G1: Veron 1 host live behind Cloudflare Tunnel

app.windygit.com / api.windygit.com / models.windygit.com are serving over
HTTPS with ZERO inbound ports open on Grant's network.

  - tunnel 4e856c5d, 4 registered edge connections, systemd-managed and bounded
  - three proxied single-level CNAMEs (Free Universal SSL covers them; a
    two-level name would need ACM and would die in the TLS handshake)
  - services bound to 127.0.0.1 with configurable host ports — Veron 1 is
    Grant's workstation and 3000/3300 belong to other projects
  - docs/RUNBOOK-VERON.md

I-12 PROVEN IN PRODUCTION: /version reports source=baked with a sha equal to
the deployed HEAD.

Also fixed: the tunnel health probe targeted localhost from inside a container,
so it was permanently red. A check that is always red is as useless as one that
is always green — it is how a fleet canary goes 37 days dead unnoticed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Grant Whitmer
2026-08-11 14:34:18 -04:00
parent 67753497f8
commit a68261a563
5 changed files with 102 additions and 3 deletions

View File

@@ -24,6 +24,9 @@ services:
# nothing needs to be reachable from the LAN, let alone the internet (G1.6).
ports: ["127.0.0.1:${API_PORT:-8600}:8600"]
depends_on: {db: {condition: service_healthy}}
# cloudflared runs on the host, not in this network. Without this the tunnel
# probe is permanently red and stops meaning anything.
extra_hosts: ["host.docker.internal:host-gateway"]
restart: unless-stopped
gitea: