Conversation
Three things stood between a member and `git push` over SSH to git.profullstack.com, all in setup.sh §9d: - app.ini is written once and never set BUILTIN_SSH_SERVER_USER, so the built-in server only accepted user "forgejo" and refused git@ with "Invalid SSH username git". The template now sets it, and every run converges the SSH keys of [server] in the EXISTING app.ini (with a numbered app.bak-NNN.ini backup the first time), so the live box gets it. - The Forgejo upgrade curl'd straight onto /usr/local/bin/forgejo while it ran, which fails with ETXTBSY. Every deploy logged "forgejo download failed" and prod stayed on 11.0.1 against an 11.0.15 pin. Download to forgejo.new, check --version, then rename (same as deploy/git-chovy). - `ufw allow 2222/tcp ... || true` hid any failure. It now warns, and the run logs whether :2222 is listening (ss) and the ufw rule, because the box has no shell and the deploy log is the only place to see it. The deploy workflow gains a report-only step that probes 2222, 563 and 6697 from the runner. A DigitalOcean Cloud Firewall drops what it does not list even when ufw allows it (docs/irc.md already notes this for 6697), and only an outside probe can see that layer. The closing reminder in setup.sh now lists every public port the cloud firewall needs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ThreatCrush Security Scan10 finding(s) HIGH/CRITICAL: 7 | LOW: 3
Snippets are redacted; ThreatCrush never prints matched credential material. |
Contributor
Author
|
Closing unmerged: root cause is a DigitalOcean cloud firewall in front of the droplet (verified on-box: app.ini already has BUILTIN_SSH_SERVER_USER = git, ufw allows 2222, forgejo listens on *:2222, nft accept counter never moves for outside connects). No setup.sh change needed for :2222. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
git pushover SSH to git.profullstack.com has never worked. The API advertisesssh://git@git.profullstack.com:2222/..., but :2222 times out from outside, and even with the port open the built-in server refusesgit@.Changes (setup.sh §9d)
BUILTIN_SSH_SERVER_USER = git:SSH_USERonly changes the advertised clone URL; the built-in server acceptsBUILTIN_SSH_SERVER_USER(default RUN_USERforgejo) and logs "Invalid SSH username git - must use forgejo". app.ini is written once, so besides the template, every run now converges the SSH keys of[server]in the existing app.ini (awk, idempotent, numberedapp.bak-NNN.inibackup the first time). Forgejo is restarted every run already./usr/local/bin/forgejo→ ETXTBSY. Every deploy log showsforgejo download failed, and prod is still11.0.1against the11.0.15pin. Now: download toforgejo.new, check--version,mv(same asdeploy/git-chovy/install.sh). This deploy will upgrade AgentGit 11.0.1 → 11.0.15 (same LTS line).ufw allow 2222/tcp >/dev/null 2>&1 || trueswallowed any failure; now it warns. The run logs whether :2222 is listening (ss) and the ufw rule, because the box has no shell and the deploy log is the only window.Changes (deploy.yml)
Test
bash -n, shellcheck (-S warning: same single pre-existing SC2097 as main)[server]and end-of-file cases handled🤖 Generated with Claude Code