id: 608247fa81db42a8abacd3584fbba0a1
parent_id: 
item_type: 1
item_id: 60fdddf4784c4d8cb17a733366977241
item_updated_time: 1788033672506
title_diff: "[{\"diffs\":[[1,\"Forgejo on moria — Installation Record\"]],\"start1\":0,\"start2\":0,\"length1\":0,\"length2\":38}]"
body_diff: "[{\"diffs\":[[1,\"# Forgejo on moria — Installation Record\\\n\\\n> Installed 2026-08-29 by agent + Jan (sudo). Canonical git forge per the\\\n> topology in \\\"Hetzner Server — Audit & Container Setup (Plan)\\\".\\\n> **COMPLETE + VERIFIED 2026-08-29 22:00: web, git-SSH (2222, key auth),\\\n> 12 repos imported (8 public, 4 private).**\\\n\\\n## What exists now\\\n\\\n| Item | Value |\\\n|---|---|\\\n| Host | moria (FreeBSD 14.4-RELEASE-p5), LAN 192.168.1.2 |\\\n| Jail | `forgejo` (auto JID), IP **192.168.1.10** on igb0, conf in `/etc/jail.conf.d/forgejo.conf` + master `/etc/jail.conf` with include |\\\n| Jail filesystem | `zroot/jails/forgejo` (mountpoint `/jails/forgejo`), FreeBSD 14.4 base.txz |\\\n| **Repo data** | **`zstorage/forgejo-data`** nested-mounted at `/jails/forgejo/root/var/db/forgejo` (12.4T pool) |\\\n| **REAL config** | **`/usr/local/etc/forgejo/conf/app.ini`** (= `$FORGEJO_CUSTOM/conf/app.ini`; the rc script sets FORGEJO_CUSTOM). The file at `/usr/local/etc/forgejo/app.ini` was never read — archived as `.unused` |\\\n| Forgejo | pkg **forgejo 15**, service user **git** (UID 211, nologin), logs `/var/log/forgejo` |\\\n| Web | http://192.168.1.10:3000 |\\\n| Git SSH | **port 2222**: `ssh://git@192.168.1.10:2222/jan/<repo>.git` — verified key auth (\\\"Laptop Jan\\\") |\\\n| Admin | user `jan` |\\\n| Privacy | DEFAULT_PRIVATE=true, DISABLE_REGISTRATION (now actually applied via conf/app.ini) |\\\n| Repos | 12 imported: rusty_emu, rustysar, rusty-marvin, top_drives, joplin-plugin-mcp, ac-telemetry-plugin, rusty-telemetry, racecraft (public) + keyfob-station, super_marvin, super-marvin-userscripts, pentest_scripts (private); refs verified |\\\n| Boot | jail_enable=YES, jail_list=forgejo, forgejo_enable=YES (in jail) |\\\n| Fallback | pre-migration data at `forgejo.old` — still deletable |\\\n| Hardening | devfs_ruleset=4, exec.clean, no raw sockets; ZFS dataset-per-jail |\\\n\\\n## Lessons learned (do not rediscover — this cost an evening)\\\n\\\n1. **The FreeBSD forgejo port reads `$FORGEJO_CUSTOM/conf/app.ini` =\\\n   `/usr/local/etc/forgejo/conf/app.ini`** — NOT `/usr/local/etc/forgejo/app.ini`.\\\n   The rc script exports FORGEJO_CUSTOM and runs `forgejo` without `--config`.\\\n   Editing the wrong file fails SILENTLY (forgejo never logs which file it\\\n   read; symptom: settings ignored, log shows default ROOT_URL localhost)\\\n2. **Unprivileged git user cannot bind ports <1024** → built-in SSH must use\\\n   ≥1024 (2222 here). On :22 it never starts and logs nothing obvious\\\n3. **Jail port fallback trap**: with nothing bound in the jail on :22, the\\\n   HOST's wildcard sshd answers the jail IP (FreeBSD semantics) — a\\\n   misleading OpenSSH banner masked the missing Forgejo SSH\\\n4. **Jail base sshd squatting**: a full base.txz jail runs the base rc;\\\n   disable sshd_enable in the jail (script 6) — it has no users\\\n5. `service jail start` needs a MASTER `/etc/jail.conf` with the include line\\\n6. jan's login shell is csh — always `sudo sh /tmp/x.sh`; pasting scripts\\\n   into csh mangles them\\\n7. First run without config initializes data dirs but the DB migration must\\\n   be run explicitly (`forgejo migrate` as git) after config exists\\\n8. `database is locked` = another forgejo process is mid-migration; wait and\\\n   retry the admin command\\\n9. Ownership fixes must run INSIDE the jail (host has no git user)\\\n10. Forgejo prints `generated random password is 'X'` BEFORE the DB insert —\\\n    a failed create still shows a password\\\n11. rc prestart runs `forgejo doctor check` — config errors surface there\\\n\\\n## Open items\\\n\\\n1. Dev-machine remote cut-over to `ssh://git@192.168.1.10:2222/jan/<repo>.git`\\\n   (Jan, when ready; old bare repos stay as fallback)\\\n2. Push mirrors moria → git.hunnius.net (needs a hunnius token stored on\\\n   moria; set per repo in Settings → Mirror)\\\n3. Jenkins re-point after cut-over\\\n4. Delete `forgejo.old` after confidence\\\n5. Snapshot routine: `zfs snapshot zstorage/forgejo-data@…` + jail dataset\\\n   before upgrades\\\n6. Revoke today's tokens (moria/hunnius/codeberg) once mirrors are wired\"]],\"start1\":0,\"start2\":0,\"length1\":0,\"length2\":3942}]"
metadata_diff: {"new":{"id":"60fdddf4784c4d8cb17a733366977241","parent_id":"cd0501fe1cc24c93bc6bc3e783fb324fd","latitude":"0.00000000","longitude":"0.00000000","altitude":"0.0000","author":"","source_url":"","is_todo":0,"todo_due":0,"todo_completed":0,"source":"joplin-desktop","source_application":"net.cozic.joplin-desktop","application_data":"","order":1787991895195,"markup_language":1,"is_shared":0,"share_id":"","conflict_original_id":"","master_key_id":"","deleted_time":0,"is_locked":0,"extracted_resource_ids":""},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-08-29T20:09:35.085Z
created_time: 2026-08-29T20:09:35.085Z
is_locked: 0
type_: 13