autonomic-bot
154b8cefdd
ssh-keys: drop claude@claude-vm, relabel sandbox key cc-ci-root-ed25519, add notplants-orchestrator pub
2026-09-28 20:09:29 +00:00
autonomic-bot
bf84f7f300
merge origin/main
...
# Conflicts:
# cc-ci-plan/JOURNAL.md
2026-09-28 20:03:33 +00:00
autonomic-bot
aaaec02f93
Merge journal/weekly-upgrade-report: 2026-09-28 outage recovery + Sep upstream re-check notes
...
# Conflicts:
# cc-ci-plan/JOURNAL.md
# cc-ci-plan/upstream/n8n.md
2026-09-28 19:58:53 +00:00
autonomic-bot
bafa9be01c
JOURNAL: 2026-09-28 cc-ci outage recovered via Hetzner hard reset (server 165014541)
2026-09-28 19:57:50 +00:00
autonomic-bot
71e3d0e852
Merge pull request 'deploy lock + journal: domain cutover 2026-09-21' ( #28 ) from post-cutover-lock into main
2026-09-21 17:23:16 +00:00
autonomic-bot
ad085efbc4
deploy lock: cc-ci input -> 2f6787f (cutover final state) + journal session 2026-09-21
2026-09-21 17:23:14 +00:00
autonomic-bot
726a4febff
Merge pull request 'domain cutover (host side): oc.ci, report URLs, cc-ci input bump' ( #27 ) from domain-cutover-host into main
2026-09-21 16:58:13 +00:00
autonomic-bot
5c5d194f61
domain cutover (host side): oc.ci host + recipe-report URLs + cc-ci input to c5106bc
...
- opencode UI: opencodeUiHost=oc.ci.autonomic.zone with the legacy name kept via the new
opencodeUiExtraHosts (dual traefik router rule + nginx serverAliases) during the bake.
- networking.hosts: new names pinned, legacy names kept.
- recipe-report.py: publish/verify/footer URLs → report.ci.autonomic.zone.
- flake.lock: cc-ci input → c5106bc (PR #39 + #40 : dual-zone SAN cert, front-door rules,
drone rename, harness naming).
2026-09-21 16:58:11 +00:00
autonomic-bot
ac73f1b63a
Merge pull request 'chore: bump recipe-maintainer submodule to 6698723 - recipe-upstream detects the upstream default branch (main vs master)' ( #26 ) from recipe-upstream-default-branch into main
2026-09-21 16:50:40 +00:00
autonomic-bot
71ca680c86
chore: bump recipe-maintainer submodule to 6698723 — recipe-upstream detects the upstream default branch (main vs master) instead of trusting the PR base
2026-09-21 16:49:30 +00:00
autonomic-bot
a1c37185d8
Merge pull request 'plan: migrate cc-ci domains to ci.autonomic.zone' ( #25 ) from plan-domain-migration into main
2026-09-21 16:31:12 +00:00
autonomic-bot
e52767665b
plan: migrate cc-ci domains to ci.autonomic.zone — DNS records, dual-cert SNI, phased cutover
2026-09-21 16:31:03 +00:00
autonomic-bot
fa73b81427
Merge pull request 'chore: bump recipe-maintainer submodule to ef3d703 (recipe-upstream laptop-fetch fix)' ( #24 ) from submodule-arm-bump-upstream-fetch into main
2026-09-21 16:29:59 +00:00
autonomic-bot
04eb8b4896
chore: bump recipe-maintainer submodule to ef3d703 — recipe-upstream prints step-0 fetch-from-mirror for the operator's laptop
2026-09-21 16:29:38 +00:00
autonomic-bot
edf1e2bd39
Merge pull request 'launchers: default LOOP_TIER to go (zen endpoint dead server-side)' ( #23 ) from tier-default-go into main
2026-09-21 16:15:55 +00:00
autonomic-bot
5aee9551d0
launchers: default LOOP_TIER to 'go' — zen endpoint dead server-side, silently ate the 2026-09-18 weekly report
2026-09-21 16:15:11 +00:00
autonomic-bot
e29b5b4101
upstream(mattermost-lts): 2026-09-18 re-check — 11.7.11 newest ESR patch; PR #2 extended 11.7.10→11.7.11, GREEN (drone 1373); CVE-2026-13426 re-adjudicated FIXED (window count 14)
