A pattern with no leading slash already matched at any depth, but the intent
was not obvious from the rules. State it explicitly and widen to `.env.*` so
variants like .env.local or .env.unraid-api cannot slip through, while keeping
.env.example and .env.<name>.example tracked.
Verified with git check-ignore at the repo root, one level down, and three
levels down.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Replace the assumed/unconfirmed environment notes with facts verified from
this box, and add docs/odin-access.md as the access reference.
Verified:
- Tailscale is the only path from dev to odin. dev (100.94.16.46) is a VPS
with a public IP, not a LAN machine; odin is 100.101.253.105, and a subnet
route puts 192.168.90.0/24 over tailscale0 at the same ~34ms RTT.
- The myunraid.net host is the canonical nginx vhost, not a cloud relay --
DNS resolves it to the private 192.168.90.103, so traffic stays on the
tailnet. The bare IP 404s on /graphql, and plain HTTP 302-redirects to the
myunraid host while stripping the x-api-key header.
- GraphQL is live: unauthenticated POSTs return HTTP 200 with an
UNAUTHENTICATED error body, so 200 must never be read as success.
Corrects unraid-docker-manager's claim that no SSL ignore is needed: TLS
verification fails from dev because ca-certificates 20250419 cannot chain
Let's Encrypt intermediate YR1. The cert is genuine and the claim likely
holds on odin itself, but curl needs -k here.
Container-polling field behaviours (UPPERCASE state, /-prefixed names,
PrefixedID ids, no isUpdateAvailable in 7.2) are carried over from
unraid-docker-manager, which is credited as the authoritative source.
No API key is present on this box; .env.unraid-api is gitignored there and
absent from the clone.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Establish this repo as a collection of independent script folders for the
self-hosted environment (odin, an Unraid host).
- CLAUDE.md: repo conventions, the odin stack, and MemPalace usage. The
infrastructure facts are carried over from the FamilySync project, where
they are documented and verified; the mapping of the name "odin" to that
host is assumed and flagged for confirmation, along with the SSH/deploy
gaps marked "?".
- Core rule: each collection is a self-contained top-level folder owning its
own docs, config, and dependencies. No shared/ or utils/ at the root —
duplication is preferred over coupling so a collection stays independently
deletable.
- _template/: scaffold making that rule concrete. The bash entrypoint ships
strict mode, --dry-run, and a required-env guard (all four paths tested).
- mempalace.yaml: wing "odin-scripts", set explicitly because basename
auto-detection would produce the colliding wing "scripts". Tracked rather
than gitignored so a fresh clone keeps the config; entities.json stays
ignored.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>