From f0a9498bfac5d576f491d6620907e47e484ef74c Mon Sep 17 00:00:00 2001 From: Ben Stull Date: Mon, 1 Jun 2026 12:21:59 -0700 Subject: [PATCH] update 0061/SESSION-0061.0-TRANSCRIPT-2026-06-01T10-28--INPROGRESS.md --- ...TRANSCRIPT-2026-06-01T10-28--INPROGRESS.md | 56 ++++++++++++------- 1 file changed, 37 insertions(+), 19 deletions(-) diff --git a/0061/SESSION-0061.0-TRANSCRIPT-2026-06-01T10-28--INPROGRESS.md b/0061/SESSION-0061.0-TRANSCRIPT-2026-06-01T10-28--INPROGRESS.md index 4fd22ed..42502e1 100644 --- a/0061/SESSION-0061.0-TRANSCRIPT-2026-06-01T10-28--INPROGRESS.md +++ b/0061/SESSION-0061.0-TRANSCRIPT-2026-06-01T10-28--INPROGRESS.md @@ -116,32 +116,50 @@ Both shell assets pass `bash -n`; the param reader round-trips wiggle-snip's tom ### Arc 3 — Dogfood step 1: GCP foundation for wiggle-snip Operator chose **full live bring-up** on a **new** billing account. Drove -`scaffold-gcp-project` for wiggle-snip: +`scaffold-gcp-project` for wiggle-snip: project `wiggle-snip` under org +`wiggleverse.org`; dedicated `wiggle-snip` profile **`--no-activate`** (verified the +active pointer stayed `benstull-infra`); **6/6 PASS** validate (gcloud-project WARN +cleared). Operator created a new billing account → linked → APIs enabled +(compute/secretmanager/iap) → ADC quota pinned to wiggle-snip. -- Created GCP project `wiggle-snip` under org `wiggleverse.org` (592336083752). -- Created the dedicated `wiggle-snip` gcloud profile **`--no-activate`**; populated - account/project/region/zone scoped by `CLOUDSDK_ACTIVE_CONFIG_NAME` only. **Verified - the active pointer stayed `benstull-infra`** — the two-layer rule held. -- Re-ran `deployment validate`: **6/6 PASS, the gcloud-project WARN cleared** — the - §4.2 gate for `provision-vm` is green. +### Arc 4 — VM + firewall + runtime (3 skill bugs found by dogfooding) -Blocked here on the operator plate (below): a **new billing account** is Console-only, -and APIs/VM can't proceed until billing links. +- Static IP `35.255.99.91`; VM `wiggle-snip-ppe` (e2-micro, debian-12, shielded) RUNNING. +- Firewall: IAP-only :22 (35.235.240.0/20), :80/:443 from Cloudflare ranges. + **Skill bug #1:** the default VPC ships `default-allow-ssh` (:22 from 0.0.0.0/0); + firewall rules union, so IAP-only wasn't structural until I deleted + default-allow-ssh + default-allow-rdp. Patched provision-vm Step 3 (3d). +- IAP SSH verified. provision-runtime installed the OS runtime (node 18.20.4, npm + 9.2.0, python 3.11.2). **Skill bug #2:** clone temp dir `${INSTALL_DIR}.clone` + under root-owned /opt couldn't be created by the service user — now root + pre-creates it user-owned. **Skill bug #3:** the Gitea host has an AAAA record + but the VM has no IPv6 route → SSH clone died "Network is unreachable"; forced + IPv4 (`AddressFamily inet` / `ssh -4` / `ssh-keyscan -4`). + +### Arc 5 — Gitea repo + the One-Name fork + +- No GITEA_TOKEN in env; org push-to-create disabled. Operator created the repo — + as `wiggleverse/wiggleverse-wiggle-snip-app` (the `--app` + convention), NOT `wiggle-snip`. **One-Name divergence (§3.3).** Operator chose: + keep deployment/project/VM = `wiggle-snip`, repoint `[app].repo` at the long + name. Logged as SPEC §3.3 friction (Wiggleverse repo convention vs + repo-name==One-Name). Pushed main + tag `v0.1.0` over SSH (as ben.stull). +- Repo is **private** (operator's choice). Added `gitea_read_secret_ref = + wiggle-snip/wiggle-snip-gitea-read-token` to the toml; re-validated (6/6); + re-imported. provision (private path) generated the VM deploy key + (`ssh-ed25519 …mYXY0 wiggle-snip-ppe-deploy`), pinned to the IPv4 fix. --- ## What lands on the operator's plate (current) -1. **New billing account** (Console-only) → give me the account ID (not a secret) so I - link it, or link it yourself: `gcloud billing projects link wiggle-snip - --billing-account=`. -2. **Gitea repo push** — export a `$GITEA_TOKEN` with org repo-create scope and either - run, or let me run, `scaffold-gitea-repos/assets/init-and-push.sh --app-dir - ~/projects/wiggleverse/wiggle-snip --repo wiggleverse/wiggle-snip` (public; no - `--private`). Pushes + tags `v0.1.0`. -3. **Cloudflare DNS** — a `$CF_API_TOKEN` + `$CF_ZONE_ID` in your env for the proxied - A record `ppe.wiggle-snip.wiggleverse.org` → the VM IP, SSL mode Full (provision - Step 6). Never pasted into the conversation. +1. **Register the VM deploy key** (read-only) on wiggleverse-wiggle-snip-app — for + the clone. +2. **Store the read token**: `gcloud secrets create wiggle-snip-gitea-read-token` + (stdin) — for flotilla's pin fetch. (NOT `flotilla secret set` — §5.1 keeps it + out of the app runtime env.) +3. **Cloudflare DNS** A `ppe.wiggle-snip.wiggleverse.org` → `35.255.99.91`, proxied, + SSL Full — before phase 8 can go green. ---