2026-09-18 07:54:13 +00:00
autonomic-bot
6f63214d30
upstream(n8n): 2.38.7 / 2.39.3-2.39.7 / 2.40.0-2.40.3 release notes (2026-09-18 window)
2026-09-18 07:43:19 +00:00
loops
9202936b2e
upstream(lasuite-drive): minio Docker Hub repo removed — quay.io pin notes (PR #7 carries the switch)
2026-09-18 03:34:58 +00:00
autonomic-bot
935a411c0c
upstream(lasuite-docs): docspec switch (docspec/docspec, port 3000), minio quay pin notes
2026-09-18 03:27:52 +00:00
autonomic-bot
e85094a8e9
upstream(immich): v3.2.1/v3.2.2 pins researched (sidecar pins unchanged)
2026-09-18 03:02:53 +00:00
autonomic-bot
bb2aac39c8
upstream(hedgedoc): PG18 mount fix resolved on PR #3 , multi-major pgautoupgrade verified
2026-09-18 02:54:26 +00:00
autonomic-bot
8b79c4db20
upstream(custom-html): note nginx 1.31.6 security release (CVE-2026-90439)
2026-09-18 02:12:54 +00:00
autonomic-bot
2d312b366e
cctest-recipe-upstream: verify merge-base before rebasing; beware stray upstream main vs master
2026-09-14 19:24:24 +00:00
autonomic-bot
43f2cf074b
cctest-recipe-upstream: derive upstream base branch (mirror main vs upstream master)
2026-09-14 19:19:45 +00:00
autonomic-bot
1b8c3966cb
cctest-recipe-upstream: guard against diverged mirror history (rebase before compare)
2026-09-14 19:16:25 +00:00
autonomic-bot
c6dad5f11b
cctest-recipe-upstream: step 0 fetches by URL, remote-name agnostic
2026-09-14 19:10:57 +00:00
autonomic-bot
b8161f15e4
cctest-recipe-upstream: step 0 is just the mirror fetch (remote-add only as fallback)
2026-09-14 16:57:55 +00:00
autonomic-bot
7934367f15
cctest-recipe-upstream: always emit step 0 fetch-from-mirror commands for the operator
2026-09-14 16:57:07 +00:00
autonomic-bot
d48e47adfe
Merge pull request 'cctest-recipe-upstream: support non-sandboxed execution' ( #22 ) from cctest-upstream-nonsandbox into main
2026-09-14 16:55:02 +00:00
autonomic-bot
0c115ea714
cctest-recipe-upstream: support non-sandboxed execution (anonymous git/API access)
2026-09-14 16:54:55 +00:00
autonomic-bot
060978209c
memory+journal: report STATUS round-2 — Gitea Anubis 307-challenges browser UAs; /pr/ proxy pins non-browser UA (cc-ci PR #38 , deployed)
2026-09-14 16:48:01 +00:00
autonomic-bot
9e7770ff43
flake.lock: move cc-ci input to main (PR #38 ) — report /pr/ proxy UA fix, test+switch health-checked
2026-09-14 16:46:52 +00:00
autonomic-bot
f33c1fe36f
journal: session 2026-09-14 — report STATUS column fixed (gitea/wordpress mirrors flipped public, enroll skill patched)
2026-09-14 16:38:29 +00:00
autonomic-bot
6e93922e01
recipe-enroll: create mirrors public (gitea/wordpress were private-from-birth, darkening report STATUS)
2026-09-14 16:38:15 +00:00
autonomic-bot
0e5995960a
Merge pull request 'memory: zen-tier dead on this host; go+glm-5.3-flash defaults documented' ( #21 ) from memory-zen-dead into main
2026-09-14 14:20:57 +00:00
autonomic-bot
0354b1714d
memory: weekly upgrader — go tier + glm-5.3-flash defaults, ZEN dead on this host (PR #20 context)
2026-09-14 14:20:55 +00:00
autonomic-bot
4454fe49ef
Merge pull request 'launch-*: default tier go + glm-5.3-flash (zen model ids dead on this host)' ( #20 ) from launcher-go-model-default into main
2026-09-14 14:20:34 +00:00
autonomic-bot
ed6e70928f
launch-*: hardcode the default tier to go + glm-5.3-flash (zen model ids are dead on this host)
...
