devmon documented and published on dev.dataroo.net
Host: rdmbair15m5 (authoring) → rdmsm4x (serving) ·
Session: Claude Code richh-69
Window: 2026-08-22 21:08 → 21:16 EDT
One-line summary: published the devmon development-resource-monitor documentation to the private dev wiki at dev.dataroo.net by adding it to the site generator's source of truth rather than hand-editing generated HTML, and verified reachability cross-host over Tailscale and LAN.
How dev.dataroo.net actually works (discovered, not assumed)
dev.dataroo.net --CNAME--> 535c417a….cfargotunnel.com (Cloudflare, proxied)
|
tunnel "dataroo-homelab-tunnel" (healthy, 4 conns)
|
ingress: dev.dataroo.net -> http://auth_proxy:80 ("*" -> 404)
|
rdmsm4x docker: dataroo-cloudflared-1 -> dataroo-auth_proxy-1 (nginx + .htpasswd)
-> dataroo-wiki-server-1 (nginx:alpine, ./wiki)
also published on host port 8787
Compose at rdmsm4x:~/dataroo.net/docker-compose.yml.
Three access paths, by design:
| Path | URL | Auth |
|---|---|---|
| Public | https://dev.dataroo.net/ |
HTTP Basic (dataroo development wiki) |
| Tailnet | https://rdmsm4x-1.kangaroo-kitefin.ts.net/ |
device-authenticated, no password |
| LAN | http://192.168.0.29:8787/ |
trusted network only, never port-forwarded |
Cloudflare Access is NOT protecting this hostname.
The account has Access apps
(18ashwoodc.cloudflareaccess.com warp + app_launcher) but
none covering dev.dataroo.net — the public path is guarded
solely by HTTP Basic auth. Worth revisiting if this ever holds anything
sensitive.
The trap avoided
The wiki is generated:
Generated by ~/dev/scripts/gen_site.py on rdmsm4x.
Hand-editing wiki/index.html or dropping a file into
wiki/p/ would have been silently overwritten by the next
run — and there is a launchd job
(com.eastcoastscience.devsite) regenerating every 5
minutes.
The real source of truth is
rdmsm4x:~/dev/data/products.json (a list
of product entries with name, path,
slug, what, tested[],
untested[], nxt[], blocked[]; hue
is derived from the name). Added a devmon entry there,
backed up the file first, then ran the generator.
What was published
https://dev.dataroo.net/p/devmon.html (67,592 B) —
devmon's page in the site's evidence-based schema, plus a card and chip
on the index. Site went 11 → 12 product pages.
Content is deliberately split the way the site's own footer demands
("Evidence or it does not count"). Tested carries only
claims with reproducible evidence: five-host deployment confirmed by
launchctl print; the rdDB re-entrant
dispatch_sync deadlock reproduced from .ips
stacks; 82 crashes classified; the footprint 7535 MB vs
leaks 32 bytes contradiction; reaper verified by
before/after counts (22→9, 4→3); the false-CRITICAL threshold bug and
its correction. NOT-tested is explicit that the leak
regression has never fired on real data, the auto-terminate path has
never executed, the 2-hourly rollup has not been observed firing on its
own schedule, pressure levels 2/4 have never been seen, reboot survival
is unexercised, and the LogTTY integration is a recommendation with no
code behind it.
Verification (cross-host, not localhost-only)
| Check | Result |
|---|---|
Origin 127.0.0.1:8787/p/devmon.html on rdmsm4x |
HTTP 200, 67,592 B |
LAN from rdmbair15m5 →
192.168.0.29:8787/p/devmon.html |
HTTP 200, 67,592 B |
Tailnet from rdmbair15m5 →
rdmsm4x-1.kangaroo-kitefin.ts.net/p/devmon.html |
HTTP 200, 67,592 B |
| Content assertion | <title>devmon</title> present |
Public https://dev.dataroo.net/p/devmon.html |
HTTP 401 — expected, Basic auth in front |
The 401 is correct behaviour, not a failure: the page is not publicly readable and was not ledgered as such.
Records
codex_linksApple Note: row added at top, stating plainly that the public URL returns 401 and naming the two verified private paths.- Backup:
~/dev/data/products.json.bak.<timestamp>on rdmsm4x before editing.
Undo
Remove the devmon entry from
rdmsm4x:~/dev/data/products.json (or restore the
.bak) and re-run
python3 ~/dev/scripts/gen_site.py. Deleting
wiki/p/devmon.html alone is not sufficient — the generator
recreates it from the JSON.
No credentials were read, printed, or stored. The Basic-auth password was never needed and was not requested; the Cloudflare key was sourced inside the remote shell and never appeared in a command line.