Created via the Gitea API (POST /repos/dtoro/Homelab-Docs/hooks) rather than the UI, since the existing PAT turned out to have sufficient scope. Webhook id 14: http://192.168.8.205:9831/deploy, push events, main branch filter, active. The shared secret was generated and registered with Gitea before the apps-side bootstrap ran (order reversed from the usual install.sh-first flow, since direct SSH deploy to apps is still pending operator execution — see oikos/console/deploy/README.md). Stored as secrets/oikos-console-deploy-secret.yaml (SOPS, recipient: apps only) rather than left as a local plaintext file, with explicit operator sign-off. When the apps-side install runs, skip webhook/install.sh's random-secret generation and write this exact value into /etc/oikos-console-deploy/secret instead. infrastructure/auto-deploy.md updated with the real webhook id (was "not yet registered"). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
7.0 KiB
7.0 KiB