Commit Graph

  • abc458260c ansible: lock in docker_build_host role for the arm64 build lane (gandalf) main chrisfu 2026-06-21 15:11:08 -0700
  • 30df7d1c12 preserve: prole-specific OpenBao K8s-auth + Kong secret-bridge + phase2-3 canary runbook chrisfu 2026-06-21 14:42:27 -0700
  • 96fba3c9bb chore(gitignore): ignore .venv-ansible-winrm/ chrisfu 2026-06-12 14:25:47 -0700
  • 9b0005aa4c fix(samba_ad_dc): bind to LAN IP only so the DC stops registering junk DNS chrisfu 2026-06-10 00:43:16 -0700
  • 0ae0ac4a8a fix(samba_reverse_dns): inline reverse-zone list so it survives tag filtering chrisfu 2026-06-10 00:35:29 -0700
  • c0c43bcf6a fix(samba_dns): strip zone suffix correctly so internal A/CNAME/PTR records are created chrisfu 2026-06-10 00:32:00 -0700
  • ca8dd6a525 Add TP-Link SG2428LP switch hardening as repeatable IaC + static IP/DNS feat/sg2428lp-harden chrisfu 2026-06-10 00:20:55 -0700
  • c9591a5da2 docs(runbook): stage db.prole.org GSSAPI auth for the airgap lane chrisfu 2026-06-03 02:59:07 -0700
  • 76522eace2 chore(vault): add WinRM passwords for morgoth (chrisfu) and fairyland (minecraft) chrisfu 2026-06-02 21:28:15 -0700
  • 26790b8ced fix(pihole): use Pi-hole 6 dns.hosts for knoe.dev records chrisfu 2026-06-02 15:00:40 -0700
  • 3877cbfd38 feat(pihole): add knoe.dev GKE service records for LAN split-horizon DNS chrisfu 2026-06-02 14:39:47 -0700
  • 11ba0c6f57 feat(winrm): wire Ansible WinRM for morgoth+fairyland Windows GPU hosts chrisfu 2026-06-02 02:16:05 -0700
  • f0d3a85fbc Avoid fact gathering for Windows Ollama playbook chrisfu 2026-06-01 23:24:11 -0700
  • e5fe9dc2a1 Disable Unix become for Windows inventory hosts chrisfu 2026-06-01 23:08:40 -0700
  • 3b1014ee4d Disable sudo become for Windows Ollama playbook chrisfu 2026-06-01 23:03:49 -0700
  • 5f60ede5d7 Add Windows Ollama model configuration playbook chrisfu 2026-06-01 22:04:11 -0700
  • 5aacee46d8 feat(migrations): 001 — prole ekosystem vector schema chrisfu 2026-05-30 02:25:17 -0700
  • 23cf4a8585 fix(ekosystem): register_tenant — RETURN QUERY + smallint cast chrisfu 2026-05-30 02:18:09 -0700
  • d114801758 feat: wire ekosystem UUID system into CNPG manifests (Tasks 1, 3, 4) chrisfu 2026-05-30 00:26:48 -0700
  • 9c5c56beb5 docs(readme): Prole. banner and header chrisfu 2026-05-28 08:18:38 -0700
  • 998c1bc94d chore: gitignore infrastructure/logs; add ekosystem UUID CNPG plan chrisfu 2026-05-28 08:10:39 -0700
  • dc099b99f9 fix(knoe-auth): wire Google Workspace login for prole.org chrisfu 2026-05-28 07:11:13 -0700
  • 0e937eb9db docs(readme): document prole.org fork — identity stack, live services, SSO chrisfu 2026-05-28 06:14:53 -0700
  • 5077e1335d feat(gitea): SPNEGO Kerberos SSO for git.prole.org chrisfu 2026-05-28 05:19:59 -0700
  • b245593b0c fix(ansible): workstation install script + Makefile target for local Macs chrisfu 2026-05-27 21:15:49 -0700
  • d945d88b5d fix(ansible): workstations group vars — become_ask_pass + no pipelining chrisfu 2026-05-27 21:10:26 -0700
