mirror of
https://github.com/fscotto/infra.git
synced 2026-10-03 13:29:58 +00:00
Record successful public Gitea SSH authentication
This commit is contained in:
16
AGENTS.md
16
AGENTS.md
@@ -328,13 +328,15 @@ successfully. The first monthly scrub remains a runtime check.
|
||||
and Syncthing remained active, the pool was healthy, and the normal Gitea run changed nothing.
|
||||
The old host account and data on Prometheus remain preserved; the old Atlas Quadlet and its
|
||||
parent-dataset traverse ACL were removed. A subsequent normal run changed nothing.
|
||||
- [ ] Complete public SSH/2222 and representative authenticated HTTPS/SSH clone/push validation.
|
||||
Prometheus' TCP/2222 socket and firewalld rule are active and the local proxy presents the
|
||||
matching Atlas host key, but Ikaros' external TCP connection timed out and no SYN reached
|
||||
Prometheus `eth0` during the test. Investigate upstream/provider filtering; do not claim the
|
||||
approved simultaneous HTTPS+SSH cutover complete. The secondary NPM hostname
|
||||
`git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had no generated NPM config file.
|
||||
Do not restart the stale source Gitea after Atlas has accepted writes.
|
||||
- [x] Validate public Gitea SSH/2222 and an authenticated read from Ikaros. After the VPS
|
||||
firewall was opened on 2026-10-02, TCP/2222 connected, the public ED25519 host-key
|
||||
fingerprint matched Atlas, Gitea authenticated `fscotto` using the `ikaros` key, and
|
||||
`git ls-remote` returned HEAD for `fscotto/infra.git` over public SSH.
|
||||
- [ ] Validate a representative authenticated SSH push and HTTPS write/login before declaring
|
||||
the full cutover complete. Do not push to an existing repository merely as a test. The
|
||||
secondary NPM hostname `git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had
|
||||
no generated NPM config file at the previous inspection. Do not restart the stale source
|
||||
Gitea after Atlas has accepted writes.
|
||||
- [ ] Design and deploy Nextcloud as another explicitly temporary Atlas service before Uranus. Give it
|
||||
separate persistent application, database, and cache storage; keep credentials in Vault; publish it only
|
||||
through NPM over the Prometheus--Aegis gateway; and define backup, upgrade, and eventual Uranus-migration
|
||||
|
||||
@@ -326,8 +326,8 @@ La migrazione Gitea da Prometheus ad Atlas è descritta in
|
||||
[`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). Gitea usa un Quadlet rootless
|
||||
di `admin` su un dataset dedicato; l'immagine derivata mantiene UID/GID 1000 ma chiama l'utente
|
||||
interno `gitea`. NPM resta su Prometheus e l'HTTPS pubblico primario serve Atlas. L'SSH pubblico
|
||||
su TCP/2222 non era ancora raggiungibile dall'esterno il 2026-10-02; non considerare completo
|
||||
il cutover HTTPS+SSH finché non sono validati clone/push autenticati. I dati sorgente restano
|
||||
su TCP/2222 autentica la chiave `ikaros` e un `git ls-remote` è riuscito; restano da provare
|
||||
push autenticato e scrittura via HTTPS prima di considerare completo il cutover. I dati sorgente restano
|
||||
conservati su Prometheus senza avviarne il vecchio container.
|
||||
|
||||
Validare il gateway con:
|
||||
|
||||
@@ -302,9 +302,8 @@ The Gitea move from Prometheus to Atlas is tracked in
|
||||
[`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). The final consistent copy runs in
|
||||
Atlas' dedicated dataset under `admin`'s rootless user Quadlet. Its pinned derived image uses an
|
||||
internal Unix user named `gitea` (UID/GID 1000), while clone URLs keep `git@`. NPM remains on Prometheus and the primary
|
||||
public HTTPS route serves Atlas. The public SSH/2222 socket works locally on Prometheus, but an
|
||||
external connection did not reach its interface on 2026-10-02; check upstream filtering before
|
||||
declaring the HTTPS+SSH cutover complete. The old Gitea data remains on Prometheus, but its container
|
||||
public HTTPS route serves Atlas. Public SSH/2222 now authenticates the `ikaros` key and serves
|
||||
read-only `git ls-remote`; authenticated push and HTTPS writes remain untested. The old Gitea data remains on Prometheus, but its container
|
||||
is absent from the desired stack.
|
||||
|
||||
The separate `wireguard_overlay` role manages `wg0` between Prometheus (`10.0.0.1`) and Aegis
|
||||
|
||||
@@ -141,9 +141,12 @@ and had no generated NPM config file at the time of inspection.
|
||||
|
||||
Prometheus' public TCP/2222 socket proxies to Atlas without changing admin
|
||||
SSH/22. The local socket presents the preserved Gitea ED25519 host key, but
|
||||
an external TCP/2222 connection from Ikaros timed out. During the test no SYN
|
||||
reached Prometheus `eth0`; its socket and firewalld port were active. Check
|
||||
upstream/provider filtering before declaring public SSH complete. Do not
|
||||
an external TCP/2222 connection from Ikaros initially timed out. During that
|
||||
test no SYN reached Prometheus `eth0`; its socket and firewalld port were active.
|
||||
After the VPS firewall was opened later on 2026-10-02, the public port connected,
|
||||
its ED25519 host-key fingerprint matched Atlas, Gitea authenticated the `ikaros`
|
||||
key as `fscotto`, and a public SSH `git ls-remote` for `fscotto/infra.git`
|
||||
returned HEAD. Authenticated push and HTTPS write/login remain untested. Do not
|
||||
restart the stale source after public HTTPS has accepted target writes.
|
||||
|
||||
The Prometheus export timer resumed with NPM-only paths. A recursive ZFS
|
||||
|
||||
Reference in New Issue
Block a user