Demo images / Build & push demo images (push) Failing after 2m28s
Scrubs the fleet SSH/UI password from every tracked file (22 occurrences) and removes inline credentials from the code paths that used them. Docs and trackers keep the surrounding context — these are published under docs/history/ per the open-source plan — with the literals replaced by <FLEET_PW> / <FLEET_PW_ALT> so the "two variants exist" detail survives without the values. Three of the eight files were in .planning/ and were NOT in the plan's enumerated list; the reworked audit-secrets.sh found them. Code changes: - neode-ui/test-openwrt.mjs: node URL and password come from ARCHY_NODE_URL / ARCHY_NODE_PW; the SSH target derives from the URL instead of a hardcoded tailnet IP; exits 2 when unset. - scripts/run-post-install-tests.sh: drops the built-in "testpass123!" default and adds --password-stdin; refuses to run unauthenticated instead of silently trying a known password. --phase1-only still needs no password. - .gitea/workflows/post-install-tests.yml: sshpass with an inline literal replaced by key auth (NODE_SSH_KEY secret); password comes from the NODE_UI_PASSWORD secret and is piped over stdin rather than argv, so it stays out of the node's process list and the job log. Default target IP removed. scripts/audit-secrets.sh now reports 5/5 pass, 0 fail. Note: rotation of the exposed credentials is deliberately deferred to the pre-publish gate and is NOT done by this commit — these values are still live. See Phase 0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
docs/archive — historical records
Documents here are finished history: completed session logs, handovers, point-in-time status snapshots, security audits of past versions, and design docs whose feature has since shipped. They are kept for provenance and are not maintained — nothing in this directory describes the current system.
For current state, start at:
docs/UNIFIED-TASK-TRACKER.md— what's open, priority-ordereddocs/PRODUCTION-MASTER-PLAN.md— north star and workstream narrativedocs/architecture.md— as-built system architecturedocs/ROADMAP.md— public-facing roadmap
| File | What it was | Why archived |
|---|---|---|
SESSION-1.8.0-OTA-PROGRESS.md |
Session narrative of the 1.8.0 OTA work | Superseded by the unified task tracker |
HANDOVER-2026-07-02-iso-feedback.md |
One-shot handover for the ISO feedback bug-bash | All fixes merged |
rust-orchestrator-migration.md |
Design for migrating container lifecycle from bash to Rust | Migration complete — prod_orchestrator.rs + boot_reconciler.rs are the live system |
demo-deployment-design.md |
Design for the public demo sandbox | Demo shipped; docs/demo-build-info.md is the live ops doc |
app-registry-status-2026-06-21.md |
Per-app migration snapshot from node .228 @ v1.7.99-alpha | Point-in-time snapshot; headline findings (immich legacy, meshtastic present) no longer true |
security-code-audit-2026-03.md |
March 2026 security audit of v0.1.0 (33 findings) | Historical record; top findings since remediated (Argon2id, persisted sessions, image verification) |
architecture-review.html |
Generated interactive architecture guide (2026-03) | Stale generated artifact; describes an early crate/app layout |
lora-functionality.html |
Generated LoRa/mesh guide (2026-04) | Predates X3DH/double-ratchet, Reticulum transport, and mesh AI |
INSTALL-SCREENS-DESIGN.md |
Installer screen design solicitation | Installer implemented in image-recipe/ |
three-mode-ui-design.md |
Design for the Pro/Easy/Chat three-mode UI | Fully implemented (stores/uiMode.ts, EasyHome.vue, Chat.vue, goals system) |