Secrets Manager
Search the build
-
eb703f42026-09-26 rotate-dw-admin-full.sh: client-side SCRAM-SHA-256 so plaintext never reaches Postgres (TK-11480) -
5673bb92026-09-26 rotate-dw-admin-full.sh: repair 4 reproduced defects + synthetic harness (TK-11480) -
576e5962026-09-25 auto-data-snapshot: 2026-09-25T11:52:49 (1 data files) — registry.json -
4464cbf2026-09-24 auto-data-snapshot: 2026-09-24T14:21:31 (1 data files) — registry.json -
4efb1362026-09-23 routes: register Kamatera full-monte/.env as a GEMINI_API_KEY destination (enrichment key switched off depleted account, TK-12090) -
b5cdf492026-09-23 auto-data-snapshot: 2026-09-23T12:42:16 (1 data files) — registry.json -
c7c44d92026-09-23 TK-12029: DW_SESSION_SECRET route moved to services.* with env_file destinations (bare top-level array was silently ignored by fanOut) -
474abf92026-09-23 TK-12029: route DW_SESSION_SECRET to all three local HMAC verifiers (room-setting-app, ImportNewSkufromURL, Letsbegin) -
1ebb0682026-09-23 register GEMINI_API_KEY_PATTY + GEMINI_API_KEY_POPPY — fixes unrouted leak targets for TK-11786 Gemini rotation -
0a9d8932026-09-23 auto-data-snapshot: 2026-09-23T09:31:43 (1 data files) — registry.json -
64fcb402026-09-22 auto-data-snapshot: 2026-09-22T16:42:26 (1 data files) — registry.json -
5b2b4172026-09-22 auto-data-snapshot: 2026-09-22T16:09:18 (1 data files) — registry.json -
542d9ff2026-09-22 routes: register BROWSERBASE_API_KEY + PROJECT_ID destinations (were unrouted → stale key shadowed ImportNewSkufromURL, causing fleet-wide BB 401) -
3c086712026-09-22 verify: okStatuses now requires a paired bodyMustContain body proof to certify a key -
ceab2262026-09-22 Register DW_SESSION_SECRET route -> room-setting-app/.env.local (TK-11786 auth fix wiring) -
30819c42026-09-22 auto-data-snapshot: 2026-09-22T12:49:04 (2 data files) — registry.json routes.json -
08b3e972026-09-22 auto-data-snapshot: 2026-09-22T12:15:47 (3 data files) — data/latest.json registry.json routes.json -
5ed32a42026-09-18 auto-data-snapshot: 2026-09-18T14:54:24 (1 data files) — registry.json -
368acb82026-09-17 auto-data-snapshot: 2026-09-17T11:32:24 (1 data files) — registry.json -
af8153b2026-09-17 auto-data-snapshot: 2026-09-17T09:53:49 (2 data files) — registry.json routes.json -
b0935a92026-09-16 TK-11683: document ENOENT-exclusion tradeoff (codex-check/Grok) — single-cycle self-healing vs chronic-WARN masking -
11e21a42026-09-16 TK-11683: harden transcript scanner read loop (mid-write race) — retry-read once + exclude ENOENT-vanished files from unreadable, add fail-safe negative test -
7c0d5552026-09-16 auto-data-snapshot: 2026-09-16T10:07:35 (1 data files) — registry.json -
0a2ee5b2026-09-14 TK-11745: stage collision-safe Stripe live-key routes for professional-directory rotation fan-out -
9bbbe672026-09-14 TK-11683: reversible dry-run redactor for Claude session transcripts -
07958112026-09-14 TK-11683: read-only live-secret scanner for Claude session transcripts -
49304152026-09-13 auto-data-snapshot: 2026-09-13T03:09:46 (1 data files) — routes.json -
cd4cd102026-09-13 secrets routes: add govarbitrage as GOOGLE_PLACES_API_KEY fan-out destination -
cc062c22026-09-12 TK-11502: register SHOPIFY_ADMIN_ACCESS_TOKEN as managed key (verify=Shopify Admin shop.json), stop TK-10930 drift -
bf737ca2026-09-11 auto-data-snapshot: 2026-09-11T12:47:38 (1 data files) — registry.json -
98ffa8e2026-09-11 auto-data-snapshot: 2026-09-11T08:57:34 (1 data files) — routes.json -
287df5a2026-09-08 routes: add DEEPSEEK_API_KEY with DeepSeek balance verify endpoint -
346ba842026-09-08 auto-data-snapshot: 2026-09-08T09:40:47 (1 data files) — registry.json -
25320722026-09-08 auto-data-snapshot: 2026-09-08T09:02:39 (1 data files) — registry.json -
1f370272026-09-04 auto-data-snapshot: 2026-09-04T09:09:45 (2 data files) — registry.json routes.json -
90f733b2026-09-03 auto-data-snapshot: 2026-09-03T14:29:24 (1 data files) — routes.json -
9e77f882026-09-03 auto-data-snapshot: 2026-09-03T07:56:56 (1 data files) — registry.json -
90369672026-09-03 Route Charge and Explore test webhook secret -
3990c332026-09-03 Route Charge and Explore Stripe test key -
d972b482026-09-02 add safe local credentials center -
08ddb772026-09-02 auto-data-snapshot: 2026-09-02T17:24:05 (1 data files) — verification/credentials-center-e2e.png -
17a01c92026-09-01 auto-data-snapshot: 2026-09-01T07:51:05 (1 data files) — registry.json -
1e0b9852026-08-31 auto-data-snapshot: 2026-08-31T17:38:21 (1 data files) — registry.json -
891f5562026-08-31 auto-data-snapshot: 2026-08-31T11:17:15 (1 data files) — tk11025-restore-map.json -
4df7ff62026-08-31 rotate xAI and Moonshot credential records -
8cc46a52026-08-31 Push Grok key to remote DTD panel -
1881ae92026-08-31 Route Grok key to remote DTD panel -
4bc2dfa2026-08-31 auto-data-snapshot: 2026-08-31T02:00:54 (2 data files) — remote-routes.json routes.json -
015d8a62026-08-31 auto-data-snapshot: 2026-08-31T00:07:16 (1 data files) — registry.json -
d56076d2026-08-30 auto-data-snapshot: 2026-08-30T21:32:01 (1 data files) — registry.json -
063ec712026-08-30 auto-data-snapshot: 2026-08-30T19:40:35 (1 data files) — registry.json -
82baf8b2026-08-29 register Norma reels authorization route -
