Skip to content

Access inventory

If something here is lost or leaked, this page says what it unlocks and where to rotate it.

Credential Unlocks Kept where Rotate at
Hangar API token deploy, env, start/stop for every site on admin.mohanad.xyz owner’s password manager; HANGAR_TOKEN when deploying Hangar dashboard → tokens (tokens cannot create tokens)
Cloudflare API token zone mohanad.xyz: cache rules, WAF rate limits (not Bot Management) owner’s password manager Cloudflare → My profile → API tokens
Neon API key the retired kalelm-test project delete it Neon console
Hugging Face token (coder0x9, named mac) downloading the gated Cohere ASR model on a worker ~/.cache/huggingface/token on each worker huggingface.co → settings → tokens
CRON_SECRET the pipeline endpoints (claim, heartbeat, complete) for any worker, and Payload’s cron runner Hangar env + every worker’s environment generate a new value, PUT Hangar env, update workers
PAYLOAD_SECRET signs admin sessions; changing it logs everyone out Hangar env same
MEILI_MASTER_KEY full control of the search index Hangar env and /srv/kalelm/.env on the search VPS change both, docker compose up -d meilisearch
POSTGRES_PASSWORD the archive database /srv/kalelm/.env and inside Hangar’s DATABASE_URL ALTER USER kalelm PASSWORD …, then both places
Search VPS root ssh everything on 49.12.78.95 owner’s ~/.ssh/id_rsa is authorized edit /root/.ssh/authorized_keys
Hangar box root ssh everything on 188.245.169.96 owner’s ~/.ssh/id_rsa, plus the search VPS’s id_ed25519 for backups same
Payload admin users the admin panel; admin role can delete and manage users, editor cannot users collection admin → المستخدمون

Three of these were pasted into chat on 2026-09-09 (Hangar, Neon, Cloudflare) and should be rotated.

From To Allowed
Internet Cloudflare → Hangar sites 80/443
Internet search VPS 22 only (plus 80 for certificate issuance)
Hangar server 188.245.169.96 search VPS 443 (Meilisearch, Ollama via Caddy), 5432 (Postgres, TLS)
search VPS Hangar server 22, for the nightly backup copy
Workers (anywhere) Hangar API, files.kalelm.com, Hugging Face outbound only
Machine Provider Admin path
Hangar box the owner’s PaaS, behind Cloudflare Hangar dashboard/API; root ssh for anything Hangar does not cover
Search VPS Hetzner ubuntu-4gb-fsn1-2 root ssh; /srv/kalelm Compose stack; ufw
files.kalelm.com existing media host, untouched by this project unknown to this project; it holds the only copy of the audio