--- name: recipe-mirrors-public-org-blocker description: "Recipe mirrors MUST be public (fleet invariant: the report's tokenless PR-STATUS proxy only sees public repos); org is public since ~2026-06, but late-enrolled mirrors (gitea, wordpress) were created private-from-birth by /recipe-enroll — fixed 2026-09-14" metadata: node_type: memory type: project originSessionId: f7960036-d990-4a21-a81e-f7c486d97fea --- The Recipe Report's live PR-STATUS column (`report.ci.commoninternet.net/pr//`, shipped in cc-ci `nix/modules/reports.nix`) is a tokenless same-origin nginx proxy to the Gitea API — it can ONLY see public repos. So **`recipe-maintainers/` mirrors MUST be public** (fleet invariant; cc-ci/cc-ci-orchestrator/archived repos stay deliberately private). History: originally ALL mirrors were private; on 2026-06-09 the 21 then-existing mirrors were flipped `private=false` after a secret-scan, and the `recipe-maintainers` org was later flipped public by the operator (the old 'org is private' blocker is RESOLVED). Recurrence (2026-09-14): /recipe-enroll still carried the old instruction to create mirrors with `"private":true` — so the later-enrolled mirrors `gitea` (2026-06-11) and `wordpress` (2026-08-03) were **private from birth**, leaving the report STATUS cells for those rows permanently "?" (gitea/wordpress rows in week-2026-09-11). Fixed: secret-scanned both, flipped `private=false` via PATCH `/repos/recipe-maintainers/`, patched the skill to create `private:false`. The report now lights up for every row — verify any new PR row with `curl https://report.ci.commoninternet.net/pr//` returning PR JSON, not 404. Related: [[push-commits-to-remote]].