cae0e8c2026-08-29 quote spaced secrets for shell consumers -
87ca9392026-08-29 auto-data-snapshot: 2026-08-29T12:47:37 (2 data files) — registry.json routes.json -
2363f172026-08-28 Sanitize verifier report fields -
f5850232026-08-28 Harden secret freshness verification failures -
76a6bf32026-08-28 Add secret freshness report command -
b712be42026-08-28 register Shopify full-access token routes -
6205d312026-08-28 auto-data-snapshot: 2026-08-28T07:45:44 (2 data files) — registry.json routes.json -
11003cd2026-08-28 auto-data-snapshot: 2026-08-28T06:30:22 (1 data files) — registry.json -
0b03b922026-08-28 auto-data-snapshot: 2026-08-28T01:33:48 (1 data files) — routes.json -
c9561cd2026-08-28 auto-data-snapshot: 2026-08-28T00:56:56 (2 data files) — registry.json routes.json -
82ca00d2026-08-26 auto-data-snapshot: 2026-08-26T08:21:31 (1 data files) — registry.json -
77e01b52026-08-19 auto-data-snapshot: 2026-08-19T11:14:55 (1 data files) — registry.json -
ea8709c2026-08-19 auto-data-snapshot: 2026-08-19T09:34:55 (1 data files) — registry.json -
141197b2026-08-14 auto-data-snapshot: 2026-08-14T13:55:45 (1 data files) — registry.json -
35d45b72026-08-12 auto-data-snapshot: 2026-08-12T17:03:39 (1 data files) — registry.json -
cc732612026-08-12 auto-data-snapshot: 2026-08-12T09:56:27 (1 data files) — registry.json -
34dcb5d2026-08-11 secrets: backup-before-overwrite guard in writeEnvFile (timestamped .bak on real change, prune last 5) — born from the ZENDESK secret incident -
1465ee82026-08-11 auto-data-snapshot: 2026-08-11T07:04:50 (1 data files) — registry.json -
bb1e5702026-08-10 auto-data-snapshot: 2026-08-10T22:20:03 (1 data files) — registry.json -
671c2d32026-08-10 auto-data-snapshot: 2026-08-10T21:49:05 (1 data files) — registry.json -
9e292952026-08-10 auto-data-snapshot: 2026-08-10T15:38:06 (1 data files) — registry.json -
05ae97c2026-08-10 auto-data-snapshot: 2026-08-10T14:35:45 (1 data files) — registry.json -
a1347652026-08-10 auto-data-snapshot: 2026-08-10T13:34:07 (1 data files) — registry.json -
0b2ec882026-08-10 auto-data-snapshot: 2026-08-10T10:58:17 (2 data files) — registry.json routes.json -
f5bf9c32026-08-10 auto-data-snapshot: 2026-08-10T10:27:30 (1 data files) — registry.json -
7de19472026-08-10 auto-data-snapshot: 2026-08-10T09:25:36 (1 data files) — registry.json -
0d61dd52026-08-09 auto-data-snapshot: 2026-08-09T09:46:33 (3 data files) — registry.json routes.json routes.json.bak.1786292832 -
3ec12572026-08-07 auto-data-snapshot: 2026-08-07T10:09:04 (1 data files) — registry.json -
94d65492026-08-06 auto-data-snapshot: 2026-08-06T15:32:11 (1 data files) — registry.json -
f2c98182026-08-06 auto-data-snapshot: 2026-08-06T14:29:57 (1 data files) — registry.json -
769e0282026-08-05 routes: fan BRAVE_SEARCH_API_KEY to rentv/.env (PR LinkedIn enrichment) -
6c6f7be2026-08-05 auto-save: 2026-08-05T14:12:38 (1 files) — registry.json -
d1886dc2026-08-05 auto-save: 2026-08-05T12:11:52 (1 files) — registry.json -
cc9dcfe2026-08-05 auto-save: 2026-08-05T08:40:35 (1 files) — registry.json -
fa122d32026-08-04 auto-save: 2026-08-04T13:03:31 (1 files) — registry.json -
98cf4a12026-08-04 auto-save: 2026-08-04T11:32:54 (1 files) — registry.json -
61fc5942026-08-04 auto-save: 2026-08-04T10:32:27 (1 files) — registry.json -
a198f882026-08-03 auto-save: 2026-08-03T12:23:59 (1 files) — registry.json -
c68e00d2026-08-03 auto-save: 2026-08-03T11:53:46 (1 files) — registry.json -
31eccc02026-08-03 auto-save: 2026-08-03T10:23:02 (2 files) — registry.json routes.json -
c560ed92026-08-02 auto-save: 2026-08-02T07:13:15 (1 files) — registry.json -
28bb6242026-07-30 secrets: DSN_REWRITE superset fix — map real dw_admin PG key names to DATABASE_URL so DB rotation rewrites the DSN (TK-10045, fixes half-fire) -
d7a86052026-07-30 auto-save: 2026-07-30T15:19:04 (1 files) — registry.json -
86c3ed32026-07-30 secrets: record rotated OPENAI_API_KEY digest in registry (session close) -
60e3fb02026-07-30 secrets: extend OPENAI_API_KEY route to holdforme/model-arena/wallco-ai/whatsmystyle/B_Version_1 (were on dead key) -
642707c2026-07-30 auto-save: 2026-07-30T08:16:08 (1 files) — registry.json -
acccd862026-07-30 auto-save: 2026-07-30T07:45:45 (1 files) — registry.json -
a6259c82026-07-30 secrets-manager: fix 2 pre-existing fan bugs (contrarian Hole 4, TK-10045) -
f9531b02026-07-29 scoping: mark skill .env as review_required (Claude-consumed, not grep-visible) + apply scoped .env to 13 code-scanned non-live projects (TK-10045) -
dda3d542026-07-29 auto-save: 2026-07-29T22:42:47 (2 files) — registry.json ROTATION-TEMPLATE.env -
a1241912026-07-29 secrets-manager scoping: fix 3 contrarian-found defects (TK-10045) -
7795cb82026-07-29 secrets-manager: least-privilege scoping (TK-10045) — derive-manifests.js + regen command + manifest-aware fanOut guard (SCOPED_FANOUT-gated) -
9c94c8a2026-07-27 auto-save: 2026-07-27T09:19:22 (2 files) — registry.json routes.json -
93096592026-07-26 auto-save: 2026-07-26T16:14:26 (1 files) — registry.json -
5907daf2026-07-23 routes: GEMINI_API_KEY_WALLCO -> model-arena (image tool fallback backend) -
6c945b42026-07-23 routes: ADOBE_CLIENT_ID/SECRET + FIGMA_TOKEN -> model-arena .env (design tools) -
