Files
archy/docs/archive
archipelagoandClaude Opus 5 19082a44f0
Demo images / Build & push demo images (push) Failing after 2m28s
security: remove node credentials from tracked files (open-source Phase 1)
Scrubs the fleet SSH/UI password from every tracked file (22 occurrences)
and removes inline credentials from the code paths that used them.

Docs and trackers keep the surrounding context — these are published under
docs/history/ per the open-source plan — with the literals replaced by
<FLEET_PW> / <FLEET_PW_ALT> so the "two variants exist" detail survives
without the values.

Three of the eight files were in .planning/ and were NOT in the plan's
enumerated list; the reworked audit-secrets.sh found them.

Code changes:
- neode-ui/test-openwrt.mjs: node URL and password come from ARCHY_NODE_URL /
  ARCHY_NODE_PW; the SSH target derives from the URL instead of a hardcoded
  tailnet IP; exits 2 when unset.
- scripts/run-post-install-tests.sh: drops the built-in "testpass123!"
  default and adds --password-stdin; refuses to run unauthenticated instead
  of silently trying a known password. --phase1-only still needs no password.
- .gitea/workflows/post-install-tests.yml: sshpass with an inline literal
  replaced by key auth (NODE_SSH_KEY secret); password comes from the
  NODE_UI_PASSWORD secret and is piped over stdin rather than argv, so it
  stays out of the node's process list and the job log. Default target IP
  removed.

scripts/audit-secrets.sh now reports 5/5 pass, 0 fail.

Note: rotation of the exposed credentials is deliberately deferred to the
pre-publish gate and is NOT done by this commit — these values are still
live. See Phase 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 09:59:10 -04:00
..

docs/archive — historical records

Documents here are finished history: completed session logs, handovers, point-in-time status snapshots, security audits of past versions, and design docs whose feature has since shipped. They are kept for provenance and are not maintained — nothing in this directory describes the current system.

For current state, start at:

  • docs/UNIFIED-TASK-TRACKER.md — what's open, priority-ordered
  • docs/PRODUCTION-MASTER-PLAN.md — north star and workstream narrative
  • docs/architecture.md — as-built system architecture
  • docs/ROADMAP.md — public-facing roadmap
File What it was Why archived
SESSION-1.8.0-OTA-PROGRESS.md Session narrative of the 1.8.0 OTA work Superseded by the unified task tracker
HANDOVER-2026-07-02-iso-feedback.md One-shot handover for the ISO feedback bug-bash All fixes merged
rust-orchestrator-migration.md Design for migrating container lifecycle from bash to Rust Migration complete — prod_orchestrator.rs + boot_reconciler.rs are the live system
demo-deployment-design.md Design for the public demo sandbox Demo shipped; docs/demo-build-info.md is the live ops doc
app-registry-status-2026-06-21.md Per-app migration snapshot from node .228 @ v1.7.99-alpha Point-in-time snapshot; headline findings (immich legacy, meshtastic present) no longer true
security-code-audit-2026-03.md March 2026 security audit of v0.1.0 (33 findings) Historical record; top findings since remediated (Argon2id, persisted sessions, image verification)
architecture-review.html Generated interactive architecture guide (2026-03) Stale generated artifact; describes an early crate/app layout
lora-functionality.html Generated LoRa/mesh guide (2026-04) Predates X3DH/double-ratchet, Reticulum transport, and mesh AI
INSTALL-SCREENS-DESIGN.md Installer screen design solicitation Installer implemented in image-recipe/
three-mode-ui-design.md Design for the Pro/Easy/Chat three-mode UI Fully implemented (stores/uiMode.ts, EasyHome.vue, Chat.vue, goals system)