Some checks failed
ci/woodpecker/push/woodpecker Pipeline failed
Using hush from an agent needed a clone and docs/MCP.md. It now needs one
command, and the instructions are served by the deployment itself.
`go install github.com/orchard9/hush/cmd/hush-mcp@latest` is the whole
install: cmd/hush-mcp imports only the standard library, so module graph
pruning never reaches the private go-chassis dependency cmd/hushd needs.
Verified against an empty module cache and the public proxy, then create ->
reveal end to end against production with the resulting binary.
The page carries the per-client configuration for Claude Code, Codex CLI,
Gemini CLI, VS Code, Claude Desktop, Cursor and omp. Each command was run
against the installed client rather than copied from documentation, which is
how the differences on it are there at all: VS Code's wrapper key is
`servers`, not `mcpServers`; gemini defaults to project scope, not user;
Claude Code rejects `--env` immediately before the server name.
The shared browser crypto moves from base.html into templates/crypto.html,
which the two pages that encrypt parse and this one does not. An empty
`{{define}}` cannot replace a non-empty one — text/template reads an empty
body as no definition — so the shell holds the call and the partial holds the
code, and the docs page ships no script at all.
Three things this exposed, fixed here:
- The public Ingress enumerates paths, so a handler without one 404s at the
edge while working in `make dev`. The Ingress is now its own manifest:
hush.yaml pins a `:bootstrap` image that does not exist, so re-applying it
to publish a path would roll the workload onto an unpullable image.
`make deploy-ingress` applies the route alone.
- release.sh guarded HEAD against `@{upstream}`, which is the GitHub mirror
here, while Kaniko clones Gitea. A commit pushed to one and not the other
would have built the previous commit silently. It now fetches and compares
the branch that actually gets built.
- smoke.sh checks that /mcp serves the install command, so a stale rollout or
an unexecutable template fails the release instead of being found later.
Confirmed it fails: against production before this deploy it reported 404.
58 lines
1.8 KiB
YAML
58 lines
1.8 KiB
YAML
# hush's public route. Split out of hush.yaml on purpose: that file pins the
|
|
# Deployment's image to a `:bootstrap` tag that does not exist, so re-applying
|
|
# it to publish a new path would roll the workload onto an unpullable image.
|
|
# Adding a route is therefore:
|
|
#
|
|
# make deploy-ingress
|
|
#
|
|
# and it touches nothing but this object.
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: hush
|
|
namespace: projects
|
|
annotations:
|
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
|
spec:
|
|
tls:
|
|
- hosts: [hush.threesix.ai]
|
|
secretName: hush-tls
|
|
rules:
|
|
- host: hush.threesix.ai
|
|
http:
|
|
paths:
|
|
# The paths are enumerated deliberately, and `/` is Exact rather than
|
|
# Prefix. A Prefix `/` would route EVERYTHING, publishing /metrics,
|
|
# /healthz and /readyz to the internet. /metrics leaks how many
|
|
# secrets are created and when; the others are just noise. Enumerating
|
|
# instead means Traefik 404s them at the edge and there is no
|
|
# basic-auth middleware to maintain and get wrong.
|
|
#
|
|
# A handler without a path here is a 404 at the edge on a route that
|
|
# works in `make dev`. Adding one is two changes, not one.
|
|
- path: /
|
|
pathType: Exact
|
|
backend:
|
|
service:
|
|
name: hush
|
|
port: { name: http }
|
|
- path: /mcp
|
|
pathType: Exact
|
|
backend:
|
|
service:
|
|
name: hush
|
|
port: { name: http }
|
|
- path: /s/
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: hush
|
|
port: { name: http }
|
|
- path: /api/
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: hush
|
|
port: { name: http }
|