id: 78cd107f17bd435b86d2fe271184cb77
parent_id: cfe2a1f1db894f6f89716ae3e298b8f1
item_type: 1
item_id: a69d84030b1742ffb63ff3248a02cb92
item_updated_time: 1788000705919
title_diff: "[]"
body_diff: "[{\"diffs\":[[0,\". **\"],[-1,\"FreeBSD Forgejo: INSTALLED\"],[1,\"Done\"],[0,\" 202\"]],\"start1\":71,\"start2\":71,\"length1\":34,\"length2\":12},{\"diffs\":[[0,\"8-29\"],[1,\":\"],[0,\" \"],[-1,\"(see \\\"\"],[0,\"Forgejo \"],[-1,\"on\\\n> moria — Installation Record\\\").** Hetzner work still pending. Mission: aud\"],[1,\"live on moria (jail) AND on\\\n> git.hunnius.net (Docker); Codeberg retired (all 8 repos archived w\"],[0,\"it\"],[1,\"h\"],[0,\"\\\n> \"],[-1,\"the Hetzner machine, improve performance, set up the container platform —\\\n> **in the context of the real topology: the FreeBSD basement server\\\n> (192.168.1.2, moria) is the canonical git hub; Codeberg is a manual public\\\n> mirror for some repos.**\"],[1,\"redirects).** Remaining: public-visibility container recreate on Hetzner\\\n> (script staged, needs sudo run), moria Forgejo repo import, moria→hunnius\\\n> push mirrors, Hetzner audit/hardening phases.\"],[0,\"\\\n\\\n##\"]],\"start1\":86,\"start2\":86,\"length1\":352,\"length2\":316},{\"diffs\":[[0,\"gy (\"],[-1,\"grounded\"],[1,\"UPDATED\"],[0,\" 202\"]],\"start1\":420,\"start2\":420,\"length1\":16,\"length2\":15},{\"diffs\":[[0,\"26-08-29\"],[1,\" afternoon\"],[0,\")\\\n\\\n| Rep\"]],\"start1\":434,\"start2\":434,\"length1\":16,\"length2\":26},{\"diffs\":[[0,\"o | \"],[-1,\"origin (c\"],[1,\"C\"],[0,\"anonical\"],[-1,\")\"],[0,\" | P\"]],\"start1\":460,\"start2\":460,\"length1\":26,\"length2\":17},{\"diffs\":[[0,\" Public \"],[-1,\"mirror\"],[1,\"location\"],[0,\" |\\\n|---|\"]],\"start1\":475,\"start2\":475,\"length1\":22,\"length2\":24},{\"diffs\":[[0,\"|\\\n| \"],[-1,\"keyfob-station | FreeBSD server `~/Development/Repositories/keyfob-station.git` | **none — PRIVATE policy** (work-related; Hetzner mirror only) |\\\n| rusty_emu | FreeBSD server | Codeberg (manual dual-push) |\\\n| top_drives | FreeBSD server | Codeberg (manual dual-push) |\\\n| super-marvin (poker line) | FreeBSD server (to confirm on import) | **none — PRIVATE policy** (commercial edge; no public mirror) |\"],[1,\"rusty_emu, rustysar, rusty_marvin, top_drives, joplin-plugin-mcp, ac-telemetry-plugin, rusty-telemetry, racecraft | moria bare repos | **git.hunnius.net/jan/\\\\<repo\\\\> (PUBLIC)** — Codeberg copies ARCHIVED with redirect notes |\\\n| keyfob-station, super_marvin, super-marvin-userscripts, pentest_scripts, rustysar/{BSW,MCAL,RTE} collection | moria bare repos | none — PRIVATE (hunnius mirror once push-mirrors are set) |\\\n\\\n**Migration facts (2026-08-29):**\\\n- Codeberg was AHEAD for rusty_emu (51 vs 47 local commits) and rusty_marvin\\\n  (July 2026 vs Nov 2025) — the hunnius copies hold the freshest history;\\\n  **moria bare repos need re-sync from hunnius during the Forgejo import**\\\n- 8 repos pushed to hunnius as PUBLIC; all refs verified MATCH\\\n- Codeberg: tombstone README commit + redirect description + archived:true\\\n  for