Skip to content

Uptime PRD §12: port-drift check + self-bootstrapping prober deploy - #76

Merged
ralyodio merged 5 commits into
masterfrom
uptime-prober-deploy
Jul 5, 2026
Merged

ralyodio merged 5 commits into
masterfrom
uptime-prober-deploy

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #75 (which squash-merged only the base PRD). Adds the remaining uptime-monitoring work on top of current master.

What's here

  • PRD §12 — Exposed-Services / Port-Drift Check (Phase 2): a security-drift monitor that flags newly-exposed ports (e.g. Redis 6379, Postgres 5432) on verified-owned hosts only. Baseline + diff, alerts on change, private security view (not the public status page).
  • Prober transport: BullMQ over Redis. Railway enqueues repeatable daily jobs; a droplet-side BullMQ Worker dials outbound to Redis (rediss://), runs nmap -sT -Pn --top-ports 100, returns the result; a Railway QueueEvents handler persists + diffs + alerts. Droplet holds only the Redis URL — no DB creds, no inbound port.
  • Self-bootstrapping deploy (.github/workflows/deploy-prober.yml): on merge to master, rsync prober/+lib/ to ubuntu@scan.crawlproof.com and run the idempotent prober/deploy/provision.sh — installs nmap/Node 20/build tools, writes the Redis env file, installs the crawlproof-prober systemd unit, builds, restarts. First run provisions a bare droplet; no manual SSH setup ever.

Required GitHub secrets (set once, in GitHub — not on the server)

  • DROPLET_SSH_KEY — private key for ubuntu@scan.crawlproof.com
  • PROBER_REDIS_URL — rediss://… (scope to the prober queue)

Notes

  • The prober/ app workspace itself (BullMQ Worker + nmap wrapper) is not built yet — this is the deploy scaffolding + design. provision.sh expects prober/package.json with a build script and dist/index.js; the deploy won't fully succeed until that lands.
  • Docs-and-CI only; touches no existing app code.

🤖 Generated with Claude Code

ralyodio and others added 4 commits July 5, 2026 13:57
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Deploys the port-drift prober to the DO droplet on merges to master:
SSH in, git reset to origin/master, npm ci + build the prober workspace,
restart the crawlproof-prober systemd service. Path-filtered to prober/**
and lib/**. Requires DROPLET_HOST/USER/SSH_KEY secrets.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
deploy-prober now rsyncs prober/+lib/ to ubuntu@scan.crawlproof.com and runs
an idempotent provision.sh that installs nmap/Node/build tools, writes the
Redis env file, installs the systemd unit, builds, and restarts the service.
First run provisions a bare droplet; no manual SSH setup ever. ubuntu user's
default passwordless sudo does the privileged steps.

Secrets: DROPLET_SSH_KEY, PROBER_REDIS_URL.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 5, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

…oplet)

TCP connect checks work from Railway (V1/M4); ICMP PING needs raw sockets so
it runs on the §12 prober droplet in Phase 2, alongside nmap port-drift scans.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@ralyodio
ralyodio merged commit e2a65d5 into master Jul 5, 2026
8 checks passed
@ralyodio
ralyodio deleted the uptime-prober-deploy branch July 5, 2026 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant