fix(scriberr): serve over HTTPS via the fleet TLS caddy so the browser recorder works

The in-browser recorder calls getUserMedia, which browsers refuse on http://
origins, so it sat at "Initializing recorder...". scriberr.nh3.phasefinal.com
is now fronted by the fleet TLS caddy on nh3-dev (wildcard cert) and added to
Scriberr's ALLOWED_ORIGINS; the Homepage link points at it. The plain
http://10.251.50.54:8080 URL keeps working except for recording.
This commit is contained in:
vh
2026-10-01 13:07:18 -07:00
parent 474f78811c
commit abcf4c3166
5 changed files with 53 additions and 4 deletions
+1
View File
@@ -160,6 +160,7 @@ _As of 2026-10-01 ~0446 PT._
### Scriberr (fv-ml1 GPU 3)
- **LIVE `scriberr:local-blackwell-a353078-dropout2`:** upstream a353078 plus patch 0001 (overlap slicer) and patch 0002 (gap retry, `PARAKEET_MODEL_PATH`), carried LOCALLY ONLY (Prime 2026-10-01: no upstream). v3 stays. `scripts/scriberr-rebuild` re-applies both. → `persistent-memory.d/2026-09-30-scriberr-slicer-gap-retry-gpu3.md`
- **URL is https://scriberr.nh3.phasefinal.com since 2026-10-01** (fronted by the fleet TLS caddy on nh3-dev; Caddyfile backup `.bak-20261001-scriberr`). Prime's "can't initialize recorder" was the SecureContext rule: `getUserMedia` is refused on http://. The HTTPS name is in `ALLOWED_ORIGINS` (`playbooks/scriberr-https-origin.yaml`); http://10.251.50.54:8080 still works except for recording. ⚠ `/opt/docker/compose/scriberr` is lkraven-owned, so `deploy-stack.sh` as infra-ops FAILS there (Permission denied); upload single files with `elway --upload --sudo --owner lkraven:lkraven`.
### nh3-pve + nh3-ml1: post-visit, all live (2026-09-25/26)