all 8 (verified via API)\\\n- Local clones: codeberg remotes removed (rusty_emu, top_drives, rusty-marvin)\\\n- Tokens used were deleted from temp; **user should revoke both tokens in the\\\n  UIs** (they exist in the chat log)\"],[0,\"\\\n\\\n**\"]],\"start1\":506,\"start2\":506,\"length1\":410,\"length2\":1048},{\"diffs\":[[0,\"push--> \"],[-1,\"FreeBSD\"],[1,\"moria\"],[0,\" Forgejo\"]],\"start1\":1597,\"start2\":1597,\"length1\":23,\"length2\":21},{\"diffs\":[[0,\"jail\"],[-1,\", native binary)  [INSTALLED\"],[1,\")      [installed, repos NOT yet imported\"],[0,\"]\\\n  \"]],\"start1\":1631,\"start2\":1631,\"length1\":36,\"length2\":49},{\"diffs\":[[0,\"--> \"],[-1,\"Codeberg (public, per-repo opt-in ONLY)\\\n                          |--push-mirror--> Hetzner Forgejo (private backup + remote access + CI)\\\nJenkins (FreeBSD) --------+-- keeps working; re-point repo URLs after migration\\\nForgejo Actions runners --+-- on Hetzner only (Linux + Docker there; FreeBSD has no Docker)\\\n```\\\n\\\n## FreeBSD corrections\\\n\\\n- No Docker on FreeBSD: container platform on Hetzner only; jails here\\\n- Joplin desktop on FreeBSD: unverified; MCP host fallback = Hetzner or Windows\\\n- Kilo CLI / Java (PD) on FreeBSD: unverified\\\n\\\n## Phase 0 — Access & agent placement\\\n\\\n- [x] FreeBSD box: agent access via SSH\"],[1,\"git.hunnius.net (Forgejo, Docker, rootless)\\\n                          |                   8 repos already there (public); private ones via mirrors\\\nJenkins (FreeBSD) --------+-- re-point after import\\\nCodeberg                 -- RETIRED (archived, redirects)   [done]\\\n```\\\n\\\n## Forgejo instances (both live)\\\n\\\n| | moria (FreeBSD jail) | git.hunnius.net (Hetzner Docker) |\\\n|---|---|---|\\\n| URL | http://192.168.1.10:3000 (LAN) | https://git.hunnius.net (TLS, Let's Encrypt) |\\\n| Version | forgejo 15 (pkg) | forgejo 11-rootless (image) |\\\n| Data | zstorage/forgejo-data (12.4T pool) | /home/jan/forgejo/data (bind mount) |\\\n| Service user | git (UID 211) | UID 1000\"],[0,\" (\"],[-1,\"p\"],[0,\"ro\"],[-1,\"ven — git pushes + full install)\\\n- [ ] Hetzner: Kilo CLI on the box; SSH keys only\\\n- [ ] Joplin access for agents: tunnel to the MCP host (decision pending)\\\n\\\n## Phase 1 — Audit\\\n\\\n- [ ] Hetzner: system/service/security/performance/Docker audit (evidence report)\\\n- [ ] FreeBSD side: partial picture from install (jails now exist, ZFS layout known);\\\n      full audit optional\\\n- [x] Repo backup gap identified — closure = Forgejo import + Hetzner mirror\\\n- [ ] Deliverable: audit report in the infra repo\\\n\\\n## Phase 2 — Harden + tune\\\n\"],[1,\"otless) |\\\n| Admin | jan | jan |\\\n| Privacy | DEFAULT_PRIVATE, registration off | DEFAULT_PRIVATE, registration off; REQUIRE_SIGNIN_VIEW **still ON — run /tmp/hetzner-forgejo3.sh** for public visibility |\\\n| Git SSH | jail :22 (LAN) | 127.0.0.1:2222 (not public — HTTPS/token only) |\\\n\\\nSee \\\"Forgejo on moria — Installation Record\\\" for FreeBSD lessons (jail.conf\\\nmaster, csh, SCRIPT_TYPE, DB-migrate recovery).