Ops/dev2 fleet kit - #110
Merged
Merged
Conversation
dev2-site reads the truth from Railway (services, domains, volumes, database variables), renders the box files from templates, provisions ~/www/<site> over ssh, copies Postgres through Railway's ssh endpoint into the shared cluster, issues the certificate over Porkbun DNS-01 before DNS moves, flips Porkbun, stops and disconnects the Railway service, and merges the per-repo deploy-dev2.yml. First site through it: bg0ne.com. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…show deploy stderr Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… cutover) + proxied gateway hosts Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
With dozens of compose networks Docker moves to 192.168.x/20 pools, which an allowlist of 172.16.0.0/12 alone drops (CONNECT_TIMEOUT to :5432 from the app). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…apps Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ify db url Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…heckouts Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… and node-postgres accept Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…austed) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…uire otherwise) Bun.SQL forwards unknown URL parameters to the server as GUCs, so uselibpqcompat=true was FATAL there while the health check stayed green. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ode 22 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ing it Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ale embedded DNS) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…o resolve Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…services only; opensocial.chat override Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… nodejs_18, --regen Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…PACKS_* command variables Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…clone/build); openaccess + openmcp overrides Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Gateway supabase.pairux.com -> :8274; URL, publishable/secret keys, db password and the LiveKit recording S3 endpoint/credentials re-pointed at the stack's own S3 protocol (secrets as secret: references). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Shares the cloud project with pairux.com, so it shares the dev2 stack too: URL, publishable/secret keys and db password re-pointed at supabase.pairux.com (secrets as secret: references). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
supabase.bl0ggers.com gateway proxy (the wildcard already routes it); NEXT_PUBLIC_SUPABASE_URL and SUPABASE_URL re-pointed, the db password and the three key variables as secret references. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Gateway supabase.brisk.news -> :8238; URL and publishable/secret keys re-pointed (keys as secret: references). Loaded from a fresh dump with supabase-load --reset right before the cutover. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ng loop input, grant functions by signature - load: 'psql -f /dev/stdin' prefixes messages with psql:/dev/stdin:N:, so the error counts were always 0; count and list them properly. - load: the schemas/extensions/buckets loops read from fd 3 -- the docker exec -i in the body swallowed the rest of stdin, so only the first entry ran (PostGIS was never created for icemap). - pull: function grants were emitted without 'function' and without the signature, so all of them failed; emit them from pg_proc with regprocedure, and revoke PUBLIC where the cloud had done so. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…OT cut over) supabase.coinpayportal.com -> :8273. The load lost public.payments (3405 rows) to a NOT VALID check constraint the dump re-creates as enforced, so the cutover is on hold until supabase-load handles NOT VALID constraints. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…nstraints, vault, S3 host, bucket limits - cutover maps sb_publishable_/sb_secret_ keys onto the stack's anon/service JWTs (they were never re-pointed before), rewrites <ref>.storage.supabase.co and swaps in the stack's S3 protocol credentials, and refuses to run while the cloud project still has Edge Functions the stack lacks. - new supabase-functions: ports supabase/functions/* from the checkout onto the stack's edge runtime, copies the cloud function secrets into volumes/functions/secrets.env (env_file on the functions service), probes one. - pull dumps NOT VALID check/fk constraints; load drops them before COPY and re-adds them NOT VALID after (coinpayportal's payments table failed on one). - pull dumps vault secrets, load recreates them; buckets keep file_size_limit and allowed_mime_types; storage FILE_SIZE_LIMIT raised to 5 GiB. - cron commands get the cloud URL and API keys rewritten before scheduling; the cloud cron probe no longer parses cron.job when pg_cron is absent. - transient auth.one_time_tokens / auth.scim_* excluded from the data dump. - stack no longer chowns an existing site root to root (CI deploys broke). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…n secrets Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… the site variables Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…_secrets overlay Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…nt monitor was a Vercel cron) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…n secrets as vault refs Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…rop DATABASE_AUTH_TOKEN)
…ate file Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…gs dropped; c0upons also loses the dead SQLITECLOUD_URL)
…ite Supabase stack and mirror storage files The backup job only knew the shared cluster. With the cloud projects deleted the 20 <slug>-supabase-db containers were the sole copy of their data. Now: each stack's postgres database is dumped (4-hourly, or daily when large) and verified like the cluster's, and volumes/storage is rsync-mirrored daily. The script and its cron file live here as templates and are installed by . Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Anthony reversed the stay-on-Railway decision ("move it all off railway").
Zone is at Cloudflare with no token in the vault, so the cert is HTTP-01
after the apex and www A records are pointed at dev2 by hand.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…les world-readable (umask 022) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…pp stays on the DO droplet) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…extensions.gin_trgm_ops); skip generated columns in the URL rewrite Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
# Conflicts: # dev2/dev2-site # dev2/sites.d/app.moshcode.sh.json # dev2/sites.d/brisk.news.json # dev2/sites.d/coinpayportal.com.json # dev2/sites.d/meshhook.com.json # dev2/templates/box-tune.sh # dev2/templates/supabase-load.sh # dev2/templates/supabase-pull.sh # dev2/templates/supabase-stack.sh
ThreatCrush Security Scan25 finding(s) HIGH/CRITICAL: 4 | MEDIUM: 12 | LOW: 9
Snippets are redacted; ThreatCrush never prints matched credential material. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.