# Root on koopa (hacktivism monitoring sites) Host Caddy runs as **root/systemd** (`caddy` user). Static monitoring HTML is **not** put into Taler containers — only host paths + Caddy `handle`. After host-agent / `generate-monitoring-sites.sh` + deploy (as hernani), files live in: ```text $DEPLOY_STAGING (or $HOME/monitoring-sites-staging)//monitoring/index.html $DEPLOY_STAGING (or $HOME/monitoring-sites-staging)//monitoring_err/index.html ``` ## One-shot as root (preferred) ```bash # absolute path — as root, ~ is /root (script not found under ~/koopa-caddy/…) sudo $APPLY_MONITORING_LIVE # same script is versioned in the suite: # host-agent/apply-monitoring-live.sh → install/sync to $KOOPA_CADDY_DIR/ ``` That rsyncs staging → `/var/www/monitoring-sites`, installs the prepared Caddyfile, reloads Caddy, and smokes mon URLs (including bare surface). ## Manual equivalent ```bash install -d -o hernani -g caddy -m 755 /var/www/monitoring-sites rsync -a --delete $DEPLOY_STAGING (or $HOME/monitoring-sites-staging)/ /var/www/monitoring-sites/ chown -R hernani:caddy /var/www/monitoring-sites install -m 644 $KOOPA_CADDY_DIR/Caddyfile /etc/caddy/Caddyfile caddy validate --config /etc/caddy/Caddyfile systemctl reload caddy systemctl is-active caddy ``` ## Snippet per hacktivism site (inside each `*.hacktivism.ch { }` block) Place **before** the catch-all `reverse_proxy`. Canonical copy: `site-gen/caddy-monitoring-handles.snippet`. Disk layout (path on disk matches URL under host root): ```text /var/www/monitoring-sites/bank.hacktivism.ch/monitoring/index.html /var/www/monitoring-sites/bank.hacktivism.ch/monitoring_err/index.html ``` ```caddy # bare → slash (MUST use redir * /path/ — see footgun below) handle /monitoring { redir * /monitoring/ 302 } handle /monitoring* { root * /var/www/monitoring-sites/{host} file_server } handle /monitoring_err { redir * /monitoring_err/ 302 } handle /monitoring_err* { root * /var/www/monitoring-sites/{host} file_server } ``` ### Caddy redir footgun (merchant code 21) ```caddy # WRONG — parsed as matcher=/monitoring/ to="302" → Location: 302 handle /monitoring { redir /monitoring/ 302 } # RIGHT handle /monitoring { redir * /monitoring/ 302 } ``` Symptom: `https://…/monitoring` or `…/taler-monitoring-surface` returns merchant JSON `{"code":21,…}` while the slash form serves HTML. ## Check ```bash curl -sS -o /dev/null -w '%{http_code}\n' https://bank.hacktivism.ch/monitoring/ curl -sS -D- -o /dev/null https://taler.hacktivism.ch/taler-monitoring-surface | head -15 # bare: expect 302 Location: /taler-monitoring-surface/ — not JSON code 21 curl -sS -o /dev/null -w '%{http_code}\n' https://taler.hacktivism.ch/taler-monitoring-surface/ ``` ## Not needed as root - Running `taler-monitoring` (use **optional outside runner** / laptop) - Writing into podman Taler containers