G1: Veron 1 host live behind Cloudflare Tunnel

app.windygit.com / api.windygit.com / models.windygit.com are serving over
HTTPS with ZERO inbound ports open on Grant's network.

  - tunnel 4e856c5d, 4 registered edge connections, systemd-managed and bounded
  - three proxied single-level CNAMEs (Free Universal SSL covers them; a
    two-level name would need ACM and would die in the TLS handshake)
  - services bound to 127.0.0.1 with configurable host ports — Veron 1 is
    Grant's workstation and 3000/3300 belong to other projects
  - docs/RUNBOOK-VERON.md

I-12 PROVEN IN PRODUCTION: /version reports source=baked with a sha equal to
the deployed HEAD.

Also fixed: the tunnel health probe targeted localhost from inside a container,
so it was permanently red. A check that is always red is as useless as one that
is always green — it is how a fleet canary goes 37 days dead unnoticed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Grant Whitmer
2026-08-11 14:34:18 -04:00
parent 67753497f8
commit a68261a563
5 changed files with 102 additions and 3 deletions

View File

@@ -50,6 +50,12 @@ class Settings(BaseSettings):
# ---- account-server OIDC (human identity) -----------------------------
account_server_base_url: str = "https://account.windyword.ai"
# cloudflared binds its metrics on the HOST, so from inside a container
# `localhost` is the wrong box. A health check that is permanently red is as
# useless as one that is permanently green -- it trains people to ignore the
# dashboard, which is how a 37-day-dead fleet canary goes unnoticed.
tunnel_metrics_url: str = "http://host.docker.internal:2000/metrics"
# ---- storage law (I-3, G4.4) ------------------------------------------
# Git object databases MUST live on a POSIX filesystem. A test asserts this
# path does not resolve to a network mount.

View File

@@ -122,7 +122,7 @@ class TunnelProvider(Provider):
async def probe(self) -> ProbeResult:
async with httpx.AsyncClient(timeout=_TIMEOUT) as client:
try:
r = await client.get("http://localhost:2000/metrics")
r = await client.get(self._s.tunnel_metrics_url)
except httpx.RequestError as exc:
return ProbeResult(False, f"cloudflared metrics unreachable: {exc}")
return ProbeResult(r.status_code == 200, f"cloudflared metrics -> {r.status_code}", True)