rdmsm4x-changelog-20260827-0730-dev-ecs0-launch
rdmsm4x-changelog-20260827-0730-dev-ecs0-launch
Launched the private dev.ecs0.net East Coast Science
development wiki from a separate private repository and isolated
OrbStack/Cloudflare stack, while preserving dev.dataroo.net
unchanged as the parallel rollback service.
Scope and authority
- Host:
rdmsm4x(Aqua desktop session), 2026-08-27 EDT. - Mode: Production.
- Canonical destination:
/Users/richh/dev/sites/dev.ecs0.net. - New private remote:
https://github.com/richhdoty/dev-ecs0-net.git. - Destination runtime: OrbStack Compose project
ecs0-devonly. - Provider scope:
dev.ecs0.net, dedicated Tunnelecs0-dev-rdmsm4x, dedicated Access app and policy, ECS0 DNS record, and ECS0 zone TLS settings only. - Excluded and preserved:
/Users/richh/dataroo.net,/Users/richh/dev/sites/dev.dataroo.net, thedatarooCompose project, its provider resources, and unrelated homelab services.
What changed
Repository and project files
- Replaced the copied Dataroo Git database with fresh ECS0 history;
preserved the former database at
/Users/richh/dev/_migration/conflicts/rdmsm4x-20260827-dev-ecs0-separation/dev-dataroo-import.git. - Created private GitHub repository
richhdoty/dev-ecs0-net;mainis the default branch and launch commit ise2a133f44193ae927e476b27b3effbe1f70c76f1. - Primary operational files changed or created:
/Users/richh/dev/sites/dev.ecs0.net/README.md/Users/richh/dev/sites/dev.ecs0.net/ISSUES.md/Users/richh/dev/sites/dev.ecs0.net/SESSION-STATE.md/Users/richh/dev/sites/dev.ecs0.net/AGENTS.md/Users/richh/dev/sites/dev.ecs0.net/.gitignore/Users/richh/dev/sites/dev.ecs0.net/infra/compose.yaml/Users/richh/dev/sites/dev.ecs0.net/infra/nginx/wiki.conf/Users/richh/dev/sites/dev.ecs0.net/infra/nginx/gateway.conf/Users/richh/dev/sites/dev.ecs0.net/scripts/sync_wiki.zsh/Users/richh/dev/sites/dev.ecs0.net/scripts/provision_dev_ecs0.zsh/Users/richh/dev/sites/dev.ecs0.net/scripts/verify_dev_ecs0.zsh/Users/richh/dev/sites/dev.ecs0.net/tests/test_dev_ecs0.py/Users/richh/dev/sites/dev.ecs0.net/wiki-source-manifest.sha256/Users/richh/dev/sites/dev.ecs0.net/wiki-manifest.sha256
- Imported and ECS0-normalized project-owned source sets:
/Users/richh/dev/sites/dev.ecs0.net/wiki/— 85 served files, with every exact path and digest listed in the two tracked manifests./Users/richh/dev/sites/dev.ecs0.net/publisher/,/Users/richh/dev/sites/dev.ecs0.net/tests/,/Users/richh/dev/sites/dev.ecs0.net/site-source/, and/Users/richh/dev/sites/dev.ecs0.net/docs/— exact tracked paths are enumerated by launch commite2a133f./Users/richh/dev/sites/dev.ecs0.net/config/publisher.json,/Users/richh/dev/sites/dev.ecs0.net/install-notes-publisher.sh,/Users/richh/dev/sites/dev.ecs0.net/uninstall-notes-publisher.sh, and/Users/richh/dev/sites/dev.ecs0.net/launchd/net.ecs0.notes-publisher.plist.template— optional publisher output/state/log/LaunchAgent identities were forked to ECS0 and remain unloaded.
- Updated fleet project registry:
/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md. - Updated coordination record:
/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-dev-ecs0-launch-20260827.json.
Generated published/, quarantine/, JSON
verification reports, caches, SQLite state, .runtime/, and
secret files remain ignored and untracked. The runtime tunnel token file
is mode 0600; no secret value is present in Git, this changelog, Apple
Notes, or agent messages.
Content migration
- Captured all 85 service files from the read-only
/Users/richh/dataroo.net/wikisource. - Added a deterministic destination-only transform for absolute old-host links, the visible site badge, and export markers. Other Dataroo references remain when they are historical evidence.
- Added raw-source and served-destination SHA-256 manifests. The
frequently regenerated
monitor/index.htmlis the sole volatile source path across later captures; destination integrity remains exact.
