Commit Graph

43 Commits

Author SHA1 Message Date
a02c4b86a2 wiki: ingest de-vds-3xui source chronicle + gitignore .tmp/.tasks/.lock
sources/de-vds-3xui-setup-2026-07-14.md (new) — session chronicle capturing
the 3x-ui 3.5.0 troubleshooting: login 403 = CSRFMiddleware (X-CSRF-Token,
GET {BP}csrf-token), direct DB insert into inbounds no longer renders
(client model split across clients/client_inbounds/client_traffics → use
panel API add with stringified settings), wrapper `x-ui setting` doesn't
persist creds (binary only). Reference JSON lifted from working nl-vds 32030.
Entity sources: bound. +index.md sources line, +log.md ingest entry.
gitignore: .tmp/ (cred-bearing local throwaway, like .scratch/) and
.tasks/.lock (runtime). .tmp/ removed from disk.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-14 15:01:26 +03:00
543ded79bd wiki: de-vds-3xui real RF-client confirmed (session via 32030)
User connected through the DE node right now — plain VLESS 32030 proven
working on real RF client again. Task [de-vds-3xui-setup] closed. Flipped
Проверено block to ; +log.md decision entry.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-14 14:57:52 +03:00
f0965cf512 wiki: ingest de-vds-3xui (Fornex Germany VPN, plain VLESS 32030)
New entity de-vds-3xui — Germany VPS 130.17.17.158 (Fornex, Ubuntu 24.04),
3x-ui 3.5.0 / xray 26.7.11, plain VLESS 32030 security=none (analog of nl-vds-3xui;
masked protocols intentionally NOT raised). Captured 3.5.0 gotchas vs 3.2.7:
CSRF on all panel POSTs (X-CSRF-Token, GET {BP}csrf-token), direct DB INSERT
into inbounds no longer renders (client model split across clients/
client_inbounds/client_traffics → use panel API add), wrapper `x-ui setting`
doesn't persist creds (binary only). Server-side e2e verified; real RF-client
test pending user. +index.md, +log.md.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-14 14:40:23 +03:00
b5839bd02d feat(tandemmebel): in-place bump 0.42.0 → 0.42.1 LIVE (stack 20, order-tag fix)
Consumer bump by operator (blocker-pattern 2026-07-04 resolved without dev-source):
pin apps/web/package.json:12 + yarn install (lock 0.42.1/core 0.24.1/liquid 0.10.2/data 0.14.1)
+ commit 0cd9351 + push origin (ls-remote confirmed).

Build on VDS → registry.kzntsv.site/tandemmebel:0cd9351 (digest f29c187f).
Throwaway-staging :5020 from live env, healthy.
Completeness-gate С VDS: 184/184 parity (NEW==PROD), /articles 404 identical to
prod oracle → benign. 0.42.1 order-fix inert on blog-portfolio (no catalog).
Operator-gated PUT stack 20 (env 8/8 preserved, prune:false pullImage:true)
→ container 0cd9351+healthy ~8s. Live-smoke GREEN, TLS cert untouched.

Closes snolla 0.42.1 rollout — all 5 snolla sites now on VDS.
Rollback = tag ed96b18 (+ b02ca18) in registry.

- compose source-of-truth: tag + comment (0.42.1)
- board task: decisions log entry
- wiki: new tandemmebel-vds-deploy-runbook, bump recipe (4 sites), index, log
2026-07-12 13:26:28 +03:00
d3d0ff48ed feat(tandemmebel): cutover LIVE on VDS — last snolla site migrated
DNS reg.ru flipped, traefik Host-rule staging->prod, LE cert issued.
Live-smoke GREEN: all pages 200, sitemap 184 locs, sharp media OK.
Gotham-Pro.css latent prod bug fixed by cutover (0B->4436B).
Snolla 0.42.x tirazh now fully alive (5/5 stacks on VDS).
2026-07-12 12:48:20 +03:00
8e3e5b4353 wiki(snolla-0.42.1): рецепт live-prod in-place bump + секции в 3 рунбука + index/log
Закрыт пропуск: тираж 0.42.1 не был зафиксирован в вике (таски emspb/labtools.pro
просили using-wiki).

