# fscotto.co domain transition ## Observed state (2026-10-03) Namecheap remains the DNS provider. The operator moved GitHub Pages to `blog.fscotto.co` in `fscotto/fscotto.github.io`, aligned Hugo and Pages settings, and changed the apex A record to `179.237.102.172`. The blog remains a CNAME to `fscotto.github.io`; mail records were left unchanged. A new Hugo deployment and cache clearing resolved the initial stale DNS and generated URLs. Blog HTTPS returned 200 with valid TLS. The `git`, `music` and `syncthing` subdomains are CNAMEs to `fscotto.co`. The operator added NPM Proxy Hosts with certificates, WebSocket support and Force SSL: | Hostname | HTTP upstream | | --- | --- | | git.fscotto.co | 192.168.178.55:3000 | | music.fscotto.co | 192.168.178.55:4533 | | syncthing.fscotto.co | 192.168.178.55:8384 | All three redirected HTTP to HTTPS and returned final HTTPS 200 with valid TLS. Only the Syncthing GUI uses NPM; native synchronization is unchanged. NPM administration remains loopback-only on port 81 via SSH tunnel. ## Gitea canonical hostname Atlas declares `atlas_gitea_public_domain: git.fscotto.co`. Ansible manages only `[server] DOMAIN`, `ROOT_URL` and `SSH_DOMAIN` in the existing private app.ini, preserving unrelated settings and mode 0600. Private configuration backups are created; diffs and secret-bearing results are suppressed. Only Gitea restarts when these fields change; a repeat run changed nothing. HTTPS uses `https://git.fscotto.co/`; public SSH remains TCP/2222. Agent read-only checks returned the same HEAD from `fscotto/infra.git` over HTTPS and authenticated SSH. SSH host identity was checked against the already-trusted old endpoint key. No test push or user-authenticated web login was performed by the agent. ```bash ansible-playbook ansible/site.yml --limit atlas --tags gitea_public_domain --check --diff ``` Client remotes do not update automatically. Update them deliberately after checking repository paths; integrations and webhooks are separate operations. For the verified infrastructure repository only: ```bash git remote set-url origin ssh://git@git.fscotto.co:2222/fscotto/infra.git ``` Do not copy this path into unrelated clones. Verify Gitea's known SSH key before accepting the new hostname's identity. ## Local DuckDNS retirement Prometheus declares `server_duckdns_enabled: false`. On 2026-10-03 the explicit Ansible cleanup removed the five-minute rocky cron entry and the private `~/duckdns` directory containing only `duck.sh` and `duck.log`. The temporary cleanup tasks and flag were subsequently removed from the playbook at the operator's request. Only the disabled provisioning state remains; ordinary provisioning cannot recreate the updater. The external DuckDNS name, Vault token, disabled NPM hosts and certificates remain untouched for a separate future decision. The repeat cleanup changed nothing; ordinary DuckDNS provisioning was skipped. The cron table had no remaining entries, NPM and the export timer were active, and NPM administration still listened only on `127.0.0.1:81`. ## Remaining transition work - Confirm user-authenticated login and push on the new Gitea hostname. - Update existing remotes and callback/webhook URLs explicitly. - Retire obsolete NPM hosts/certificates and the old upstream override after confirming they are no longer needed. At inspection the three old DuckDNS Proxy Hosts were already disabled, not deleted. They are not working HTTPS rollback endpoints. Existing backup archives remain preserved. DNS/Pages/NPM changes were operator actions; the Gitea application configuration change was deployed through Ansible.