# Live local services — 2026-09-12

Gitea at http://localhost:3000 and Drone at http://localhost:8085 passed their
health checks. Real Gitea OAuth login to Drone succeeded. The Docker runner
connected to Drone using the dedicated local Podman build engine.

The private gitea-admin/my-app repository was activated in Drone; Gitea's
webhook triggered real builds from pushed commits. Build #1 exposed a host
bridge isolation problem during clone. After configuring the dedicated CI
bridge and local forwarding, build #2 passed every step: clone, build-image,
Syft, Grype, Trivy, security-gate, and evidence. See live-build.json and build-2/.

The services remain running. devsecops-local-engine.service and
 devsecops-local-services.service are enabled and active. Scanner data uses the
existing offline snapshots, with freshness checks preserved. No application
was deployed, and no Jira or JFrog results were published.

Existing Gitea data was retained. Its webhook allowlist was extended to permit
localhost; the prior configuration was backed up privately. OAuth and Drone
credentials are kept in config/ with restricted permissions. Only the local
my-app repository is accepted by this runner.
