Range-diff !501

back to !501 web: one register for empty states and contribution hints

 -:  ------- >  1:  ca8187d runner next: say whether the build is trusted
 -:  ------- >  2:  94f55ff runner: disposable home for untrusted builds
 -:  ------- >  3:  7b64442 wiki: trusted and untrusted build homes
 -:  ------- >  4:  b022fed status set: ci/ is reserved for the instance's builds
 -:  ------- >  5:  b1f4bf1 ci: reuse only trusted results on the job's image
 -:  ------- >  6:  dc10160 repo settings: required contexts turn the checks gate on, pending until reported
 -:  ------- >  7:  d19e518 wiki: reserved ci/ statuses, trusted reuse, required contexts
 -:  ------- >  8:  7a5f2a1 changelog: #255, #258
 -:  ------- >  9:  42a7b12 wiki, changelog: last finisher sets ci/<job>; required contexts report on heads
 -:  ------- > 10:  c21c7ea runner next: send the instance's public ssh destination
 -:  ------- > 11:  28f6758 runner: builds off the host's loopback when the runner polls over it
 -:  ------- > 12:  23e979a sshd: test the auth limiter's lockout by registration mode
 -:  ------- > 13:  9809a86 runner host: builds reach only the forge's public ports on it
 -:  ------- > 14:  9467ed2 runner egress: remove the rule when it blocks the runner's poll
 -:  ------- > 15:  26e387e wiki: what a build can reach
 -:  ------- > 16:  24c714d runner: builds reach the forge at pasta's host address
 -:  ------- > 17:  dcd9380 runner: only a loopback runner's podman builds leave -remote
 -:  ------- > 18:  b4e14d4 store: failed step and reason on a build
 -:  ------- > 19:  6421e2f runner done: record the failed step and reason
 -:  ------- > 20:  286e0c3 runner: name the failed step and report it
 -:  ------- > 21:  e6b51c1 build show: failed step and duration; build log --step, --tail
 -:  ------- > 22:  ec5fe62 web: build log folded by step, failed step open
 -:  ------- > 23:  bb4c0ae wiki: failed step, build log --step and --tail
 -:  ------- > 24:  3bcdce3 web: step fold shows the step's first line; changelog: deploy order
 -:  ------- > 25:  e5b80f7 control: runner done parses its flags through c.parseArgs
 -:  ------- > 26:  ed99c93 seal: AES-256-GCM keyring for secret columns
 -:  ------- > 27:  b13a247 config: server.secret_key_file, outside server.root
 -:  ------- > 28:  1ec2c9c store: seal CI secrets, webhook secrets, mirror tokens and device tokens
 -:  ------- > 29:  24b9cdb gitbayd: load the secret key file; admin secrets init, rotate, check
 -:  ------- > 30:  1481a12 e2e: a key file per instance; the archive carries secrets sealed and no key
 -:  ------- > 31:  7e5de53 deploy, wiki: provision and document the secret key file
 -:  ------- > 32:  03e5ee3 config: [backup] age_recipients (filippo.io/age v1.3.2)
 -:  ------- > 33:  12a6859 backup: encrypt archives to [backup] age_recipients; --verify --identity
 -:  ------- > 34:  03757af deploy, wiki: encrypted archives in the backup scripts and docs
 -:  ------- > 35:  0d343c9 sshd: the disable test waits for the connection's account to be recorded
 1:  44c1222 = 36:  584dc8d web: one empty-state register — no CLI commands, no 'yet' on finished items
 2:  5dc95a2 = 37:  a8ca19c web: MR list offers a fork link or a sign-in prompt to visitors who cannot open one directly
 3:  707bbcb = 38:  ff759b5 web: search scope caption is permanent; document the tab zero-count rule