6c6d1f82026-07-22 auto-save: 2026-07-22T17:45:47 (1 files) — registry.json -
4604d182026-07-22 auto-save: 2026-07-22T14:44:58 (2 files) — registry.json routes.json -
367cf902026-07-22 auto-save: 2026-07-22T13:14:23 (4 files) — dw-scroll-debug.js dw-scroll-debug2.js dw-scroll-debug3.js dw-scroll-verify.js -
2b76a662026-07-22 chore: refactor — rename GOOGLE→GOOGLE_YOUTUBE for clarity (session close, no behavior change) -
d27dd682026-07-22 auto-save: 2026-07-22T10:13:11 (2 files) — registry.json routes.json -
aaa98bd2026-07-22 Coordonné Cotswolds: activate 29 wallcoverings LIVE (ACTIVE + Online Store + New Arrival, Google excluded 0/29) per DTD verdict B; 8 murals held with Coco Dávez batch -
ffff5332026-07-22 Coordonné Cotswolds (Ybarra & Serret): create 37 settlement-OK SKUs as DRAFT on Shopify (0 channels), PG-first→Shopify, $4.25 sample + real $169/$113.62 sellable variant; 10 BLOCK held -
e908b8f2026-07-22 Coordonné Cotswolds (Coco Dávez): settlement post-gen-vision gate — 47 rows, 37 OK / 10 BLOCK (5 Royal-Oak + 5 Mallard-Duck, all Part-B bird catches; gemini-2.5-flash) -
2930b392026-07-22 Coordonné Coco Dávez: create 16 held murals @ $113.62 (DTD Option C); collection now 54/54 by real membership -
b45ce412026-07-22 auto-save: 2026-07-22T09:12:53 (5 files) — coordonne-collab-audit/coco-create-result.json _shopify_channel_fill.py coordonne-collab-audit/check-membership.js coordonne-collab-audit/coco-create-mural.json coordonne-collab-audit/create-coco-mural.js -
46149782026-07-22 Coco Dávez canary: create 38 $169 wallcoverings PG-first→Shopify, publish to Online Store; 16 murals HELD per DTD-C (pricing differs $113.62) -
bdb85102026-07-22 Coco Dávez: settlement post-gen-vision gate — 54/54 OK, 0 BLOCK (gemini-2.5-flash) -
99088962026-07-22 Coordonné: tag 11 Artisan overmatch fabrics with Artisan By Bodo Sperlein (ADD-only) -
93325432026-07-22 Coordonné Phase 1: ADD-only tag 52 Artisan + 48 CSM live DWDC products; both smart-collections populated (52/48) -
d09d3212026-07-22 auto-save: 2026-07-22T07:42:20 (1 files) — audits/ -
3d0b1df2026-07-21 auto-save: 2026-07-21T18:09:04 (3 files) — hero-image-fallback.py hero-polish.py set-categories.py -
e415f0e2026-07-21 auto-save: 2026-07-21T17:38:50 (1 files) — deploy-faqs-bymaterial.py -
1b7fdd12026-07-21 auto-save: 2026-07-21T17:08:42 (5 files) — deploy-collection-faqs.py greenland-cleanup-backups/dw-collection-hero-BACKUP-banner.liquid greenland-cleanup-backups/dw-collection-hero-BACKUP-v2pre.liquid halve-banner.py update-collection-aeo-v2.py -
fc3b6fb2026-07-21 auto-save: 2026-07-21T16:38:33 (3 files) — deploy-collection-aeo.py find-theme-token.sh greenland-cleanup-backups/dw-collection-hero-BACKUP-20260721-manual.liquid -
1afa9362026-07-21 auto-save: 2026-07-21T16:08:25 (1 files) — greenland-cleanup-backups/live-titles-backup-20260721-154549.tsv -
e6f3f312026-07-21 Greenland leak cleanup: archive-duplicates script + mirror-orphan backup/plan -
48f095f2026-07-21 auto-save: 2026-07-21T14:38:01 (3 files) — add-blog-images.py fix-pr-naturals-schema.py publish-pr-naturals-blog.py -
95b77ef2026-07-21 auto-save: 2026-07-21T14:07:54 (3 files) — alias-content-token.py find-content-token.sh publish-creatures-article.py -
be72efe2026-07-20 auto-save: 2026-07-20T13:32:24 (1 files) — registry.json -
4bc9b1f2026-07-20 auto-save: 2026-07-20T12:32:08 (2 files) — registry.json routes.json -
2c94ffa2026-07-20 auto-save: 2026-07-20T10:01:15 (2 files) — registry.json routes.json -
2f5c5482026-07-17 auto-save: 2026-07-17T11:46:26 (1 files) — registry.json -
30d247e2026-07-17 Add Threads (Meta) key routes → MCC .env -
71832442026-07-17 auto-save: 2026-07-17T10:46:15 (2 files) — registry.json routes.json -
30d2c8d2026-07-16 auto-save: 2026-07-16T08:42:12 (1 files) — registry.json -
77e15152026-07-15 auto-save: 2026-07-15T14:07:06 (1 files) — registry.json -
6fddcb62026-07-15 auto-save: 2026-07-15T09:35:38 (1 files) — registry.json -
53e2a802026-07-14 routes: pre-stage TikTok client key/secret fan-out to marketing-command-center (local + Kamatera live .env) -
1e022732026-07-14 auto-save: 2026-07-14T10:00:24 (1 files) — registry.json -
e0ef3072026-07-14 auto-save: 2026-07-14T09:00:07 (1 files) — registry.json -
aa8138c2026-07-14 auto-save: 2026-07-14T07:59:52 (1 files) — registry.json -
37188872026-07-13 auto-save: 2026-07-13T15:55:55 (2 files) — registry.json routes.json -
54f0bcc2026-07-13 routes: fan Meta/IG token to Norma instagram-agent .env (sync master+MCC+Norma+canary on one paste) -
83d15ae2026-07-12 auto-save: 2026-07-12T10:17:36 (2 files) — registry.json routes.json -
becc8fb2026-07-10 auto-save: 2026-07-10T11:07:57 (1 files) — registry.json -
19c6f0c2026-07-10 auto-save: 2026-07-10T00:12:54 (1 files) — registry.json -
e8a10312026-07-10 routes: add YORKWALL_USER/PASS fan-out for brewster/york scraper -
6a602802026-07-09 auto-save: 2026-07-09T23:42:48 (2 files) — registry.json routes.json -
b8a25342026-07-09 secrets: arm Low+Medium remote routes per Steve go + DTD-A (31 keys; GEORGE_AUTH kept manual) -
fa26afa2026-07-09 secrets: fleet secrets→service audit → remote-routes.proposed.json (32 candidates, review-before-arm; live routes unchanged) -