- NEW concepts/snolla-live-prod-inplace-image-bump.md — переиспользуемый рецепт
  (build на VDS → throwaway-staging-acceptance С VDS → env-preserving Portainer PUT
  put-stack.js → live-smoke), встроен put-stack.js, гочи.
- UPDATE 3 рунбука секцией «0.42.1 in-place bump» (labtools.ru/emspb/labtools.pro)
  с образами/acceptance/rollback.
- FIX orphan: все 3 deploy-рунбука добавлены в index.md (не были каталогизированы).
- log.md: decision-запись.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-05 12:16:15 +03:00
2e5adcf11e deploy(cms-s3): S3 FileStorage provider LIVE on RUVDS — admin↔MinIO split-brain closed
Разбор 500 на /admin/assets/<owner>/delete → корень ACL (app pool RX-only на
App_Data после scp-миграции) → полная развязка хранилища CMS:

- S3 FileStorage провайдер (MoreThenCms.FileStorage.S3) построен (координация с
  интерн-сессией) и раскатан LIVE на прод RUVDS: 6 контентных классов web.config
  → S3/MinIO, кэши остались Local. Смок 7 тенантов 200/301, 0×500, S3-read byte-parity.
  Upload-гоча: UseChunkEncoding=false (MinIO ⊥ AWSSDK aws-chunked).
- Весь локальный контент RUVDS → MinIO (galleries 5.3G, themes 2.7G, maxMind);
  imageCache-блоат (2.1G) выпилен из бакета themes.
- stostayer.old определён как stale-копия (не мигрировать).

Новый concept: snolla-admin-appdata-acl-500-after-scp-migration.
Трекеры: morethencms-s3-filestorage-provider (LIVE), reconcile-local-assets-to-minio (done).
Rollback: web.config.bak-pre-s3-2026-07-03 на хосте.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-03 13:47:21 +03:00
685f273571 deploy(pilonuxt): cf2bba2 LIVE — forms-api + full @snollajs/snolla drop
ADR-0010: forms moved to @snollajs/forms-api, @snollajs/snolla dropped
entirely, core@0.1.1 (Buffer over btoa). Stack 16 → pilonuxt:cf2bba2.
Pre-deploy tree-check of .output/server/node_modules 4/4: 0x snolla,
0x btoa, exactly 1x data@0.9.1, core 0.1.1 + content-api 0.14 + forms-api
0.1.0. Smoke green: SSR /+/catalog 200, robots/yandex from DB (ADR-0009
no regress), form ?path=/checkout empty -> 422 JSON, /nope -> 404 (no
valid submitted). Smoke gotcha: 422 only with Accept: application/json.

Closes [deploy-pilonuxt-forms-api-drop-snolla].

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 23:01:25 +03:00
dca1bf77d9 deploy(pilonuxt): 40bb383 LIVE — staticPages + robots.txt from DB
Stack 16 redeployed to registry.kzntsv.site/pilonuxt:40bb383 (ADR-0009:
DB-backed staticPages + robots.txt). Build from monorepo with forced client
regen (rm src/generated + schema-gen 0.6 → getStaticPage/getRobotsTxt);
home push hit traefik-499 on .output layer (425MB) → save|ssh load + push
from VDS. Smoke acceptance 6/6 verified by body (robots full from DB w/
Yandex Clean-param + Sitemap, yandex/google verifications, /nope→404).

Closes [deploy-pilonuxt-static-pages-robots].

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 12:05:27 +03:00
c3e845831d wiki(books-vds): document public bookva-db endpoint :33306
bookva MariaDB is published at 89.253.255.133:33306 (0.0.0.0:33306->3306,
port 33306 since 3306 is slovo books-db). Added public DB-endpoints block
to § Доступ (slovo + bookva), noted mongo/ES stay internal, and a
.Ports-vs-.Networks reminder. Closes the port wiki-drift in follow-up #2.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 11:54:50 +03:00
fb47d5deb2 wiki(vdsina): document Amsterdam Outline+3x-UI VDS 46.151.25.64
New entity + inventory source for previously-undocumented family VPN.
Secrets stored separately in pass vdsina-outline/full-env.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 15:54:36 +03:00
b7f2edc5bd docs(wiki): registryGc real-run outcome + named-tag-loss lesson
Первый боевой registryGc dryRun:false (books master-289c660, под добро юзера):
63 DELETE, 0 ошибок, 0x405 -> REGISTRY_STORAGE_DELETE_ENABLED=true подтверждён
живьём; 61 dangling + 2 datable снесены, реестр почищен.