  • 9571f42568 fix(ansible): wire vault_password_file to repo-root .vault_pass chrisfu 2026-05-27 21:05:49 -0700
  • c1d2a91991 fix(spnego): Subject.callAs, AES keytab, and krb5.conf sync for JDK 21 chrisfu 2026-05-27 20:06:36 -0700
  • 9523045add feat(oidc): fix knoe-auth routing for Kong strip_path=false; add Flyway baseline chrisfu 2026-05-26 02:13:33 -0700
  • cf33342500 feat(prole): bootstrap knoe-auth on k3s; tenant onboarding; cluster stabilisation chrisfu 2026-05-26 00:50:37 -0700
  • 03d1c3d9e8 docs: update README and branch/plan indexes for pg-knoe-auth import (Task 1 complete) chrisfu 2026-05-23 21:54:35 -0700
  • e5cf9b1bb6 docs(branches): mark upstream-knoe-db-20260523 Task 1 complete (pg-knoe-auth imported) chrisfu 2026-05-23 21:52:15 -0700
  • 57886f9268 feat(pg-knoe-auth): import upstream PostgreSQL JWT auth extension; compile in knoe-db image chrisfu 2026-05-23 21:52:06 -0700
  • 0e822ea976 docs(branches): upstream knoe-db/20260523 review — branch doc, index, and Junie integration brief chrisfu 2026-05-23 21:44:13 -0700
  • 5babe04516 docs: update status — cfg files clean, no pending working-tree changes chrisfu 2026-05-23 21:38:25 -0700
  • 568f03ba42 fix(conf): remove MagicMock contamination from k3d.cfg and k3s.cfg chrisfu 2026-05-23 21:38:08 -0700
  • d806905b2e feat(mock_val): common_core_lib — mode-aware default config path helper chrisfu 2026-05-23 21:32:23 -0700
  • 73dce037f3 docs: reorganise briefs into docs/completed/; add conf/service/knoe.cfg chrisfu 2026-05-23 21:32:01 -0700
  • 3ada16c875 feat(infrastructure): add Pi-hole DNS flush playbook and logs dir chrisfu 2026-05-23 21:31:52 -0700
  • decb9a5ad0 feat(scripts): upstream knoe-db sync tooling and docs chrisfu 2026-05-23 21:31:48 -0700
  • 3943d1b298 feat(mock_val): add diagnostics, utilities, and misc operational scripts chrisfu 2026-05-23 21:31:40 -0700
  • 3f96f66a78 feat(mock_val): rewrite init scripts; add new service init scripts chrisfu 2026-05-23 21:31:27 -0700
  • 11064cbd5b refactor(mock_val): rename prole_* shell lib and cfg tooling to knoe_* namespace chrisfu 2026-05-23 21:31:14 -0700
  • da0fd2c545 feat(env): auto-detect gke_ kubecontext prefix as prod; status.py context helpers chrisfu 2026-05-23 21:31:07 -0700
  • ef20c8a598 fix(cfg): refuse to serialize non-string widget values into knoe.cfg chrisfu 2026-05-23 21:31:02 -0700
  • b5f17ffa72 fix(samba_dns): update vault with correct AD Administrator password chrisfu 2026-05-14 23:58:09 -0700
  • a2a82bc495 fix(samba_dns): use admin credentials instead of machine Kerberos (-P) chrisfu 2026-05-14 23:15:13 -0700
  • e014fd5b71 feat(k3s): add pg.prole.org as CNPG postgres endpoint with split-horizon DNS chrisfu 2026-05-14 22:46:46 -0700
  • f34d10908a docs(knoe-auth): use [placeholder] instead of <placeholder> in mermaid chrisfu 2026-05-11 16:31:22 -0700
  • f1450605c2 docs: knoe-auth — prole.org deployment overlay chrisfu 2026-05-11 16:19:14 -0700
