Compare commits
16
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b6bfbe2a3d | ||
|
|
5c6a1dbcf7 | ||
|
|
36019ed8c8 | ||
|
|
004c9bcdd3 | ||
|
|
075c9d356d | ||
|
|
154b8cefdd | ||
|
|
bf84f7f300 | ||
|
|
aaaec02f93 | ||
|
|
bafa9be01c | ||
|
|
71e3d0e852 | ||
|
|
ad085efbc4 | ||
|
|
726a4febff | ||
|
|
5c5d194f61 | ||
|
|
ac73f1b63a | ||
|
|
aa2c6dbf98 | ||
|
|
bc26c64065 |
@@ -1238,3 +1238,96 @@ the host: `opencode-go/deepseek-v4-flash` and `opencode-go/glm-5.3-flash` answer
|
||||
`upgrader.env` (`LOOP_TIER=go` maps to the `opencode-go` auth entry; `LOOP_MODEL` overrides the
|
||||
tier default). Next fire Fri 2026-09-11 02:00 UTC.
|
||||
- The steering orchestrator agent stays on `opencode-go/glm-5.2` (not asked to change).
|
||||
|
||||
## Session 2026-09-21 — domain cutover to ci.autonomic.zone (orchestrator)
|
||||
|
||||
**What happened.** Morning: hourly supervisor resumed the stalled 09-18 weekly run on the GO tier
|
||||
(ZEN endpoint dead server-side — `UnknownError`; run completed 13 green PRs, 0 failed). Published
|
||||
the missing week-2026-09-18 report (PR-finding #4; launcher defaults flipped to `go` in
|
||||
cc-ci-orchestrator PR #23). Then executed the full domain cutover per
|
||||
`cc-ci-plan/plan-domain-migration-ci-autonomic-zone.md` (PR #25).
|
||||
|
||||
**Plan deviation (simplification).** No dual-cert SNI: ONE Let's Encrypt cert carries SANs for
|
||||
BOTH zones (`ci` + `*.ci` of autonomic.zone AND commoninternet.net) — the unchanged single-pair
|
||||
`ssl_cert/ssl_key` traefik reconciler keeps working; Phase 4 reissues without the legacy SANs.
|
||||
The new zone's DNS-01 challenge reuses the SAME acme-dns account: storage re-keyed by
|
||||
`cc-ci-acme-storage-seed.service` (jq clone of the legacy entry under `ci.autonomic.zone`),
|
||||
CNAME already delegated. Proven by a hand lego **staging** run before any production change.
|
||||
|
||||
**Merged:** cc-ci #39 (front doors dual Host rules, bridge/dashboard env URLs, drone abra rename,
|
||||
runner RPC, naming.py → `*.ci.autonomic.zone`, dual-zone name regexes in lifecycle/warm/prune,
|
||||
recipe-report URLs) · cc-ci #40 (seed-unit nesting fix) · cc-ci #41 (have_secret stack-scope —
|
||||
caught live: the old stack's `*_rpc_secret_v1` satisfied the check post-rename) · cc-ci #42 (nix
|
||||
interpolation escape) · orchestrator #27 (oc.ci host + `opencodeUiExtraHosts`, host self-pins,
|
||||
flake bump).
|
||||
|
||||
**Deployed** via `nixos-rebuild test` → verify → `switch` (generation `nn1vwiv7v1k…`, running ==
|
||||
boot). Cert SANs confirmed 4-name; all 5 front doors answer on BOTH zones
|
||||
(200/200/303/401 + traefik 200), TLS verify=0 from outside; zero failed units; disk dropped
|
||||
88%→45% after prune.
|
||||
|
||||
**Drone migration.** New abra app `drone.ci.autonomic.zone`, FRESH DB (module's
|
||||
`DRONE_USER_CREATE` re-injected the sops bridge token). The Gitea OAuth app redirect now has both
|
||||
URIs; the client secret was rotated (each Gitea PATCH regenerates it) and synced through
|
||||
sops → `sops-install-secrets` → swarm secret v1 → drone. Bootstrapped OAuth
|
||||
(`drone login ok (admin=true)`), re-enabled cc-ci + discourse repos, build timeout 60m.
