11 KiB
STAGING-STATE.md
Live state of the Mechanical Compiler staging instance on srv-b.
| Updated | 2026-08-15, after network isolation |
| Instance | Staging / development |
| Specification | ENVIRONMENT.md revision 5 |
| Failure log | FAILURES.md |
| Method | Manual, one command group at a time |
0. How to use this file
This is the authoritative record of what is true on srv-b. Where it and
ENVIRONMENT.md disagree, this file wins for facts and the specification
is defective and must be corrected.
Completed and remaining work are in the same document deliberately. They are two halves of one boundary; separating them guarantees they drift.
Before any command: read this file, confirm the immediately relevant live state
with a read-only command, then issue one command group. If it fails, record it
in FAILURES.md before changing anything else.
Production will get its own PRODUCTION-STATE.md. The specification is shared;
the state is not.
1. Instance values
These are the srv-b bindings for the parameters in ENVIRONMENT.md.
Host
hostname srv-b / srv-b.dev.infra
platform Proxmox VE 8.4.0, Debian 12, kernel 6.8.12-9-pve
hardware HP ProLiant DL360 G7, 2 x Xeon X5650, 24 threads, 31 GiB
storage P410i, 4 x EG0146FAWHU, RAID 1+0, all SMART OK
local directory /var/lib/vz, ~70 GiB free iso,vztmpl,backup
local-lvm LVM-thin pve/data, 166.9 GiB rootdir,images
vmbr0 10.0.0.12/24 on enp3s0f0, gw 10.0.0.1 management, LAN
vmbr1 10.20.0.1/24, bridge-ports none service, portless
wg0 10.110.0.12/32, peer wg-pk.civicus.us:51820, allowed 10.110.0.0/22
resolver 75.75.75.75, search dev.infra
spare NICs enp3s0f1, enp4s0f0, enp4s0f1 — unconfigured, deliberately
template local:vztmpl/debian-12-standard_12.12-1_amd64.tar.zst
Containers
| CT 100 | CT 101 | |
|---|---|---|
| hostname | mechcomp |
mcproxy |
| role | application, worker | reverse proxy, TLS |
| features | nesting=1,keyctl=1 |
nesting=1 |
| cores / RAM / swap | 16 / 16384 / 4096 | 2 / 1024 / 512 |
| rootfs | 40 GiB local-lvm |
8 GiB local-lvm |
mp0 |
60 GiB → /var/lib/mechcomp, backup=0 |
— |
net0 |
eth0 on vmbr1, 10.20.0.10/24, gw 10.20.0.1 |
eth0 on vmbr1, 10.20.0.11/24, gw 10.20.0.1 |
| Debian | 12.15 | 12.15 |
Neither container has a LAN interface. See F-017.
Names and identity
mechanical-compiler.dev.infra -> 10.20.0.11 (CT 101, the proxy)
mechcomp.dev.infra -> 10.20.0.10 PVE-generated
mcproxy.dev.infra -> 10.20.0.11 PVE-generated
ADMIN_USER sandor
uid 1000, groups sandor + mechcomp(996)
shell /bin/bash, both containers
authorized key SHA256:2pNffCscUUW5Wbs9uMepLEvMLKPqUV/7Lpk5tw7iWSY
root@srv-b — bastion pattern, see §4
service user mechcomp, uid 999, gid 996
home /var/www/mechcomp, shell /usr/sbin/nologin
Host NAT, as persisted in /etc/iptables/rules.v4
nat POSTROUTING
-s 10.20.0.0/24 -d 10.0.0.0/24 -j RETURN # LAN not translated
-s 10.0.0.0/24 -o wg0 -j MASQUERADE # pre-existing
-s 10.20.0.0/24 -o wg0 -j MASQUERADE # containers -> WireGuard
-s 10.20.0.0/24 -o vmbr0 -j MASQUERADE # containers -> internet
filter FORWARD
-s 10.20.0.0/24 -d 10.20.0.0/24 -j ACCEPT # container <-> container
-s 10.20.0.0/24 -d 10.0.0.0/24 -j DROP # LAN blocked
Rule order is load-bearing. RETURN must precede both masquerades.