Every manual launch of launch-report/launch-upgrader bypasses the systemd EnvironmentFile (/srv/cc-ci/upgrader.env sets LOOP_TIER=go + the go models) and fell back to hardcoded zen defaults, which die instantly here (ProviderModelNotFoundError: opencode/glm-5.2 — the host holds no ZEN key and zen models vanished from the provider catalogue, 2026-09-14). This crashed the 2026-09-11 report agent at launch and again on every manual retry.
- launch-upgrader.py + launch-report.py: default TIER go, go-tier model default glm-5.3-flash (mirrors the 2026-09-08 operator choice in upgrader.env); zen stays an explicit opt-in on a host with a key.
- launch-supervisor.py: default SUPERVISOR_MODEL glm-5.3-flash.
- docstrings updated to match.
Verified with env -i: bare invocation resolves tier=go, model=opencode-go/glm-5.3-flash on all three. The 2026-09-11 weekly report is published live (report.ci.commoninternet.net/week-2026-09-11.html) after a fresh glm-5.3-flash report run.
2026-09-14 14:20:25 +00:00
autonomic-bot
dc6aa1c2c4
upstream(n8n): release-notes sources 2.38.5-2.39.2 (2026-09-11 run)
2026-09-11 07:27:07 +00:00
nptest2
951a108c1f
upstream(immich): v3.2.0 pins (valkey 70739f85, pg combo unchanged) + ghcr pagination gotcha
2026-09-11 07:23:17 +00:00
notplants
55ce8e3830
upstream(mattermost-lts): 2026-09-11 re-check — 11.7.10 still ESR tip; CVE-2026-13426 adjudicated FIXED (window count 14)
2026-09-11 07:20:26 +00:00
notplants
8e9d2ef759
upstream(hedgedoc): PG18 layout gotcha + 1.12.0 notes (17 settled on PR #3 )
2026-09-11 03:13:32 +00:00
notplants
f58a600fbd
upstream(gitea): add mariadb release-notes sources (overlay db pin was invisible to abra survey)
2026-09-11 02:41:09 +00:00
notplants
193befdb99
upstream(bluesky-pds): add @atproto/pds changelog URL (image 0.4.5NNN == pds 0.5.NN)
2026-09-11 02:11:06 +00:00
notplants and Claude Opus 5
f3c871665a
README + journal: the /secrets layout, and the weekly run's flash models
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 17:30:18 +00:00
notplants and Claude Opus 5
e7aa055784
/secrets is the authoritative location for every secret, incl. the ssh host keys
...
Operator rule: secrets live in /secrets and consumers reach them from there.
Three subdirectories with the ownership each consumer needs — files/ (loops),
host/ (root: ssh host keys + sops age identity), nginx/ (root:nginx: the
opencode UI htpasswd) — under a 0711 /secrets so nginx can traverse to its own
without the directory being listable.
sshd's hostKeys and sops-nix's sshKeyPaths/keyFile are pointed at /secrets
DIRECTLY rather than through symlinks: the ed25519 host key is load-bearing
beyond ssh, since its age identity (age1tmvg…) is a recipient of cc-ci-secrets,
and a dangling symlink would let sshd write a NEW key and silently make every
cc-ci secret undecryptable. The /etc/ssh symlinks are added for discoverability
only, so nothing depends on activation ordering.
nginx's htpasswd path becomes an option (opencodeUiHtpasswdFile) defaulting
under /secrets, rather than a hard-coded /etc/nginx path.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 17:23:28 +00:00
notplants and Claude Opus 5
360999d623
journal: secrets audit of the cc-ci host; leaked keys found in rsynced agent logs and redacted
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 17:07:23 +00:00
cc-ci-orchestrator
8af6c5fb45
journal: orchestrator startup entry (opencode agent, phase sequence confirmed DONE)
2026-09-08 16:53:57 +00:00
notplants and Claude Opus 5
c14c56147d
launchers: the opencode UI is oc.ci.commoninternet.net (not tailnet-only); journal the key switch
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 16:53:20 +00:00