diff --git a/agent-builder/.claude/context.md b/agent-builder/.claude/context.md index a031c1a..e90c1e6 100644 --- a/agent-builder/.claude/context.md +++ b/agent-builder/.claude/context.md @@ -339,11 +339,27 @@ Build, test, and push both builder agents to production. Work as long as it take - Hermes exploration day memory added: schedule full day after id=138 deploys before adding more Hermes-dependent tasks - SSH sudo requires TTY — bridge bootstrap problem: allowlist.json is root-owned, must use manual sudo once to update it -**Next session first task:** Coolify + standalone Traefik retirement (personal_projects id=147) -- Read legacy-docker-compose/traefik/ files in boilerplates (starting point) -- Audit current coolify-proxy config on primary + server-01 -- Build standalone Traefik configs for both servers -- Swap traffic, verify all routes, retire Coolify +### 2026-06-24 Sprint Day 6 facts +- id=147 Phase 1 COMPLETE ✅ — standalone Traefik deployed as `coolify-proxy` on `coolify` network +- Config at /opt/appdata/docker/docker-compose/traefik/ (traefik.yml + docker-compose.yml + docker-compose.test.yml) +- Mount: /data/coolify/proxy/:/traefik — certs (acme.json) preserved, dynamic configs unchanged +- All 21 routes live: 17 Docker-label + 4 file-based (jenkins, n8n, sudo-bridge-server01, coolify) +- Cloudflare Tunnel routes confirmed working end-to-end (secrets-proxy /health verified) +- Architecture clarified: Cloudflare Tunnel = encrypted transport, Traefik = HTTP-only (no TLS at origin) + - Legacy setup was wrong: double TLS + port forwarding — current is correct + - fileConfig.yml not needed: TLS irrelevant (Cloudflare terminates), securityHeaders not wired up anywhere +- Vault auth pattern for Claude: AppRole creds at /opt/appdata/docker/docker-compose/vault/approle/, Vault IP 172.16.16.5:8200 (coolify network), use curlimages/curl container on coolify network +- Proxy caller key: Vault secret/data/proxy/callers → claude-code field; use via docker run + Vault login, never print +- New memory rule: feedback_secrets_via_proxy_only.md — always use secrets-proxy /shell with env_secrets, never docker exec env +- server-01 Coolify proxy has zero routes — all routing handled from primary; no standalone Traefik needed on server-01 +- Gitea repo for Traefik config: NOT YET CREATED — Phase 2 task + +**Next session first task:** id=147 Phase 2 — Coolify retirement +1. Migrate N8N env var rotation workflows from Coolify API → Vault +2. Create Gitea repo for Traefik config (boilerplates entry + repo) +3. Shut down Coolify stack on primary (coolify, coolify-realtime, coolify-redis, coolify-db) +4. Shut down Coolify stack on server-01 +5. Verify all routes still live after Coolify gone ## Update instructions Update at the end of every agent-builder session. Keep agent status, key decisions, and prereq checklist current.