15d072c2026-07-09 secrets: register Browserbase key+project-id as remote routes → all-dw prod .env (rotation push-remote coverage) -
2c788742026-07-09 secrets: explicit remote-route push (push-remote.js) for CF token → Kamatera all-dw .env + pm2 reload; compare-first no-op; sync stays local-only (remote push is opt-in) -
a8646ea2026-07-09 auto-save: 2026-07-09T18:11:36 (3 files) — cli.js remote-routes.json scripts/push-remote.js -
9c999a32026-07-09 auto-save: 2026-07-09T17:11:25 (1 files) — routes.json -
08c4c572026-07-08 auto-save: 2026-07-08T15:06:23 (1 files) — registry.json -
ab4778a2026-07-08 auto-save: 2026-07-08T10:05:08 (1 files) — registry.json -
77326d92026-07-08 auto-save: 2026-07-08T09:35:02 (1 files) — registry.json -
ff4755c2026-07-07 auto-save: 2026-07-07T10:30:01 (1 files) — registry.json -
7e4f32e2026-07-07 auto-save: 2026-07-07T09:59:53 (1 files) — registry.json -
75dc44c2026-07-07 browserbase: pre-stage one-shot prod dedicated-key swap helper (+gitignore stage secrets) -
a9ae69e2026-07-07 auto-save: 2026-07-07T08:56:34 (2 files) — registry.json stage/ -
627cc262026-07-07 browserbase: unhook Kamatera prod all-dw from shared key fan-out (dedicated prod key set out-of-band) -
53a3c702026-07-07 routes: fan Browserbase creds to all-designerwallcoverings (local + Kamatera .env) for the live-scrape backend -
b2ee5682026-07-03 chore: macstudio3 migration — reconcile from mac2 + repoint paths (stevestudio2→macstudio3, node/npm/npx→/opt/homebrew) -
43cd7642026-06-30 auto-save: 2026-06-30T16:41:53 (1 files) — registry.json -
fd2a12b2026-06-30 routes: add SHOPIFY store domain / sample variant / storefront token for vendor microsites -
430f55c2026-06-29 auto-save: 2026-06-29T15:54:24 (1 files) — registry.json -
6f50c9b2026-06-29 auto-save: 2026-06-29T10:48:32 (2 files) — registry.json routes.json -
307a2a62026-06-27 auto-save: 2026-06-27T01:06:38 (2 files) — registry.json routes.json -
1679ff22026-06-26 auto-save: 2026-06-26T15:04:14 (2 files) — registry.json routes.json -
bac2bac2026-06-26 auto-save: 2026-06-26T11:45:25 (1 files) — registry.json -
e6940f52026-06-25 Route SHOPIFY_THEME_TOKEN to DW-Agents env files (token scrubbed from source) -
5355d142026-06-24 Pre-wire GOOGLE_OAUTH_CLIENT_ID/SECRET routes to dw-activation-calendar/.env -
e93bf2c2026-06-24 auto-save: 2026-06-24T13:27:11 (1 files) — registry.json -
bc755b52026-06-24 auto-save: 2026-06-24T12:57:01 (1 files) — registry.json -
ac2d3d82026-06-23 secrets: pre-stage GEMINI_API_KEY_DW_ENRICH route (empty) for leaked-key rotation — instant fan on Steve's new key -
201ce582026-06-23 auto-save: 2026-06-23T12:21:34 (1 files) — registry.json -
a8db0562026-06-23 auto-save: 2026-06-23T09:20:41 (1 files) — registry.json -
8aeb1ce2026-06-23 auto-save: 2026-06-23T08:50:33 (1 files) — registry.json -
55f7d512026-06-22 auto-save: 2026-06-22T21:17:54 (1 files) — registry.json -
b269ff02026-06-22 auto-save: 2026-06-22T10:35:23 (1 files) — registry.json -
bc23c752026-06-21 auto-save: 2026-06-21T20:01:45 (2 files) — registry.json routes.json -
af4923b2026-06-21 auto-save: 2026-06-21T19:01:26 (1 files) — CF-TOKEN-LEAK-ROTATION-BLOCKED-20260621.md -
74dfa622026-06-21 auto-save: 2026-06-21T18:53:00 (7 files) — .gitignore registry.json registry.json.bak.20260507-122845 routes.json.bak-1779124119 routes.json.bak.20260505-fanout -
7fe7f4e2026-06-21 Reconcile ROTATION-CHECKLIST against 2026-06-21 read-only verification: dw_admin item #1 still genuinely OUTSTANDING (old pw live in 4 DSNs, canonical fan key unset); Shopify item #4 was STALE -> RESOLVED (token HTTP 200). DTD verdict A unanimous: compromised flag stays. -
22971492026-06-19 secrets: add PG_DW_ADMIN_PASSWORD fan route (4 env_file dests) — unblocks dw_admin rotation fan -
333c7402026-06-18 Route SHOPIFY_DRAFT_TOKEN (full-access, write_draft_orders) → DW mural PDP checkout -
da036c72026-06-16 Add automated encrypted off-box backup of secrets master (.env) -
f342dbe2026-06-15 feat: backup-env.sh — encrypted off-box backup of canonical .env (ciphertext-only to gdrive); dry-run default, --apply gated -
e1b76f72026-06-11 retire Desktop secret mirror (~/Desktop/site-factory.env) — DTD verdict A -
93d83912026-06-09 fan-out: honor per-destination d.key remap in env_file branch (was writing master key name, ignoring remap); route SHOPIFY_ADMIN_TOKEN -> ImportNewSkufromURL/.env.local as SHOPIFY_ADMIN_ACCESS_TOKEN -
41aafea2026-06-09 fix secrets fan: top-level routes invisible (22) + dw_admin never rewrote DATABASE_URL -
8b0e8f02026-06-03 add rotate-dw-admin-full.sh — complete the forward dw_admin rotation -
4e224ba2026-06-03 secrets viewer: add read-only /rotation page (renders ROTATION-CHECKLIST.md as status cards) -
f461d5c2026-06-01 update tracker: add 'to configure' section for 16 not-set keys (mint links + route-back templates) -
c35aa922026-06-01 credentials/tokens update tracker web viewer (:9778) + dw_admin rotation pre-stage doc -
4fbb01c2026-06-01 Add credential rotation checklist (dw_admin pw + 2 Gemini keys + DTD-cleared Norma scoped rotation) -
89bebba2026-05-31 durable daily post-bubbe Tier-1 secret-rotation reminder -
a1e5d792026-05-31 gitignore: add patterns for backup/scratch files (*.bak, *.bak-*, *.pre-*, *.orig etc) -
ed8feec2026-05-19 chore: sync registry + routes -