|
||||
Webhooks: ghost + discourse repointed (secrets preserved); cc-ci repo's bridge webhook →
|
||||
`ci.autonomic.zone/hook`, stale drone hook deleted, Drone's auto-created new-zone hook active.
|
||||
Old stack removed + orphaned secrets reaped.
|
||||
|
||||
**E2E proof.** `!testme` on keycloak PR #9 → bridge → drone build #1 (new DB numbering) → runner →
|
||||
harness → `results.json` + PR card `✅ passed` linking `ci.autonomic.zone/runs/1/summary.png`.
|
||||
|
||||
**Deferred / open.**
|
||||
- Warm stacks + backupbot stay on the legacy zone (data-warm volumes / restic password tied to
|
||||
abra app names) — post-bake migration; harness regexes accept both zones meanwhile.
|
||||
- Docs sweep (~60 references: AGENTS.md, README, skills incl. cc-ci-status front-door list,
|
||||
launcher printed URLs).
|
||||
- Phase 4 (after ≥7 clean days): drop legacy SANs (reissue), remove legacy Host arms + host
|
||||
self-pins + Gandi records (`ci`, `*.ci`, `_acme-challenge.ci`), TTLs back to 3600.
|
||||
- Host auto-update was `failed` 2026-09-15 (health check) — `/cc-ci-orchestrator-update` still
|
||||
pending; next auto-attempt Tue 09-22.
|
||||
|
||||
## Session 2026-09-28 20:00 UTC — operator-broken cc-ci recovered by plain hard reset
|
||||
|
||||
- Operator reported ci.autonomic.zone down after their own change, supplied a Hetzner API token
|
||||
in chat (token is now in the transcript — SHOULD BE ROTATED). Staged at /tmp/opencode/hcloud-token
|
||||
(0600) instead of echoing it.
|
||||
- Triage: SSH (port 22) timed out, ICMP 100% loss, tailscale 100.95.31.88 no reply — yet Hetzner
|
||||
reported "running". Old recovery note's server id 134485294 is GONE; current cc-ci is id
|
||||
165014541, public 195.201.88.249 (token project also holds 114514766 autonomic-cc-testing).
|
||||
Last Hetzner action was 2026-09-07 (rescue cycles during the rebuild), so the outage was
|
||||
OS-internal, not API-driven.
|
||||
- Fix: single hard reset via `POST /servers/165014541/actions/reset`. ICMP after ~60s, SSH after
|
||||
~90s. Box booted the default profile nixos-system-cc-ci-26.05.20260906.c257840 — no rescue/
|
||||
GRUB generation-picking needed this time.
|
||||
- Post-checks: nginx + gitea active, drone-runner-exec active (NOT drone-runner-docker — wrong
|
||||
guess), disk 41%, https://ci.autonomic.zone → 200. One failed unit:
|
||||
acme-order-renew-ci.autonomic.zone.service — renewal itself fine (cert valid to 2026-12-20),
|
||||
it died on `chmod: out/acme-dns-accounts.json: Operation not permitted` because the file was
|
||||
root:root (touched today 19:54, likely by whatever the operator did) while the unit runs as
|
||||
acme. chown acme:acme (matching the healthy ci.commoninternet.net dir) + restart → unit green,
|
||||
zero failed units.
|
||||
- NOTE: no tailscale on this host (`tailscale: command not found`) — the AGENTS.md "ssh cc-ci"
|
||||
alias + 100.90.116.4 peer notes are stale post-rebuild; public-IP SSH is the access path.
|
||||
Recovery scripts in scripts/recovery/ still reference old server id 134485294 — worth updating.
