Lab note #55: Going public at sudowin.dev: staging, deploys and slimmer backups

The ask

Take the site public at sudowin.dev without exposing openclaw01, keep every change reversible, stop media from bloating git, and update the About page so it describes how the site works now.

What changed

  • Migrated the site to Hostinger behind Cloudflare. openclaw01 is now staging and stays private; only outbound SSH reaches production.
  • New deploy script (ops/deploy.sh): snapshots staging and production, syncs files and the database, rewrites URLs, removes application passwords on production, purges the cache and checks for HTTP 200.
  • Production snapshots and rollback on Hostinger. Unchanged images are hardlinked, so a second snapshot cost 6 MB instead of 437 MB.
  • Media is out of git. A media manifest (path, size, sha256) replaces it, and git rollbacks no longer delete uploads. Old history was rewritten to drop the images: the repo went from 339 MB to 25 MB.
  • Commit IDs in earlier Lab Notes were remapped to the rewritten history, so every change record still points at a real commit.
  • Admin email set to a real mailbox.
  • About page: rewrote “About this site” to cover staging, production, deploys, snapshots and the paper trail.
  • Rules updated: harnesses never edit production directly and only deploy when Paul asks.

How

Claude (Cowork) over SSH: WP-CLI on staging through ops/wp.sh, rsync and mysqldump to production, git filter-repo for the history cleanup.

What worked, what didn’t

  • Hostinger disables proc_open, so wp db export and wp db import fail there. The MySQL client works fine.
  • After the database import the bare domain kept showing Hostinger’s placeholder: the server-level LiteSpeed cache had no plugin to purge it. Turning LiteSpeed Cache back on and purging fixed it, and deploys now keep it active.
  • Staging’s application passwords came over with the database and were valid on the public site. All of them were deleted on production, and every deploy deletes them again.
  • The first test deploy and the force push of the rewritten history were held for Paul’s approval, so production still shows the previous About text until the next deploy.

Change record

Harnessclaude
Date2026-10-11 10:51
Latest snapshot20261011-104959
Undo this sessionops/rollback.sh --git 71e2603

Commits

  • 19b0ad2 content: About page, rewrite About this site for staging/production/deploy design
  • 7ec13c9 config: set admin email to [email protected] (requested by Paul)
  • 37781b4 ops: remove media from git history (filter-repo); remap commit IDs in Lab Notes to rewritten history
  • 6e453cd ops: add production deploy (sudowin.dev), prod snapshot/rollback scripts, stop tracking media in git (media manifest instead)
  • d62eed2 scoreboard: refresh after Lab note #54