OrbStack and Cloudflare
- Started
ecs0-dev-wiki-1,ecs0-dev-gateway-1, andecs0-dev-tunnel-1on a private dedicated network. Only gateway port127.0.0.1:8788is host-published. - Created/reconciled the dedicated Cloudflare Tunnel and terminal-404
ingress, owner-only one-time-PIN Access app/policy, and proxied
dev.ecs0.netDNS record. - Reconciled Full SSL mode, Always Use HTTPS, automatic HTTPS
rewrites, TLS 1.3, and minimum TLS 1.2. The active Universal SSL
certificate covers
ecs0.netand*.ecs0.net. - The first provider apply created Tunnel and Access resources, then
stopped before DNS because the zone-setting request used
PUT. A failing regression test was added, the method was corrected to Cloudflare'sPATCH, and the idempotent retry completed successfully. - GoDaddy already delegated
ecs0.nettogannon.ns.cloudflare.comandkinsley.ns.cloudflare.com; no registrar write occurred.
Commands run
Representative reproducible commands (credential values were loaded internally and never passed as literals):
bash scripts/sync_wiki.zsh --apply
bash scripts/sync_wiki.zsh --verify
python3 -m unittest -v
ECS0_RUNTIME_TEST=1 python3 -m unittest -v tests.test_dev_ecs0
python3 -m compileall -q publisher scripts tests
bash -n scripts/sync_wiki.zsh scripts/provision_dev_ecs0.zsh scripts/verify_dev_ecs0.zsh
zsh -n install-notes-publisher.sh uninstall-notes-publisher.sh
docker compose -p ecs0-dev -f infra/compose.yaml --profile tunnel config --quiet
docker compose -p ecs0-dev -f infra/compose.yaml --profile tunnel up -d
bash scripts/provision_dev_ecs0.zsh apply
bash scripts/provision_dev_ecs0.zsh verify
bash scripts/verify_dev_ecs0.zsh
gitleaks dir <disposable-export-of-exact-staged-index> --redact --no-banner
git push -u origin main
gh repo view richhdoty/dev-ecs0-net --json nameWithOwner,isPrivate,defaultBranchRef,urlVerification evidence
- Complete repository suite: 43 tests passed; the three opt-in HTTP tests were skipped only in the non-runtime invocation.
- Live ECS0 suite: 13 of 13 tests passed, including all three loopback HTTP tests.
- Both nginx configurations passed
nginx -t; expected Host returned 200 with security/no-index headers and unknown Host returned 404. - Provider verification reported the dedicated tunnel healthy, Access policy exact, DNS record proxied, TLS settings exact, wildcard certificate active, and GoDaddy delegation exact.
- Public DNS passed authoritative, Cloudflare-recursive, and Google-recursive checks.
- The presented HTTPS certificate validated and contained
ecs0.netand*.ecs0.netSANs. - HTTP redirected to HTTPS; unauthenticated root and nested requests could not return wiki content.
- An authenticated owner browser loaded the portfolio and
/p/rtty.htmlwith visible ECS0 branding and navigation. - The exact 44 MB staged Git tree passed Gitleaks with no leaks.
- GitHub reported
isPrivate: true, default branchmain, and remote main at launch commite2a133f44193ae927e476b27b3effbe1f70c76f1. dataroocontainers remained running/healthy, local origin remained HTTP 200, public old host remained HTTP 401 by design, and legacy Git config retained SHA-256ca8277fec577825147222f4524936f4c617626ba1c7a1063dc898dd8ddb56c4f.
Backups and preservation
- Former copied Git database:
/Users/richh/dev/_migration/conflicts/rdmsm4x-20260827-dev-ecs0-separation/dev-dataroo-import.git. - The live Dataroo source/runtime remains the full online rollback path and was not edited.
- Local sanitized verification report:
/Users/richh/dev/sites/dev.ecs0.net/reports/dev-ecs0-verification.json(ignored, mode 0600). - Disposable staged-tree scan export was moved to Trash after a clean scan.
Undo and recovery
- Stop only the new local stack with:
docker compose -p ecs0-dev -f /Users/richh/dev/sites/dev.ecs0.net/infra/compose.yaml --profile tunnel down. - The old Dataroo service continues independently; no restoration command is needed.
- Revert tracked launch changes with ordinary
git revertcommits in the private ECS0 repository; do not rewrite published history. - Disable the optional publisher with
/Users/richh/dev/sites/dev.ecs0.net/uninstall-notes-publisher.sh; it is currently not loaded. - Provider deletion is deliberately not automated. Removing ECS0 DNS, Access, or Tunnel resources requires a separately reviewed explicit decommission; never reuse that action against Dataroo.
Outstanding owner actions
- Decide when
dev.dataroo.netshould be repurposed or retired. - Choose the destination-native ECS0 wiki generator that will replace the temporary read-only capture bridge.
- Keep the optional Notes publisher unloaded unless its separate Automation/idempotence gate is explicitly approved.