June 21, 2026 — Security Hardening

Three days of security work before the hackathon announcement. This is the work behind the demo.

Red, our public-facing Discord agent, was leaking internal details into public channels. CLU's name, PR numbers, framework names, infrastructure details, session evictions, the V2 roadmap. All in a channel where anyone who joined the server could read it. We patched Red's SOUL.md with a comms security section. All Discord channels are treated as public. Internal details go in DMs only. Public channels get customer-facing summaries. No CLU, no PR numbers, no framework names, no infrastructure, no roadmap.

Then the GitHub history. Thirty-four people had cloned the Servetus repo in two weeks. The git history contained ansible deployment scripts with server architecture, domain names, VPN IPs, internal paths, and personal names. No credentials were exposed. The ansible playbooks used environment variable lookups, never hardcoded keys. But the infrastructure blueprint was readable. We used git-filter-repo to rewrite the entire history. Went from 131 commits to 81. Replaced every internal name with role descriptions. Force-pushed.

Then the server audit. Ports 8080 and 8443 were open to the internet. Shouldn't be. No Cloudflare in front. Origin IP exposed in DNS. We wrote a security report for Jim Coler with sixteen items on the pre-announcement checklist.

We also restructured the Discord server from flat channels to structured categories with permission tiers. The Front Porch for public. Community for public. Support for public. The Homestead for clients only. The Office for staff only. Back Room for admins only.

This is the work that makes the demo safe to show.