Ignore ML checkpoints, trained model safetensors, stray ml/ml/ dir, and .claude/worktrees/. Clean up duplicate hive-mind-prompt entries. Add 17 design/implementation plan docs from 2026-02-20 to 2026-02-22. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
66 lines
2.2 KiB
Markdown
66 lines
2.2 KiB
Markdown
# Dev Git Server Design — Scaleway + Tailscale
|
|
|
|
**Date**: 2026-02-22
|
|
**Status**: Approved
|
|
|
|
## Goal
|
|
|
|
Replace the existing Azure `vm-fxhnt-git` VM with a Scaleway DEV1-S instance running Gitea, accessible only via Tailscale. Migrate `fxhnt.ai` DNS from Azure to Scaleway.
|
|
|
|
## Infrastructure
|
|
|
|
| Component | Value |
|
|
|-----------|-------|
|
|
| Provider | Scaleway |
|
|
| Project | foxhunt (`c293eb98-228d-427d-9b16-f0941f3f2adb`) |
|
|
| Instance | DEV1-S (2 vCPU, 2GB RAM, 20GB SSD) |
|
|
| Zone | nl-ams-1 |
|
|
| OS | Ubuntu 24.04 |
|
|
| Hostname | `vm-fxhnt-git` |
|
|
|
|
## Networking
|
|
|
|
- **Public IP**: Temporary during provisioning only (Tailscale auth + package install)
|
|
- **Tailscale**: Authenticated via auth key, hostname `vm-fxhnt-git`
|
|
- **Post-setup**: Public IP detached, all access via Tailscale only
|
|
- **Security group**: Inbound SSH allowed temporarily, then locked down
|
|
|
|
## Software Stack
|
|
|
|
- **Gitea**: Latest stable binary
|
|
- **Database**: SQLite (no external DB needed)
|
|
- **Binds to**: Tailscale interface only (`100.x.x.x:3000` HTTP, `100.x.x.x:22` SSH)
|
|
- **No reverse proxy** — Gitea serves directly
|
|
|
|
## DNS Migration
|
|
|
|
- **Domain**: `fxhnt.ai`
|
|
- **Current provider**: Azure DNS (`ns{1-4}-09.azure-dns.{com,net,org,info}`)
|
|
- **Target**: Scaleway DNS (`ns0.dom.scw.cloud`, `ns1.dom.scw.cloud`)
|
|
- **Validation**: TXT record `_scaleway-challenge.fxhnt.ai` = `dba2b386-a13d-4dd8-8cb7-f31e014471a4`
|
|
- **Status**: External domain registered, awaiting validation
|
|
|
|
## Access Patterns
|
|
|
|
| Method | URL |
|
|
|--------|-----|
|
|
| Web UI | `http://vm-fxhnt-git:3000` (Tailscale DNS) |
|
|
| Git SSH | `git@vm-fxhnt-git:foxhunt/foxhunt.git` |
|
|
| Git HTTP | `http://vm-fxhnt-git:3000/foxhunt/foxhunt.git` |
|
|
|
|
## Provisioning Flow
|
|
|
|
1. Create Scaleway security group (temporary SSH inbound)
|
|
2. Create DEV1-S instance with cloud-init user-data
|
|
3. Cloud-init: install Tailscale, authenticate, install Gitea
|
|
4. Verify Tailscale connectivity from workstation
|
|
5. SSH via Tailscale, configure Gitea (admin user, foxhunt org/repo)
|
|
6. Detach public IP
|
|
7. Switch `fxhnt.ai` nameservers to Scaleway at registrar
|
|
8. Remove old Azure `vm-fxhnt-git` from Tailscale
|
|
|
|
## Decommissioning
|
|
|
|
- Old Azure VM: remove from Tailscale, then delete in Azure
|
|
- Azure DNS zone: can be deleted after nameserver switch propagates
|