root@ works fine (standard key, same as every other host) — the
SSH-blocked claim was from a session that only tested malin@pinky.
Adds real survey detail: SDK path, no-JDK-on-host build pattern, the
shared Android emulator container.
Pinky was missing from the map entirely. Documents its purpose
(Docker/Linux-only workloads, esp. Android SDK/emulator builds) and the
current SSH access gap (root's key not authorized, user is malin) found
while chasing an apuntiq Android build.
- server-fleet-map: add gringo row
- bastille-jail-provisioning: elevate default-deny-outbound to the standard
for every new jail; reference gringo's live pf.conf
- modded-app-update-pattern: new skill, fork/rebase pattern for locally
patched apps; uses tailnetatlas on gringo as the concrete example
- dependency-vuln-scanning: new skill, npm audit / pip-audit / osv-scanner
cadence for deployments and monthly thereafter
WordPress plugin rebrand/conventions/remote-CLI patterns, Gitea release
workflow, bastille jail provisioning, remote shell quoting safety, server
fleet map, delegate brief writing, and verification discipline -- all
derived from real incidents this session, plus two skills adapted (MIT
license, attributed) from obra/superpowers and andrej-karpathy-skills.