# Status — deploy (digalot.fyi/festifun) ## Round 1 — 2026-07-16 — STATUS: app deploy-ready; BLOCKED on server access **Ask:** host the app live at `digalot.fyi/festifun` on `dealgod@100.94.195.115` (tailscale). **Owner decision:** fully open (all features public + unauthenticated). Risk flagged + accepted. ### Done — the app is now deployable behind a path prefix - **Frontend deploy-ready.** `API_BASE` is env-driven (`VITE_API_BASE`, default `localhost:8000` so dev is unchanged); added `vite.config.js` with `base` from `FESTIVAL4D_BASE`. A prod build `FESTIVAL4D_BASE=/festifun/ VITE_API_BASE=/festifun npm run build` emits assets under `/festifun/` with the API base baked as `/festifun` (localhost:8000 absent from the bundle). - **Validated end-to-end locally.** Built the prod bundle, ran a Python reverse proxy mirroring the nginx config (static + prefix-stripping `/festifun/api` & `/festifun/media` with Range), loaded it in a browser: **app boots, manifest/pointcloud proxy OK, media Range = 206, videos play, 3D scene + overlays + timeline all render under the `/festifun` prefix.** - **Deploy artifacts written** in `deploy/`: `festifun.nginx.conf` (location blocks, prefix strip, Range), `festifun-api.service` (uvicorn on 127.0.0.1:8000, localhost-only, no keys), `DEPLOY.md` (build → rsync → service → nginx, plus Caddy note). - Default build unchanged (root asset paths); backend suite still **103 passed**. ### Deliberate deploy choice — keys OFF the public box `POST /api/events/detect` spends real AI credits. Rather than expose that on an unauthenticated public endpoint, moment labels are baked into the shipped DB by running `events` locally before deploy; the server carries no `GEMINI_API_KEY`/OpenRouter creds and `detect` degrades to candidate-only (no spend). Owner can opt into live classification, but that needs nginx rate-limiting first (documented in DEPLOY.md). ### BLOCKED — cannot finish without server access - My SSH key is **not authorized** on `dealgod@100.94.195.115` (rejected directly and via the johnking box — both `Permission denied (publickey)`). Need the key added to that host's `~/.ssh/authorized_keys`: `ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPL3EE4wE6nv0V0BNMbJ0Gl+px3wOM8K+V6LvCJZa7PM monsterrobotparty@gmail.com` - Also need to know the server's web stack (nginx vs caddy, where digalot.fyi's server block lives). Recon command in the chat; I'll adapt the config once I can see it. **Next (once access granted):** recon the web stack → adapt `deploy/festifun.nginx.conf` (or write the Caddy equivalent) → build+rsync+service+reload per DEPLOY.md → verify `https://digalot.fyi/festifun/`.