|
||||
|
||||
---
|
||||
## 2026-09-28 — upgrader session (weekly /upgrade-all)
|
||||
|
||||
Weekly run 2026-09-28 complete: 19 considered · 7 GREEN PRs · 1 externally-CI-blocked (lasuite-docs, quay minio 401) · 0 failed · 11 skipped. Summary (PR list): `<logs>/upgrades/upgrade-all-2026-09-28.md` — repo ignores .cc-ci-logs, so the PR list lives in the file + the weekly report.
|
||||
|
||||
**Operational config change (no PR):** subagent `general` model `deepseek-v4-flash` was killed upstream ("Model access is disabled", zen endpoint; glm-5.2 also dead) — pointed to `deepseek-v4.1-flash` in `/srv/cc-ci-orch/cc-ci/opencode.json`, `/srv/cc-ci-orch/opencode.json` (uncommitted) + live `/etc/cc-ci/opencode.json`. Prior committed setting still in the cc-ci repo's main. Operator: confirm + PR the bump (config change precedent #37/#42).
|
||||
|
||||
**minio watch:** docker.io removal (2026-09-18) → now quay.io/minio/minio 401s since ~09-24; lasuite-docs CI-blocked on it; lasuite-drive passed (image cached).
|
||||
|
||||
**abandoned worktree note:** `/srv/cc-ci-orch/cc-ci-conc/` (worktree of cc-ci, untracked in orch repo) has a stale worktree at 2f6787f; no writes this week; recorded so the next sweep notices.
|
||||
|
||||
Key logs: .cc-ci-logs/upgrades/*-2026-09-28.md (8 per-recipe + summary).
|
||||
|
||||
## 2026-10-02 — upgrader session (weekly /upgrade-all)
|
||||
|
||||
Weekly run 2026-10-02 complete: 20 considered · 9 upgraded (PRs opened/extended) · 8 GREEN (!testme) · 1 live-verified but CI-blocked externally (lasuite-docs base canonical, commented) + 1 RED on a genuinely stale gitea LFS test (commented; operator re-runs --with-tests) · 0 failed · 9 skipped. Summary (PR list): <logs>/upgrades/upgrade-all-2026-10-02.md — repo ignores .cc-ci-logs, so the PR list lives in the file + the weekly report.
|
||||
Key highlights: gitea upstream shipped its first 2-digit stable (28.0.0-rootless, 2026-09-29 — BREAKING git-egress/actions-retention notes documented in PR #10); ghost 6.67.0 fixes HIGH CVE-2026-84383; nulls held at mysql 8.4 / mariadb 12.3 / postgres 13/15 lines per precedent; matrix-synapse extended to synapse 1.162.0 + MAS 1.26.0; immich bumped v3.2.4 (rc.3.3 declined). Operational: recipe-maintainers/gitea mirror had LOST its master branch (abra whole-recipe FATA) — repaired both refs to upstream HEAD f167b73; reconcile-upstream.sh should learn to recreate a missing upstream-default branch ref, not only sync main. 2 targets (gitea, n8n 2.42.2) were caught in follow-up passes after the initial worklist mis-derivation — nothing left unprocessed. Sweep start: 4 leaked volumes + 46.3 GB images reclaimed (disk 70%->40%); end-of-run reap 0 leaked dev deploys; disk 65% (51G free).
|
||||
Per-recipe logs: .cc-ci-logs/upgrades/<recipe>-upgrade-2026-10-02.md (10 files incl. survey).
|
||||
NEVER MERGED anything; all PRs await operator review + the operator's `abra recipe release <recipe> -x/y/z` after each merge.
|
||||
|
||||
@@ -303,7 +303,7 @@ def render(spec_path, out_path):
|
||||
for p in lead.split("\n\n") if p.strip())
|
||||
body = (_mast() +
|
||||
f'<div class="dateline"><span>{_esc(sub)}</span>'
|
||||
f'<span>report.ci.commoninternet.net</span><span>{gen}</span></div>'
|
||||
f'<span>report.ci.autonomic.zone</span><span>{gen}</span></div>'
|
||||
f'<div class="lead">{lead}</div>')
