Update VPS invariants for live cutover state
This commit is contained in:
parent
e7bfd3734f
commit
6f1b8e2587
2 changed files with 25 additions and 8 deletions
|
|
@ -102,7 +102,10 @@ Examples:
|
|||
|
||||
1. SSH:
|
||||
- keep the real target as `212.227.13.220`
|
||||
- add new `Host` aliases in `~/.ssh/config`
|
||||
- add new `Host` aliases in `~/.ssh/config`, for example:
|
||||
- `platform-main-root`
|
||||
- `platform-main-dev`
|
||||
- `platform-main-deploy`
|
||||
- do not change the real server paths or accounts
|
||||
|
||||
2. Scheduled tasks:
|
||||
|
|
@ -119,6 +122,7 @@ Examples:
|
|||
4. Wrapper scripts:
|
||||
- `run-platform-remote-dev-seed.ps1`
|
||||
- `run-platform-authorship-sync.ps1`
|
||||
- `run-platform-remote-dev-reverse-sync.ps1`
|
||||
- internally call the current `scriptorium*` scripts
|
||||
|
||||
5. Password manager / credential registry:
|
||||
|
|
|
|||
|
|
@ -96,7 +96,7 @@ Forgejo current state:
|
|||
- `SSH_DOMAIN = git.scriptoriumai.io`
|
||||
- `SSH_PORT = 2222`
|
||||
- `DISABLE_REGISTRATION = true`
|
||||
- `REQUIRE_SIGNIN_VIEW = true`
|
||||
- `REQUIRE_SIGNIN_VIEW = false`
|
||||
- existing accounts/data were copied; no passwordless public access was enabled
|
||||
|
||||
Woodpecker current state:
|
||||
|
|
@ -108,7 +108,9 @@ Woodpecker current state:
|
|||
|
||||
Operational implication:
|
||||
|
||||
- Forgejo still expects authenticated use
|
||||
- public web viewing and anonymous read access to public repositories are now
|
||||
allowed
|
||||
- Forgejo still expects authenticated write access
|
||||
- Git push auth is still the normal Forgejo model: SSH key or HTTPS credential
|
||||
- Woodpecker open mode is inherited from the old stack and should be revisited
|
||||
later if tighter enrollment is desired
|
||||
|
|
@ -142,13 +144,24 @@ Current design:
|
|||
- nightly at `03:30`
|
||||
- changed-file reverse sync from `/home/dev/src`
|
||||
- conservative excludes for obviously rebuildable artifacts
|
||||
- `mirrors` are excluded from the retained reverse-sync payload
|
||||
- no second full local mirror root by default; it syncs back into the existing
|
||||
local project paths
|
||||
local project paths when enabled
|
||||
|
||||
Measured retained payload with rebuildable junk and `mirrors` omitted:
|
||||
|
||||
- about `18.6 GiB`
|
||||
|
||||
Measured omitted `mirrors` payload:
|
||||
|
||||
- about `107.9 GiB`
|
||||
|
||||
Current safety rule:
|
||||
|
||||
- the task refuses to overwrite a dirty local Git worktree by default
|
||||
- that safeguard currently matters because several local repos are dirty
|
||||
- the scheduled task is currently **disabled** by operator request until the
|
||||
retained backup lane is reviewed
|
||||
|
||||
## VerticalTension git/ci alias stance
|
||||
|
||||
|
|
@ -174,10 +187,10 @@ Why:
|
|||
|
||||
Current prep state:
|
||||
|
||||
- the new VPS already has HTTP redirect vhost coverage staged for both alias
|
||||
hosts
|
||||
- after their DNS `A` records are moved to `212.227.13.220`, the remaining
|
||||
step is VPS-side certificate issuance for those two hostnames
|
||||
- the new VPS has HTTPS redirect coverage live for both alias hosts:
|
||||
- `git.verticaltension.com`
|
||||
- `ci.verticaltension.com`
|
||||
- both now redirect to the canonical ScriptoriumAI control-plane hosts
|
||||
|
||||
## IONOS SSL posture
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue