From de0190283b6c89b399a9089dbaa1865e0b4cb337 Mon Sep 17 00:00:00 2001 From: root Date: Fri, 7 Aug 2026 08:36:59 -0400 Subject: [PATCH] docs: Git structure audit -- 40 Gitea repos, 13 findings, prioritized action plan --- docs/git-audit-2026-08-07.md | 207 +++++++++++++++++++++++++++++++++++ 1 file changed, 207 insertions(+) create mode 100644 docs/git-audit-2026-08-07.md diff --git a/docs/git-audit-2026-08-07.md b/docs/git-audit-2026-08-07.md new file mode 100644 index 0000000..890b93f --- /dev/null +++ b/docs/git-audit-2026-08-07.md @@ -0,0 +1,207 @@ +# Git Structure Audit -- August 7, 2026 + +**Scope:** All Gitea-hosted repos (40 on git.itpropartner.com) plus local-only repos under /root/projects/ + +**Auditor:** Sho'Nuff (Hermes Agent) + +--- + +## Summary Verdict + +Your Git structure has solid bones but significant hygiene gaps. For a private, solo-developer setup it's functional -- but if you ever go public, the current state would fail a basic security review. The issues below are ordered by severity. + +--- + +## CRITICAL: Fix Immediately + +### 1. Hardcoded Credentials in `scripts` Repo + +The `scripts` repo (11 commits, 75KB) contains Windows provisioning PowerShell scripts with **plaintext passwords committed to history:** + +- `LoveMyBoys73!` -- ippadmin MSP backdoor account +- `Liberty4All!` -- liberty-admin customer admin +- `tire` -- tire power user + +These appear in `dell-reimage-kit/` unattend XML and PowerShell. Even if this repo stays private forever, credentials in git history is a ticking time bomb. One accidental `git clone` to the wrong place and those passwords are exposed. + +**Fix:** `git filter-branch` or BFG Repo-Cleaner to purge from history, then rotate all three passwords everywhere they're used (Liberty UDM, Windows workstations, etc). + +### 2. Blob Repository: `hermes-skills` = 13.6 MB + +The `hermes-skills` repo tracks 2,251 files including: +- `skills/.hub/index-cache/hermes-index.json` -- **39 MB** JSON blob +- `skills/.curator_backups/2026-07-12T15-48-44Z/skills.tar.gz` -- **2.7 MB** tarball + +These are cache/backup artifacts, not source code. They bloat every clone by 40+ MB and will grow with time. The repo has no `.gitignore` to prevent this. + +**Fix:** Add `.gitignore` excluding `.hub/` and `.curator_backups/`, `git rm --cached` the tracked artifacts, commit. Expect the repo size to drop from 13.6 MB to well under 1 MB. + +### 3. No `.gitignore` on 33 of 35 Gitea Repos + +Only `itpp-infrastructure` and `hermes-recovery` have a `.gitignore`. Every other repo is unprotected against accidental commits of `.env` files, backup directories, `__pycache__/`, `.DS_Store`, editor swap files, etc. + +**Fix:** Apply a standard `.gitignore` template across all repos (see recommendation below). + +--- + +## HIGH: Structural Problems + +### 4. Stale Duplicate: `itpp-infra` (SSH remote, orphaned) + +`/root/projects/itpp-infra` has an SSH remote (`git@git.itpropartner.com:ippadmin/itpp-infra.git`) pointing to a repo that **does not exist on Gitea**. This was its one and only commit (Jul 24, "Initial commit -- audit Jul 24 2026"). The actual infrastructure docs live in `/root/projects/itpp-infrastructure` (49 commits, active). + +The `itpp-infra` local copy also has 5 dirty files (uncommitted edits to server DR plans and network diagrams). These are likely valuable changes trapped in a dead repo. + +**Fix:** +1. Recover any uncommitted changes from `itpp-infra` +2. Verify they don't duplicate `itpp-infrastructure` content +3. Delete or archive the stale repo + +### 5. Branch Naming Inconsistency + +| Branch | Count | Repos | +|--------|-------|-------| +| `master` | 25 | apex-track, backup-restore, boxpilot, content-creation-pipeline, digital-signage, disaster-recovery, dre, fleettracker360, forefront-wireless-portal, gift-a-roast, hermes-recovery, hermes-skills, hudu, itpropartner-website, mcp-*, ops-portal, osint-tool, personal-assistant, pipeline, scripts, shark-game, startup-studio, track-a-flock, unifi, unms, voipsimplicity, voipsimplicity-manual | +| `main` | 7 | cartmylist, homelab, itpp-infrastructure, launchcheck, model-fallback, nvr-shield, super-search-business | + +**Plus:** `itpp-infrastructure` locally is on `main` but Gitea's default branch for that repo is `master` -- the remote has an empty `master` branch alongside the active `main`. + +Industry standard has moved to `main`. Your newer repos use it, older ones don't. + +**Fix:** Standardize on `main` for new repos. Migrating existing `master` repos is optional for private use but recommended before any public release. + +### 6. Dirty Working Trees: 21 Repos with Uncommitted Changes + +``` +hermes-skills 33 dirty files +hermes-recovery 24 dirty files +voipsimplicity-manual 11 dirty files +digital-signage 6 dirty files +itpp-infra 5 dirty files +pipeline 5 dirty files +disaster-recovery 4 dirty files +shark-game 2 dirty files +--- plus 13 repos with 1 dirty file each --- +``` + +Several of these repos haven't been committed since July 15-16. That's three weeks of potentially valuable changes sitting uncommitted and un-backed-up. + +**Fix:** Audit each dirty repo, commit or discard changes, push. This is also a DR concern -- uncommitted files don't exist in S3 backups. + +### 7. Remote URL Anomalies + +- **`gift-a-roast`** uses username `git` instead of `ippadmin` in its HTTPS remote. Functionally works (Gitea ignores the username with token auth) but inconsistent and sloppy. +- **`itpp-infra`** uses SSH (`git@...