|
||||
# 1) the full wire — every recipe, in the agent's recommended priority order (CVEs first); CVEs column.
|
||||
wire = ("The full wire — every recipe, in priority order" if kind == "week"
|
||||
@@ -322,7 +322,7 @@ def render(spec_path, out_path):
|
||||
if s.get("changes"):
|
||||
body += f'<h2>What changed</h2>{_changes(s.get("changes"), repo_url)}'
|
||||
body += (f'<footer>{title} · generated {gen} · '
|
||||
f'<a href="https://ci.commoninternet.net/">dashboard</a> · <a href="./">archive</a></footer>')
|
||||
f'<a href="https://ci.autonomic.zone/">dashboard</a> · <a href="./">archive</a></footer>')
|
||||
open(out_path, "w").write(_page(f"{title} · " + s["date"], body))
|
||||
print("wrote", out_path)
|
||||
|
||||
@@ -347,10 +347,10 @@ def publish(html_path, date, kind="week"):
|
||||
for d, k in sorted(set(entries), reverse=True))
|
||||
idx = _page("The Recipe Report — Archive", _mast() +
|
||||
'<div class="dateline"><span>Weekly review of Co-op Cloud recipe upgrades & CI</span>'
|
||||
'<span>report.ci.commoninternet.net</span></div>'
|
||||
'<span>report.ci.autonomic.zone</span></div>'
|
||||
f'<ul class="idx">{lis or "<li><em>No reports yet.</em></li>"}</ul>')
|
||||
subprocess.run(["ssh", "cc-ci", f"cat > {HOST_REPORTS}/index.html"], input=idx.encode(), check=True)
|
||||
print(f"published https://report.ci.commoninternet.net/{page} (+ index)")
|
||||
print(f"published https://report.ci.autonomic.zone/{page} (+ index)")
|
||||
|
||||
|
||||
def main():
|
||||
|
||||
@@ -79,6 +79,24 @@
|
||||
reassign-faces fix) — no breaking changes, no config additions, no operator action. Done in
|
||||
the 2026-09-18 upgrade (v3.2.0→v3.2.2, app+ML only; fresh PR — PR #4 was closed when its
|
||||
v3.2.0 content merged upstream as #19 / `1.11.0+v3.2.0`).
|
||||
- **immich-server v3.2.4 (2026-09-28, latest stable) pins** (from `docker/docker-compose.yml` @ the
|
||||
v3.2.4 tag): `postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357…` and
|
||||
`valkey:9@sha256:70739f85ad…` — **BOTH identical to the recipe's v3.2.2-era pins** (DB + redis stay
|
||||
put; live `valkey:9` tag has now moved to `ac9c858b…` = **9.1.2**, but immich's tested
|
||||
`70739f85…` = 9.1.1 is kept per the 2026-07-17 precedent). `example.env` @ v3.2.4 byte-identical to
|
||||
v3.2.2. Window v3.2.2→v3.2.4 is 4 commits: mobile sync-status fix (#31644), an internal `v3.2.3`
|
||||
version commit (no Release object), a base-image dep bump to `202609281550` (#31854), and `v3.2.4`.
|
||||
The v3.2.4 release body: "small patch that primarily fixes the memory leak people have observed
|
||||
through a dependency update." **No breaking changes, no config additions, no operator action.**
|
||||
The base-image bump (`202608300913`→`202609281550`, immich-app/base-images) adds a hardened
|
||||
ImageMagick security policy (#390), reduces server image size (#388), and restores `curl` in the
|
||||
prod image so `immich-healthcheck` works (#391) — all internal to the server image. `v3.3.0-rc.0/1`
|
||||
are pre-releases (2026-09-29/30) — do NOT bump to rc. Done in the 2026-10-02 upgrade
|
||||
(v3.2.2→v3.2.4, app+ML only, fresh PR). Direct registry check confirmed
|
||||
`immich-server/ml:v3.2.4` exist; `abra recipe upgrade` still FATAs on the tag+digest DB pin.
