From 6f1b8e2587c8f8436bc87b0c8447a25392e99dc9 Mon Sep 17 00:00:00 2001 From: axiomlogicnexus Date: Sat, 30 May 2026 19:18:11 +0200 Subject: [PATCH] Update VPS invariants for live cutover state --- ...XONOMY_ALIAS_AND_RENAME_PLAN_2026-05-30.md | 6 ++++- ...TOVER_OPERATIONAL_INVARIANTS_2026-05-30.md | 27 ++++++++++++++----- 2 files changed, 25 insertions(+), 8 deletions(-) diff --git a/docs/ops/HYPERTWIST_PLATFORM_TAXONOMY_ALIAS_AND_RENAME_PLAN_2026-05-30.md b/docs/ops/HYPERTWIST_PLATFORM_TAXONOMY_ALIAS_AND_RENAME_PLAN_2026-05-30.md index e3d9d68..3969f30 100644 --- a/docs/ops/HYPERTWIST_PLATFORM_TAXONOMY_ALIAS_AND_RENAME_PLAN_2026-05-30.md +++ b/docs/ops/HYPERTWIST_PLATFORM_TAXONOMY_ALIAS_AND_RENAME_PLAN_2026-05-30.md @@ -102,7 +102,10 @@ Examples: 1. SSH: - keep the real target as `212.227.13.220` - - add new `Host` aliases in `~/.ssh/config` + - add new `Host` aliases in `~/.ssh/config`, for example: + - `platform-main-root` + - `platform-main-dev` + - `platform-main-deploy` - do not change the real server paths or accounts 2. Scheduled tasks: @@ -119,6 +122,7 @@ Examples: 4. Wrapper scripts: - `run-platform-remote-dev-seed.ps1` - `run-platform-authorship-sync.ps1` + - `run-platform-remote-dev-reverse-sync.ps1` - internally call the current `scriptorium*` scripts 5. Password manager / credential registry: diff --git a/docs/ops/HYPERTWIST_VPS_POST_CUTOVER_OPERATIONAL_INVARIANTS_2026-05-30.md b/docs/ops/HYPERTWIST_VPS_POST_CUTOVER_OPERATIONAL_INVARIANTS_2026-05-30.md index f6a0d15..e0f0045 100644 --- a/docs/ops/HYPERTWIST_VPS_POST_CUTOVER_OPERATIONAL_INVARIANTS_2026-05-30.md +++ b/docs/ops/HYPERTWIST_VPS_POST_CUTOVER_OPERATIONAL_INVARIANTS_2026-05-30.md @@ -96,7 +96,7 @@ Forgejo current state: - `SSH_DOMAIN = git.scriptoriumai.io` - `SSH_PORT = 2222` - `DISABLE_REGISTRATION = true` -- `REQUIRE_SIGNIN_VIEW = true` +- `REQUIRE_SIGNIN_VIEW = false` - existing accounts/data were copied; no passwordless public access was enabled Woodpecker current state: @@ -108,7 +108,9 @@ Woodpecker current state: Operational implication: -- Forgejo still expects authenticated use +- public web viewing and anonymous read access to public repositories are now + allowed +- Forgejo still expects authenticated write access - Git push auth is still the normal Forgejo model: SSH key or HTTPS credential - Woodpecker open mode is inherited from the old stack and should be revisited later if tighter enrollment is desired @@ -142,13 +144,24 @@ Current design: - nightly at `03:30` - changed-file reverse sync from `/home/dev/src` - conservative excludes for obviously rebuildable artifacts +- `mirrors` are excluded from the retained reverse-sync payload - no second full local mirror root by default; it syncs back into the existing - local project paths + local project paths when enabled + +Measured retained payload with rebuildable junk and `mirrors` omitted: + +- about `18.6 GiB` + +Measured omitted `mirrors` payload: + +- about `107.9 GiB` Current safety rule: - the task refuses to overwrite a dirty local Git worktree by default - that safeguard currently matters because several local repos are dirty +- the scheduled task is currently **disabled** by operator request until the + retained backup lane is reviewed ## VerticalTension git/ci alias stance @@ -174,10 +187,10 @@ Why: Current prep state: -- the new VPS already has HTTP redirect vhost coverage staged for both alias - hosts -- after their DNS `A` records are moved to `212.227.13.220`, the remaining - step is VPS-side certificate issuance for those two hostnames +- the new VPS has HTTPS redirect coverage live for both alias hosts: + - `git.verticaltension.com` + - `ci.verticaltension.com` +- both now redirect to the canonical ScriptoriumAI control-plane hosts ## IONOS SSL posture