ebc0fdc2026-05-19 snapshot — gitify backup 2026-05-19 -
17d95122026-05-13 fix env wiring — add 22 DW microsites to admin-passes + GEORGE_AUTH routes -
d6a1fe62026-05-13 snapshot: backup uncommitted work (1 files) -
4adfd0a2026-05-13 snapshot: 3 file(s) changed, +1 new, ~2 modified -
60334082026-05-12 feat(secrets): TMDB_API_KEY + TMDB_READ_ACCESS_TOKEN routes (asseeninmovies/.env) -
5afad012026-05-07 log: 9-domain batch DNS+cert session 2026-05-07 -
6d8118e2026-05-07 tighten .gitignore: add missing standing-rule patterns (tmp/) -
56e6b612026-05-07 remove ANTHROPIC_API_KEY from registry per standing rule (Max-plan only) -
f2bf4832026-05-06 fix: envEscape() so #-containing values keep quotes through sync -
e14bede2026-05-06 routes: add NPH (Mac2 + Kamatera) to STRIPE_SECRET_KEY + STRIPE_PUBLISHABLE_KEY fan-out -
05d62f12026-05-04 [overnight] pre-debate baseline
Authors
- Steve157
- auto-commit-fleet52
- steve5
Agents used
- secrets-manager6
Skills used
- /claude11
- /code11
- /dw-collection-hero-3
- /latest2
- /rotation2
- /rotate-dw-admin-full1
- /projects1
- /private-key1
- /sendgrid1
- /twilio1
- /bearer1
- /env-key1
- /placeholder1
- /credentials-center-e2e1
- /model-arena1
- /wallco-ai1
- /whatsmystyle1
- /undefined1
- /shell1
- /coco-create-result1
- /check-membership1
- /coco-create-mural1
- /create-coco-mural1
- /live-titles-backup-20260721-1545491
- /plan1
- /secret1
- /york1
- /push-remote1
- /npm1
- /npx1
Creative ideas + design notes
eb703f4 · 2026-09-26 · rotate-dw-admin-full.sh: client-side SCRAM-SHA-256 so plaintext never reaches Postgres (TK-11480)
ALTER now carries a pre-hashed verifier (pw to python on stdin, never argv), so log_statement / pg_stat_statements can never capture the plaintext. Harness T6 proves it on a real throwaway PG14 cluster (TCP-only; new pw authenticates, wrong pw rejected) and goes RED on a corrupted verifier. T6 fails NOT-MEASURED if the cluster does not start (fixed a false-green negative control). 22/22 green. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01J3gBZfBgR2c7TZugF5Ybz4
5673bb9 · 2026-09-26 · rotate-dw-admin-full.sh: repair 4 reproduced defects + synthetic harness (TK-11480)
Fixes: password in python3 argv (now printf builtin); ssh pipe+heredoc stdin collision (script now the ssh command, pw alone on stdin); CHG passed as argv not env (zero restarts); no errexit (failed Mac2 ALTER continued to prod). Hardening per contrarian review: pm2 jlist failure fails closed (was a silent zero-restart via process substitution), exclusive timestamped backups, opt-in split-brain start, broad-cwd restart guard, partial-rotation STATE report, xtrace disabled. test/rotate-dw-admin-full.test.sh: 19/19 green; RED vs original. No secret read, script never executed against a real host. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01J3gBZfBgR2c7TZugF5Ybz4
c7c44d9 · 2026-09-23 · TK-12029: DW_SESSION_SECRET route moved to services.* with env_file destinations (bare top-level array was silently ignored by fanOut)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136w4V3yGy3mAqRf1dtgYkr
474abf9 · 2026-09-23 · TK-12029: route DW_SESSION_SECRET to all three local HMAC verifiers (room-setting-app, ImportNewSkufromURL, Letsbegin)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136w4V3yGy3mAqRf1dtgYkr
3c08671 · 2026-09-22 · verify: okStatuses now requires a paired bodyMustContain body proof to certify a key
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DP24DdLpG6PHXgmjr47TVb
ceab226 · 2026-09-22 · Register DW_SESSION_SECRET route -> room-setting-app/.env.local (TK-11786 auth fix wiring)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G3ChReG53fwpNgUESv4SY7
b0935a9 · 2026-09-16 · TK-11683: document ENOENT-exclusion tradeoff (codex-check/Grok) — single-cycle self-healing vs chronic-WARN masking
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qf3DHSrZSGBXkNENgsYdM8
11e21a4 · 2026-09-16 · TK-11683: harden transcript scanner read loop (mid-write race) — retry-read once + exclude ENOENT-vanished files from unreadable, add fail-safe negative test
A live transcript caught mid-write or rotated away between find-enumeration and read (TK-11795) flipped the whole canary to WARN 'cannot certify clean'. Now: retry the read once after a 150ms sync sleep for the transient case; a VANISHED file (ENOENT — no longer on disk, so it cannot hold a persistent secret) is excluded rather than counted as an unmeasured gap; a genuinely-unreadable (non-ENOENT) file surviving the retry still counts unreadable -> WARN. Negative test extended to prove the fail-safe direction holds (EACCES file -> WARN). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qf3DHSrZSGBXkNENgsYdM8
9bbbe67 · 2026-09-14 · TK-11683: reversible dry-run redactor for Claude session transcripts
Masks high-confidence live-secret spans (the hc:true patterns the scanner flags, shared via transcript-secret-lib.mjs so redaction touches exactly what the scan reports) with a REDACTED:pattern:last4:sha16 placeholder. Reversibility: backs up each file (chmod 600) BEFORE any write, records a restore-map (sha_before/sha_after + redacted digests, never a raw value), and --restore reverses byte-for-byte. Dry-run is the DEFAULT; a live --apply is refused without an explicit --yes-modify-live confirm flag. Ships a negative test proving dry-run is a no-op, --apply masks + self-verifies clean, the restore-map holds no raw secret, and --restore reverses exactly. The actual live-transcript sweep is DESTRUCTIVE and stays Steve-gated. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: 963c1354-d10a-451f-8e5b-936663056ab7 (yoloforever-night)
