Update VPS invariants for live cutover state

This commit is contained in:
axiomlogicnexus 2026-05-30 19:18:11 +02:00
parent e7bfd3734f
commit 6f1b8e2587
2 changed files with 25 additions and 8 deletions

View file

@ -102,7 +102,10 @@ Examples:
1. SSH:
- keep the real target as `212.227.13.220`
- add new `Host` aliases in `~/.ssh/config`
- add new `Host` aliases in `~/.ssh/config`, for example:
- `platform-main-root`
- `platform-main-dev`
- `platform-main-deploy`
- do not change the real server paths or accounts
2. Scheduled tasks:
@ -119,6 +122,7 @@ Examples:
4. Wrapper scripts:
- `run-platform-remote-dev-seed.ps1`
- `run-platform-authorship-sync.ps1`
- `run-platform-remote-dev-reverse-sync.ps1`
- internally call the current `scriptorium*` scripts
5. Password manager / credential registry:

View file

@ -96,7 +96,7 @@ Forgejo current state:
- `SSH_DOMAIN = git.scriptoriumai.io`
- `SSH_PORT = 2222`
- `DISABLE_REGISTRATION = true`
- `REQUIRE_SIGNIN_VIEW = true`
- `REQUIRE_SIGNIN_VIEW = false`
- existing accounts/data were copied; no passwordless public access was enabled
Woodpecker current state:
@ -108,7 +108,9 @@ Woodpecker current state:
Operational implication:
- Forgejo still expects authenticated use
- public web viewing and anonymous read access to public repositories are now
allowed
- Forgejo still expects authenticated write access
- Git push auth is still the normal Forgejo model: SSH key or HTTPS credential
- Woodpecker open mode is inherited from the old stack and should be revisited
later if tighter enrollment is desired
@ -142,13 +144,24 @@ Current design:
- nightly at `03:30`
- changed-file reverse sync from `/home/dev/src`
- conservative excludes for obviously rebuildable artifacts
- `mirrors` are excluded from the retained reverse-sync payload
- no second full local mirror root by default; it syncs back into the existing
local project paths
local project paths when enabled
Measured retained payload with rebuildable junk and `mirrors` omitted:
- about `18.6 GiB`
Measured omitted `mirrors` payload:
- about `107.9 GiB`
Current safety rule:
- the task refuses to overwrite a dirty local Git worktree by default
- that safeguard currently matters because several local repos are dirty
- the scheduled task is currently **disabled** by operator request until the
retained backup lane is reviewed
## VerticalTension git/ci alias stance
@ -174,10 +187,10 @@ Why:
Current prep state:
- the new VPS already has HTTP redirect vhost coverage staged for both alias
hosts
- after their DNS `A` records are moved to `212.227.13.220`, the remaining
step is VPS-side certificate issuance for those two hostnames
- the new VPS has HTTPS redirect coverage live for both alias hosts:
- `git.verticaltension.com`
- `ci.verticaltension.com`
- both now redirect to the canonical ScriptoriumAI control-plane hosts
## IONOS SSL posture