Console is live: cloned to /opt/oikos-console, deploy.sh ran clean, webhook secret written to /etc/oikos-console-deploy/secret from the pre-registered SOPS secret (never printed — decrypted and piped straight into the target file in one command), both systemd units enabled and active. Verified locally (127.0.0.1:8091 -> 200) and end-to-end (https://oikos.hubris.network/ -> 302, the Authentik gate firing correctly). Found a real bug during first boot: oikos-console.service's ReadWritePaths listed /opt/homelab-context/signals and .../approvals, but neither existed yet on apps' clone — git doesn't track empty directories, and nothing had ever written a signal/approval from that host. ProtectSystem=strict + a missing ReadWritePaths target is a hard 226/NAMESPACE crash, not a graceful degradation. Fixed two ways: the unit now marks those paths optional (`-` prefix) so a fresh deploy never crash-loops on this again, and deploy.sh now mkdir -p's them explicitly so the console has real write access from the first boot, not just a non-crashing-but-broken start. This is also the first real exercise of the auto-deploy pipeline: this push should land via Gitea webhook 14 -> oikos-console-deploy.service on apps, same as homelab-mcp/secrets-issuance already work. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
1.3 KiB
1.3 KiB