wiki: sync 2026-08-02 22:18 UTC — 4 file(s) updated
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
# Channel Wiki: #jarvis-jr-v1-hermes-setup
|
||||
_Channel ID: 1526844602303123466_
|
||||
_Created: 2026-07-23 18:22 UTC_
|
||||
_Last sync: 2026-08-02 18:06 UTC_
|
||||
_Last sync: 2026-08-02 22:16 UTC_
|
||||
|
||||
## Purpose
|
||||
Hermes installation, persistent runtime configuration, secret management, and setup troubleshooting.
|
||||
@@ -13,7 +13,9 @@ Hermes installation, persistent runtime configuration, secret management, and se
|
||||
|
||||
## Active Topics
|
||||
- **Bitwarden setup:** enabled and operational. Live verification at sync time showed project access, `bws 2.0.0`, and one applied key: `HL_V1_GITEA_ACCESS_TOKEN` (value never exposed).
|
||||
- **PENDING:** the gateway process observed during the 2026-08-02 conversation predated the corrected Bitwarden cache and had not imported `HL_V1_GITEA_ACCESS_TOKEN`; run `/restart` once, then verify the variable is present without printing its value.
|
||||
- **VERIFIED:** after gateway restart, `HL_V1_GITEA_ACCESS_TOKEN` is present in the Hermes runtime. Authenticated `GET /api/v1/user` against the internal Gitea upstream returned HTTP 200 for `jarvis-at-skic`; the account is active and not prohibited. Repository metadata for `skic-v1-playground/documentation` reported pull, push, and admin permissions.
|
||||
- **ROOT CAUSE — public Nginx outage:** at `2026-08-02T18:07:35Z`, Argo CD application `0000-ingress-nginx` synced Helm chart `ingress-nginx` 4.11.3. Its DaemonSet declares host ports 80/443 on every Linux node, including Osgiliath (`192.168.148.249`), so Kubernetes CNI host-port NAT intercepts traffic before the host's system Nginx. System Nginx remains active, enabled, listening, and has valid vhost configuration, but public requests are answered by Kubernetes ingress instead. Since Kubernetes has only one Ingress (`argo-workflows.apps.lego-cloud.eu`), legacy hostnames such as Gitea and Keycloak get the ingress controller's fake `ingress.local` certificate and default HTTP 404. The internal Gitea upstream remains healthy. Durable repair must change the GitOps values file `cluster/0500-resources/0000-ingress-nginx/ingress-nginx/values.yml` in `home-v1/gondor-v1.git` to avoid hostPort 80/443 on Osgiliath (for example, schedule ingress only on worker nodes), while preserving a route for Kubernetes-hosted applications.
|
||||
- **VERIFIED — Gondor node SSH:** Hermes can authenticate as `lego` to all three known Gondor v1 nodes: Osgiliath 000, Minas Tirith 010, and Minas Tirith 020. Verified node addresses are recorded in the `gondor-v1-nodes` skill. Lego authorized Hermes's existing ED25519 public key on both Minas Tirith workers.
|
||||
|
||||
## Key Context
|
||||
- `HERMES_HOME=/opt/data`; this is persistent storage, so Bitwarden configuration survives gateway/container restarts and container recreation as long as `/opt/data` remains mounted and `HERMES_HOME` is unchanged.
|
||||
@@ -21,6 +23,7 @@ Hermes installation, persistent runtime configuration, secret management, and se
|
||||
- Bitwarden configuration uses `access_token_env: BWS_ACCESS_TOKEN`, a 300-second cache TTL, automatic `bws` installation, and exact-key export.
|
||||
- A permissions incident made `/opt/data/.env` unreadable and caused repeated gateway `PermissionError` responses. It was fixed; at 2026-08-02 18:06 UTC both `/opt/data/.env` and `/opt/data/config.yaml` were owned by `hermes:hermes` with mode `0600`.
|
||||
- `gitea-repository-operations`, `gitea-docusaurus-projects`, and the Discord knowledge-wiki Gitea creation workflow were updated to require `HL_V1_GITEA_ACCESS_TOKEN` and reject `GITHUB_TOKEN` for `gitea.lego-cloud.eu`. GitHub-specific workflows may continue using `GITHUB_TOKEN` for `github.com`.
|
||||
- Reusable skill: `/opt/data/skills/cloud-architecture/gondor-v1-nodes/SKILL.md`. It documents the persistent SSH identity (`/opt/data/home/.ssh/id_ed25519`, fingerprint `SHA256:7qkAFkIMxFHhCjd8FazFyQFLi75y+gMfUm08tHjYNjU`), node inventory, safe read-only checks, MicroK8s/Argo CD guidance, and the distinction between remote `authorized_keys` and client `known_hosts`.
|
||||
- The blank human message `1533511724370624693` included `message.txt`; its CDN URL returned HTTP 403 when this sync attempted retrieval, so its contents remain **UNKNOWN**. Subsequent messages and live verification establish the setup outcome above.
|
||||
|
||||
## People & Roles
|
||||
@@ -28,9 +31,12 @@ Hermes installation, persistent runtime configuration, secret management, and se
|
||||
- **Hermes:** validates secret integration without revealing values and maintains Gitea-related skills.
|
||||
|
||||
## Action Items
|
||||
- [ ] **Owner: infrastructure operator / Lego — due date UNKNOWN:** restart the Hermes gateway once so `HL_V1_GITEA_ACCESS_TOKEN` is imported into the gateway environment.
|
||||
- [ ] **Owner: Hermes — due date after restart:** verify gateway access to `HL_V1_GITEA_ACCESS_TOKEN` without displaying the value, then use it for future authenticated Gitea API operations.
|
||||
- [x] **Owner: infrastructure operator / Lego:** restart the Hermes gateway so `HL_V1_GITEA_ACCESS_TOKEN` is imported.
|
||||
- [x] **Owner: Hermes:** verify gateway access to `HL_V1_GITEA_ACCESS_TOKEN` without displaying the value and authenticate to Gitea.
|
||||
- [ ] **Owner: infrastructure operator / Lego — due date UNKNOWN:** choose and apply the ingress ownership model. Recommended: keep host system Nginx on Osgiliath ports 80/443, constrain the Argo CD-managed `ingress-nginx` DaemonSet to the two worker nodes via GitOps values, and proxy required `*.apps.lego-cloud.eu` routes from Osgiliath to worker ingress endpoints.
|
||||
- [x] **Owner: Lego / Hermes:** authorize and verify Hermes SSH access to `gondor-v1-minas-tirith-010` and `gondor-v1-minas-tirith-020`; completed 2026-08-02.
|
||||
- [x] **Owner: Hermes:** create and verify the reusable `gondor-v1-nodes` skill; completed 2026-08-02.
|
||||
|
||||
## Source Anchors
|
||||
- Latest processed human message: `1533516194106048725` (2026-08-02 16:45 UTC).
|
||||
- Decision thread: human messages `1533507837391798413` through `1533516194106048725` (2026-08-02 16:12–16:45 UTC), with bot responses used only to establish implementation and verification outcomes.
|
||||
- Latest processed human message: `1533557577361916045` (2026-08-02 19:30 UTC).
|
||||
- Current thread: human messages `1533543425167593484` through `1533557577361916045` (2026-08-02 18:34–19:30 UTC), with bot output used only to establish live Gitea authentication, outage diagnosis, node access, and skill implementation results.
|
||||
|
||||
Reference in New Issue
Block a user