Record operator-validated Gitea SSH pull and push

This commit is contained in:
Fabio Scotto di Santolo
2026-10-02 17:47:40 +02:00
parent 309d64b4ed
commit ed3fee06e8
4 changed files with 11 additions and 6 deletions

View File

@@ -332,8 +332,10 @@ successfully. The first monthly scrub remains a runtime check.
firewall was opened on 2026-10-02, TCP/2222 connected, the public ED25519 host-key firewall was opened on 2026-10-02, TCP/2222 connected, the public ED25519 host-key
fingerprint matched Atlas, Gitea authenticated `fscotto` using the `ikaros` key, and fingerprint matched Atlas, Gitea authenticated `fscotto` using the `ikaros` key, and
`git ls-remote` returned HEAD for `fscotto/infra.git` over public SSH. `git ls-remote` returned HEAD for `fscotto/infra.git` over public SSH.
- [ ] Validate a representative authenticated SSH push and HTTPS write/login before declaring - [x] Validate authenticated SSH pull and push. On 2026-10-02 the operator reported both
the full cutover complete. Do not push to an existing repository merely as a test. The operations working through the public SSH endpoint; the earlier agent-run `git ls-remote`
remains the independent read-only check. The agent did not perform a test push.
- [ ] Validate HTTPS write/login before declaring the full cutover complete. The
secondary NPM hostname `git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had secondary NPM hostname `git.ov-ad3410.infomaniak.ch` did not resolve from Ikaros and had
no generated NPM config file at the previous inspection. Do not restart the stale source no generated NPM config file at the previous inspection. Do not restart the stale source
Gitea after Atlas has accepted writes. Gitea after Atlas has accepted writes.

View File

@@ -326,8 +326,8 @@ La migrazione Gitea da Prometheus ad Atlas è descritta in
[`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). Gitea usa un Quadlet rootless [`docs/atlas-gitea-migration.md`](docs/atlas-gitea-migration.md). Gitea usa un Quadlet rootless
di `admin` su un dataset dedicato; l'immagine derivata mantiene UID/GID 1000 ma chiama l'utente di `admin` su un dataset dedicato; l'immagine derivata mantiene UID/GID 1000 ma chiama l'utente
interno `gitea`. NPM resta su Prometheus e l'HTTPS pubblico primario serve Atlas. L'SSH pubblico interno `gitea`. NPM resta su Prometheus e l'HTTPS pubblico primario serve Atlas. L'SSH pubblico
su TCP/2222 autentica la chiave `ikaros` e un `git ls-remote` è riuscito; restano da provare su TCP/2222 autentica la chiave `ikaros` e un `git ls-remote` è riuscito; l'operatore ha
push autenticato e scrittura via HTTPS prima di considerare completo il cutover. I dati sorgente restano confermato pull e push SSH. Resta da provare la scrittura via HTTPS. I dati sorgente restano
conservati su Prometheus senza avviarne il vecchio container. conservati su Prometheus senza avviarne il vecchio container.
Validare il gateway con: Validare il gateway con:

View File

@@ -303,7 +303,8 @@ The Gitea move from Prometheus to Atlas is tracked in
Atlas' dedicated dataset under `admin`'s rootless user Quadlet. Its pinned derived image uses an Atlas' dedicated dataset under `admin`'s rootless user Quadlet. Its pinned derived image uses an
internal Unix user named `gitea` (UID/GID 1000), while clone URLs keep `git@`. NPM remains on Prometheus and the primary internal Unix user named `gitea` (UID/GID 1000), while clone URLs keep `git@`. NPM remains on Prometheus and the primary
public HTTPS route serves Atlas. Public SSH/2222 now authenticates the `ikaros` key and serves public HTTPS route serves Atlas. Public SSH/2222 now authenticates the `ikaros` key and serves
read-only `git ls-remote`; authenticated push and HTTPS writes remain untested. The old Gitea data remains on Prometheus, but its container read-only `git ls-remote`; the operator also confirmed SSH pull and push. HTTPS writes remain
untested. The old Gitea data remains on Prometheus, but its container
is absent from the desired stack. is absent from the desired stack.
The separate `wireguard_overlay` role manages `wg0` between Prometheus (`10.0.0.1`) and Aegis The separate `wireguard_overlay` role manages `wg0` between Prometheus (`10.0.0.1`) and Aegis

View File

@@ -146,7 +146,9 @@ test no SYN reached Prometheus `eth0`; its socket and firewalld port were active
After the VPS firewall was opened later on 2026-10-02, the public port connected, After the VPS firewall was opened later on 2026-10-02, the public port connected,
its ED25519 host-key fingerprint matched Atlas, Gitea authenticated the `ikaros` its ED25519 host-key fingerprint matched Atlas, Gitea authenticated the `ikaros`
key as `fscotto`, and a public SSH `git ls-remote` for `fscotto/infra.git` key as `fscotto`, and a public SSH `git ls-remote` for `fscotto/infra.git`
returned HEAD. Authenticated push and HTTPS write/login remain untested. Do not returned HEAD. The operator subsequently reported successful authenticated
SSH pull and push; the agent did not perform a write test. HTTPS write/login
remain untested. Do not
restart the stale source after public HTTPS has accepted target writes. restart the stale source after public HTTPS has accepted target writes.
The Prometheus export timer resumed with NPM-only paths. A recursive ZFS The Prometheus export timer resumed with NPM-only paths. A recursive ZFS