Three things that all blocked tunnel-start: 1. justfile: dropped set dotenv-load / set export — they pulled .env.development into every recipe shell, where empty values beat docker compose --env-file .env per shell-env precedence (POSTGRES_PASSWORD was the visible casualty). Dev recipes now pass --env-file .env.development explicitly so they're not affected by the change. 2. canary image is distroless/static, so the wget-based healthcheck had no binary to run and every check failed → nginx/tunnel never started. Added cmd/healthcheck (tiny Go HTTP probe of /healthz), built alongside canary, swapped compose healthcheck to /healthcheck. 3. Added tunnel-build and tunnel-rebuild recipes so the next person doesn't have to remember which compose files the tunnel overlay needs. |
||
|---|---|---|
| .. | ||
| base64-tool | ||
| c2-beacon | ||
| caesar-cipher | ||
| canary-token-generator | ||
| dns-lookup | ||
| firewall-rule-engine | ||
| hash-cracker | ||
| keylogger | ||
| linux-cis-hardening-auditor | ||
| linux-ebpf-security-tracer | ||
| metadata-scrubber-tool | ||
| network-traffic-analyzer | ||
| simple-port-scanner | ||
| simple-vulnerability-scanner | ||
| systemd-persistence-scanner | ||