rdmsm4x-changelog-20260827-2320-dataroo-overnight-auth-exception
rdmsm4x-changelog-20260827-2320-dataroo-overnight-auth-exception
Applied a narrowly scoped, time-bounded owner-WAN exception to the Dataroo origin Basic Auth layer so local Codex/browser clients can read the development wiki overnight while preserving the password challenge for every other source.
Scope
- Host:
rdmsm4x - Runtime: OrbStack Compose project
dataroo - Service recreated:
auth_proxyonly - Public hostname affected:
dev.dataroo.net - ECS0 and Dataroo content, DNS, Tunnel, and credentials were not changed
Files changed
/Users/richh/dataroo.net/nginx_auth.conf- Added two exact IPv4
/32allow entries derived only from successful authenticated requests by the configured owner. - Added an explicit expiry comment for 2026-08-28 08:00 America/New_York.
- Preserved the existing verified IPv6 prefix,
deny all, and Basic Auth fallback.
- Added two exact IPv4
/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-dataroo-ecs0-agent-access-20260827.json- Declared the bounded writer lease and rollback boundary.
No address values or credentials are recorded in this changelog.
Backup and hashes
- Baseline backup:
/Users/richh/dataroo.net/backups/2026-08-27-overnight-auth-bypass/nginx_auth.conf.before - Baseline SHA-256:
6fdd4963eaee9f34473a9e008d8875ddc7442554d598bd3d5a7ef81bdbeb73db - Temporary configuration SHA-256:
ae5c38b3b62c201f3fcfb15950564889bb5f48fc2b1a22bc581b581efd3710ed
Commands run
- Synchronized fleet check-ins and inspected unread peer traffic.
- Read recent
auth_proxylogs and selected only distinct global IPv4 sources with successful owner-authenticated responses; safety cap was four and the observed set contained two. - Validated the prospective configuration using:
docker compose -f /Users/richh/dataroo.net/docker-compose.yml run --rm --no-deps auth_proxy nginx -t
- Recreated the single-file bind-mounted service using:
docker compose -f /Users/richh/dataroo.net/docker-compose.yml up -d --force-recreate --no-deps auth_proxy
- Performed repeated unauthenticated HTTPS checks and an internal non-allowlisted virtual-host check.
Verification evidence
- Nginx configuration syntax: successful.
dataroo-auth_proxy-1: healthy after recreation.- Five consecutive local unauthenticated public requests: HTTP 200.
- Non-allowlisted request to the same
dev.dataroo.netvirtual host: HTTP 401. wiki-server: healthy.cloudflared: remained running.
Automatic removal
- Codex automation:
remove-dataroo-overnight-auth-exception - Schedule: one run at the next 08:00 local time, 2026-08-28.
- The removal instructions require a three-way safety check against
the saved baseline, nginx validation, recreation of only
auth_proxy, restoration of the public challenge, and another durable changelog.
Undo
If removal is needed before the automation runs:
- Compare the live file with the saved baseline so unrelated edits are not overwritten.
- Remove only the temporary comment block and two temporary
/32entries, or restore the baseline when no unrelated edits exist. - Run the nginx validation command above.
- Force-recreate only
auth_proxy. - Verify a public unauthenticated request returns HTTP 401 and all three Dataroo services remain healthy.
Outstanding owner action
None for the overnight window. Google identity sign-in and any longer-lived agent/service authentication remain separate ECS0 design work; this temporary exception must not be made permanent.