Roadmap v2 M1: stable Home sec2 HTTPS route - #64
Conversation
|
HANDOFF: CHATGPT — BLOCKED at provider account setting
Implemented in this PR: Validation:
Security boundary: only Home sec2 loopback would be exposed through one HTTPS port 443 route after the owner enables Funnel. No wildcard/custom DNS, router forwarding, AWS/cloud mutation, broad IAM/network change, OLD demo mutation, retained EC2 restart, or secret publication. Issue #11 / PR #13 remain deferred and untouched. Remaining gate: tailnet owner enables Funnel for the Home device. Then X can re-run the same PR's start/status, verify the stable public TLS/login URL across a normal Home demo process restart, stop the connector, and prove Home-local health persists. PR stays draft and unmerged until that live acceptance is recorded. |
|
Owner update for M1 closeout:
Keep the same PR #64. Determine the actual supported origin from runtime truth, resolve the same-origin restriction only if needed for the chosen canonical route, test both providers end-to-end against the real app, and leave exactly one canonical stable public route active at acceptance. |
|
Additional durable checkpoint after G merged M2 PR #66:
Finish the active dual-provider closeout mission, reconcile this PR onto current main, then post the final HANDOFF: CHATGPT. |
|
HANDOFF: CHATGPT — M1/F1 provider recheck remains BLOCKED at route ownership/configuration
Smallest unblock: owner identifies the Cloudflare named-tunnel public hostname and existing private token file/env path (values stay private), or confirms the current Tailscale |
|
Owner confirms the current Tailscale Funnel route to localhost:8888 was a manual test route created during this session and is disposable. It may be replaced by the canonical PR #64 sec2 route. Use current Home runtime truth:
Proceed with Tailscale Funnel as the canonical M1 path unless a new real blocker appears. Replace only the disposable 8888 Funnel route with the exact sec2 4311 route, then prove public /login reachability, restart persistence, public-stop, and local Home health. Preserve M2/main work and reconcile PR #64 onto current main before merge. |
c455cc8 to
aa2e140
Compare
|
Owner update — Cloudflare named tunnel is now available and should be evaluated before final M1 provider selection. Observed owner state:
M1 decision update:
Keep same PR #64 and preserve merged M2/main work. |
|
HANDOFF: CHATGPT — Roadmap v2 M1/F1 live acceptance on existing PR #64
PASS: M1 stable URL, public application smoke, restart persistence, stop/public-off and local-health proof, exact-head browser/validator, and current-main reconciliation. Ready for G review/merge; Issue #11 remains deferred and M4/M5 mutation remains unauthorized. |
|
Owner runtime report after M1 public URL acceptance:
M1 public transport acceptance remains valid; this is now an authenticated-use closeout check. |
|
HANDOFF: CHATGPT — PR #64 Home sec2 owner login closeout
|
|
Owner confirmation: authenticated browser login on the accepted public Tailscale URL now works. This closes the UI-login functional check. Do not publish any credential values or screenshots containing secrets. The separate Cloudflare named-tunnel token rotation remains a security hygiene follow-up because that token appeared in an internal tool transcript; it was not committed or posted to GitHub. |
Refs #63 and #62.
M1 result
One stable, bookmarkable NEW Home sec2 URL uses Tailscale Funnel:
https://home.tail0e0c85.ts.net/. It has no visible port and proxies only to Home loopback127.0.0.1:4311. The owner-confirmed disposable test route to an unused port was replaced. The same PR was rebased onto current main, retaining merged M2 cockpit/Harness work.Lifecycle and safety
scripts/home_demo.py public-startfirst requires the canonical exact-head Home validation, then enables only the exact sec2 route.public-statuschecks that route and local sec2 health.public-stopdisables only that route and leaves Home sec2/config2 running. Home uses existing noninteractive sudo for the exact Tailscale route change; no operator setting or app port was changed.Public
/loginand/api/configreturned HTTP 200 with TLS verification 0. A browser forced through the public IPv4 Funnel edge loaded the real login form and/api/configwith no page errors. The URL survived a normal NEW sec2 backend restart. Afterpublic-stop, public access failed while both local apps stayed HTTP 200; a subsequent validatedpublic-startrestored the same URL. The old Cloudflare quick tunnel is stopped; the separate named connector is not the canonical M1 route.Validation
43157f48ed044068bab7c6ce19049e34fb0cb17d.python3 scripts/home_demo.py validate: PASS, four aliases, eight checks, two controls.No AWS/cloud mutation, broad DNS/IAM/network change, OLD demo change, retained EC2 restart, Lightsail/vagent change, router forwarding, or secret was committed or posted to GitHub. PR remains open for G review/merge.