0795811 · 2026-09-14 · TK-11683: read-only live-secret scanner for Claude session transcripts
Sweeps ~/.claude/projects/**/*.jsonl for high-confidence live-secret patterns
(reuses the secrets skill's routes.json leak_patterns + adds AKIA/private-key/
gitlab/sendgrid/twilio/bearer/env-key). Closes the gap where cli.js cmdAudit
never scanned the transcript tree. Emits DIGEST-ONLY findings
{file,line,pattern,last4,sha256_16} — never a raw secret value — and a
data/latest.json verdict in the fleet-health PASS/WARN/FAIL vocabulary
(unmeasured input is never a false PASS). Ships --test negative test proving it
FLAGS an injected fake secret + ignores a clean/placeholder line + goes FAIL +
leaks no raw value. Detection logic shared via transcript-secret-lib.mjs so the
(gated) redactor masks exactly what the scanner flags. Scan output dir gitignored.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cd4cd10 · 2026-09-13 · secrets routes: add govarbitrage as GOOGLE_PLACES_API_KEY fan-out destination
So a future key rotation covers govarbitrage/.env, which was previously missed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G37asNBxx31ZhuCqY5kk46
cc062c2 · 2026-09-12 · TK-11502: register SHOPIFY_ADMIN_ACCESS_TOKEN as managed key (verify=Shopify Admin shop.json), stop TK-10930 drift
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01REdBiwStXHMkuwrHD8Rfzc
287df5a · 2026-09-08 · routes: add DEEPSEEK_API_KEY with DeepSeek balance verify endpoint
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ELf753u6xu7AiZjNRD4yY6
a6259c8 · 2026-07-30 · secrets-manager: fix 2 pre-existing fan bugs (contrarian Hole 4, TK-10045)
- SHOPIFY_ORDERS_TOKEN skill dest used 'path' not 'name' -> fanOut skill branch built skills/undefined/.env (token never reached weekend-csv-products). Fixed to name. - cmdSync iterated only ROUTES.services, skipping ~37 top-level legacy routes (SHOPIFY_ORDERS_TOKEN, SPOONFLOWER_*, GOOGLE_DRIVE_*, TWILIO_*...) on every sync. Now fans services+top-level = 103 keys. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
f9531b0 · 2026-07-29 · scoping: mark skill .env as review_required (Claude-consumed, not grep-visible) + apply scoped .env to 13 code-scanned non-live projects (TK-10045)
Applied full non-review non-customer-facing batch (Steve-approved), verified each, then ROLLED BACK 12 skills after verify caught that a skill's .env is read by Claude at invoke-time (not a scannable script) — stripping them was unsafe. derive now forces isSkill->review_required so it can't recur. 13 real projects stay scoped (backups .env.pre-scope.* kept). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
a124191 · 2026-07-29 · secrets-manager scoping: fix 3 contrarian-found defects (TK-10045)
- Hole1 (CRITICAL): derive now scans .py (os.environ) + .sh ($VAR) — a Python/shell consumer no longer gets its key stripped on --apply (verified: restaurant-directory GOOGLE_PLACES_API_KEY protected) - Hole2 (HIGH): scopedSkip fails-open on DSN-driving keys (PG_DW_ADMIN_PASSWORD) + env_file per-dest d.dsn — SCOPED_FANOUT rotation can't drop the DATABASE_URL rewrite - Hole3: auto-prune ~/.claude.json.bak.* to last 5 (135 secret-bearing copies had piled up in $HOME) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
7795cb8 · 2026-07-29 · secrets-manager: least-privilege scoping (TK-10045) — derive-manifests.js + regen command + manifest-aware fanOut guard (SCOPED_FANOUT-gated)
Blast-radius fix: per-service secret manifests (values-free), regen writes each project a scoped .env = manifest INTERSECT master (remove-only default; --add-missing opt-in), and fanOut skips re-broadening a scoped .env when SCOPED_FANOUT=1. Master .env hard-excluded; review_required (dynamic env access) projects held for hand-review. Dry-run: 67 projects / 111 over-shared keys removable. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
e6f3f31 · 2026-07-21 · Greenland leak cleanup: archive-duplicates script + mirror-orphan backup/plan
143 live '| Greenland' products are stale duplicates of live canonical Phillipe Romano twins; DTD panel (5/5) ruled ARCHIVE not rename. Script archives them on the live store + syncs mirror (Steve-gated, dry-run default). 66 mirror-only orphan rows already deleted locally (reversible; backup TSV included). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
da036c7 · 2026-06-16 · Add automated encrypted off-box backup of secrets master (.env)
Council #1 leftover: secrets-manager/.env had ZERO automated backup (one disk loss = total secret loss). backup-env.sh: AES256 GPG-symmetric versioned snapshots in ~/.secrets-backups (last 30), round-trip-verified each run (decrypt==source), mirrored off-box to iCloud Drive. Passphrase in login Keychain + one-time escrow handoff. Daily launchd com.steve.secrets-env-backup. Both pass+fail paths proven.