`) -- won't work without SSH keys on Gitea. The repo doesn't exist on Gitea anyway, confirming this was never successfully pushed. +- **`msp-claude-skills`** is a direct GitHub clone (`github.com/RTFM-IT-Services-LLC/msp-claude-skills.git`, CC BY-NC-SA 4.0). This is fine for reference but should be marked as upstream-sourced. It has no Gitea remote. + +--- + +## MEDIUM: Operational Gaps + +### 8. Twenty Local-Only Repos (No Remote) + +These are projects with local git init but never pushed anywhere: + +`assistant`, `auth`, `capabilities`, `hear-read`, `intelsight`, `intelsight-landing`, `internal`, `mockup`, `my-itpropartner-portal`, `ops`, `ops-v2-portal`, `osint`, `proposals`, `pry`, `research-search-mcp`, `schedule`, `shonuff`, `shonuff-caller`, `static`, `status`, `voice-previews` + +Some are real projects (intelsight, auth, pry). Some look like duplicates/abandoned scaffolds (ops vs ops-portal vs ops-v2-portal). None are backed up via Gitea push, meaning they live only on this server's disk. + +**Fix:** Either push to Gitea or explicitly decide they're abandoned and delete. The duplication (ops/ops-portal/ops-v2-portal) should be consolidated. + +### 9. Single-Branch Linear History + +Every repo uses exactly one branch with linear commits. No feature branches, no pull requests, no tags, no releases. This is acceptable for solo development but means: +- No way to experiment without polluting the main line +- No tagged versions for rollback +- No PR workflow if you ever collaborate + +### 10. Abandoned Single-Commit Repos + +Sixteen repos have only 1-2 commits, most with the message "Initial commit -- 2026-07-15" and nothing since. This suggests batch scaffolding on July 15 that never got follow-up. These clutter the Gitea org. + +--- + +## LOW: Nice-to-Have + +### 11. No Repo Templates + +No `ISSUE_TEMPLATE.md`, `PULL_REQUEST_TEMPLATE.md`, `CODEOWNERS`, or `CONTRIBUTING.md` on any repo. Low priority for solo work but standard for public repos. + +### 12. Commit Message Quality Varies + +`itpp-infrastructure` has clean, descriptive messages (e.g., "docs: fallback chain overhaul, two-key strategy, operational model update"). Many others use "Initial commit" or "Update 2026-07-15 -- root" which conveys nothing. + +### 13. Token in Remote URLs + +All HTTPS remotes embed the Gitea token directly. This is convenient but means the token appears in shell history, process lists, and any `git remote -v` output. If any repo directory is ever copied or backed up without sanitization, the token travels with it. + +--- + +## Recommendations: Action Plan + +### Immediate (This Week) + +1. **Purge credentials from `scripts` repo history** and rotate those three passwords everywhere +2. **Add `.gitignore`** to all 33 repos missing it (see template below) +3. **Clean `hermes-skills`** -- gitignore `.hub/` and `.curator_backups/`, rm cached, repush +4. **Resolve `itpp-infra`** -- salvage any unique content, then archive/delete + +### Short-Term (This Month) + +5. **Audit dirty repos** -- commit or discard all pending changes +6. **Push or delete local-only repos** -- decide which are real projects vs abandoned scaffolds +7. **Fix remote URL anomalies** -- normalize gift-a-roast username, decide on msp-claude-skills disposition +8. **Standardize branch naming** -- pick `main` as default, migrate at least the active repos + +### Before Any Public Release + +9. Rotate the Gitea token and move to SSH keys or a credential helper +10. Add repo templates (issue/PR) +11. Audit every repo's history for secrets with `git-secrets` or `truffleHog` +12. Tag releases on active projects + +--- + +## Standard `.gitignore` Template + +```gitignore +# Environment & secrets +.env +.env.* +*.key +*.pem +credentials.json + +# Python +__pycache__/ +*.py[cod] +*.egg-info/ +.venv/ +venv/ + +# Node +node_modules/ + +# OS +.DS_Store +Thumbs.db + +# Editor +*.swp +*.swo +*~ + +# Backups +*.bak +.backup-*/ + +# Large cache files +*.tar.gz +*.zip +index-cache/ +``` + +--- + +*Report generated by Sho'Nuff (Hermes Agent) on August 7, 2026.* +*Full repo inventory and remote URL map available on request.*