  • 3f34fa8b32 fix(installer): k3s --reset path hardening (kdc deploy, no-TTY 1password, context overrides) chrisfu 2026-05-11 13:34:10 -0700
  • 6f99f95f84 kdc: verify install.sh --reset converges to a working cross-realm trust chrisfu 2026-05-11 02:33:38 -0700
  • d6586cf1d9 kdc: backport init_kdc.sh trust fixes + add reset-repeatable Junie brief chrisfu 2026-05-11 01:24:34 -0700
  • ad1ecedb5e kerberos_trust_setup: pin trust account to RC4 only (msDS-Supported... 4) chrisfu 2026-05-11 00:29:01 -0700
  • 4fe8647953 init_kdc.sh: fix realm default from PROLE.LOCAL to KNOE.LOCAL chrisfu 2026-05-10 23:37:31 -0700
  • 19d1f136de ansible: fix klist principal form in trust-setup summary print chrisfu 2026-05-10 22:37:54 -0700
  • 78eef6fbd9 ansible: hoist ldb-tools install to top of play chrisfu 2026-05-10 22:35:18 -0700
  • 4be9fbcafe ansible: idempotency check now uses underscore account name chrisfu 2026-05-10 22:32:49 -0700
  • 52ab023ae2 ansible: install ldb-tools package (provides ldbmodify) chrisfu 2026-05-10 22:20:26 -0700
  • c45671283b ansible: locate ldbmodify binary explicitly (not on sudo PATH) chrisfu 2026-05-10 22:19:38 -0700
  • 3485046dbd ansible: temp-disable Samba password complexity for trust account write chrisfu 2026-05-10 22:09:41 -0700
  • aa541af3f5 ansible: use krbtgt_KNOE.LOCAL sAMAccountName + UPN for trust account chrisfu 2026-05-10 22:02:55 -0700
  • 6740e3dcc5 ansible: guard krbtgt smoke probe against --check mode failure chrisfu 2026-05-10 21:57:51 -0700
  • 555da4acfc ansible: rewrite kerberos_trust_setup for MIT KDC trust chrisfu 2026-05-10 15:54:24 -0700
  • 227f49042c ansible: opt read-only kubectl/samba-tool tasks into --check mode chrisfu 2026-05-10 01:51:30 -0700
  • 5cece408bd ansible: switch kerberos_trust_setup to KNOE.LOCAL + vault wiring chrisfu 2026-05-10 00:26:31 -0700
  • 48def19637 fix(inventory): specify ssh key for zinfandel — non-default key name chrisfu 2026-05-09 22:42:26 -0700
  • 9020eae91e fix(ansible): remove become from Windows play — connect as admin directly chrisfu 2026-05-09 22:36:48 -0700
  • 67b483bcf2 fix(ansible): split workstation playbook into two plays for Unix vs Windows chrisfu 2026-05-09 22:33:51 -0700
  • 5cd22c53d9 feat(inventory): add all 4 workstations; add Windows SPNEGO policy support chrisfu 2026-05-09 22:21:21 -0700
  • d5f6e8f6a9 fix(gitea): set recovery password after admin promotion, not before chrisfu 2026-05-09 22:15:50 -0700
  • 5d545d238c fix(gitea): include email in admin API set-password PATCH call chrisfu 2026-05-09 22:05:29 -0700
  • 7b782afef4 chore: restore vault secrets added on myrddin chrisfu 2026-05-09 21:48:54 -0700
  • cad75996b5 fix: set recovery password unconditionally after any admin token path chrisfu 2026-05-09 21:33:15 -0700
  • 7b391ab5ed feat(onboarding): scalable Kerberos SSO onboarding — service account auth, Ansible workstation policy chrisfu 2026-05-09 20:10:32 -0700
  • acfdee1fdc fix(gitea): replace UUID placeholder email with configured address on admin promotion chrisfu 2026-05-09 19:40:54 -0700