Урок: master у books-api/books-ops-mcp был dangling (не пересобирались ~3нед)
-> логика drop-dangling снесла named-тег -> :master 404. Outage нет (контейнеры
на локальных образах), но redeploy упрётся. Политика: НЕ удалять named-теги
master/latest даже dangling (protectRe -> +master/latest); проверить keep/drop
на digest-коллизию (books-api keep=1 но 0 не-buildcache осталось).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-18 13:21:37 +03:00
93b4ef1d13 docs(wiki): dangling image-index finding — registry full of tag-tombstones
Перепрогон registryGc dryRun на descent-фиксе (master-dcd7c91) вскрыл 2-й
root-cause: реестр засорён dangling OCI image-индексами — тег жив, но его
платформенный sub-manifest отдаёт MANIFEST_UNKNOWN (вычищен прежним host-side
registry garbage-collect, не следящим index->child для multi-arch).
books-web: 19 тегов -> 3 датируемых, 16 dangling.

date-based GC защищает dangling как null-dated -> никогда не удаляет, хотя они
и есть мусор (логика задом наперёд). Рекомендация books: различать
transient-error (protect) vs MANIFEST_UNKNOWN (eligible for delete).
freedBytes от dangling ~0 (слои уже вычищены).

+registry-oci-image-index-gc.md (раздел) +index.md +log.md.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-18 12:51:28 +03:00
85b13ae6a4 docs(wiki): OCI image-index GC gotcha + bind-mount config-shadow lesson
Следствие закрытия [books-task-runner-registry-auth-cred].

concepts/registry-oci-image-index-gc.md (new): books-* образы в registry =
OCI image-index (buildx), top-level .config=null, дата .created в платформенном
sub-manifest. Наивный GC по top-level дате → null у всех → null-dated группы
защищаются → drop=0 всегда (keepLastN не применяется). Правила: Accept со
всеми media-types, дата из sub, DELETE по index-digest не sub. Зафиксировано
на books registryGc dryRun (deleted=0 при 14 tags) + манифест-dump books-web.

concepts/bindmount-config-edit-preserve-mode.md: дополнен гочей про
bind-mount shadow (config образа затенён целиком → полная секция, не дельта)
+ worked example task-runner (mode не слетел, постмортем сработал).

+index.md (2 строки) +log.md.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-18 12:31:41 +03:00
28de8e60e0 docs(wiki): registry.kzntsv.site auth-model concept + bind-mount config-mode postmortem
- concepts/registry-kzntsv-auth-model.md (new): standalone registry:2 + htpasswd
  Basic, binary access, NOT Gitea-packages; how to add htpasswd users (hot-reload),
  GC via v2 DELETE + host garbage-collect; users vitya + books-ci.
- concepts/bindmount-config-edit-preserve-mode.md (new): mktemp+mv drops file mode
  644->600 -> non-root container (uid 1000) EACCES crash-loop; chmod --reference.
  Worked example: books-job-scheduler prod-down incident 2026-06-18.
- vds-kzntsv entity registry row links the auth-model concept.
- index.md + log.md updated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-18 11:28:58 +03:00
5ffca96934 docs(wiki): runbook stostayer-web deploy + park complaint-form task
Ingest .wiki/concepts/stostayer-web-deploy-runbook.md — канал деплоя легаси
web (build offline → push docker.stostayer.ru → Portainer-стек 16 через
container-IP API с хоста, мимо Angie BA) + rollback + гоча VPN-IP бан
хостером при retry-push-шторме.

БЛОКЕР задокументирован: легаси packages/web (node16/CJS/Nuxt2) не
пересобрать ни с какого свежего дерева — 5 ESM-ставших депов (@snollajs/snolla,
@snollajs/content-api, @stostayer/api, @stostayer/data ×2). 0.3.18 заморожен.
Фикс формы (120bc07) едет с web4-cutover.

Таска stostayer-web-complaint-form-deploy → 🔵 park (blocker=web4-cutover);
попытка деплоя 0.3.19 откатана на 0.3.18, сайт восстановлен. Дохлый 0.3.19
оставлен в registry по решению vitya.

