Merge pull request 'domain cutover (host side): oc.ci, report URLs, cc-ci input bump' (#27) from domain-cutover-host into main
This commit was merged in pull request #27.
This commit is contained in:
@@ -303,7 +303,7 @@ def render(spec_path, out_path):
|
||||
for p in lead.split("\n\n") if p.strip())
|
||||
body = (_mast() +
|
||||
f'<div class="dateline"><span>{_esc(sub)}</span>'
|
||||
f'<span>report.ci.commoninternet.net</span><span>{gen}</span></div>'
|
||||
f'<span>report.ci.autonomic.zone</span><span>{gen}</span></div>'
|
||||
f'<div class="lead">{lead}</div>')
|
||||
# 1) the full wire — every recipe, in the agent's recommended priority order (CVEs first); CVEs column.
|
||||
wire = ("The full wire — every recipe, in priority order" if kind == "week"
|
||||
@@ -322,7 +322,7 @@ def render(spec_path, out_path):
|
||||
if s.get("changes"):
|
||||
body += f'<h2>What changed</h2>{_changes(s.get("changes"), repo_url)}'
|
||||
body += (f'<footer>{title} · generated {gen} · '
|
||||
f'<a href="https://ci.commoninternet.net/">dashboard</a> · <a href="./">archive</a></footer>')
|
||||
f'<a href="https://ci.autonomic.zone/">dashboard</a> · <a href="./">archive</a></footer>')
|
||||
open(out_path, "w").write(_page(f"{title} · " + s["date"], body))
|
||||
print("wrote", out_path)
|
||||
|
||||
@@ -347,10 +347,10 @@ def publish(html_path, date, kind="week"):
|
||||
for d, k in sorted(set(entries), reverse=True))
|
||||
idx = _page("The Recipe Report — Archive", _mast() +
|
||||
'<div class="dateline"><span>Weekly review of Co-op Cloud recipe upgrades & CI</span>'
|
||||
'<span>report.ci.commoninternet.net</span></div>'
|
||||
'<span>report.ci.autonomic.zone</span></div>'
|
||||
f'<ul class="idx">{lis or "<li><em>No reports yet.</em></li>"}</ul>')
|
||||
subprocess.run(["ssh", "cc-ci", f"cat > {HOST_REPORTS}/index.html"], input=idx.encode(), check=True)
|
||||
print(f"published https://report.ci.commoninternet.net/{page} (+ index)")
|
||||
print(f"published https://report.ci.autonomic.zone/{page} (+ index)")
|
||||
|
||||
|
||||
def main():
|
||||
|
||||
Generated
+4
-4
@@ -10,11 +10,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1789404337,
|
||||
"narHash": "sha256-FY5oOz/C6i6Ct6Qe6DqN6nOq+TXCyiZq5Am1LKLpDss=",
|
||||
"lastModified": 1790009762,
|
||||
"narHash": "sha256-pg5aOho9rJZmHtuGwiQgaW/uQ01vFb0f6lKsH+BB62o=",
|
||||
"ref": "refs/heads/main",
|
||||
"rev": "eb5fb826114f2b141dffb270fd36f7a22d1bf343",
|
||||
"revCount": 1550,
|
||||
"rev": "c5106bc1eb3bcb1b8056b1f1bd2ed8ae7b652503",
|
||||
"revCount": 1554,
|
||||
"type": "git",
|
||||
"url": "https://git.autonomic.zone/recipe-maintainers/cc-ci.git"
|
||||
},
|
||||
|
||||
@@ -30,8 +30,10 @@
|
||||
# Weekly self-update (Tue 03:00 UTC; skips itself while CI is busy; see nix/modules/auto-update.nix).
|
||||
cc-ci-orchestrator.autoUpdate.enable = true;
|
||||
|
||||
# The opencode UI: traefik (public 443, the *.ci.commoninternet.net cert) → nginx basic auth.
|
||||
cc-ci-orchestrator.opencodeUiHost = "oc.ci.commoninternet.net";
|
||||
# The opencode UI: traefik (public 443, the dual-zone wildcard cert) → nginx basic auth.
|
||||
# Domain cutover 2026-09: new name primary; legacy name kept answering during the bake window.
|
||||
cc-ci-orchestrator.opencodeUiHost = "oc.ci.autonomic.zone";
|
||||
cc-ci-orchestrator.opencodeUiExtraHosts = [ "oc.ci.commoninternet.net" ];
|
||||
cc-ci-orchestrator.opencodeUiTraefikNetwork = "proxy";
|
||||
|
||||
# ---- no tailscale on this host (operator 2026-09-07) --------------------------------------
|
||||
@@ -124,7 +126,13 @@
|
||||
# This host's own public names resolve to itself regardless of external DNS state (host
|
||||
# processes: the drone runner, the harness, the orchestrator; containers use the resolvers
|
||||
# above). Per-run recipe domains are random and cannot be pinned — those follow public DNS.
|
||||
# Domain cutover 2026-09: new names pinned; legacy names kept during the bake window.
|
||||
networking.hosts."195.201.88.249" = [
|
||||
"ci.autonomic.zone"
|
||||
"drone.ci.autonomic.zone"
|
||||
"report.ci.autonomic.zone"
|
||||
"traefik.ci.autonomic.zone"
|
||||
"oc.ci.autonomic.zone"
|
||||
"ci.commoninternet.net"
|
||||
"drone.ci.commoninternet.net"
|
||||
"report.ci.commoninternet.net"
|
||||
|
||||
@@ -62,6 +62,16 @@ in
|
||||
description = "nginx server_name for the opencode web UI (TLS + basic auth).";
|
||||
};
|
||||
|
||||
opencodeUiExtraHosts = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = ''
|
||||
Extra hostnames routed to the opencode UI alongside opencodeUiHost, rendered as
|
||||
`||`-joined Host conditions on the same router. Domain cutover 2026-09: the
|
||||
legacy oc.ci.commoninternet.net keeps answering here during the bake window.
|
||||
'';
|
||||
};
|
||||
|
||||
opencodeUiHtpasswdFile = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "/secrets/nginx/oc-htpasswd";
|
||||
@@ -216,6 +226,7 @@ SSHCFG
|
||||
recommendedProxySettings = true;
|
||||
virtualHosts.${cfg.opencodeUiHost} = {
|
||||
listen = [ { addr = "0.0.0.0"; port = cfg.opencodeUiBackendPort; } ];
|
||||
serverAliases = cfg.opencodeUiExtraHosts;
|
||||
basicAuthFile = cfg.opencodeUiHtpasswdFile;
|
||||
extraConfig = ''
|
||||
# traefik sits on the docker networks (ingress 10.0.0.0/24, gwbridge 172.18.0.0/16)
|
||||
@@ -256,7 +267,7 @@ SSHCFG
|
||||
replicas: 1
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.opencode-ui.rule=Host(`${cfg.opencodeUiHost}`)"
|
||||
- "traefik.http.routers.opencode-ui.rule=${lib.concatStringsSep " || " (map (h: "Host(`${h}`)") ([ cfg.opencodeUiHost ] ++ cfg.opencodeUiExtraHosts))}"
|
||||
- "traefik.http.routers.opencode-ui.entrypoints=web-secure"
|
||||
- "traefik.http.routers.opencode-ui.tls=true"
|
||||
- "traefik.http.services.opencode-ui.loadbalancer.server.port=${toString cfg.opencodeUiBackendPort}"
|
||||
|
||||
Reference in New Issue
Block a user