diff options
| author | Monzero Build System <builds@monzero.org> | 2026-08-15 21:47:24 +0100 |
|---|---|---|
| committer | Monzero Build System <builds@monzero.org> | 2026-08-15 21:47:24 +0100 |
| commit | 0ac4c97369e60523c2bf95c3eaa7777f7703d2e8 (patch) | |
| tree | 495e0b1905d191036622b6237e0e223442bd9ea1 /docs | |
| parent | 04c61909364622016863f62567a5a87d63f1b97a (diff) | |
| download | monzero-core-0ac4c97369e60523c2bf95c3eaa7777f7703d2e8.tar.gz monzero-core-0ac4c97369e60523c2bf95c3eaa7777f7703d2e8.tar.xz monzero-core-0ac4c97369e60523c2bf95c3eaa7777f7703d2e8.zip | |
Deploy read-only Monzero source service
Diffstat (limited to 'docs')
| -rw-r--r-- | docs/MONZERO_PUBLIC_REPOSITORIES.md | 28 |
1 files changed, 22 insertions, 6 deletions
diff --git a/docs/MONZERO_PUBLIC_REPOSITORIES.md b/docs/MONZERO_PUBLIC_REPOSITORIES.md index 4cc2a5f76..296eebb1b 100644 --- a/docs/MONZERO_PUBLIC_REPOSITORIES.md +++ b/docs/MONZERO_PUBLIC_REPOSITORIES.md @@ -1,6 +1,7 @@ # Monzero public repository setup -Three Monzero-owned repositories are required before public reproducible builds: +Three Monzero-owned, read-only public repositories are deployed at +`https://code.monzero.org`: | Repository | Purpose | Initial local source | | --- | --- | --- | @@ -8,6 +9,17 @@ Three Monzero-owned repositories are required before public reproducible builds: | `monzero-gui` | Desktop GUI | `/home/pinhead/Projects/Monzero-Fork-backups/git-remotes/monzero-gui.git` | | `monzero-gitian-sigs` | Independent reproducible-build assertions and builder public keys | `/home/pinhead/Projects/Monzero-Fork-backups/git-remotes/monzero-gitian-sigs.git` | +Public clone URLs: + +- `https://code.monzero.org/monzero-core.git` +- `https://code.monzero.org/monzero-gui.git` +- `https://code.monzero.org/monzero-gitian-sigs.git` + +The VPS publishes source browsing through Cgit and cloning through Git smart +HTTP. HTTP redirects to HTTPS, certificate renewal is enabled and tested, and +HTTP write routes are deliberately absent. The repositories retain local +backup `origin` remotes and use `public` for this read-only deployment. + Do not publish these under an individual contributor's account if a Monzero organization is intended. Create the organization first, enable multifactor authentication for owners, and retain at least two organization owners. @@ -26,9 +38,14 @@ Protect `main` in all three repositories: Core release tags should be annotated and signed. Do not allow an automated workflow to possess a human builder's private Gitian signing key. -## Publishing the prepared repositories +## Publishing updates -After creating empty public repositories, replace the example URLs and push: +The public service is intentionally read-only. Commit and push to each local +backup `origin`, then deploy its bare mirror to `/srv/git` over the restricted +administrator SSH connection. Do not expose `git-receive-pack` through Nginx. + +The following is retained as the future migration pattern if the projects move +to a hosted forge with protected write access: ```bash git remote set-url origin https://HOST/MONZERO_ORG/monzero-core.git @@ -63,12 +80,11 @@ artifacts before those artifacts are marked verified. The Gitian command requires an explicit source repository: ```bash -MONZERO_GITIAN_SIGS_URL=https://HOST/MONZERO_ORG/monzero-gitian-sigs.git \ +MONZERO_GITIAN_SIGS_URL=https://code.monzero.org/monzero-gitian-sigs.git \ contrib/gitian/gitian-build.py --setup --docker \ - --url https://HOST/MONZERO_ORG/monzero-core.git BUILDER RELEASE + --url https://code.monzero.org/monzero-core.git BUILDER RELEASE ``` Asset/NFT consensus functionality remains inactive throughout repository and release setup. Its activation requires the separate review and public-testnet gates in `MONZERO_PHASE0_STABILIZATION.md`. - |
