atlas, Gitea authenticated `fscotto` using the `ikaros` key, and
`git ls-remote` returned HEAD for `fscotto/infra.git` over public SSH.
- [ ] Validate a representative authenticated SSH push and HTTPS write/login before declaring
the full cutover complete. Do not push to an existing repository merely as a test. The
secondary NPM hostname `git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had
no generated NPM config file at the previous inspection. Do not restart the stale source
Gitea after Atlas has accepted writes.
- [ ] Design and deploy Nextcloud as another explicitly temporary Atlas service before Uranus. Give it
separate persistent application, database, and cache storage; keep credentials in Vault; publish it only
through NPM over the Prometheus--Aegis gateway; and define backup, upgrade, and eventual Uranus-migration

View File

@@ -326,8 +326,8 @@ La migrazione Gitea da Prometheus ad Atlas è descritta in
[`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). Gitea usa un Quadlet rootless
di `admin` su un dataset dedicato; l'immagine derivata mantiene UID/GID 1000 ma chiama l'utente
interno `gitea`. NPM resta su Prometheus e l'HTTPS pubblico primario serve Atlas. L'SSH pubblico
su TCP/2222 non era ancora raggiungibile dall'esterno il 2026-10-02; non considerare completo
il cutover HTTPS+SSH finché non sono validati clone/push autenticati. I dati sorgente restano
su TCP/2222 autentica la chiave `ikaros` e un `git ls-remote` è riuscito; restano da provare
push autenticato e scrittura via HTTPS prima di considerare completo il cutover. I dati sorgente restano
conservati su Prometheus senza avviarne il vecchio container.
Validare il gateway con:

View File

@@ -302,9 +302,8 @@ The Gitea move from Prometheus to Atlas is tracked in
[`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). The final consistent copy runs in
Atlas' dedicated dataset under `admin`'s rootless user Quadlet. Its pinned derived image uses an
internal Unix user named `gitea` (UID/GID 1000), while clone URLs keep `git@`. NPM remains on Prometheus and the primary
public HTTPS route serves Atlas. The public SSH/2222 socket works locally on Prometheus, but an
external connection did not reach its interface on 2026-10-02; check upstream filtering before
declaring the HTTPS+SSH cutover complete. The old Gitea data remains on Prometheus, but its container
public HTTPS route serves Atlas. Public SSH/2222 now authenticates the `ikaros` key and serves
read-only `git ls-remote`; authenticated push and HTTPS writes remain untested. The old Gitea data remains on Prometheus, but its container
is absent from the desired stack.
The separate `wireguard_overlay` role manages `wg0` between Prometheus (`10.0.0.1`) and Aegis

View File

@@ -141,9 +141,12 @@ and had no generated NPM config file at the time of inspection.
Prometheus' public TCP/2222 socket proxies to Atlas without changing admin
SSH/22. The local socket presents the preserved Gitea ED25519 host key, but
an external TCP/2222 connection from Ikaros timed out. During the test no SYN
reached Prometheus `eth0`; its socket and firewalld port were active. Check
upstream/provider filtering before declaring public SSH complete. Do not
an external TCP/2222 connection from Ikaros initially timed out. During that
test no SYN reached Prometheus `eth0`; its socket and firewalld port were active.
After the VPS firewall was opened later on 2026-10-02, the public port connected,
its ED25519 host-key fingerprint matched Atlas, Gitea authenticated the `ikaros`
key as `fscotto`, and a public SSH `git ls-remote` for `fscotto/infra.git`
returned HEAD. Authenticated push and HTTPS write/login remain untested. Do not
restart the stale source after public HTTPS has accepted target writes.
The Prometheus export timer resumed with NPM-only paths. A recursive ZFS