Files
itpp-infrastructure/docs/audit/git-audit-2026-08-07.md
T

208 lines
8.7 KiB
Markdown

# Git Structure Audit -- August 7, 2026
**Scope:** All Gitea-hosted repos (40 on git.itpropartner.com) plus local-only repos under /root/projects/
**Auditor:** Sho'Nuff (Hermes Agent)
---
## Summary Verdict
Your Git structure has solid bones but significant hygiene gaps. For a private, solo-developer setup it's functional -- but if you ever go public, the current state would fail a basic security review. The issues below are ordered by severity.
---
## CRITICAL: Fix Immediately
### 1. Hardcoded Credentials in `scripts` Repo
The `scripts` repo (11 commits, 75KB) contains Windows provisioning PowerShell scripts with **plaintext passwords committed to history:**
- `LoveMyBoys73!` -- ippadmin MSP backdoor account
- `Liberty4All!` -- liberty-admin customer admin
- `tire` -- tire power user
These appear in `dell-reimage-kit/` unattend XML and PowerShell. Even if this repo stays private forever, credentials in git history is a ticking time bomb. One accidental `git clone` to the wrong place and those passwords are exposed.
**Fix:** `git filter-branch` or BFG Repo-Cleaner to purge from history, then rotate all three passwords everywhere they're used (Liberty UDM, Windows workstations, etc).
### 2. Blob Repository: `hermes-skills` = 13.6 MB
The `hermes-skills` repo tracks 2,251 files including:
- `skills/.hub/index-cache/hermes-index.json` -- **39 MB** JSON blob
- `skills/.curator_backups/2026-07-12T15-48-44Z/skills.tar.gz` -- **2.7 MB** tarball
These are cache/backup artifacts, not source code. They bloat every clone by 40+ MB and will grow with time. The repo has no `.gitignore` to prevent this.
**Fix:** Add `.gitignore` excluding `.hub/` and `.curator_backups/`, `git rm --cached` the tracked artifacts, commit. Expect the repo size to drop from 13.6 MB to well under 1 MB.
### 3. No `.gitignore` on 33 of 35 Gitea Repos
Only `itpp-infrastructure` and `hermes-recovery` have a `.gitignore`. Every other repo is unprotected against accidental commits of `.env` files, backup directories, `__pycache__/`, `.DS_Store`, editor swap files, etc.
**Fix:** Apply a standard `.gitignore` template across all repos (see recommendation below).
---
## HIGH: Structural Problems
### 4. Stale Duplicate: `itpp-infra` (SSH remote, orphaned)
`/root/projects/itpp-infra` has an SSH remote (`git@git.itpropartner.com:ippadmin/itpp-infra.git`) pointing to a repo that **does not exist on Gitea**. This was its one and only commit (Jul 24, "Initial commit -- audit Jul 24 2026"). The actual infrastructure docs live in `/root/projects/itpp-infrastructure` (49 commits, active).
The `itpp-infra` local copy also has 5 dirty files (uncommitted edits to server DR plans and network diagrams). These are likely valuable changes trapped in a dead repo.
**Fix:**
1. Recover any uncommitted changes from `itpp-infra`
2. Verify they don't duplicate `itpp-infrastructure` content
3. Delete or archive the stale repo
### 5. Branch Naming Inconsistency
| Branch | Count | Repos |
|--------|-------|-------|
| `master` | 25 | apex-track, backup-restore, boxpilot, content-creation-pipeline, digital-signage, disaster-recovery, dre, fleettracker360, forefront-wireless-portal, gift-a-roast, hermes-recovery, hermes-skills, hudu, itpropartner-website, mcp-*, ops-portal, osint-tool, personal-assistant, pipeline, scripts, shark-game, startup-studio, track-a-flock, unifi, unms, voipsimplicity, voipsimplicity-manual |
| `main` | 7 | cartmylist, homelab, itpp-infrastructure, launchcheck, model-fallback, nvr-shield, super-search-business |
**Plus:** `itpp-infrastructure` locally is on `main` but Gitea's default branch for that repo is `master` -- the remote has an empty `master` branch alongside the active `main`.
Industry standard has moved to `main`. Your newer repos use it, older ones don't.
**Fix:** Standardize on `main` for new repos. Migrating existing `master` repos is optional for private use but recommended before any public release.
### 6. Dirty Working Trees: 21 Repos with Uncommitted Changes
```
hermes-skills 33 dirty files
hermes-recovery 24 dirty files
voipsimplicity-manual 11 dirty files
digital-signage 6 dirty files
itpp-infra 5 dirty files
pipeline 5 dirty files
disaster-recovery 4 dirty files
shark-game 2 dirty files
--- plus 13 repos with 1 dirty file each ---
```
Several of these repos haven't been committed since July 15-16. That's three weeks of potentially valuable changes sitting uncommitted and un-backed-up.