|
||||
Valkey CVE note: CVE-2026-56684 / CVE-2026-63639 (UAF→RCE) are fixed in 9.1.1 and are therefore
|
||||
**already closed** by the recipe's pinned 9.1.1 — not by this app bump; ignore the live-`9`-tag
|
||||
drift. CVE-2026-25243 (valkey RESTORE zipmap) is vendor-page-only and undecided.
|
||||
- **2026-08-07 INFRA note: cc-ci runner's gitea clone-token is STALE (HTTP 401).** `!testme` build
|
||||
#1210 died at the recipe `git clone` step (~5s, before any deploy) with `could not read Username for
|
||||
'https://git.autonomic.zone'` — the runner's mounted gitea token `13e299f2…` is rejected (verified
|
||||
|
||||
@@ -134,6 +134,18 @@
|
||||
2026-08-15 (upstream main still pins 10.11.22 = EXPIRED ESR → the 10→11 ESR move PR #2 carries
|
||||
remains required; Mattermost docs: ESR→ESR is "fully supported and tested"). postgres 15-alpine
|
||||
still HELD (DB-major out of scope, operator dump/pg_upgrade).
|
||||
- **2026-09-04 re-check** (endoflife.date/api/mattermost.json 2026-09-04; Mattermost release-policy
|
||||
docs `https://docs.mattermost.com/product-overview/release-policy.html`; `mattermost-server-releases.html`;
|
||||
GitHub releases `v11.7.10`): **11.7 ESR is STILL the current supported ESR/LTS line** — "v11.7 &
|
||||
Desktop App v6.2 Extended Support: 2026-05-15 → 2027-05-15" (the chart on the release-policy page;
|
||||
ESR cadence = every 9 months, supported 12 months). Latest 11.7.x patch **11.7.10** (2026-08-26,
|
||||
"Mattermost Platform Extended Support Release 11.7.10 contains various bug fixes") — NOT a
|
||||
prerelease; target confirmed. 11.8/11.9/11.10 remain Feature/innovation releases (EOL 2026-09-15 /
|
||||
10-15 / 11-15, `lts:false`), NOT ESR — do NOT target; wait for the NEXT official ESR (expected
|
||||
~Feb 2027 on the 9-month cadence). No newer 11.7.x ESR patch exists as of this week, so PR #2's
|
||||
head (`59e8c2c`, app image `11.7.10`) is still the correct target → this run RE-VERIFIES PR #2
|
||||
(no new app bump). 11.11.0-rc1/rc2 seen on GitHub but innovation + pre-release — not a target.
|
||||
postgres 15-alpine still HELD (DB-major out of scope, operator dump/pg_upgrade).
|
||||
|
||||
## NVD CPE fallback
|
||||
This project publishes nothing machine-readable we can reach — no GitHub advisory feed,
|
||||
|
||||
@@ -239,3 +239,66 @@
|
||||
safe (sqlite, TypeORM auto-migrate). Operator flags unchanged (API-caller-level deprecations,
|
||||
encryption-key rework informational, N8N_DB_PING_TIMEOUT warn-only, recipe doesn't set it).
|
||||
2.40.3 exists (see above) — flagged, not taken. Recommended release: `-y`.
|
||||
- 2.40.4 (2026-09-21, Pre-release): core fix (tear down workflow triggers when publication meets a
|
||||
node type the instance cannot load) + perf (stop loading project members when listing
|
||||
credentials).
|
||||
- 2.40.5 (2026-09-21, Pre-release): core fix (limit declarative routing during base URL ownership
|
||||
checks). Docker Hub `2.40.5` manifest verified active multi-arch (amd64+arm64, digest
|
||||
sha256:9f693fd5..., 2026-09-21) — not a withdrawn 2.37.5-style partial tag. NOTE: 2.40.x
|
||||
`POST /rest/login` now takes `emailOrLdapLoginId` instead of `email` (request-shape change; the
|
||||
cc-ci login-state test only GETs /rest/login so unaffected).