  • 0877fe5190 fix(gitea): downgrade 1Password failures to WARN; add signin hint chrisfu 2026-05-09 19:37:00 -0700
  • cddd9c8889 fix(gitea): redirect log() calls to stderr in value-returning functions chrisfu 2026-05-09 19:34:58 -0700
  • 23e87f074c fix(gitea): include email in PATCH body; fix HTTP status parsing; add diagnostics chrisfu 2026-05-09 19:31:34 -0700
  • a2aaea8bda fix(gitea): add required scopes to API token creation (Gitea ≥1.22) chrisfu 2026-05-09 19:28:58 -0700
  • f8c948b2ab fix(gitea): read admin password from running pod's RS, add API diagnostic logs chrisfu 2026-05-09 19:27:11 -0700
  • 6de7218ec7 fix(gitea): read Helm admin credentials from Deployment env vars, not secret chrisfu 2026-05-09 19:14:21 -0700
  • 5fba20b651 fix(gitea): correct Helm admin secret name to 'gitea' (not 'gitea-gitea') chrisfu 2026-05-09 19:06:26 -0700
  • dbe249ce9f fix(gitea): REST API bootstrap path bypasses broken admin CLI; fix DB namespace resolver chrisfu 2026-05-09 18:53:55 -0700
  • abb38fc1e9 fix(cfg): pre-scan --mode before sourcing knoe_cfg.sh so k3s.cfg is loaded chrisfu 2026-05-09 18:40:04 -0700
  • 58496a31e4 feat(gitea): 1Password-backed credential management; never log plaintext passwords chrisfu 2026-05-09 14:07:47 -0700
  • abb060d614 fix(users): remove fictitious ron@prole.org email; show Kerberos identity in provisioning log chrisfu 2026-05-09 13:03:59 -0700
  • 57cd93ae00 fix(init_kdc): prevent stale k3d LOCAL_REGISTRY_INTERNAL from leaking into init_kdc.sh chrisfu 2026-05-09 12:53:57 -0700
  • 385f74b4f7 fix(init_knoe_users): replace multiline die with err+exit to fix pipe syntax error chrisfu 2026-05-09 12:33:58 -0700
  • 991c04d936 feat(init_knoe_users): 1Password fallback for KDC passwords; try prole-kdc-secrets chrisfu 2026-05-09 12:15:02 -0700
  • 2f8b88a97a fix(init_knoe_users): allow 'default' kubectl context in k3s/k8s mode chrisfu 2026-05-09 00:44:02 -0700
  • 3d92781ae6 feat(init_knoe_users): add Gitea SPNEGO keytab step; fix PROLE.LOCAL→KNOE.LOCAL chrisfu 2026-05-09 00:31:16 -0700
  • 1cc9c4e07a fix(gitea): pin image registry to docker.io, disable rootless variant chrisfu 2026-05-08 23:18:16 -0700
  • 363123ca8e fix(gitea): disable valkey-cluster; pin storageClass in Helm values chrisfu 2026-05-08 22:04:26 -0700
  • 5b30c2c5b2 fix(spnego-proxy): add statusCapture to log SPNEGO auth failures chrisfu 2026-05-08 21:43:20 -0700
  • 5cfd24cd05 fix(auth): fix gitea krb5.conf KDC hostname: knoe-auth→auth chrisfu 2026-05-08 12:18:22 -0700
  • 9fe954d30e feat(auth): KNOE.LOCAL realm; prole-kerberos-ad-dc ExternalName svc; Gitea reverse proxy auth chrisfu 2026-05-08 12:13:46 -0700
  • 063667c0b7 fix(gitea-spnego): upgrade probes tcpSocket→httpGet; halve memory limits chrisfu 2026-05-08 11:35:01 -0700
  • 83a9a44c74 refactor(gitea): replace Apache SPNEGO proxy with Go-based proxy chrisfu 2026-05-08 03:30:36 -0700
  • 2a2b16d0fa feat(gitea): add Kerberos SPNEGO proxy for git.prole.org SSO chrisfu 2026-05-08 02:53:05 -0700