Commit graph

22 commits

Author SHA1 Message Date
20a8d50084 Fix git log SSH: split SHA and timestamp into separate calls to avoid shell quoting
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-14 09:16:05 +00:00
e66164cdb7 Fix git log format — pipe in --format broken by remote shell, use space
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-14 09:14:55 +00:00
66355bd698 Add RAM and disk stats to health-status endpoint via SSH
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-14 09:04:22 +00:00
90c2e69d51 Replace execSync/exec shell interpolation with spawn arg arrays in updater
sshGet() and deploy() built SSH commands via template literal string
interpolation, which would allow shell injection if host/path values
from the app registry were tampered with. Replaced with spawnAsync()
using shell: false and explicit argv arrays. Added path validation
guard (/^\/opt\/[a-z0-9-]+$/) before both SSH calls. Also removes
the event-loop-blocking execSync in deploy().

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-13 09:25:09 +00:00
7e19f9361c Test webhook delivery after signature fix
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-05 13:55:10 +00:00
568cd8d299 Fix webhook signature verification — raw body capture + Forgejo header support
- fastify-raw-body was never registered, so HMAC ran over re-serialised
  JSON and every Forgejo delivery failed with 401
- accept X-Forgejo-Signature / X-Gitea-Signature (bare hex) as well as
  the GitHub-style sha256= prefix, and reject length mismatches instead
  of crashing timingSafeEqual with a 500

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-05 13:54:37 +00:00
2bc57ee89d Test Forgejo→updater webhook delivery
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-05 13:53:15 +00:00
e2a86bf30f feat(updater): include commit timestamps in status response
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-02 15:58:41 +00:00
d9dc5bf798 Pass CENTRAL_AUTH_SECRET and AUTH_URL to updater container
Without these, the updater sent Bearer <empty> to the auth registry
endpoint, causing 401 and an empty app registry.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-01 20:55:51 +00:00
c26f7e18b2 Replace static deploy-map with dynamic auth registry
updater now fetches app registry from auth /api/auth/internal/registry
and uses internal_host/internal_port for SSH status checks and deploys.
Removes hardcoded host map; platform infra (auth, portal, settings)
kept in INFRA_DEPLOY/INFRA_HEALTH constants.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-01 20:49:39 +00:00
b120fbf44e Add settings service to deploy map and health monitor
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-01 19:23:25 +00:00
1d5b345ea4 Add force=true param to bypass status cache on manual refresh
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-01 17:49:59 +00:00
dae5524dbc Fix health check treating 404 as unreachable
Apps without a /health route return 404 from nginx, but the service IS
running. Treat any HTTP response as up; only connection errors are down.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-01 17:43:32 +00:00
5b3b45a45c Add /health-status endpoint for live HTTP health checks
Parallel-fetches /health on each app LXC, returns up/down + response
time. Used by the portal Uptime tab instead of embedding Uptime Kuma.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-01 17:34:56 +00:00
78f29ff0d0 Remove --base-path command (handled by nginx sub_filter instead)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 17:22:01 +00:00
cfb3986584 Remove management from deploy-map (can't self-update)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 17:14:50 +00:00
8fdf3c8e4e Async SSH for parallel status checks; Kuma 2 --base-path via CLI arg
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 17:13:38 +00:00
32b4a98160 Fix SSH key path: use hotel-manage_deploy not id_ed25519
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 17:08:31 +00:00
5984043e7c Updater: /status endpoint (Forgejo vs deployed commit), /deploy/:repo manual trigger
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 17:04:57 +00:00
6e1c57a4ec Uptime Kuma 2.x with UPTIME_KUMA_BASE_PATH=/monitor for sub-path proxying
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 17:00:23 +00:00
b075975746 Docker-in-LXC: security_opt apparmor=unconfined (all services) 2026-07-01 13:28:52 +00:00
ab329d497b Initial commit: management 2026-07-01 12:09:54 +00:00