|
||||
- 2026-09-21 run: the flagged catch-up. PR #8 (branch `upgrade-ef0dd56`, at 2.40.2, !testme GREEN
|
||||
2026-09-18) extended **2.40.2 → 2.40.5** on the same upstream main tip `0b436ec` (n8n NOT
|
||||
merged upstream today, unlike discourse/keycloak/matrix-synapse). 2.40.2→2.40.5 is bugfix-only
|
||||
(encryption-key raw-repair, trigger teardown, declarative-routing limit); no breaking
|
||||
compose/env changes; no new migrations beyond the 15 already verified at 2.40.2. Stable badge
|
||||
now on the 2.39.x line (2.39.9/2.39.10 released 2026-09-21); 2.40.x pre-release per precedent.
|
||||
Recommended release: `-y`.
|
||||
- 2.40.6 (2026-09-24, patch): core fixes (keep OpenTelemetry export working after a restart when
|
||||
Sentry is enabled; retry instance reports that cross the UTC midnight boundary) + feature
|
||||
(authenticate instance reports with the license certificate).
|
||||
- 2.40.7 (2026-09-25, patch): 1 core fix (propagate project span attributes to node spans).
|
||||
- 2.41.0 (2026-09-22, Pre-release; the 2.41 feature minor — note the 2.40.x patch line continued
|
||||
alongside with 2.40.6/2.40.7): a large feature/bugfix release. Features: standalone node
|
||||
execution as a Workflow Builder / AI Assistant tool, admin permission for node execution in the
|
||||
assistant, API credential creation with source IDs, push-based reload endpoint for custom-node
|
||||
development, execution view/delete permissions in project roles, MCP-registry capability
|
||||
filtering, Databricks Embeddings/Chat-Model node, MS Teams @mentions + a Chat resource, MiniMax
|
||||
dynamic model list, email-change confirmation flow. Core bugfixes include repair of
|
||||
data-encryption keys stored as the raw instance key, stalled-job success finalization,
|
||||
multi-main workflow-publishing fix, stop an unreachable external-secrets provider blocking
|
||||
startup, undici 7.29.1 + vm2 3.12.2 bumps, RFC 9068 MCP OAuth compliance. **No breaking
|
||||
compose/env/migration changes; no `N8N_*` env renames.** (2.41.1/2.41.2 = patch bugfixes.)
|
||||
- 2.41.3 (2026-09-25, patch): 1 core fix (propagate project span attributes to node spans). Last
|
||||
week's PR #9 target — !testme GREEN (run 21, 2026-09-28); TypeORM migrations clean live.
|
||||
- 2.41.4 (2026-09-30, patch): API/core/editor fixes (return an execution when its stored trace
|
||||
context is incomplete; count a database ping as successful when its reply arrives during
|
||||
event-loop lag; store queue job results only for executions this process enqueued) + features
|
||||
(n8n Assistant onboarding thread for new Cloud signups; route assistant credit CTAs to top-up).
|
||||
- 2.41.5 (2026-10-01, patch): atom-feed release body empty (release republish / no listed changes).
|
||||
- 2.42.0 (2026-09-29, Pre-release; the 2.42 feature minor): a large feature/bugfix release.
|
||||
Features: AI Agent Tool can use its own tools under a pre-v3 parent agent, workflow descriptions
|
||||
on create, `extendsCredential` in workflow create/update, OpenAPI path-parameter validation,
|
||||
credential descriptions behind an instance flag, Anthropic prompt caching in the Message op,
|
||||
API projects with source IDs, pinned Apply/Apply-Continue CLI commands, MCP-registry feature-flag
|
||||
removal, Agent Builder/editor improvements. ~60 core/editor/node bugfixes (chat-integration
|
||||
shutdown, Redis pubsub reconnect + half-open detection, OTel-after-restart-with-Sentry,
|
||||
instance-report unique index, expression-isolate release, async delete retries). **No breaking
|
||||
compose/env/migration changes; no `N8N_*` env renames.**
|
||||
- 2.42.1 (2026-09-30, patch): API/editor fixes (emit valid schemas for untyped values in the Public
|
||||
API spec; return an execution when its trace context is incomplete) + editor feature (show the
|
||||
n8n logo on canvas in canvas-only mode).