+ index.md, log.md.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 19:21:56 +03:00
c677b23f81 docs(wiki): уточнён live-state stostayer IIS на windows-recovery-host
Добавлена таблица порт->conn-string->БД для двух оставшихся IIS-сайтов
(stostayer :8090 -> внешний прод www.stostayer.ru; stostayer.old :8091
-> наш mssql.kzntsv.site), путь админок /admin, live-проверка 2026-06-17.
Пофикшена стейловая строка stostayer.old conn (localhost -> mssql.kzntsv.site).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 13:13:37 +03:00
cad9f02c0e feat(deploy): pilonuxt 19a4a84 — structured-data (description/brand/return-policy) live; close redeploy-pilonuxt-gsc-structured-data
Перекат stack 16 на registry.kzntsv.site/pilonuxt:19a4a84 (build на
workstation, push, Portainer PUT pullImage). Smoke на проде через
--resolve: description непустой, brand=Пилорама 98, offers→
hasMerchantReturnPolicy/returnPolicyCategory=MerchantReturnNotPermitted,
прежние offers-поля целы, регрессий нет. Отчёт в inbox pilonuxt.

Wiki ingest: portainer-stack-management-vds — раздел Stack redeploy
(новый тег) + gotcha #9 (PS 5.1 Invoke-RestMethod декодит /file как
ISO-8859-1 → mojibake кириллицы → PUT падает YAML; fix байты+UTF8) +
#10 (пустой env). index/log обновлены.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 10:22:30 +03:00
7ebab0a79d docs(wiki): add S3-access lookup block for client apps (books-vds MinIO)
Запрос snolla (raw-stream content-api) потребовал MinIO endpoint+креды;
ответ был выводим из вики, но не собран одним куском. Добавлен раздел
«S3 access для клиентских приложений» в minio-imgproxy-on-vds.md:
endpoint (https://minio.kzntsv.site / сырой :9000 / inter minio:9000),
root accessKey + pass-ссылка на secret, форма ключа, ssl/region/pathStyle.
Следующий такой вопрос — grep по вики, без SSH на сервер.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-14 10:49:13 +03:00
f04426617c feat(galleries): migrate pilorama98 gallery originals Local-disk → S3
snolla galleries 404 (imgproxy "Source unreachable"): legacy storageClient
"galleries" = MoreThenCms Local storage class (App_Data\galleries\<siteId>),
never in S3 — products were migrated, galleries weren't. Path A (user pick):
new bucket `galleries`, 301 pilorama98 originals (77 MiB) rclone'd from RUVDS
IIS → s3://galleries/37e6…/<guid>.jpg verbatim. snolla code unchanged
(storageClient=bucket is the working convention). imgproxy smoke from
books-vds: real obj 200 image/webp, fake guid 404. Other sites unmigrated
(scope). Inbox sent to victor/snolla.

- close [migrate-gallery-originals-to-s3] (scope pilorama98)
- NEW .wiki concept galleries-storage-class-local-not-s3
- fix stale minio-imgproxy-on-vds (pipeline on books-vds since 2026-06-08)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 14:50:16 +03:00
eb21b282d8 wiki(ingest): concepts/yarn-npm-minimal-age-gate — YN0016 на свежих версиях
Yarn >=4.16 npmMinimalAgeGate (default 1d) карантинит версии <24ч на
КЛИЕНТЕ — независимый от auth gate #2 (после 401). Серверного карантина
в verdaccio нет; первичная гипотеза опровергнута пруфом из yarn.js.
Глобальный config (per-scope не работает), fix npmMinimalAgeGate:0.
Backlink из verdaccio-token-lifecycle + index/log.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 18:21:41 +03:00
15c273c153 wiki(ingest): concepts/verdaccio-restore-packument-desync — 409 postmortem
disaster-restore вернул тарболлы но древний/пустой packument →
publish свежей версии EEXISTS 409. Fix: снять только коллизирующий
целевой .tgz (backup first), republish; НЕ rm -rf каталог.
Применено к @snollajs/{data,mailer,numbering,content-api}.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 17:10:01 +03:00
7f998d5222 wiki(ingest): concepts/verdaccio-token-lifecycle — restart trap + JWT fix
Постмортем утреннего фикса verdaccio: ephemeral secret (нет `secret:` в
конфиге) → инвалидация всех токенов при каждом рестарте; max_users:-1 +
pnpm login → 409; web-UI login как обход; JWT config fix (пинуем secret,
api.jwt 900d). Recipe рефреша для yarn classic vs berry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 16:28:31 +03:00
e2338b6fdd wiki(lint): close all 10 lint issues + delete windows-host backup task
- deleted .tasks/windows-host-fallback-backup-daily.md (MSSQL removed on decommission 2026-06-08)
- recovery-architecture-snapshot.md: marked ИСТОРИЧЕСКАЯ ЗАПИСЬ; removed 3 broken [[wiki-links]] (cms-server-port-leak-fix, cms-admin-assets-root-folder-seed, webconfig-password-xml-escape)
- snolla-recovery-vm.md: marked УДАЛЕНА 2026-06-08
- ruvds-iis-host.md: struck 2 resolved risks (imgproxy SPOF, LE renewal); cross-ref winacme
- future-resilient-architecture-goals.md: dead task link → plain text
- mssql-on-vds.md: frontmatter fix; Backup TODO section replaced with implemented block (Express COPY_ONLY, sqlcmd, bind-mount pattern)
- vds-kzntsv.md: added MSSQL row to software stack table
- log.md: update entries for lint + mssql backup implementation