\\\n\\\n## Phase status\\\n\\\n- [x] Forgejo on moria installed + verified\\\n- [x] Forgejo on git.hunnius.net installed + TLS + admin\"],[0,\"\\\n- [\"],[-1,\" ] Hetzner firewall/SSH/fail2ban/updates per audit\\\n- [ ] Repo backup closure via Forgejo import + Hetzner mirror\\\n\\\n## Phase 3 — Container platform (H\"],[1,\"x] Codeberg → hunnius migration (8 repos, public) + archival with redirects\\\n- [ ] **hunnius public visibility: run /tmp/h\"],[0,\"etzner\"],[-1,\") + F\"],[1,\"-f\"],[0,\"orgejo\"],[-1,\" (both)\\\n\"],[1,\"3.sh (sudo, staged)**\"],[0,\"\\\n- [\"],[-1,\"x] FreeBSD:\"],[1,\" ] moria\"],[0,\" For\"]],\"start1\":1718,\"start2\":1718,\"length1\":1347,\"length2\":1363},{\"diffs\":[[0,\"ejo \"],[-1,\"jail INSTALLED and verified (2026-08-29) — see install record\\\n- [ ] Repo import into Forgejo (git\"],[1,\"import (16 repos incl. hunnius-newer rusty_emu/rusty_marvin tips)\\\n- [ ] moria→hunnius\"],[0,\" push \"],[-1,\"--\"],[0,\"mirror\"],[-1,\" per\"],[1,\"s (all\"],[0,\" repo\"],[1,\"s\"],[0,\"; \"],[-1,\"old bare repos stay\\\n      as fallback until cut-over; dev-machine remotes re-pointed at\\\n      192.168.1.10; keyfob + super-marvin created PRIVATE)\\\n- [ ] Push mirrors: Codeberg opt-in (rusty_emu, top_drives); Hetzn\"],[1,\"private stay private)\\\n- [ ] Jenkins re-point after import\\\n- [ ] Hetzner audit + hardening (phases 1-2 below)\\\n- [ ] Hetzner Actions runners (container-capable CI)\\\n\\\n## Phase 1 — Audit (pending)\\\n\\\n- [ ] System/service/security/p\"],[0,\"er\"],[-1,\" \"],[0,\"for\"],[-1,\" all\\\n- [ ] Hetzner: reverse proxy + TLS, Forgejo mirror target, Actions runners\\\n- [ ] Jenkins: re-point to Forgejo URLs after import\"],[1,\"mance/Docker audit (evidence report)\\\n- [ ] Backups incl. /home/jan/forgejo/data and moria zstorage datasets\\\n\\\n## Phase 2 — Harden + tune (pending)\\\n\\\n- [ ] Firewall/SSH/fail2ban/updates per audit findings\"],[0,\"\\\n\\\n##\"]],\"start1\":3082,\"start2\":3082,\"length1\":481,\"length2\":549},{\"diffs\":[[0,\"s + \"],[-1,\"compose\"],[1,\"docker run script + vhost\"],[0,\" in \"]],\"start1\":3701,\"start2\":3701,\"length1\":15,\"length2\":33},{\"diffs\":[[0,\"erywhere\"],[1,\" (forgejo web\\\n  is public-by-design with per-repo visibility; registration closed)\"],[0,\"\\\n- Agent\"]],\"start1\":3939,\"start2\":3939,\"length1\":16,\"length2\":98},{\"diffs\":[[0,\"SSH keys\"],[1,\"/tokens\"],[0,\", stored\"]],\"start1\":4052,\"start2\":4052,\"length1\":16,\"length2\":23},{\"diffs\":[[0,\"in repos\"],[1,\"; **revoke the\\\n  two tokens used today**\"],[0,\"\\\n- Priva\"]],\"start1\":4084,\"start2\":4084,\"length1\":16,\"length2\":56},{\"diffs\":[[0,\"vin \"],[-1,\"(poker line) — LAN + private\\\n  Hetzner mirror only, never public forges; DEFAULT_PRIVATE=true (set)\"],[1,\"line + pentest_scripts — LAN +\\\n  hunnius private only, never public\"]],\"start1\":4176,\"start2\":4176,\"length1\":103,\"length2\":71}]"
metadata_diff: {"new":{},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-08-29T10:59:35.389Z
created_time: 2026-08-29T10:59:35.389Z
is_locked: 0
type_: 13