The app is pre-launch and shared by link with a handful of people at Prime
Intellect. It should not be accumulating a search footprint yet.
Three layers, because each covers a gap the others leave:
- robots.txt asks well-behaved crawlers not to fetch at all.
- The <meta name="robots"> tag covers the HTML document for anything that
fetched anyway.
- X-Robots-Tag covers everything that is NOT the HTML document — og.png,
the manifest, the built assets — which the meta tag cannot reach.
noarchive and nosnippet are there so a cache or an excerpt cannot outlive
the page once this is reversed.
Deliberately NOT stripped: the og:/twitter: tags. Link unfurlers are not
crawlers — they fetch on behalf of the person pasting the link, and a
rendered card is exactly what we want when this is shared.
The real gate remains authentication: / returns the sign-in screen and every
/api/ route returns 401. This only stops the app being indexed.
To go public: delete robots.txt, drop the meta tag, drop the header.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The deployment came up healthy, served a valid certificate, and returned 200 —
and was completely unreachable. Two distinct causes, both invisible from
inside the host:
1. Every other site on this proxy binds to a private VNIC address. Caddy
groups site blocks into servers BY listen address, so a block without
`bind` landed in a separate server on :443. The specific listener wins for
traffic arriving on that address, which is all public traffic after NAT, so
requests hit the server that had never heard of these hostnames and fell
through to an empty 200. Testing from the host with --resolve 127.0.0.1
worked perfectly, which is exactly why this was worth chasing from a third
machine instead of trusting a local check.
2. The CSP blocked the inline pre-paint theme script, so dark-mode users would
have seen a white flash on every load. Fixed with the script's hash rather
than 'unsafe-inline', which would have defeated the policy, and rather than
an external file, which would have reintroduced the flash. Editing that
script changes its hash and silently breaks it, so that is written down.
Verified from an independent host: health returns JSON, the app serves, an
unauthenticated API call is refused, the short alias redirects, security
headers are present, and the existing sites on the proxy are unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One container plus a Postgres behind any TLS-terminating proxy. Nothing is
specific to a particular host.
The app and API are served from a SINGLE origin. This is not tidiness: browser
auth sessions live in per-origin storage, so splitting them across two
hostnames makes sign-in loop in a way that presents as a server fault. The
short alias redirects rather than serving a second origin.
Two safety properties verified by running the image, not by reading the code:
- With NODE_ENV=production and no SUPABASE_URL, the process refuses to start
and says why. Serving the whole CRM unauthenticated is a worse outcome than
failing to deploy, so the failure is deliberate and loud.
- In production the development auth bypass does not apply: an unauthenticated
request to /api/dashboard returns 401 rather than adopting the first user in
the table.
The Dockerfile typechecks all six packages as a build gate, so a deploy that
does not compile fails at build time rather than in front of a user. Runtime
runs unprivileged as `node`, and Postgres is not published to the host.
Docs cover the ontology and why it is shaped this way, agent connection for
Claude Code / Codex / prime-agent / Buzz, and the provenance rules governing
seed data about real people — including how to have your record removed.
Verified: image builds, container reports healthy, serves the SPA, enforces
auth, and the production guard exits non-zero.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>