journal: evening changes on the cc-ci host (opencode agent, secrets minimised, weekly run started)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
This commit is contained in:
@@ -1071,3 +1071,24 @@ on the old host; a fresh orchestrator session is up on the new box (`ssh root@19
|
|||||||
`sudo -iu loops tmux attach -t cc-ci-orchestrator`). Details + the two incidents:
|
`sudo -iu loops tmux attach -t cc-ci-orchestrator`). Details + the two incidents:
|
||||||
`cc-ci-plan/plan-cc-ci-combined-host.md` (log) and README §2a/§7. Operator to merge
|
`cc-ci-plan/plan-cc-ci-combined-host.md` (log) and README §2a/§7. Operator to merge
|
||||||
notplants-nix `chore/drop-cc-ci`, delete the old CI server in a week, revoke the Hetzner token.
|
notplants-nix `chore/drop-cc-ci`, delete the old CI server in a week, revoke the Hetzner token.
|
||||||
|
|
||||||
|
## Session 2026-09-07 21:35 UTC — evening changes on the cc-ci host (from Claude on notplants-orchestrator)
|
||||||
|
|
||||||
|
- notplants-nix `chore/drop-cc-ci` merged + applied on the old box (gen 57). cc-ci push self-test
|
||||||
|
green again (#33 ruff format, #34 statix). cc-ci input relocked on the host (NAR-hash note in
|
||||||
|
README day-2).
|
||||||
|
- Operator: NO Claude on the cc-ci host. The orchestrator there is an opencode agent
|
||||||
|
(agents.toml: opencode/glm-5.2) steered from https://oc.ci.commoninternet.net; claude-install,
|
||||||
|
CLAUDE_BIN and all Claude state removed from the host. Claude sessions stay on
|
||||||
|
notplants-orchestrator, whose loops `ssh cc-ci` now points at 195.201.88.249.
|
||||||
|
- Operator: only strictly necessary secrets on the cc-ci host, none of this machine's keys.
|
||||||
|
`/secrets/files` there now holds exactly: cc-ci.testenv (GITEA_PASSWORD, DOCKERHUB_*),
|
||||||
|
cc-ci-local-ed25519 (loops→root loopback, generated there, pub in nix/hosts/cc-ci/ssh-keys),
|
||||||
|
autonomic-bot-cc-ci-ed25519 (generated there, Gitea key id 156, root uses it for cc-ci-secrets),
|
||||||
|
opencode-auth.json. Gone: tailscale key, tangled key, copied cc-ci-root + bot keys, htpasswd
|
||||||
|
plaintext, TINFOIL/OPENAI keys, the master age key (cc-ci-secrets re-keyed to the host's ssh
|
||||||
|
host key age1tmvg…, cc-ci PR #35; /var/lib/sops-nix/key.txt = host-derived identity). /old-root
|
||||||
|
deleted. Inventory: /secrets/README.txt on the host.
|
||||||
|
- Weekly upgrade run started by hand on the new host at 21:23 UTC (`systemctl start
|
||||||
|
cc-ci-upgrade-all`; opencode/deepseek-v4-flash, session ses_f823e7a18ffejcu0) as the post-move
|
||||||
|
proof; result + report recorded below when done.
|
||||||
|
|||||||
Reference in New Issue
Block a user