TLS
CA CN = Mechanical Compiler Staging CA (locally generated)
leaf CN = mechanical-compiler.dev.infra
SAN = DNS:mechanical-compiler.dev.infra
validity 2026-08-16 -> 2028-11-18 <-- expires, nothing renews it
trusted srv-b, CT 100, CT 101
key mode 0600 on CT 101
No Kane County Civic Infrastructure CA issuance path exists on srv-b: no
trust anchor, no step, no cfssl, no EasyRSA. Proxmox's own CA was
deliberately not reused. Replacing this leaf later is two file copies and a
reload.
Application environment
/etc/mechcomp/mechcomp.env, root:mechcomp, 0640:
MECHCOMP_ENV=staging
MECHCOMP_BIND=10.20.0.10
MECHCOMP_PORT=8770
MECHCOMP_BASE_URL=https://mechanical-compiler.dev.infra
MECHCOMP_DATA_DIR=/var/lib/mechcomp
MECHCOMP_LOG_LEVEL=info
MECHCOMP_DB_URL=sqlite:////var/lib/mechcomp/db/mechcomp.sqlite3
MECHCOMP_WORKER_CONCURRENCY=4
MECHCOMP_CAD_BACKEND=none
MECHCOMP_ARTIFACT_RETENTION_DAYS=30
MECHCOMP_SECRET_KEY=<generated, not recorded>
Rollback copies on disk
srv-b /etc/network/interfaces.before-mechcomp
/etc/hosts.before-mechcomp
/etc/hosts.before-svcfqdn
/etc/iptables/rules.v4.before-svcnat
/etc/iptables/rules.v4.before-lanblock
/root/pct-100.before-svcnet
/root/pct-101.before-svcnet
CT 100 /etc/hosts.before-svcfqdn
CT 101 /etc/hosts.before-svcfqdn
2. Verified
Each line was demonstrated by command output, not inferred.
Host and network
vmbr1created, active,10.20.0.1/24, portless- Duplicate address detection run before each container creation
- Container → internet reachable (
deb.debian.org,gitea.barternetwork.us, both 200) - Container → WireGuard network reachable (
10.110.0.12) - Container → LAN unreachable — the isolation requirement
- Container →
srv-breachable at10.0.0.12(INPUT path, required) - Container ↔ container reachable over
vmbr1 - LAN → Proxmox console unaffected (
10.0.0.12:8006→ 200) - Network configuration persisted, survives reboot
CT 100
- Debian 12.15, systemd running, zero failed units, no pending upgrades
en_US.UTF-8generated and active/var/lib/mechcompis a real separate ext4 filesystem- Service user
mechcomp, home/var/www/mechcomp, writable - Application directory layout created with correct ownership
- Base packages installed; OpenSCAD / Qt / X11 absent — verified
clean - Docker working,
overlay2/systemd, nofuse-overlayfsneeded - Repository cloned at
e85c4f4e, verified as the owning user - Python 3.11.2 venv created, owned by
mechcomp mechcomp.envwritten with generated secretopenssh-serverinstalled, enabled, active- Application listener bound to service network only — LAN-side bind refused
CT 101
- Debian 12.15, systemd running, zero failed units after
nesting=1 en_US.UTF-8generated and active- nginx 1.22.1 installed,
nginx -tpasses - Debian
defaultsite removed; only the project vhost is enabled - Local CA created, leaf issued, trusted on all three hosts
- HTTP → HTTPS redirect, TLS termination, proxy to
10.20.0.10:8770 openssh-serverinstalled, enabled, activeX-Forwarded-Proto: httpsobserved at the backend — needs re-proof, see §3
3. Remaining — infrastructure
In dependency order. Application-dependent work is in §5.