|
||||
- 2.42.2 (2026-10-01, patch; **newest numeric tag on Docker Hub — verified 2026-10-02**): 1 core
|
||||
fix (stop waiting on Bull `job.finished()` for queued executions). Docker Hub `2.42.2` manifest
|
||||
active; no 2.43.x exists.
|
||||
- 2026-10-02 run: reconcile confirmed coopcloud upstream main still `9141e23` (3.5.1+2.40.5) and
|
||||
PR #9 (branch `upgrade-a144baf`, at 2.41.3, !testme GREEN 2026-09-28) still open/unmerged — so
|
||||
per the one-evolving-PR contract the run extends PR #9 with a fast-forward commit
|
||||
**2.40.5 → 2.42.2**. abra lists 2.42.2 as the newest candidate and a direct Docker Hub tag
|
||||
enumeration agrees (no 2.43.x). The delta spans two feature minors (2.41.0, 2.42.0) plus patches
|
||||
on both lines; **no breaking compose/env/migration changes, no `N8N_*` renames**. Rolling
|
||||
upgrade safe (sqlite default; TypeORM migrations auto-run on boot). Operator flags remain
|
||||
HTTP-API-caller-level only (2.33.0 workflow activate/deactivate deprecation; 2.36.0
|
||||
`Array.merge`→`mergeIntoObject`; 2.37.0 JSON content-type on decorator body routes + binary-data
|
||||
endpoint adapt; 2.39.0 workflow-version endpoint deprecation; 2.40.x `POST /rest/login`
|
||||
`emailOrLdapLoginId` rename). Recommended release: `-y`.
|
||||
|
||||
Generated
+4
-4
@@ -10,11 +10,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1789404337,
|
||||
"narHash": "sha256-FY5oOz/C6i6Ct6Qe6DqN6nOq+TXCyiZq5Am1LKLpDss=",
|
||||
"lastModified": 1790010051,
|
||||
"narHash": "sha256-0dz8fg4zqg54tk+1A7CHZAw+lK9vWxre6Tioi5B0ocU=",
|
||||
"ref": "refs/heads/main",
|
||||
"rev": "eb5fb826114f2b141dffb270fd36f7a22d1bf343",
|
||||
"revCount": 1550,
|
||||
"rev": "2f6787f0433e7ff3053116039f10c00cde34128f",
|
||||
"revCount": 1558,
|
||||
"type": "git",
|
||||
"url": "https://git.autonomic.zone/recipe-maintainers/cc-ci.git"
|
||||
},
|
||||
|
||||
@@ -30,8 +30,10 @@
|
||||
# Weekly self-update (Tue 03:00 UTC; skips itself while CI is busy; see nix/modules/auto-update.nix).
|
||||
cc-ci-orchestrator.autoUpdate.enable = true;
|
||||
|
||||
# The opencode UI: traefik (public 443, the *.ci.commoninternet.net cert) → nginx basic auth.
|
||||
cc-ci-orchestrator.opencodeUiHost = "oc.ci.commoninternet.net";
|
||||
# The opencode UI: traefik (public 443, the dual-zone wildcard cert) → nginx basic auth.
|
||||
# Domain cutover 2026-09: new name primary; legacy name kept answering during the bake window.
|
||||
cc-ci-orchestrator.opencodeUiHost = "oc.ci.autonomic.zone";
|
||||
cc-ci-orchestrator.opencodeUiExtraHosts = [ "oc.ci.commoninternet.net" ];
|
||||
cc-ci-orchestrator.opencodeUiTraefikNetwork = "proxy";
