Force push
Force Push
We pulled a copy of the crownspire-deploy repository off a leaked Cinderbound backup. Word is the production warden's key for the reliquary got committed by mistake and then cleaned up before anyone noticed. The current history looks spotless. Recover what they tried to bury.
โจทย์ข้อนี้เกี่ยวกับข้อใูลที่ถูกลบใน git ลองเช็ค log ดู
git log --oneline --all
7ae3842 (HEAD -> main) docs: creds come from CI secret store / local .env only
4c92bf1 chore: gitignore .env and *.creds so keys never land in git again
7440b30 deploy.sh: load creds from env, retry once on 403
dbe130d bump version to 0.3.0-dev; update changelog
8ed496f chore: add bug report issue template
2b258f6 add key rotation script + ashmarch example manifest
1178aec docs: architecture overview
0a12d7d docs: security policy + CODEOWNERS
721969d cli: load local .env automatically (--env-file)
2944d91 tests: dotenv loader
5156ee7 add tiny built-in dotenv loader (no third-party dep)
3598356 cli: add altar subcommand
0c08713 tests: altar verification
694e71a add altar-side verification of published sets
5853566 release: 0.2.0
ไม่เจออะไรน่าสนใจ เลยเช็ค reflog
ไม่มีอะไรอยู่แสดงว่าถูก clone มา ลองเช็ค fsck ดู
git fsck
Checking ref database: 100% (1/1), done.
Checking object directories: 100% (256/256), done.
dangling commit 3c8803d7146cd07c75325d6b555116200f2569ee
เจอ commit ที่น่าสนใจเลยลอง show ดู
git show 3c8803d7146cd07c75325d6b555116200f2569ee
commit 3c8803d7146cd07c75325d6b555116200f2569ee
Author: Doran Ash <d.ash@crownspire.valyssar>
Date: Wed May 27 23:47:19 2026 +0000
temp: add reliquary.creds to debug 403 on manifest push (REVERT ME)
diff --git a/reliquary.creds b/reliquary.creds
new file mode 100644
index 0000000..12b1497
--- /dev/null
+++ b/reliquary.creds
@@ -0,0 +1,6 @@
+# Crownspire reliquary -- production warden's key. DO NOT COMMIT.
+RELIQUARY_ENDPOINT=https://reliquary.crownspire.valyssar:9000
+RELIQUARY_BUCKET=crownspire-reliquary-prod
+AWS_ACCESS_KEY_ID=AKIACROWNSPIRE7WARD3N
+AWS_SECRET_ACCESS_KEY=HTB{th3_r3l1qu4ry_n3v3r_f0rg3ts}
+WARDEN_SIGNING_KEY=astrael-relic-sigil-2f9c