secrets: the 12 remaining reused logins as a checklist; repo stays public (operator rulings)
gates / gates (push) Successful in 5m44s

Operator ruled 2026-10-09, after seeing the measurement:
  (a) he rotates the remaining services himself -- CC's scope stopped at the
      Felhom boundary;
  (b) felhom.eu STAYS anonymously readable for now, because making it private
      breaks the website git-sync and the installer tag fetch, which both
      clone with NO credentials (R-110).

The standing consequence of (b): no secret may ever enter this repo again,
which manifest_bearer_gate.py now enforces with no exemption. If (b) is ever
reversed, the 32 <!-- source --> comments served on /adatkezeles must be
stripped in the same change, because they are a map of the repo.

secrets.md now carries the exact checklist -- namespace / secret / key, 12
rows, RE-MEASURED after the Felhom rotation by hashing against the value git
history still serves, which also confirms the three CC rotated are absent
from it.

Two things recorded with it, both learned the hard way the same day:
  - a DATABASE password is not changed by editing the Secret. bookstack-db
    root-password is read at first init and then lives in the engine, exactly
    like umami's POSTGRES_PASSWORD did.
  - check the app can still RESTART before trusting the rotation: umami ran
    124 days at 512Mi and was OOMKilled on every restart attempt.

And the urgency, measured rather than assumed: these are not LAN-only.
nextcloud / paperless / bookstack / qbittorrent .dooplex.hu all resolve in
PUBLIC DNS to the public address and answer HTTPS with a login page. No login
was attempted; reachability is the point.
This commit is contained in:
2026-10-09 13:37:28 +02:00
parent e467785fd3
commit eba522f06e
2 changed files with 48 additions and 5 deletions
File diff suppressed because one or more lines are too long
+47 -4
View File
@@ -222,7 +222,50 @@ sudo kubectl create secret generic gitea-creds -n felhom-system \
# secretKeyRef resend-api/RESEND_API_KEY rather than inlining it (see the Resend section above).
```
**Still owed, and NOT done here** (they are outside this repo): the same password is still the admin
password in ~12 other namespaces — `nextcloud`, `paperless`, `bookstack` (a **database root**
password), `tandoor`, `calibre`, `adventurelog`, `gokapi`, `qbittorrent`, `servarr`, `homepage`.
Rotating Gitea does not touch those; each is its own login and each is still the published string.
### Still owed — the same password opens 12 more services (operator's, 2026-10-09 ruling)
Rotating Gitea does **not** touch these: each is its own login and each is still the exact string that
was published. The operator chose to do these himself; CC's scope stopped at the Felhom boundary.
**Measured 2026-10-09 after the Felhom rotation** (hash comparison against the value still served from
git history — the three CC rotated are confirmed absent from this list):
```
[ ] adventurelog-system adventurelog-admin password
[ ] bookstack-system bookstack-db root-password <-- DATABASE root, do first
[ ] calibre-system calibre-auth password
[ ] fileshare-system gokapi-app admin-password
[ ] homepage-system homepage-secrets calibreweb-pass
[ ] homepage-system homepage-secrets qbittorrent-pass
[ ] mediaserver-system qbittorrent-admin password
[ ] nextcloud-system nextcloud nextcloud-password
[ ] paperless-system paperless-admin password
[ ] servarr-system download-client-credentials qbittorrent-password
[ ] servarr-system servarr-credentials password
[ ] tandoor-system tandoor-admin password
```
**These are not LAN-only.** `nextcloud`, `paperless`, `bookstack`, `tandoor`, `calibre`,
`adventurelog`, `fileshare`, `plex`, the whole `servarr` set and `homepage` all have
`*.dooplex.hu` ingresses; spot-checked in **public DNS** — `nextcloud/paperless/bookstack/qbittorrent
.dooplex.hu` all resolve to the public address and answer HTTPS with a login page. No login was
attempted; reachability is the point.
**Two traps when rotating these**, both learned on the Felhom side the same day:
1. **A database password is not changed by editing the Secret.** `bookstack-db/root-password` is read
when the database is first initialised; afterwards it lives in the database. Change it *in the
engine* and in the Secret, then restart — exactly as `umami-config/POSTGRES_PASSWORD` had to be.
2. **Check the app can still RESTART before you trust it.** Patching a Secret does nothing until the
pod restarts, and a pod that has run for months may not come back: umami ran 124 days at
`512Mi` but was OOMKilled on every restart attempt. Rotate when you can watch it.
### Repository visibility — DECIDED 2026-10-09: stays public for now
The operator ruled that `felhom.eu` stays anonymously readable for the moment. Making it private
breaks two live paths that clone it with **no credentials**: the website git-sync in
`manifests/webpage.yaml`, and the installer fetched from the `installer-v…` tag by every new box
(R-110). Both would have to be given credentials first. The standing consequence of that ruling:
**no secret may ever enter this repo again** — which `manifest_bearer_gate.py` now enforces with no
exemption. If the decision is ever reversed, the 32 `<!-- source: … -->` comments served on
`/adatkezeles` must be stripped in the same change, because they are a map of the repo.