**Fix:** Audit each dirty repo, commit or discard changes, push. This is also a DR concern -- uncommitted files don't exist in S3 backups.
### 7. Remote URL Anomalies
- **`gift-a-roast`** uses username `git` instead of `ippadmin` in its HTTPS remote. Functionally works (Gitea ignores the username with token auth) but inconsistent and sloppy.
- **`itpp-infra`** uses SSH (`git@...`) -- won't work without SSH keys on Gitea. The repo doesn't exist on Gitea anyway, confirming this was never successfully pushed.
- **`msp-claude-skills`** is a direct GitHub clone (`github.com/RTFM-IT-Services-LLC/msp-claude-skills.git`, CC BY-NC-SA 4.0). This is fine for reference but should be marked as upstream-sourced. It has no Gitea remote.
---
## MEDIUM: Operational Gaps
### 8. Twenty Local-Only Repos (No Remote)
These are projects with local git init but never pushed anywhere:
`assistant`, `auth`, `capabilities`, `hear-read`, `intelsight`, `intelsight-landing`, `internal`, `mockup`, `my-itpropartner-portal`, `ops`, `ops-v2-portal`, `osint`, `proposals`, `pry`, `research-search-mcp`, `schedule`, `shonuff`, `shonuff-caller`, `static`, `status`, `voice-previews`
Some are real projects (intelsight, auth, pry). Some look like duplicates/abandoned scaffolds (ops vs ops-portal vs ops-v2-portal). None are backed up via Gitea push, meaning they live only on this server's disk.
**Fix:** Either push to Gitea or explicitly decide they're abandoned and delete. The duplication (ops/ops-portal/ops-v2-portal) should be consolidated.
### 9. Single-Branch Linear History
Every repo uses exactly one branch with linear commits. No feature branches, no pull requests, no tags, no releases. This is acceptable for solo development but means:
- No way to experiment without polluting the main line
- No tagged versions for rollback
- No PR workflow if you ever collaborate
### 10. Abandoned Single-Commit Repos
Sixteen repos have only 1-2 commits, most with the message "Initial commit -- 2026-07-15" and nothing since. This suggests batch scaffolding on July 15 that never got follow-up. These clutter the Gitea org.
---
## LOW: Nice-to-Have
### 11. No Repo Templates
No `ISSUE_TEMPLATE.md`, `PULL_REQUEST_TEMPLATE.md`, `CODEOWNERS`, or `CONTRIBUTING.md` on any repo. Low priority for solo work but standard for public repos.
### 12. Commit Message Quality Varies
`itpp-infrastructure` has clean, descriptive messages (e.g., "docs: fallback chain overhaul, two-key strategy, operational model update"). Many others use "Initial commit" or "Update 2026-07-15 -- root" which conveys nothing.
### 13. Token in Remote URLs
All HTTPS remotes embed the Gitea token directly. This is convenient but means the token appears in shell history, process lists, and any `git remote -v` output. If any repo directory is ever copied or backed up without sanitization, the token travels with it.
---
## Recommendations: Action Plan
### Immediate (This Week)
1. **Purge credentials from `scripts` repo history** and rotate those three passwords everywhere
2. **Add `.gitignore`** to all 33 repos missing it (see template below)
3. **Clean `hermes-skills`** -- gitignore `.hub/` and `.curator_backups/`, rm cached, repush
4. **Resolve `itpp-infra`** -- salvage any unique content, then archive/delete
### Short-Term (This Month)
5. **Audit dirty repos** -- commit or discard all pending changes
6. **Push or delete local-only repos** -- decide which are real projects vs abandoned scaffolds
7. **Fix remote URL anomalies** -- normalize gift-a-roast username, decide on msp-claude-skills disposition
8. **Standardize branch naming** -- pick `main` as default, migrate at least the active repos
### Before Any Public Release
9. Rotate the Gitea token and move to SSH keys or a credential helper
10. Add repo templates (issue/PR)
11. Audit every repo's history for secrets with `git-secrets` or `truffleHog`
12. Tag releases on active projects
---
## Standard `.gitignore` Template
```gitignore
# Environment & secrets
.env
.env.*
*.key
*.pem
credentials.json
# Python
__pycache__/
*.py[cod]
*.egg-info/
.venv/
venv/
# Node
node_modules/
# OS
.DS_Store
Thumbs.db
# Editor
*.swp
*.swo
*~
# Backups
*.bak
.backup-*/
# Large cache files
*.tar.gz
*.zip
index-cache/
```
---
*Report generated by Sho'Nuff (Hermes Agent) on August 7, 2026.*
*Full repo inventory and remote URL map available on request.*