state: the composer is public at dev.mechcomp.kane-il.us

browser to DNS to Lets Encrypt TLS on wg-pk to the WireGuard tunnel to a DNAT on srv-b to CT 100. Proven 200 over v4 and v6, 301 from http, and real build JSON through the full chain.

No WireGuard change and no route were made. The hub peer entry for srv-b is still a slash 32, as all twenty peers are. An earlier plan widened it to carry the service network; that was abandoned once the hub convention was read. Every vhost there proxies to a 10.110.0.x tunnel address directly, so following the convention removed the only step that could have locked the operator out of srv-b.

The srv-b side is one DNAT rule in nat PREROUTING, scoped to the hub as source so the other nineteen peers cannot reach the service network through it. Added live, proven from the hub, then persisted. Rollback copy kept. POSTROUTING order verified unchanged after iptables-save rewrote the file, and mail from srv-b was confirmed delivered afterwards because it traverses the same interface.

WORK-ORDER-004 is rewritten as executed rather than as planned. Its section 0 states that the original proposed a route and a WireGuard change, that neither was done, and why. The original text stays in history at a8081e1.

Three things recorded as not settled: renewal has never been observed to succeed for this name and is first due before 2026-12-10; no acceptance criteria exist for the composer itself, only for the path to it; and the service has no authentication. Also filed an estate finding: shell.infra.civicus.us and corpusdb.infra.civicus.us publish an AAAA one hex digit off the address wg-pk holds, so both are broken for v6 preferring clients.
This commit is contained in:
2026-09-11 12:06:40 -05:00
parent 39a6b02c63
commit 1fdb11542e
2 changed files with 149 additions and 188 deletions
+52 -5
View File
@@ -4,7 +4,7 @@ Live state of the Mechanical Compiler staging instance on `srv-b`.
| | |
|---|---|
| Updated | 2026-09-11, after the composer replaced the placeholder |
| Updated | 2026-09-11, after the composer was published at `dev.mechcomp.kane-il.us` |
| Instance | Staging / development |
| Specification | `ENVIRONMENT.md` revision 5 |
| Failure log | `FAILURES.md` |
@@ -465,6 +465,49 @@ so SSH adds no privilege — but **every path to a container runs through
Direct WireGuard-side access to the catalogue would be a route addition for
`10.20.0.0/24` on the hub. Not now.
**Superseded 2026-09-11. A public path now exists, and it is not a route.**
```
browser
-> dev.mechcomp.kane-il.us A 198.58.111.109
AAAA 2600:3c00::f03c:92ff:fe42:43d7
-> nginx on wg-pk, Let's Encrypt TLS, expires 2026-12-10
-> proxy_pass http://10.110.0.12:8770 (srv-b's own tunnel address)
-> DNAT on srv-b -> 10.20.0.10:8770
-> mechcomp.service in CT 100
```
**No WireGuard change was made and no route was added.** The hub's peer entry
for `srv-b` is still `AllowedIPs = 10.110.0.12/32`, as all twenty peers are.
An earlier plan widened it to carry `10.20.0.0/24`; that was abandoned once the
hub's own convention was read. Every existing vhost there --
`witness.diagnostics.kane-il.us`, `otium.civicus.us`, `shell.infra.civicus.us`,
`corpusdb.infra.civicus.us` -- proxies to a `10.110.0.x` tunnel address
directly. Following that pattern removed the only step with a lockout risk.
The rule on `srv-b`, in `nat PREROUTING`, persisted:
```
-A PREROUTING -s 10.110.0.1/32 -d 10.110.0.12/32 -i wg0 \
-p tcp -m tcp --dport 8770 -j DNAT --to-destination 10.20.0.10:8770
```
**Scoped to source `10.110.0.1` only** -- the hub. The other nineteen tunnel
peers cannot reach the service network through it. Widening that is one field.
Rollback copy at `/etc/iptables/rules.v4.before-mechcomp-dnat`. `POSTROUTING`
order was verified unchanged after `iptables-save` rewrote the file: the
`RETURN` still precedes both masquerades.
**`curl http://10.110.0.12:8770` from `srv-b` itself fails, and that is
correct.** Locally-originated traffic traverses `OUTPUT`, not `PREROUTING`, so
it never meets the rule. Test from the hub.
Proven 2026-09-11: `https 200` over v4 and v6, `http` returning 301, real build
JSON through the full chain, and the mail path unaffected -- a test message
from `srv-b` was delivered to `theron@kane-il.us` via `wg-pk` and `mx1` after
the ruleset was rewritten.
**Reopened 2026-09-11 by `WORK-ORDER-004`.** That decision was correct while
there was no application to reach. There is one now, and the consequence of
the decision is that CIVICVS cannot see it: `mechanical-compiler.dev.infra`
@@ -508,9 +551,12 @@ provisioning:
is still a stub
- [ ] Reference toolchain image `mechcomp/reference-toolchain:8.0.0`
- [ ] Fixture reproduction against `ddd0f154...`
- [ ] Application-runtime acceptance — partial. The composer serves and is
reachable through CT 101; no acceptance criteria have been written for
it, and it is not reachable from outside (see section 6, question 4)
- [ ] Application-runtime acceptance — partial. The composer serves, is
reachable through CT 101 internally and at
`https://dev.mechcomp.kane-il.us` publicly, and no acceptance criteria
have been written for it. Certificate renewal is unattended via certbot
and **has not yet been observed to succeed** for this name; first
renewal is due before 2026-12-10.
- [x] ~~Replacing the placeholder with the real service~~ — done 2026-09-11
**Applied 2026-08-18:** `venv/` is in `.gitignore`, along with `.cache/`,
@@ -529,7 +575,8 @@ The Shapely port gates all of the above.
| 1 | Should `wg-pk` `mynetworks` narrow to explicit hosts? | F-025 estate half |
| 2 | What is the backup strategy? | all backup work |
| 3 | Where is the 3+ TB USB disk attached? | gold redundancy step |
| 4 | Public ingress for the composer at `dev.mechcomp.kane-il.us` | `WORK-ORDER-004`; anyone outside `srv-b` seeing the application at all |
| 4 | ~~Public ingress for the composer~~ | **Closed 2026-09-11.** Live at `https://dev.mechcomp.kane-il.us`; see §4 |
| 5 | `shell.infra.civicus.us` and `corpusdb.infra.civicus.us` publish AAAA `2600:3c00:e000:365::`, but `wg-pk` holds `2600:4c00:e000:365::` -- one hex digit apart. Both names are broken for v6-preferring clients. | CIVICVS, estate; not this project |
All three need CIVICVS.