webhook.py: HMAC-signed receiver (X-Gitea-Signature), validates ref==main,
one-concurrent-deploy lock, no request data reaches shell.
deploy-webhook.sh: installs llm-bench-webhook systemd service (runs as
aygea, in docker group), generates + stores secret in .webhook.secret.
deploy.sh: port read from compose (now 31415).
Installed on mewtwo: listening 0.0.0.0:41798, enabled for boot.
Gitea webhook target: http://10.0.0.22:41798/hook
Co-Authored-By: Claude <noreply@anthropic.com>
Run on mewtwo: bound 0.0.0.0:8081 -> nginx :80.
Rebuilds site from source on every 'deploy.sh up' so new grades
flow through without Coolify. Point Netbird at http://<host>:8081.
Co-Authored-By: Claude <noreply@anthropic.com>