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-11 08:18:19 +03:00
4fd8288e8c meta(wiki): log += ingest concepts/mcp-init-resilience 2026-06-10 10:58:10 +00:00
1eb58aa940 task(decommission): windows-recovery-host cleanup complete (C: 62->275GB)
Elevated finale ran clean: stostayer.old repointed to mssql.kzntsv.site
(orphaned snolla user fixed agent-side as sa), smoke 200; removed snolla
IIS site + C:\sites\snolla + local MSSQL. Both kept sites verified 200
(stostayer :8090 external DB, stostayer.old :8091 on VDS).

Updated entities/windows-recovery-host with post-decommission state
(old hosting sections marked historical); image-pipeline SPOF retired.
Remaining: WSL vhdx compact (~176GB, outside session).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 15:15:12 +03:00
2811b5a180 fix(iis-migration): maljarka.tandemmebel.ru 502-on-HTTPS resolved
Root cause (NOT a migration defect): MoreThenCms tenant `maljarka`
had `dbo.Sites.SettingsData = NULL` (no `httpSecure` block) -> on a
real HTTPS request SnollaMiddleware throws KeyNotFoundException ->
502. HTTP served 200 fine. DNS/TLS/IIS binding all correct.

Fix applied to shared MSSQL (mssql.kzntsv.site): UPDATE Sites set
SettingsData with httpSecure{enableHttps:true,...} + recycle snolla
pool. Verified 443->200 server-local and external via 80.64.31.36;
kupimknigi untouched. Audit: maljarka was the only NULL-settings
site with a :443 binding (of 25); rimiz degraded for another reason.

- new concept: morethencms-null-settingsdata-https-502
- entities/ruvds-iis-host: maljarka moved from Degraded -> fixed
- index.md + log.md + STATUS.md + NEXT_SESSION.md updated

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 15:15:12 +03:00
2094f90e31 wiki(nl-vds-3xui): +3 Shadowsocks inbounds for Outline-app
3 classic chacha20-ietf-poly1305 SS inbounds (ports 32031/32/33),
one ss:// key each, per-key revocable. Protocol e2e-tested OK;
RF reachability unverified (SS DPI-blocked in RF on this node).
Keys/passwords in pass nl-vds-3xui/full-env.
Also flagged undocumented VLESS:13027 inbound found in DB.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 09:34:01 +03:00
3c7ca3416b feat(iis-migration): win-acme HTTP-01 auto-renewal on RUVDS IIS
Stood up a permanent self-renewing Let's Encrypt pipeline on the RUVDS
IIS host, replacing the manual traefik acme.json -> PFX import and
closing the 2026-07-22 cert-expiry deadline (new 25-SAN cert valid to
2026-09-03, SYSTEM scheduled task renews 55 days before expiry).

Key obstacle: the MoreThenCms OWIN catch-all (owin:HandleAllRequests)
swallowed /.well-known/acme-challenge/. Solved by carving the challenge
path into a separate IIS application in a No-Managed-Code app pool, plus
patching win-acme's Web_Config.xml template to remove the inherited Owin
handler. Staging + prod validation green for all 25 hostnames; live TLS
smoke confirms the new cert is served (incl degraded maljarka/rimiz).

