docs: ADR 0031 — git-SSH via rootless image + built-in server (bitborg-infra#91) #40

Sammanfogat
supernaut sammanfogade 1 incheckning från docs/0031-git-ssh-builtin-rootless in i main 2026-07-18 22:49:15 +00:00
Ägare

Decision record for #91 (option A2). Move git-SSH from the rootful image's bundled OpenSSH (pasta SNATs the client IP) to the rootless image's built-in Go SSH server + systemd socket activation for :22 — the #81 source-IP-preserving pattern, now applicable because Forgejo matches activated fds by address (verified in net_unix.go).

  • Why A2 over A1: the rootful image starts OpenSSH via s6 regardless (no supported disable); the built-in server is the rootless image's model. A1 (custom image / s6 hack) is fragile.
  • Why now: no external users → the uid 2000→1000 / /data/gitea→/var/lib/gitea / userns / host-key migration is at its cheapest.
  • Phased + rehearse-first (ADR 0030): implement + local preview → restore-drill clone rehearsal (ADR 0027) proving git-SSH + real IPs + data intact → off-peak prod cutover with a backup rollback anchor + the #107 health gate.
  • Blast radius: backup dump paths, backup-drill, and podman exec -u git/GITEA_*/path refs (reconciler, web, create-user) retarget to uid 1000 / the rootless layout.

Refs #91 (implementation follows this ADR).

Decision record for #91 (option A2). Move git-SSH from the rootful image's bundled OpenSSH (pasta SNATs the client IP) to the **rootless image's built-in Go SSH server + systemd socket activation for :22** — the #81 source-IP-preserving pattern, now applicable because Forgejo matches activated fds **by address** (verified in `net_unix.go`). - **Why A2 over A1:** the rootful image starts OpenSSH via s6 regardless (no supported disable); the built-in server is the rootless image's model. A1 (custom image / s6 hack) is fragile. - **Why now:** no external users → the uid 2000→1000 / `/data/gitea`→`/var/lib/gitea` / userns / host-key migration is at its cheapest. - **Phased + rehearse-first (ADR 0030):** implement + local preview → restore-drill clone rehearsal (ADR 0027) proving git-SSH + real IPs + data intact → off-peak prod cutover with a backup rollback anchor + the #107 health gate. - **Blast radius:** backup dump paths, backup-drill, and `podman exec -u git`/`GITEA_*`/path refs (reconciler, web, create-user) retarget to uid 1000 / the rootless layout. Refs #91 (implementation follows this ADR).
supernaut lade till 1 incheckning 2026-07-18 22:44:48 +00:00
docs: ADR 0031 — git-SSH via rootless image + built-in server (gitborg-infra#91)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 13s
558ee7f169
Preserve real client IPs for git-over-SSH by moving from the rootful
image's bundled OpenSSH (pasta SNATs the source) to the rootless image's
built-in Go SSH server with systemd socket activation for :22 — the
source-IP-preserving pattern from #81, now applicable because the
built-in server matches activated fds by address (net_unix.go, verified).

Chosen (A2) over disabling openssh on the rootful image (A1, fragile —
s6 starts sshd regardless) and over accept-and-document. Acting now
because there are no external users → the uid/path/data-volume + host-key
migration is at its cheapest.

Phased + rehearse-first (ADR 0030): implement + local-preview → restore-
drill clone rehearsal (ADR 0027) → off-peak prod cutover with a backup
rollback anchor + the #107 health gate.

Refs #91.
supernaut sammanfogade incheckning a288ae1055 till main 2026-07-18 22:49:15 +00:00
supernaut tog bort grenen docs/0031-git-ssh-builtin-rootless 2026-07-18 22:49:15 +00:00
supernaut ändrade titeln från docs: ADR 0031 — git-SSH via rootless image + built-in server (gitborg-infra#91) till docs: ADR 0031 — git-SSH via rootless image + built-in server (bitborg-infra#91) 2026-08-03 09:59:21 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-docs!40
Ingen beskrivning angiven.