Per-bottle git-gate state (bare repos under /git/<id>, deploy creds under
/git-gate/creds/<id>) was provisioned once at bottle launch and lived only
in the gateway's ephemeral storage. A gateway rebuild/restart wiped it and
nothing re-provisioned already-running bottles, so their agents 404'd on
fetch/push. Same class of bug as the CA (#510); the orchestrator restores
only egress tokens, not git-gate declarations.
Persist the state on both backends, mirroring the CA-persistence approach:
- firecracker: attach a second persistent data drive (/dev/vdc) to the
gateway VM and bind-mount its git/ + creds/ subdirs onto /git and
/git-gate/creds in the gateway guest init, before the data plane starts.
Generalize the VM config to a stable-ordered data_drives tuple (CA=vdb,
git=vdc; orchestrator registry stays vdb).
- docker: bind-mount host dirs (host_gateway_git_dir / creds_dir, under the
never-pruned app-data root) onto /git and /git-gate/creds, with
BOT_BOTTLE_DOCKER_GIT_MOUNT / _CREDS_MOUNT env overrides so CI isolates
them to per-run volumes it cleans up.
Teardown already rm -rf's /git/<id> + creds, so the persistent store
self-cleans over the normal lifecycle.
Closes#512
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>