- scripts/iis-migration-to-ruvds/03-ruvds-winacme.ps1 (idempotent setup)
- scripts/iis-migration-to-ruvds/winacme-Web_Config.xml (patched template)
- .wiki/concepts/winacme-iis-owin-catchall-http01.md (recipe + gotchas)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 21:08:41 +03:00
5cdedb376a wiki(nl-vds-3xui): ingest session 2026-06-05 — honest final state + lessons
- new sources/nl-vds-3xui-setup-2026-06-05.md (full chronicle; HONEST outcome:
  у реальных клиентов из РФ работает только plain VLESS 32030; Reality/MTProto/
  SOCKS не поднялись)
- new concepts/proxy-debugging-test-the-real-client.md (anti-pattern: own curl/
  standalone tests passed while user's real clients failed; overclaim + bad
  MSS-clamp fix that broke things)
- rewrote entities/nl-vds-3xui.md — removed false "Reality verified/fixed" &
  "mtg works" claims; honest status table; MSS-clamp removed
- caveat added to reality-pq concept (disabling PQ != working Reality for GUI
  clients); index.md + log.md updated

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 14:36:36 +03:00
4fc7cbf688 wiki(nl-vds-3xui): new NL 3x-UI node + Reality PQ×dest root-cause
Reality 443 inbound silently fails: ML-DSA-65 (post-quantum) ClientHello
key-share X25519MLKEM768 relayed to dest www.intel.com (Akamai) -> HRR ->
borrowed-TLS handshake never completes. Plain VLESS 32030 unaffected.
Isolated via replica xray pair (matrix: intel+PQ is the only failing cell).
Fix (NOT applied, awaiting user): switch dest/SNI -> www.microsoft.com
(PQ-capable, verified) on both inbound and client profile.

- new entities/nl-vds-3xui.md
- new concepts/reality-pq-mldsa65-dest-incompatibility.md
- index.md + log.md updated
- creds saved to pass nl-vds-3xui/full-env (not in repo)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 11:26:16 +03:00
063910e265 incident(books-vds-es): true RCA — ransom-бот через открытый :9200, не оператор
Рецидив вчерашнего ES-инцидента вскрыл истинную причину. Вчерашняя
гипотеза «оператор в cutover попал на canonical» опровергнута.

Root cause: ES (stack 33) публиковал 0.0.0.0:9200 мимо traefik. Free-ES
7.10 без auth → порт открыт всему интернету. Ransom-бот сносил индексы
by-name (мимо Control #1 destructive_requires_name), оставлял read_me с
BTC-выкупом. accessLog (Control #2) пуст — бот шёл прямо в порт, не через
traefik. firewalld бесполезен (docker-publish обходит INPUT-зоны).

Fix (Control #3): убрана публикация host-порта из stack 33 (Portainer
PUT), дыра закрыта; re-restore epz/products/artmone из daily-2026-05-25.

Отдельный баг: epz-поиск падал у ОБОИХ тенантов — getTenantIdSeller(
config.get("tenant")) через node-config, а tenant не задан ни в
default.json, ни в env-маппинге (TENANT env = мёртвый груз). Добавлен
tenant в overlay default.json (slovo/bookva). products работал —
отдельный код-путь.

accessLog откатан (сторожил не ту дверь).

- wiki concept: correction-блок + секция «Рецидив 2026-05-29» + exposure-audit
- tasks: restore-es reopened+reclosed; new  harden-books-vds-exposed-ports
- NEXT_SESSION handoff

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-29 09:31:25 +03:00
48a5cf397e tasks(restore-es-indices-books-vds): closed — snapshot restore + 2 preventive controls
snapshot restore из kreknin:daily-2026-05-25 за 46 сек (epz=820604,
products=105922, artmone=2621, counts == source).

RCA: 5 индексов (включая system .tasks) удалены через ES API DELETE _all
за 1 сек на 2026-05-26 10:21 UTC — 1ч 11мин после создания bookva-es в
cutover-prep. Каноничный endpoint elasticsearch.kzntsv.site попал под
команду которая предназначалась bookva-es:9200 (internal-only, без
traefik route). Caller identity unrecoverable: ES audit = X-Pack платный,
traefik accessLog был выключен, Portainer CE без audit.

Preventive controls applied + verified:
1. ES env action.destructive_requires_name=true (stack 33) — DELETE _all
   и wildcard теперь 400 BadRequest; by-name DELETE работает (нужно для
   reindex). Pattern удаления что случился физически невозможен.
2. Traefik JSON accessLog в /letsencrypt/access.log — будущие DELETE
   оставят forensic след с IP/user/method/path.

Wiki concept: .wiki/concepts/es-destructive-delete-incident-2026-05-26.md
с recovery runbook + preventive controls + cross-refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-28 20:11:07 +03:00
11554d45ac wiki(ingest): vds-kzntsv network-stack mismatch RCA + ifupdown anti-pattern
Incident 2026-05-28 ~05:45–13:52 MSK на vds-kzntsv. ~2.5ч активного outage
+ ~5.5ч на эфемерной статике до окончательного fix хостером.