e1b76f7 · 2026-06-11 · retire Desktop secret mirror (~/Desktop/site-factory.env) — DTD verdict A
The Desktop is a high-exposure location (Time Machine / iCloud Desktop-sync / screenshots) and chmod 600 gives no protection against code running as the user — the prompt-injection threat that prompted this. The mirror was pure redundancy with the canonical master at ~/Projects/secrets-manager/.env. fanOut() no longer writes the Desktop copy; sync verified it is not recreated. KAMATERA_ORIGIN_IP and ANTHROPIC_API_KEY (previously only on the Desktop) were ingested into master first so no value was lost. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
41aafea · 2026-06-09 · fix secrets fan: top-level routes invisible (22) + dw_admin never rewrote DATABASE_URL
Root cause of the 2026-06-03 dw_admin rotation half-fire — three stacked bugs, all fixed in cli.js with ZERO routes.json churn: 1. cli.js read only ROUTES.services[key], but ~22 routes (PG_DW_ADMIN_PASSWORD, SHOPIFY_ORDERS_TOKEN, TWILIO_*, GOOGLE_DRIVE_*, ANTHROPIC_*…) live at routes.json top-level -> invisible -> fanned 0 destinations. Fix: routeFor() top-level fallback. 2. fanOut had no env_file branch (dw_admin dests' type) -> silently skipped. Added it. 3. fan set a bare *_PASSWORD var, but dw_admin consumers read a full DATABASE_URL DSN. Fix: rewriteDsnPassword() + DSN_REWRITE map rewrites the pw inside DATABASE_URL for dw_admin (URL-encoding + / =). Verified: unit + full-branch temp-file tests; route visible (8 dests); routes.json byte-identical to HEAD. Corrected ROTATION-PRESTAGE.md (real step 3 + prod 3b SSH step + revert guard). Prod DATABASE_URL still manual (3b).
8b0e8f0 · 2026-06-03 · add rotate-dw-admin-full.sh — complete the forward dw_admin rotation
Console-ready (Steve-run, supervised) script that finishes what ROTATION-PRESTAGE.md half-did on 2026-06-03: mint new pw (never echoed) -> ALTER dw_admin on Mac2 + prod -> fan to Mac2 consumers via secrets cli -> in-place DSN rewrite on Kamatera with .pre-rot.bak backups -> restart ONLY affected apps in batches <=6 (never restart all) -> converge the 2 split-brain workers -> verify 0 auth failures. --dry-run validated.
4e224ba · 2026-06-03 · secrets viewer: add read-only /rotation page (renders ROTATION-CHECKLIST.md as status cards)
- new /rotation route + markdown→HTML renderer (cards w/ outstanding/done pills, summary counts) - nav link from main viewer page - checklist: added items 4 (SHOPIFY_ADMIN_TOKEN burned) + 5 (repl_user pw lost on sub drop) - page shows key names + mint URLs + route-back commands only — never secret values Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
89bebba · 2026-05-31 · durable daily post-bubbe Tier-1 secret-rotation reminder
LaunchAgent-driven (com.steve.postbubbe-rotation-reminder, 8:37am daily, survives restarts) replacement for the session-only cron. Compares each Tier-1 key's registry digest against the 2026-05-31 baseline; a changed digest = rotated. Fires a macOS notification listing keys still un-rotated, and SELF-RETIRES (boots out the agent + drops a RESOLVED marker) once all 9 have been rotated. Re-verify + remind only — never rotates console-only keys. Tracks: the reminder script + the digest baseline (digests are last4:sha-prefix, not secrets). Plist lives in ~/Library/LaunchAgents (outside the repo).
a1e5d79 · 2026-05-31 · gitignore: add patterns for backup/scratch files (*.bak, *.bak-*, *.pre-*, *.orig etc)
Prevents future accidental commits of routes.json.bak-* and similar temporary backup files that the secrets-manager tooling generates during key rotations and audits. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
6033408 · 2026-05-12 · feat(secrets): TMDB_API_KEY + TMDB_READ_ACCESS_TOKEN routes (asseeninmovies/.env)
Both forms (v3 query-param + v4 bearer token) routed to ~/Projects/asseeninmovies/.env. Verify endpoints set to GET https://api.themoviedb.org/3/authentication (expects success:true) so paste-then-validate flow works. Steve to paste either key form; secrets skill auto-routes.
5afad01 · 2026-05-07 · log: 9-domain batch DNS+cert session 2026-05-07
Group A (4 microsites) + Group B (5 typo redirects) fully live on Kamatera with LE SSL. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
f2bf483 · 2026-05-06 · fix: envEscape() so #-containing values keep quotes through sync
Bug: loadEnvFile() strips quotes on read but writeEnvFile()/serializeEnvBody() never re-add them, so any value with a # (e.g. MAILING_ADDRESS="… 15442 Ventura Bl #102 …") gets de-quoted on the next sync and dotenv silently parses only the prefix, fail-closing every gate that depended on the full value. Symptom in prod (NPH, 2026-05-06): MAILING_ADDRESS sync flipped CAN-SPAM compliance from PASS → no_mailing_address even though the Kamatera .env file looked correct on cat. Fix: envEscape() wraps any value containing #, quotes, newlines, or edge-whitespace in double quotes (escaping inner quotes/backslashes). Both writeEnvFile() and serializeEnvBody() now run values through it.
e14bede · 2026-05-06 · routes: add NPH (Mac2 + Kamatera) to STRIPE_SECRET_KEY + STRIPE_PUBLISHABLE_KEY fan-out
NPH joins site-factory, lawyer-directory, professional-directory, and the 3 home-history sites on the same live Stripe account fan-out. Marketplace differentiation remains via application_fee_amount + Stripe Connect destination accounts, not account-level isolation. Sync ran clean: 122 destination entries written. (Includes accumulated additions to routes since baseline 05d62f1 — Brave, MOONSHOT, CF, multiple Stripe variants, Vercel, Purelymail, GoDaddy, Browserbase, Anthropic, OpenAI, Gemini, Shopify, Resend, restricted-key, DPLA, Gemini-Ralph, ElevenLabs, Google-Maps, LinkedIn x2, NPH-Google-OAuth x2, GEORGE_AUTH — all already in master and routed through prior add invocations; this is just the catchup commit.)
File tree
- .auto-ingest-state
- .clipboard-last-hash
- .gitignore
- .postbubbe-rotation-RESOLVED
- CF-TOKEN-LEAK-ROTATION-BLOCKED-20260621.md
- CHANGES.md
- DW-ADMIN-ROTATION-RUNBOOK-2026-06-19.sh
- ROTATION-CHECKLIST.md
- ROTATION-PRESTAGE.md
- ROTATION-TEMPLATE.env
- _shopify_channel_fill.py
- add-blog-images.py
- admin-passes.json
- alias-content-token.py
- audit-2026-04-30.txt
- audits/coordonne-canary-BLOCKED-20260722-073952.json
- auto-ingest.launchd.err
- auto-ingest.launchd.out
- auto-ingest.sh
- backup-env.sh
- cli.js
- clipboard-watcher.launchd.err
- clipboard-watcher.launchd.out
- clipboard-watcher.sh
- coordonne-collab-audit/artisan-fabric-overmatch.json
- coordonne-collab-audit/artisan-fabric-tag-result.json
- coordonne-collab-audit/artisan-match.json
- coordonne-collab-audit/artisan-tag-result.json
- coordonne-collab-audit/check-membership.js
- coordonne-collab-audit/coco-backfill.js
- coordonne-collab-audit/coco-backfill.json
- coordonne-collab-audit/coco-create-mural-result.json
- coordonne-collab-audit/coco-create-mural.json
- coordonne-collab-audit/coco-create-result-rest.json
- coordonne-collab-audit/coco-create-result.json
- coordonne-collab-audit/coco-create-wall-rest.json
- coordonne-collab-audit/coco-create-wall.json
- coordonne-collab-audit/coco-hold-murals.json
- coordonne-collab-audit/coco-rows.json
- coordonne-collab-audit/coco-settlement-result.json
- coordonne-collab-audit/cotswolds-activate-result.json
- coordonne-collab-audit/cotswolds-activate-wallcoverings.js
- coordonne-collab-audit/cotswolds-create-drafts.js
- coordonne-collab-audit/cotswolds-create-result.json
- coordonne-collab-audit/cotswolds-rows.json
- coordonne-collab-audit/cotswolds-settlement-result.json
- coordonne-collab-audit/create-coco-mural.js
- coordonne-collab-audit/create-coco-wall.js
- coordonne-collab-audit/csm-match.json
- coordonne-collab-audit/csm-tag-result.json
- coordonne-collab-audit/settlement-gate-coco.js
- coordonne-collab-audit/settlement-gate.js
- coordonne-collab-audit/tag-collab.js
- data/latest.json
- deploy-collection-aeo.py
- deploy-collection-faqs.py
- deploy-faqs-bymaterial.py
- derive-manifests.js
- dw-scroll-debug.js
- dw-scroll-debug2.js
- dw-scroll-debug3.js
- dw-scroll-verify.js
- find-content-token.sh
- find-theme-token.sh
- fix-greenland-titles.py
- fix-pr-naturals-schema.py
- greenland-cleanup-backups/archive-plan.json
- greenland-cleanup-backups/dw-collection-hero-BACKUP-20260721-manual.liquid
- greenland-cleanup-backups/dw-collection-hero-BACKUP-banner.liquid
- greenland-cleanup-backups/dw-collection-hero-BACKUP-v2pre.liquid
- greenland-cleanup-backups/live-titles-backup-20260721-151605.tsv
- greenland-cleanup-backups/live-titles-backup-20260721-151720.tsv
- greenland-cleanup-backups/live-titles-backup-20260721-154549.tsv
- greenland-cleanup-backups/mirror-orphans-20260721-151458.tsv
- halve-banner.py
- hero-image-fallback.py
- hero-polish.py
- manifests.json
- postbubbe-rotation-reminder.sh
- postbubbe-tier1-baseline.json
- publish-creatures-article.py
- publish-pr-naturals-blog.py
- redact-transcripts.mjs
- registry.json
- remote-routes.json
- remote-routes.proposed.json
- rotate-dw-admin-full.sh
- routes.json
- routes.json.bak.1786292832
- scan-transcripts.mjs
- scripts/backup-env.sh
- scripts/push-remote.js
- set-categories.py
- stage/swap-prod-bb-key.mjs
- test/rotate-dw-admin-full.test.sh
- test/verify-all.test.js
- tk11025-restore-map.json
- transcript-secret-lib.mjs
- update-collection-aeo-v2.py
- update-viewer/index.html
- update-viewer/server.mjs
- update-viewer/update-items.json
- verification/credentials-center-e2e-proof.json
- verification/credentials-center-e2e.png
- verification/e2e-proof.json
- viewer.js
- yolo-overnight-log.md
- yolo-session-2026-05-05-overnight.md