From dcc1abc7ea796ddc57478c9fcc5826d83328ce64 Mon Sep 17 00:00:00 2001 From: Vuong Hoang Date: Thu, 17 Sep 2026 02:10:20 -0700 Subject: [PATCH] orientation: override the gitea NAME on the host, not each repo's remote nh3-dev was reaching gitea over the public route from every repo on the box. brokkr-smithy-dev flagged it while pushing a new repo: brokkr-smithy, sleipnir, Galdrabok and kvasir all carried git@gitea.phasefinal.com remotes, and brokkr-smithy is pushed several times a week, so the fail2ban trigger this doc already warned about was live and recurring rather than dormant. Measured before changing anything, because the plausible explanation was a split-horizon rewrite making the public name internally correct: getent hosts gitea.phasefinal.com -> 38.120.12.44 (public, ana-srv1) grep -i gitea ~/.ssh/config -> nothing ssh -G git@gitea.phasefinal.com -> hostname gitea.phasefinal.com, port 22 No rewrite, no alias, no per-repo exception. A `Host gitea.phasefinal.com` block pointing at 10.250.50.70:222 now covers every repo on the box at once, which beats rewriting N remotes: it also catches repos nobody audited and fresh clones that copy the public URL out of a README, and nothing has to be remembered next time. Verified as a route change and not just a config edit: both paths already authenticated as `vh` with the same key, and `git ls-remote origin HEAD` succeeds over the alias in brokkr-smithy and in this repo. Backup at ~/.ssh/config.bak-20260917-020929. The alias is per-host; the doc now says to check `ssh -G` rather than assume another host inherits it. --- docs/orientation.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/docs/orientation.md b/docs/orientation.md index 365794f..dbb225f 100644 --- a/docs/orientation.md +++ b/docs/orientation.md @@ -182,6 +182,23 @@ These caught us once; don't let them catch you twice. - **`:22` on `10.250.50.70` is ana-docker's HOST sshd, not gitea.** A gitea deploy key there returns `Permission denied (publickey)` — gitea's git-SSH is the container port `:222`. (HTTP/clone-over-HTTPS is `:3000`.) +- ⭐ **Override the NAME, not each repo's remote — and on `nh3-dev` this is + already done (2026-09-17).** `~/.ssh/config` there carries a + `Host gitea.phasefinal.com` block pointing at `10.250.50.70:222`, so every + repo on the box is routed internally whatever its remote URL says, including + a fresh clone that copied the public URL out of a README. Rewriting remotes + one by one fixes only the repos someone remembered to audit: brokkr-smithy, + sleipnir, Galdrabok and kvasir were all still on the public name when + brokkr-smithy-dev flagged it, and brokkr-smithy is pushed several times a + week — a recurring ban trigger, not a dormant one. + **Check before assuming a host inherits it; the alias is per-host:** + ```bash + ssh -G git@gitea.phasefinal.com | grep -E '^(hostname|port) ' # want 10.250.50.70 / 222 + ``` + ⚠ Verify both routes authenticate as the same user with the same key BEFORE + adding the alias, then prove it with a real `git ls-remote origin HEAD` — a + routing change that is only inspected, not exercised, is the classic + looks-right-and-is-broken. ### Workflow