Revised RCA: наш netplan+systemd-networkd конфликтовал с provider's expected
ifupdown stack. Их start/ipadd procedure ожидает чистый ifupdown и не может
auto-recover когда networkd «держит» eth0. 8 дней работало потому что
networkd сам тянул DHCP. Когда что-то на стороне Rusonyx разорвало
DHCP-binding — auto-recovery не сработала.

Fix: systemctl mask netplan + systemd-networkd* (на running system без stop —
IP и SSH сохранились), Rusonyx ребутнул VM и положил чистый
/etc/network/interfaces.d/ifcfg-eth0 через свой start/ipadd. Netmask /18,
gw 89.253.192.1, чистый ifupdown.

Wiki:
- NEW concepts/vds-kzntsv-dhcp-outage-2026-05-28 — full RCA + recovery
  runbook (эфемерная статика + permanent-fix via ifupdown) + diagnostic
  dot-graph + revised lessons-learned + anti-pattern
- NEW sources/vds-kzntsv-incident-2026-05-28 — timeline 05:25 backup OK →
  08:43 statics → 13:52 final reset; provider's ifcfg-eth0 content; ticket
  text reference
- UPDATE entities/vds-kzntsv — mask /18, ifupdown stack, kernel cmdline
  net.ifnames=0 объясняет eth0 naming, hypervisor hw80, pass-store путь,
  Known issues §
- UPDATE concepts/rusonyx-vps-onboarding-quirks — quirk #9 переписан про
  /18 layout + canonical ifcfg, quirk #10 NEW про ifupdown vs netplan
  stack choice + bootstrap mask commands
- UPDATE index.md + log.md

Tasks:
- STATUS header: incident RESOLVED summary
- NEXT_SESSION: следующая сессия — cleanup netplan-artifacts (optional),
  registry GC (~20G pending), board-viewer-build unhealthy разбор

Memory (out-of-repo): vds-kzntsv-rusonyx-network-recovery переписан с
revised RCA — canonical bootstrap step «mask netplan/networkd» для всех
Rusonyx Ubuntu VDS.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-28 14:12:14 +03:00
22786e1865 wiki(ingest): RUVDS IIS migration + daily backup pipeline
- entities/ruvds-iis-host (NEW) — 80.64.31.36, Win Server 2025 Core,
  25 SNI HTTPS bindings, 2/24 hostnames DNS-flipped
- sources/iis-migration-to-ruvds-2026-05-23 (NEW) — chronology,
  SSH/scp pivot после home-ISP outbound 445 block
- sources/ruvds-backup-daily-kreknin-2026-05-24 (NEW) — rclone+SFTP
  SYSTEM task daily 04:30, ntfy общий канал
- concepts/traefik-acme-json-to-iis-cert-import (NEW) — PFX + SNI
  recipe
- concepts/windows-server-2025-core-bootstrap — SMB deprecate,
  HTTP middlebox warning, HTTP/2 note; backup/cert open-Qs закрыты
- entities/windows-recovery-host — partial-cutover state,
  imgproxy SPOF carve-out, tandemmebel indefinitely здесь
- overview / index / log — catalog refresh

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 23:31:14 +03:00
b7b8e27a27 tasks(books-ssh-audit-shared-vds): close 🟢 — audit clean (1 retained, 0 revoked)
SSH audit на shared VDS vds-kzntsv (89.253.255.94, hosts books Slovo +
Bookva в shared compose-стеке) перед Phase 3 cutover'ом tenant-split.

Findings:
- 1 retained key: vitya@DESKTOP-NSEF0UK (core dev, sole admin)
- 0 keys to revoke — никаких analyst / former employee / unknown keys
- 1 cosmetic cleanup: removed dead root authorized_keys entry (was
  duplicate of vitya's key, dead из-за `permitrootlogin no`)
- sshd hardening verified via `sshd -T` (effective config: root-no,
  password-no, kbd-no). **Gotcha** noted: raw grep of /etc/ssh/sshd_config
  shows defaults; sshd_config.d/ overrides делают effective. Future
  audits use `sshd -T`, not raw grep.
- fail2ban active, 2670 failed / 37 banned hist, currently 0
- last 7 days journalctl ssh: только vitya@94.19.247.14 (мой home IP)

Acceptance per spec (Фаза 3, шаг 2 tenant-split):
 authorized_keys reviewed
 Non-core keys revoked (N/A — none existed)
 Analyst keys revoked (N/A — never issued)
 Documented in .wiki/concepts/books-ssh-access.md

Ingest: .wiki/concepts/books-ssh-access.md — retained keys table +
sshd state + fail2ban + login history + add/revoke processes +
cross-refs. Logged + indexed.