Immediate
mechcomp-placeholder.service— recreate the backend as a supervised unit. It died on the F-017 reboot and nothing currently listens on 8770. Everything below that touches the proxy depends on this. See F-019.- Re-prove
X-Forwarded-Protoend to end. The earlier proof was taken when clients were on10.0.0.x; header values will now read10.20.0.x. Re-establish rather than assume it survived the topology change. default_serveron the CT 101 vhost, bothlisten 443lines. Two words. Prevents catch-all behaviour depending on file ordering once a second server block exists. See F-012.
Mail — blocks alerting
- Postfix relay. Currently
inet_interfaces = loopback-only,relayhostempty, noroot:alias. Alerts go to a mailbox nobody opens. root:alias to a real destination.- Needs: address of the
wg-pkrelay, and whether it accepts unauthenticated from10.110.0.12. Open question for CIVICVS.
Monitoring and backup
smartdon/dev/sda -d cciss,0throughcciss,3. Depends on mail.vzdumpjob — both containers,local, snapshot, zstd, 02:30.mp0already carriesbackup=0.- First
vzdumprun — report the archive size. Retention is a placeholderkeep-last=3until this number exists. - Free-space guard — refuse and alert below 20 GiB on
/var/lib/vz. /var/lib/vz/mechcomp-app/and the host-side pull script.mechcomp-backup --stdoutin CT 100. Structure can be built and tested against the current data directories without application output.
Gold media
- 32 GB USB stick: LUKS2, ext4, label
MC-GOLD-01,/mnt/goldnoauto. gold-archive.shwithSHA256SUMSverification before unmount.- Open: where the 3+ TB USB disk is attached now that
annalesis out of scope. Until known, stick-to-disk copying is a manual step.
4. Access model
Confirmed by CIVICVS: no workstation access from the home LAN is required.
internet -> WireGuard -> srv-b -> containers
srv-b is the bastion. The authorized key is root@srv-b, which is
consistent: root on the host can pct enter regardless, so SSH to the
containers adds no privilege. It does mean every path to a container runs
through srv-b — deliberate, not a limitation.
If direct WireGuard-side access to the catalogue is wanted later, that is a
route addition for 10.20.0.0/24 on the hub. Not now.
No DHCP anywhere. Two containers with fixed addresses on a portless bridge is the entire address space; a DHCP server would add a daemon, a lease database and a failure mode in exchange for nothing.
5. Blocked on application code
None of this can be honestly completed while the repository is LICENSE and
README.md. It is not provisioning work and should not be attempted as such.
requirements-base.txt/requirements-cad.txtand dependency installmechcomp.serviceandmechcomp-worker.service- Reference toolchain image
mechcomp/reference-toolchain:8.0.0 - Fixture reproduction against
ddd0f154… - Application-runtime acceptance
- Replacing the placeholder with the real service
The Shapely port is the architect's work item and gates all of the above.
6. Open questions
| # | Question | Blocks |
|---|---|---|
| 1 | wg-pk relay address; unauthenticated from 10.110.0.12? |
mail, smartd, backup alerts |
| 2 | Where is the 3+ TB USB disk attached? | gold redundancy step |
| 3 | First vzdump archive size |
final retention value |
Question 3 is answered by doing. Questions 1 and 2 need CIVICVS.
7. Closed questions
| Question | Answer |
|---|---|
| Kane County CA issuance path | None on srv-b. Local staging CA generated instead. |
openssh-server present |
Yes, both containers. |
ADMIN_USER / key |
sandor; root@srv-b key, bastion pattern. |
DHCP pool on 10.0.0.0/24 |
Not applicable. Containers are no longer on that network. |
| Docker storage driver | overlay2 / systemd. No fallback needed. |
| LAN workstation access | Not required. WireGuard through srv-b. |