Fleet changelogs · dev.ecs0.net
rdmbair15m5-changelog-20260822-2116-devmon-published-to-dev-dataroo-net

devmon documented and published on dev.dataroo.net

Host: rdmbair15m5 (authoring) → rdmsm4x (serving) · Session: Claude Code richh-69 Window: 2026-08-22 21:08 → 21:16 EDT

One-line summary: published the devmon development-resource-monitor documentation to the private dev wiki at dev.dataroo.net by adding it to the site generator's source of truth rather than hand-editing generated HTML, and verified reachability cross-host over Tailscale and LAN.

How dev.dataroo.net actually works (discovered, not assumed)

dev.dataroo.net  --CNAME-->  535c417a….cfargotunnel.com   (Cloudflare, proxied)
                              |
        tunnel "dataroo-homelab-tunnel" (healthy, 4 conns)
                              |
        ingress: dev.dataroo.net -> http://auth_proxy:80   ("*" -> 404)
                              |
   rdmsm4x docker: dataroo-cloudflared-1 -> dataroo-auth_proxy-1 (nginx + .htpasswd)
                                          -> dataroo-wiki-server-1 (nginx:alpine, ./wiki)
                                             also published on host port 8787

Compose at rdmsm4x:~/dataroo.net/docker-compose.yml. Three access paths, by design:

Path URL Auth
Public https://dev.dataroo.net/ HTTP Basic (dataroo development wiki)
Tailnet https://rdmsm4x-1.kangaroo-kitefin.ts.net/ device-authenticated, no password
LAN http://192.168.0.29:8787/ trusted network only, never port-forwarded

Cloudflare Access is NOT protecting this hostname. The account has Access apps (18ashwoodc.cloudflareaccess.com warp + app_launcher) but none covering dev.dataroo.net — the public path is guarded solely by HTTP Basic auth. Worth revisiting if this ever holds anything sensitive.

The trap avoided

The wiki is generated: Generated by ~/dev/scripts/gen_site.py on rdmsm4x. Hand-editing wiki/index.html or dropping a file into wiki/p/ would have been silently overwritten by the next run — and there is a launchd job (com.eastcoastscience.devsite) regenerating every 5 minutes.

The real source of truth is rdmsm4x:~/dev/data/products.json (a list of product entries with name, path, slug, what, tested[], untested[], nxt[], blocked[]; hue is derived from the name). Added a devmon entry there, backed up the file first, then ran the generator.

What was published

https://dev.dataroo.net/p/devmon.html (67,592 B) — devmon's page in the site's evidence-based schema, plus a card and chip on the index. Site went 11 → 12 product pages.

Content is deliberately split the way the site's own footer demands ("Evidence or it does not count"). Tested carries only claims with reproducible evidence: five-host deployment confirmed by launchctl print; the rdDB re-entrant dispatch_sync deadlock reproduced from .ips stacks; 82 crashes classified; the footprint 7535 MB vs leaks 32 bytes contradiction; reaper verified by before/after counts (22→9, 4→3); the false-CRITICAL threshold bug and its correction. NOT-tested is explicit that the leak regression has never fired on real data, the auto-terminate path has never executed, the 2-hourly rollup has not been observed firing on its own schedule, pressure levels 2/4 have never been seen, reboot survival is unexercised, and the LogTTY integration is a recommendation with no code behind it.

Verification (cross-host, not localhost-only)

Check Result
Origin 127.0.0.1:8787/p/devmon.html on rdmsm4x HTTP 200, 67,592 B
LAN from rdmbair15m5 → 192.168.0.29:8787/p/devmon.html HTTP 200, 67,592 B
Tailnet from rdmbair15m5 → rdmsm4x-1.kangaroo-kitefin.ts.net/p/devmon.html HTTP 200, 67,592 B
Content assertion <title>devmon</title> present
Public https://dev.dataroo.net/p/devmon.html HTTP 401 — expected, Basic auth in front

The 401 is correct behaviour, not a failure: the page is not publicly readable and was not ledgered as such.

Records

Undo

Remove the devmon entry from rdmsm4x:~/dev/data/products.json (or restore the .bak) and re-run python3 ~/dev/scripts/gen_site.py. Deleting wiki/p/devmon.html alone is not sufficient — the generator recreates it from the JSON.

No credentials were read, printed, or stored. The Basic-auth password was never needed and was not requested; the Cloudflare key was sourced inside the remote shell and never appeared in a command line.