Hetzner Server — Audit & Container Setup (Plan)

# Hetzner Server — Audit & Container Setup (Plan)

> Created 2026-08-29. **Done 2026-08-29: Forgejo live on moria (jail, 12
> repos imported, git-SSH verified) AND on git.hunnius.net (Docker, 8 public
> repos); Codeberg retired (archived with redirects).** Remaining: public-
> visibility container recreate on Hetzner (script staged, needs sudo run),
> moria→hunnius push mirrors, Jenkins re-point, dev remote cut-over, Hetzner
> audit/hardening phases.

## Repository topology (UPDATED 2026-08-29 22:00)

| Repo | Canonical | Public location |
|---|---|---|
| rusty_emu, rustysar, rusty_marvin, top_drives, joplin-plugin-mcp, ac-telemetry-plugin, rusty-telemetry, racecraft | **moria Forgejo (imported)** | git.hunnius.net/jan/\<repo\> (PUBLIC) — Codeberg copies ARCHIVED with redirects |
| keyfob-station, super_marvin, super-marvin-userscripts, pentest_scripts | **moria Forgejo (imported, PRIVATE)** | none — private forever |
| rustysar sub-repos (os_abstraction, mcal, RTE, infineon_traveo) | moria bare (EMPTY stubs, 0 commits) | not imported (nothing to import) |

**Migration facts (2026-08-29):**
- Codeberg was AHEAD for rusty_emu (51 vs 47) and rusty_marvin (July 2026 vs
  Nov 2025) — hunnius + moria Forgejo hold the freshest history; the OLD
  moria bare repos for these two are stale until cut-over deletes them
- All Codeberg repos had 0 issues — nothing exported; issue architecture:
  issues live on moria canonical only
- Git URLs: moria `ssh://git@192.168.1.10:2222/jan/<repo>.git` (key auth
  verified); hunnius `https://git.hunnius.net/jan/<repo>.git`
- Tokens used today (moria, hunnius, codeberg) should be revoked once the
  push mirrors are wired

**Target architecture:**

```
dev machines --push--> moria Forgejo (canonical, jail)   [DONE: 12 repos]
                          |--push-mirror--> git.hunnius.net [8 there; mirrors pending]
Jenkins (FreeBSD) --------+-- re-point after cut-over      [pending]
Codeberg                 -- RETIRED (archived, redirects)  [DONE]
```

## Forgejo instances (both live)

| | moria (FreeBSD jail) | git.hunnius.net (Hetzner Docker) |
|---|---|---|
| URL | http://192.168.1.10:3000 (LAN) | https://git.hunnius.net (TLS, Let's Encrypt) |
| Version | forgejo 15 (pkg) | forgejo 11-rootless (image) |
| Data | zstorage/forgejo-data (12.4T pool) | /home/jan/forgejo/data (bind mount) |
| Git SSH | **:2222 verified key auth** | 127.0.0.1:2222 (HTTPS/token only from outside) |
| Repos | 12 (8 public, 4 private) | 8 public (the Codeberg set) |
| Config gotcha | real config = /usr/local/etc/forgejo/conf/app.ini (FORGEJO_CUSTOM) | env FORGEJO__section__KEY (baked into app.ini on first start) |
| Pending | — | REQUIRE_SIGNIN_VIEW still ON → run /tmp/hetzner-forgejo3.sh |

See "Forgejo on moria — Installation Record" for the full lessons list
(11 entries — config path, port privileges, jail port fallback, csh, etc.).

## Phase status

- [x] Forgejo on moria installed, verified, 12 repos imported, SSH auth OK
- [x] Forgejo on git.hunnius.net installed + TLS + admin
- [x] Codeberg → hunnius migration (8 repos, public) + archival with redirects
- [ ] **hunnius public visibility: run /tmp/hetzner-forgejo3.sh (sudo, staged)**
- [ ] moria→hunnius push mirrors (all repos; needs hunnius token stored on moria)
- [ ] Dev-machine remote cut-over (Jan, when ready)
- [ ] Jenkins re-point after cut-over
- [ ] Hetzner audit + hardening (phases below)
- [ ] Hetzner Actions runners (container-capable CI)

## Phase 1 — Audit (pending)

- [ ] System/service/security/performance/Docker audit (evidence report)
- [ ] Backups incl. /home/jan/forgejo/data and moria zstorage datasets

## Phase 2 — Harden + tune (pending)

- [ ] Firewall/SSH/fail2ban/updates per audit findings

## Phase 4 — Operate as a process-project

- [ ] Infra repo: jail configs + docker run script + vhost in git; tagged releases
- [ ] Status note linked from the Development Projects Index

## Security invariants

- Joplin MCP: never exposed — tunnel only
- No database/admin UIs on public ports; proxy + auth everywhere (forgejo web
  is public-by-design with per-repo visibility; registration closed)
- Agent credentials = SSH keys/tokens, stored nowhere in repos; revoke
  today's three tokens when mirrors are done
- Private repos: keyfob-station + super-marvin line + pentest_scripts — LAN +
  hunnius private only, never public

id: a69d84030b1742ffb63ff3248a02cb92
parent_id: cd0501fe1cc24c93bc6bc3e783fb324fd
created_time: 2026-08-29T06:33:50.147Z
updated_time: 2026-08-29T20:01:47.357Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author: 
source_url: 
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data: 
order: 1787985230147
user_created_time: 2026-08-29T06:33:50.147Z
user_updated_time: 2026-08-29T20:01:47.357Z
encryption_cipher_text: 
encryption_applied: 0
markup_language: 1
is_shared: 0
share_id: 
conflict_original_id: 
master_key_id: 
user_data: 
deleted_time: 0
is_locked: 0
extracted_resource_ids: 
type_: 1