|
||||
|
||||
# ---- no tailscale on this host (operator 2026-09-07) --------------------------------------
|
||||
@@ -124,7 +126,13 @@
|
||||
# This host's own public names resolve to itself regardless of external DNS state (host
|
||||
# processes: the drone runner, the harness, the orchestrator; containers use the resolvers
|
||||
# above). Per-run recipe domains are random and cannot be pinned — those follow public DNS.
|
||||
# Domain cutover 2026-09: new names pinned; legacy names kept during the bake window.
|
||||
networking.hosts."195.201.88.249" = [
|
||||
"ci.autonomic.zone"
|
||||
"drone.ci.autonomic.zone"
|
||||
"report.ci.autonomic.zone"
|
||||
"traefik.ci.autonomic.zone"
|
||||
"oc.ci.autonomic.zone"
|
||||
"ci.commoninternet.net"
|
||||
"drone.ci.commoninternet.net"
|
||||
"report.ci.commoninternet.net"
|
||||
|
||||
@@ -6,6 +6,6 @@ ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJVlfoLBPseQ9fA9534KmRg2KWcksKZGzAJIpHJ2JpsI
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAQFuqUB2qNZSDNjDsjjhVA/WnnQNVAMmsUscW6OgMDN
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHOcLo0YBa0UYi7i/l8K/Y/7cF2OclmDqSTlAsHM0dOS notplants-orchestrator
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMniNzAzuI527bfk/EipqFILFayUCwYXDoZ3R7+QgYq6
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOk8NaeBdPbS2gfUvbny8h0AkZlVjGYHzx4QPXSJ38gd claude@claude-vm
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAcyTGb/wVgdhg5oBCZZvBaR1RuUQRY/3WHnOQpNDCsp claude-cc-ci-sandbox@20260526
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAcyTGb/wVgdhg5oBCZZvBaR1RuUQRY/3WHnOQpNDCsp cc-ci-root-ed25519@cc-ci-orchestrator-sandbox
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKmGDZC6wrOQNJAW5PPDpxgEXXrcsnIU4b3QJLtq05RQ cc-ci-loops-to-root@cc-ci
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHIa8iunWtA4mqLKV6MuiTo3RkVj2ucsk3gLL4ArMEPO notplants-orchestrator
|
||||
|
||||
@@ -62,6 +62,16 @@ in
|
||||
description = "nginx server_name for the opencode web UI (TLS + basic auth).";
|
||||
};
|
||||
|
||||
opencodeUiExtraHosts = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = ''
|
||||
Extra hostnames routed to the opencode UI alongside opencodeUiHost, rendered as
|
||||
`||`-joined Host conditions on the same router. Domain cutover 2026-09: the
|
||||
legacy oc.ci.commoninternet.net keeps answering here during the bake window.
|
||||
'';
|
||||
};
|
||||
|
||||
opencodeUiHtpasswdFile = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "/secrets/nginx/oc-htpasswd";
|
||||
@@ -216,6 +226,7 @@ SSHCFG
|
||||
recommendedProxySettings = true;
|
||||
virtualHosts.${cfg.opencodeUiHost} = {
|
||||
listen = [ { addr = "0.0.0.0"; port = cfg.opencodeUiBackendPort; } ];
|
||||
serverAliases = cfg.opencodeUiExtraHosts;
|
||||
basicAuthFile = cfg.opencodeUiHtpasswdFile;
|
||||
extraConfig = ''
|
||||
# traefik sits on the docker networks (ingress 10.0.0.0/24, gwbridge 172.18.0.0/16)
|
||||
@@ -256,7 +267,7 @@ SSHCFG
|
||||
replicas: 1
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.opencode-ui.rule=Host(`${cfg.opencodeUiHost}`)"
|
||||
- "traefik.http.routers.opencode-ui.rule=${lib.concatStringsSep " || " (map (h: "Host(`${h}`)") ([ cfg.opencodeUiHost ] ++ cfg.opencodeUiExtraHosts))}"
|
||||
- "traefik.http.routers.opencode-ui.entrypoints=web-secure"
|
||||
- "traefik.http.routers.opencode-ui.tls=true"
|
||||
- "traefik.http.services.opencode-ui.loadbalancer.server.port=${toString cfg.opencodeUiBackendPort}"
|
||||
|
||||
Reference in New Issue
Block a user