Skip to content

Ops/dev2 fleet kit - #110

Merged
ralyodio merged 105 commits into
masterfrom
ops/dev2-fleet-kit
Sep 26, 2026
Merged

ralyodio merged 105 commits into
masterfrom
ops/dev2-fleet-kit

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

No description provided.

ralyodio and others added 30 commits September 25, 2026 09:30
dev2-site reads the truth from Railway (services, domains, volumes, database
variables), renders the box files from templates, provisions ~/www/<site> over
ssh, copies Postgres through Railway's ssh endpoint into the shared cluster,
issues the certificate over Porkbun DNS-01 before DNS moves, flips Porkbun,
stops and disconnects the Railway service, and merges the per-repo
deploy-dev2.yml. First site through it: bg0ne.com.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…show deploy stderr

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… cutover) + proxied gateway hosts

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
With dozens of compose networks Docker moves to 192.168.x/20 pools, which an
allowlist of 172.16.0.0/12 alone drops (CONNECT_TIMEOUT to :5432 from the app).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…apps

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ify db url

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…heckouts

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… and node-postgres accept

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…austed)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…uire otherwise)

Bun.SQL forwards unknown URL parameters to the server as GUCs, so
uselibpqcompat=true was FATAL there while the health check stayed green.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ode 22

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ing it

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ale embedded DNS)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…o resolve

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…services only; opensocial.chat override

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… nodejs_18, --regen

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…PACKS_* command variables

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…clone/build); openaccess + openmcp overrides

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
ralyodio and others added 28 commits September 25, 2026 15:23
Gateway supabase.pairux.com -> :8274; URL, publishable/secret keys, db
password and the LiveKit recording S3 endpoint/credentials re-pointed at the
stack's own S3 protocol (secrets as secret: references).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Shares the cloud project with pairux.com, so it shares the dev2 stack too:
URL, publishable/secret keys and db password re-pointed at supabase.pairux.com
(secrets as secret: references).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
supabase.bl0ggers.com gateway proxy (the wildcard already routes it);
NEXT_PUBLIC_SUPABASE_URL and SUPABASE_URL re-pointed, the db password and the
three key variables as secret references.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Gateway supabase.brisk.news -> :8238; URL and publishable/secret keys
re-pointed (keys as secret: references). Loaded from a fresh dump with
supabase-load --reset right before the cutover.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ng loop input, grant functions by signature

- load: 'psql -f /dev/stdin' prefixes messages with psql:/dev/stdin:N:, so the
  error counts were always 0; count and list them properly.
- load: the schemas/extensions/buckets loops read from fd 3 -- the docker exec -i
  in the body swallowed the rest of stdin, so only the first entry ran (PostGIS
  was never created for icemap).
- pull: function grants were emitted without 'function' and without the
  signature, so all of them failed; emit them from pg_proc with regprocedure,
  and revoke PUBLIC where the cloud had done so.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…OT cut over)

supabase.coinpayportal.com -> :8273. The load lost public.payments (3405 rows)
to a NOT VALID check constraint the dump re-creates as enforced, so the
cutover is on hold until supabase-load handles NOT VALID constraints.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…nstraints, vault, S3 host, bucket limits

- cutover maps sb_publishable_/sb_secret_ keys onto the stack's anon/service
  JWTs (they were never re-pointed before), rewrites <ref>.storage.supabase.co
  and swaps in the stack's S3 protocol credentials, and refuses to run while
  the cloud project still has Edge Functions the stack lacks.
- new supabase-functions: ports supabase/functions/* from the checkout onto the
  stack's edge runtime, copies the cloud function secrets into
  volumes/functions/secrets.env (env_file on the functions service), probes one.
- pull dumps NOT VALID check/fk constraints; load drops them before COPY and
  re-adds them NOT VALID after (coinpayportal's payments table failed on one).
- pull dumps vault secrets, load recreates them; buckets keep file_size_limit
  and allowed_mime_types; storage FILE_SIZE_LIMIT raised to 5 GiB.
- cron commands get the cloud URL and API keys rewritten before scheduling;
  the cloud cron probe no longer parses cron.job when pg_cron is absent.
- transient auth.one_time_tokens / auth.scim_* excluded from the data dump.
- stack no longer chowns an existing site root to root (CI deploys broke).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…n secrets

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… the site variables

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…_secrets overlay

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…nt monitor was a Vercel cron)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…n secrets as vault refs

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ate file

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…gs dropped; c0upons also loses the dead SQLITECLOUD_URL)
…ite Supabase stack and mirror storage files

The backup job only knew the shared cluster. With the cloud projects deleted the
20 <slug>-supabase-db containers were the sole copy of their data. Now: each stack's
postgres database is dumped (4-hourly, or daily when large) and verified like the
cluster's, and volumes/storage is rsync-mirrored daily. The script and its cron file
live here as templates and are installed by .

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Anthony reversed the stay-on-Railway decision ("move it all off railway").
Zone is at Cloudflare with no token in the vault, so the cert is HTTP-01
after the apex and www A records are pointed at dev2 by hand.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…les world-readable (umask 022)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…pp stays on the DO droplet)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…extensions.gin_trgm_ops); skip generated columns in the URL rewrite

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
# Conflicts:
#	dev2/dev2-site
#	dev2/sites.d/app.moshcode.sh.json
#	dev2/sites.d/brisk.news.json
#	dev2/sites.d/coinpayportal.com.json
#	dev2/sites.d/meshhook.com.json
#	dev2/templates/box-tune.sh
#	dev2/templates/supabase-load.sh
#	dev2/templates/supabase-pull.sh
#	dev2/templates/supabase-stack.sh
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

25 finding(s)

HIGH/CRITICAL: 4 | MEDIUM: 12 | LOW: 9

Severity Rule Location
HIGH sh-remote-script-execution root-ubuntu.sh:3236
HIGH sh-remote-script-execution root-ubuntu.sh:3237
HIGH sh-remote-script-execution root-ubuntu.sh:5071
HIGH sh-remote-script-execution root-ubuntu.sh:5075
MEDIUM sql-template-interpolation dev2/dev2-site:805
MEDIUM sql-template-interpolation dev2/dev2-site:882
MEDIUM sh-remote-script-execution root-ubuntu.sh:5248
MEDIUM redos-nested-quantifier src/domain-free.ts:56
MEDIUM redos-nested-quantifier src/emoji.ts:167
MEDIUM redos-nested-quantifier src/icon.ts:166
MEDIUM redos-nested-quantifier src/mail.ts:1042
MEDIUM sql-template-interpolation src/users-dump.ts:487
MEDIUM sql-string-concatenation src/users-dump.ts:507
MEDIUM sql-template-interpolation src/users-dump.ts:540
MEDIUM sql-string-concatenation src/users-dump.ts:574
MEDIUM redos-nested-quantifier src/wcag.ts:556
LOW secret-generic-credential src/credentials.ts:36
LOW secret-generic-credential src/user-export.ts:632
LOW secret-generic-credential src/user-export.ts:638
LOW secret-generic-api-key test/credentials.test.ts:208
LOW secret-generic-credential test/mail.test.ts:141
LOW secret-generic-credential test/shorten.test.ts:36
LOW secret-database-url test/users-dump.test.ts:108
LOW secret-database-url test/users-dump.test.ts:119
LOW secret-database-url test/users-dump.test.ts:120

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 2a05dc6 into master Sep 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant