Retire CoulombCore references; correct the 16443 diagnosis
CoulombCore is being retired, so the docs stop using it as the reference host: state-hub-coulombcore examples become state-hub-railiance01, and the reuse-surface playbook no longer attributes bao.coulomb.social to it — that resolves to 92.205.62.239, which is railiance01. The openrouter lane keeps its factual note about ESO on the CoulombCore cluster, with a retirement flag for its owner. Also corrects this session's own error. The WP-0031 evidence blamed the Unauthorized on a local-port collision between k3s-api-coulombcore and k3s-api-haskelseed. That was wrong: the haskelseed tunnel is a reverse forward, where local_port is a destination rather than a listener, so they never competed. 16443 was simply CoulombCore's k3s — a different cluster whose client CA does not know that cert. The wrong reason had already gone to flex-auth, so it is corrected in the file rather than quietly dropped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
e22f9b3434
commit
661176e37a
9 changed files with 34 additions and 20 deletions
|
|
@ -225,7 +225,7 @@ actors:
|
|||
hosts:
|
||||
# Optional: documents which principals are allowed on each host.
|
||||
# Not enforced by warden; used for reference and future tooling.
|
||||
coulombcore:
|
||||
railiance01:
|
||||
allowed_principals:
|
||||
agt:
|
||||
- agt-task-bridge
|
||||
|
|
@ -271,8 +271,8 @@ Add `cert_command` to a tunnel in `~/.config/bridge/tunnels.yaml`:
|
|||
|
||||
```yaml
|
||||
tunnels:
|
||||
state-hub-coulombcore:
|
||||
host: coulombcore
|
||||
state-hub-railiance01:
|
||||
host: railiance01
|
||||
remote_port: 8001
|
||||
local_port: 8000
|
||||
ssh_user: agt-state-hub-bridge
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue