Skip to content

fix(agentgit): make git push over SSH work on :2222 - #135

Closed
ralyodio wants to merge 1 commit into
mainfrom
fix/agentgit-ssh-2222
Closed

ralyodio wants to merge 1 commit into
mainfrom
fix/agentgit-ssh-2222

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Problem

git push over SSH to git.profullstack.com has never worked. The API advertises ssh://git@git.profullstack.com:2222/..., but :2222 times out from outside, and even with the port open the built-in server refuses git@.

Changes (setup.sh §9d)

  • BUILTIN_SSH_SERVER_USER = git: SSH_USER only changes the advertised clone URL; the built-in server accepts BUILTIN_SSH_SERVER_USER (default RUN_USER forgejo) and logs "Invalid SSH username git - must use forgejo". app.ini is written once, so besides the template, every run now converges the SSH keys of [server] in the existing app.ini (awk, idempotent, numbered app.bak-NNN.ini backup the first time). Forgejo is restarted every run already.
  • Forgejo upgrade never applied: the download curl'd onto the running /usr/local/bin/forgejo → ETXTBSY. Every deploy log shows forgejo download failed, and prod is still 11.0.1 against the 11.0.15 pin. Now: download to forgejo.new, check --version, mv (same as deploy/git-chovy/install.sh). This deploy will upgrade AgentGit 11.0.1 → 11.0.15 (same LTS line).
  • ufw: ufw allow 2222/tcp >/dev/null 2>&1 || true swallowed any failure; now it warns. The run logs whether :2222 is listening (ss) and the ufw rule, because the box has no shell and the deploy log is the only window.

Changes (deploy.yml)

  • A report-only step probes 2222 / 563 / 6697 from the runner. Evidence so far points at a DigitalOcean Cloud Firewall: :563 (NNTPS, also ufw-allowed by setup.sh) and :2222 both time out, while :587 is refused (reached the host). docs/irc.md already records that 6697 had to be added to the cloud firewall by hand. No DO token exists in the vault, so that layer cannot be changed from CI.
  • The closing setup.sh reminder now lists every public port the cloud firewall needs.

Test

  • bash -n, shellcheck (-S warning: same single pre-existing SC2097 as main)
  • the app.ini converge function run against a copy of the prod template: adds exactly one line, second run is a no-op, missing [server] and end-of-file cases handled

🤖 Generated with Claude Code

Three things stood between a member and `git push` over SSH to
git.profullstack.com, all in setup.sh §9d:

- app.ini is written once and never set BUILTIN_SSH_SERVER_USER, so the
  built-in server only accepted user "forgejo" and refused git@ with
  "Invalid SSH username git". The template now sets it, and every run
  converges the SSH keys of [server] in the EXISTING app.ini (with a
  numbered app.bak-NNN.ini backup the first time), so the live box gets it.
- The Forgejo upgrade curl'd straight onto /usr/local/bin/forgejo while it
  ran, which fails with ETXTBSY. Every deploy logged "forgejo download
  failed" and prod stayed on 11.0.1 against an 11.0.15 pin. Download to
  forgejo.new, check --version, then rename (same as deploy/git-chovy).
- `ufw allow 2222/tcp ... || true` hid any failure. It now warns, and the
  run logs whether :2222 is listening (ss) and the ufw rule, because the
  box has no shell and the deploy log is the only place to see it.

The deploy workflow gains a report-only step that probes 2222, 563 and
6697 from the runner. A DigitalOcean Cloud Firewall drops what it does not
list even when ufw allows it (docs/irc.md already notes this for 6697), and
only an outside probe can see that layer. The closing reminder in setup.sh
now lists every public port the cloud firewall needs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

10 finding(s)

HIGH/CRITICAL: 7 | LOW: 3

Severity Rule Location
HIGH secret-generic-credential deploy/ergo/ircd.yaml:162
HIGH secret-generic-credential deploy/ergo/ircd.yaml:221
HIGH secret-generic-credential deploy/ergo/ircd.yaml:638
HIGH secret-generic-credential deploy/ergo/ircd.yaml:787
HIGH secret-database-url deploy/ergo/ircd.yaml:893
HIGH secret-generic-credential deploy/ergo/ircd.yaml:1025
HIGH secret-generic-credential deploy/ergo/ircd.yaml:1033
LOW secret-generic-credential deploy/ergo/ircd.yaml:772
LOW tls-verification-disabled internal/mail/mail.go:109
LOW secret-generic-credential internal/mailu/mailu_test.go:44

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio

ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Closing unmerged: root cause is a DigitalOcean cloud firewall in front of the droplet (verified on-box: app.ini already has BUILTIN_SSH_SERVER_USER = git, ufw allows 2222, forgejo listens on *:2222, nft accept counter never moves for outside connects). No setup.sh change needed for :2222.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant