[object Object]

← back to Wallco Ai

curator: stage Kamatera reverse-proxy fallback vhost (DTD-A, not deployed)

94ea8f3267f5edf784f1633d53aadcf73734f3fb · 2026-06-24 12:51:49 -0700 · Steve

Files touched

Diff

commit 94ea8f3267f5edf784f1633d53aadcf73734f3fb
Author: Steve <steve@designerwallcoverings.com>
Date:   Wed Jun 24 12:51:49 2026 -0700

    curator: stage Kamatera reverse-proxy fallback vhost (DTD-A, not deployed)
---
 deploy/curator-kamatera-fallback.conf | 52 +++++++++++++++++++++++++++++++++++
 1 file changed, 52 insertions(+)

diff --git a/deploy/curator-kamatera-fallback.conf b/deploy/curator-kamatera-fallback.conf
new file mode 100644
index 0000000..f055f20
--- /dev/null
+++ b/deploy/curator-kamatera-fallback.conf
@@ -0,0 +1,52 @@
+# ============================================================================
+# FALLBACK ONLY — Kamatera reverse-proxy vhost for curator.wallpapersback.com
+# STAGED, NOT DEPLOYED. DTD verdict (2026-06-24, 3/3) = OPTION A (Cloudflare
+# Tunnel). This file exists so the pivot is one Steve-approval away if the
+# token path is ever abandoned. DO NOT install on the live Kamatera nginx
+# without Steve's explicit approval of the pending-approval memo — editing the
+# production storefront box is hard-gated.
+#
+# Path it would serve:
+#   CF edge (proxied A curator→45.61.58.125) → THIS Kamatera nginx vhost
+#     → Tailscale → Mac2:9916 (the existing Basic-Auth wall) → curator app:9905
+#
+# PREREQUISITE (also Steve-gated, also NOT done):
+#   Mac2 nginx must additionally listen on its Tailscale IP so Kamatera can
+#   reach it. Today /opt/homebrew/etc/nginx/servers/curator.conf binds
+#   `127.0.0.1:9916` ONLY. Pivot requires adding:  listen 100.65.187.120:9916;
+#   (Mac2 Tailscale IP) — a Mac2-local nginx edit + reload, surfaced for Steve.
+#
+# Verified read-only 2026-06-24: Tailscale link Kamatera(100.107.67.67) ↔
+#   Mac2(100.65.187.120) is ACTIVE/direct/healthy (tx 3.4GB). The ONLY missing
+#   piece on the Mac2 side is the extra listen directive above.
+# ============================================================================
+
+server {
+    listen 80;
+    listen [::]:80;
+    server_name curator.wallpapersback.com;
+
+    # Cloudflare terminates TLS at the edge (proxied A record); origin is plain
+    # HTTP over the trusted Kamatera↔CF path. (If origin TLS is wanted later,
+    # add certbot for this host — but CF Full mode over :80 is acceptable here
+    # since the sensitive gate is Mac2's Basic Auth, reached over Tailscale.)
+
+    client_max_body_size 64m;
+
+    location / {
+        # Mac2 over Tailscale. Mac2 nginx:9916 enforces Basic Auth + the app's
+        # dw_auth admin cookie — this box only forwards; it adds NO auth of its
+        # own and strips NO headers (parity with the tunnel path).
+        proxy_pass         http://100.65.187.120:9916;
+        proxy_http_version 1.1;
+        proxy_set_header   Host              $host;
+        proxy_set_header   X-Real-IP         $remote_addr;
+        proxy_set_header   X-Forwarded-For   $proxy_add_x_forwarded_for;
+        proxy_set_header   X-Forwarded-Proto https;
+        proxy_read_timeout 300s;
+
+        # If Mac2 is asleep/unreachable over Tailscale, fail clean rather than
+        # hang the storefront worker pool.
+        proxy_connect_timeout 5s;
+    }
+}

← 6a41dda Add API-path tunnel finish-script (DTD-C: scoped CF token, n  ·  back to Wallco Ai  ·  auto-save: 2026-06-24T16:28:13 (1 files) — data/logs/gate-re 184b469 →