docs: correct file references and the dev reachability claim #156
No reviewers
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: Jinemi/thermograph#156
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/doc-accuracy"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Audited the five
CLAUDE.mdfiles and all twenty-oneREADME.mdfiles against the tree: 334 in-repo path claims machine-checked, plus live verification against vps1/vps2 wherever a claim was testable.The one that matters is in the root file.
devwas documented as reachable on the mesh at10.10.0.2:8137. It is not —infra/docker-compose.ymlbinds the port to127.0.0.1, and the address answers from neither vps2 nor vps1 itself. Only loopback responds. Anyone following it gets a connection refused with nothing to explain it.The rest are stale paths, several dating to the reunification:
infra/deploy/twa/README.md×2frontend/.well-known/assetlinks.jsonfrontend/static/.well-known/assetlinks.jsoninfra/deploy/twa/README.mdbackend/push.py,backend/notify.pybackend/notifications/…observability/README.mdINFRA.mdinfra/deploy/forgejo/README.mddeploy/stack/READMEinfra/terraform/README.mddeploy/Caddyfiledeploy/stack/lb/CaddyfileThe assetlinks one is the sharpest: the file moved under
static/in the subtree merge, so following the README would put it where nothing serves it and Android app-link verification would fail silently.Plus three bare relative paths that resolve for a reader but not from the directory the file sits in —
units.jsis the frontend's,deploy.shis infra's,entrypoint.shis the backend's.One addition.
infra/deploy/forgejo/README.mdexplains pinninggit.thermograph.orgon mesh clients but not that the registry's bearer-token realm followsROOT_URL— so pinning the image host alone still sends the token request out the public route, where the/v2/*matcher returns 403 and docker falls back to anonymous. That surfaces asunauthorized: reqPackageAccess, indistinguishable from a bad credential. It cost an outage today.Verified true and left alone: the four-domain layout, both
.claude/runbooks, the absence of any domain-level.forgejo/directory, the pinned compose project name, theSERVICE=…/BACKEND_IMAGE_TAG=sha-<12hex>contract, prod's eight stack services, beta's five prefixed ones with nodbof its own, dev's five,PAYLOAD_VERacross five source files, and every documentedmaketarget.No behaviour changes — documentation only.
Audited the five CLAUDE.md files and all twenty-one README.md files against the tree, machine-checking every in-repo path they name and verifying the testable claims against the live hosts. The one that matters is in the root file: dev was documented as reachable on the mesh at 10.10.0.2:8137. It is not, and never was from anywhere but vps1 — infra/docker-compose.yml binds the port to 127.0.0.1, and the address answers from neither vps2 nor vps1 itself. Anyone following it gets a connection refused with nothing to explain it. The rest are stale paths, several from the reunification: * assetlinks.json moved under frontend/static/ in the subtree merge; the TWA README kept the pre-merge path in both places it names it. Following it would put the file where nothing serves it and Android app-link verification would fail silently. * push.py and notify.py now live in backend/notifications/. * INFRA.md and deploy/stack/README have never existed in this repo, in any branch. * the Caddyfile is at deploy/stack/lb/Caddyfile. * three bare relative paths that resolve for a reader but not from the directory the file sits in: units.js is the frontend's, deploy.sh is infra's, entrypoint.sh is the backend's. Also records why mesh clients must pin the ROOT_URL host and not only the image host: the registry's bearer-token realm follows ROOT_URL, so pinning git.thermograph.org alone still sends the token request out the public route, where the /v2/* matcher returns 403 and docker falls back to anonymous. That surfaces as `unauthorized: reqPackageAccess`, indistinguishable from a bad credential. Verified true and left alone: the four-domain layout, both .claude runbooks, the absence of any domain-level .forgejo directory, the pinned compose project name, the deploy contract, prod's eight stack services, beta's five prefixed ones with no db of its own, dev's five, and every documented make target.