STATUS.md  block → ARCHIVE.md (per-task file kept in .tasks/).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 15:59:50 +03:00
fdefe96d6f tasks(iis-migration-to-ruvds): pause после failed-robocopy + ingest SMB-default finding
Temp admin (2026-05-23 09:37-18:08) начал импл iis-migration-to-ruvds,
не закончил bootstrap, упал на UNC robocopy (exit 16) и dropped tree dirty.

Session recovery:
- secrets leak fix: `.secrets/ruvds-iis.env` → `pass show ruvds-iis/full-env`
  (etap-2 discipline restored). `.secrets/` + `*.env` + `*-log.txt` + `*-size.txt`
  added to `.gitignore` чтобы не повторилось.
- root cause зафиксирован: TCP/445 closed по дефолту на fresh Win Server 2025
  Core + SMB share не создан → UNC robocopy не работает без RUVDS bootstrap.
- new concept `windows-server-2025-core-bootstrap.md` — default-blockers
  table + transfer-методов матрица (RDP-redirect / SMB / WinRM / SFTP) +
  bootstrap-чеклист 12 шагов. Recommendation = SMB inbound с source-IP
  whitelist.
- task 🟡 paused с concrete next-step (capacity audit, transfer-method
  confirm, RUVDS bootstrap, backup source, recreate IIS sites + conn-string
  swap, pilot kupimknigi + DNS swap).
- Open question raised: source 11 sites сумма vs RUVDS 30 GB HDD — capacity
  blocker possible (snolla одна 8.66 GB).

Не push'нуто — ждёт user grant per project-discipline Rule 4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 22:07:34 +03:00
68706d0bee tasks(owncloud-vds-deploy): close 🟢 — 26 GB live + 60s timeout finding
Import complete: 25 044 objs / 26 GB. 99.97% залито rclone'ом (22.2 GB
за ~2.5 ч), оставшиеся 6 файлов (4.04 GB) — 4× .pat ~221 MB + 2× .seospider
1.55+1.7 GB — упали с 502/500 на каждом rclone PUT из-за 60-секундного
HTTP timeout в reva v2.27 datagateway (hardcoded в Go http.Client.Timeout,
не env-configurable).

Workaround: VDS-side curl PUT loopback через throwaway sftp key.
Local network 142 MB/s → 4.04 GB за 28 секунд, все PROPFIND size match.

Wiki: §Gotcha 5 в concepts/ocis-on-vds-deploy-recipe.md документирует
finding + recipe для workaround. Traefik buffering middleware пробован,
не помог (likely vulcand/oxy buffer bug на больших телах) — откатил.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-22 07:26:07 +03:00
74cf219533 wiki(concepts): ingest ocis-on-vds-deploy-recipe + entity refresh
New concept page documents the oCIS-on-VDS deploy pattern with the 4
non-obvious gotchas surfaced during owncloud-vds-deploy:

  1. UID mismatch — image ocis-user is 1000, host vitya is 1001 →
     compose `user: "1001:1001"` override (alt chown rejected as orphan-UID)
  2. PROXY_TLS=false — explicit per docs when reverse proxy terminates HTTPS
  3. PROXY_ENABLE_BASIC_AUTH=true — required for WebDAV/LibreGraph API
  4. LibreGraph POST /graph/v1.0/users — only way to create users (no CLI)

Plus decomposedfs storage layout, atomic-revert recipe, backup integration
note. Source: .tasks/owncloud-vds-deploy.md.

entities/vds-kzntsv.md updated: stack table + hostnames + file layout
include owncloud row.

index.md catalog + log.md ingest entry refreshed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-21 19:29:43 +03:00
38f1d3358a wiki(index): refresh catalog after subtree import — 6 entities, 18 concepts, 3 sources
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-21 13:52:32 +03:00
d558ccfaed chore: mark admin-infra-project-pointers done, unblock morecms-subtree-split
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-21 13:37:10 +03:00
4c35e2a925 meta(wiki): log += ingest concepts/admin-infra-project 2026-05-21 10:21:29 +00:00
34e779e002 bootstrap: admin project skeleton (CLAUDE.md, .wiki/, .tasks/) 2026-05-21 13:17:45 +03:00