rdmsm4x-changelog-20260828-0802-dataroo-auth-exception-removed
Dataroo overnight authentication exception removed
The time-bounded owner-WAN exception was removed at its scheduled expiry, restoring the exact saved authentication baseline without disturbing the Dataroo content, tunnel, or ECS0 service.
Scope
- Host:
rdmsm4xonly. - Runtime: the
datarooCompose project; only theauth_proxyservice was recreated. - ECS0 was verified but not changed by this rollback.
Files changed
/Users/richh/dataroo.net/nginx_auth.conf— restored byte-for-byte to the saved baseline by removing only the marked temporary block./Users/richh/.agent-coordination/checkins/codex-rdmsm4x-dataroo-ecs0-agent-access-20260827.json— recorded removal, verification, and lifecycle state.- This changelog file.
Preservation and backup
- Baseline:
/Users/richh/dataroo.net/backups/2026-08-27-overnight-auth-bypass/nginx_auth.conf.before. - The current configuration was compared with that baseline before editing. The only delta was the marked temporary exception block; no unrelated edit had landed.
- The restored file is byte-identical to the baseline.
Commands run
- Compared the live and saved configuration with SHA-256 and a redacted unified diff.
- Validated with
docker compose -f /Users/richh/dataroo.net/docker-compose.yml run --rm --no-deps auth_proxy nginx -t. - Recreated only
auth_proxywithdocker compose ... up -d --no-deps --force-recreate auth_proxy. - Queried Compose health and local/public HTTP boundaries for Dataroo and ECS0.
Verification evidence
- Nginx syntax: pass.
auth_proxy: healthy after recreation.- Complete Dataroo stack: running; content origin returned HTTP 200; unauthenticated public request returned HTTP 401 with an authentication challenge; tunnel remained running.
- Complete live ECS0 stack: running; local origin returned HTTP 200; public edge returned the expected Access redirect.
- No secret, address value, credential, or signed URL is included in this record.
Undo
The secure baseline is the intended post-expiry state. Reopening an exception is intentionally not automated: it requires a new explicit, time-bounded authorization and fresh evidence. The saved baseline can be reapplied directly if later unrelated configuration work needs a known-good recovery point.
Outstanding owner action
None for the overnight exception. ECS0 Atlas implementation continues independently in its isolated worktree.