# Proposed `~/.config/bridge/tunnels.yaml` changes — CUST-WP-0067-T02 Claude could not edit this file (outside any repo; blocked by the permission classifier). Apply manually or grant the write. **Back up first:** ```bash cp ~/.config/bridge/tunnels.yaml ~/.config/bridge/tunnels.yaml.bak-$(date +%Y%m%d%H%M%S) ``` ## 1. `state-hub-primary` — health check probes the wrong thing Its `local_port: 8000` is already correct and needs no change. The health check does: ```yaml health_check: - url: http://127.0.0.1:8000/state/health + url: http://127.0.0.1:8000/state/health # correct only now that no local hub binds 8000 ``` No edit required today, but note *why* it read healthy for seven weeks: it probed the local cache, not the tunnel it opened on `[::1]:8000`. A tunnel health check that can be satisfied by a different process is not a health check. Prefer probing through the tunnel's own bind address once instance identity lands (T03). ## 2. `state-hub-mcp-railiance01` — retire (was: probes the wrong port) Superseded 2026-08-24. An MCP server now runs on central (`state-hub-mcp`, ClusterIP `10.43.110.80:8001`, CUST-WP-0067-T08), so this tunnel has nothing left depending on it — the documented `dev-hub` registration has been repointed at the ClusterIP. **Remove the entry** rather than fixing its health check, which probed `:8000` while forwarding `:8001`. ```yaml - state-hub-mcp-railiance01: # -R 18001 -> workstation:8001 ``` ## 3. Reverse relay tunnels — retire ```yaml - state-hub-railiance01: # -R 18000 -> workstation:8000 - state-hub-mcp-railiance01: # -R 18001 -> workstation:8001 ``` Both make a remote box dial back into this workstation to reach a hub. That was correct when the workstation *was* the hub. It is not: the primary runs on railiance01, so an agent there currently routes `localhost:18000 -> workstation:8000 -> jump host -> 10.43.68.154:8000` to reach a service on its own machine. Status 2026-08-24: - `state-hub-mcp-railiance01` — **safe to remove now.** Central MCP is serving and the global port map points at it. - `state-hub-railiance01` — **safe to remove as of 2026-08-25.** All 178 `AGENTS.md` files on both machines are repointed to the in-cluster address and both machines report zero stale rows. Nothing documented still points at this tunnel. On railiance01 both services are reachable in-cluster with no tunnel at all — this is where "abandon tunneling" genuinely applies. **Applied (2026-08-28):** both reverse relays are absent from the live `tunnels.yaml` and from `bridge status`. `CUST-WP-0067-T02` is done. The cache Postgres container remains until `CUST-WP-0068-T08`.