diff --git a/engine/lint-report.md b/engine/lint-report.md index daa1fc5..5926448 100644 --- a/engine/lint-report.md +++ b/engine/lint-report.md @@ -1,6 +1,6 @@ # Vault Lint Report -Generated: 2026-06-21T12:00:06Z | Docs scanned: 92 | Elapsed: 0.0s +Generated: 2026-06-21T18:00:06Z | Docs scanned: 92 | Elapsed: 0.0s ## Summary diff --git a/vault/.obsidian/workspace.json b/vault/.obsidian/workspace.json index f4586f1..5ffe0eb 100644 --- a/vault/.obsidian/workspace.json +++ b/vault/.obsidian/workspace.json @@ -199,6 +199,9 @@ }, "active": "8d53cdb6c257e685", "lastOpenFiles": [ + "projects/fleet-patch-audit.md.tmp.1493418.d8e931cebade", + "projects/fleet-patch-audit.md.tmp.1493418.a678a379866b", + "projects/fleet-patch-audit.md.tmp.1493418.d8edfcdae2a0", "projects/fleet-patch-audit.md.tmp.1493418.2fea79b9eb48", "projects/fleet-patch-audit.md.tmp.1493418.f0355595161e", "projects/fleet-patch-audit.md.tmp.1493418.00879ee0f4e5", @@ -207,9 +210,6 @@ "projects/fleet-patch-audit.md.tmp.1493418.23b2caf55e12", "projects/fleet-patch-audit.md.tmp.1493418.f30558958079", "projects/fleet-patch-audit.md.tmp.1493418.5fe5d2d39856", - "projects/fleet-patch-audit.md.tmp.1493418.6c2a45ea0ecd", - "projects/fleet-patch-audit.md.tmp.1493418.9a000c8ac5aa", - "projects/fleet-patch-audit.md.tmp.1493418.c361bd10be1b", "projects/nominatim-v5-reimport.md", "2026-06-19.md", "Untitled.canvas", diff --git a/vault/projects/fleet-patch-audit.md b/vault/projects/fleet-patch-audit.md index 7856897..798778d 100644 --- a/vault/projects/fleet-patch-audit.md +++ b/vault/projects/fleet-patch-audit.md @@ -150,7 +150,7 @@ Lowest-risk changes first; everything reboot-bearing deferred to scheduled windo |------|-------|---------|-------| | **1 — Guest/VM security apt** | utility CT100,101,102,103,104,106,107,108,109,112,118,119 · cloud CT120,121 · media VM105,CT110,CT111 · data VM1130 · edge2 CT100–107 | No | Lowest blast radius. Worst-first: CT119, CT108, immich/nextcloud guest-OS, peertube. | | **2 — Hypervisor host OS security** | data, utility, cloud, media host OSes (**not toc**) | No | One node at a time; restarts hypervisor-side daemons (smbd etc.). edge2 host already patched. | -| **3 — App / container updates (Tier 2)** | per-app, native updater each | Per-app | **Substantially complete 2026-06-21** — all security-critical apps done; low-urgency batch + cortex AI stack remain. See Phase 2 Execution Log and "special handling" below. | +| **3 — App / container updates (Tier 2)** | per-app, native updater each | Per-app | **COMPLETE 2026-06-21** — all app upgrades done (security-critical, low-urgency batch, and cortex AI stack). See Phase 2 Execution Log. | | **4 — Reboot windows (Tier 3)** | PVE 9.2 + QEMU 11 + LXC 7 + kernel on the 5 PVE-9 nodes; pi-nas kernel + OMV; cortex NVIDIA/DKMS | **Yes** | Schedule deliberately; toc+cortex coordinated. | | **Cross-cutting** | Tailscale 1.94→1.98 fleet-wide | No | Can ride along Phase 1/2. | @@ -264,7 +264,7 @@ Headscale stale-node cleanup: deleted dead nodes `mailcow` (destroyed CT108) and ## Phase 2 — Execution Log (2026-06-21) -**Status: substantially complete; paused 2026-06-21.** All high-priority and security-critical app upgrades are done. Only the low-urgency batch items and the cortex AI stack (protected host, own window) remain. +**Status: COMPLETE (2026-06-21).** All app upgrades done — high-priority, security-critical, low-urgency batch, and cortex AI stack. Only Phase 3 (platform/reboots) and the deferred Nominatim project remain. ### Completed upgrades @@ -320,21 +320,33 @@ Empirically confirmed during the OTS update: updating OTS to 1.7.12 does **not** - **Radarr:** set up a `\\192.168.1.160\manual` SMB drop folder on the same NFS export as the library (atomic-move imports) for manual movie filing. - **Snapshot hygiene:** all rollback snapshots cleaned up after validation — Phase 1 `presec-*`, Phase 2 `prewave2-*`, OTS `pre-ots-*` snapshots all removed. -### Remaining work (next session) +### Completed — low-urgency batch and cortex AI stack -**Low-urgency batch:** -- Caddy (edge2 CT101) -- CouchDB 3.4 → 3.5 (livesync CT104 edge2) -- valkey-8 sidecar (searxng CT102) -- NATS 2.14.0 → 2.14.2 (central CT104 utility) -- MediaMTX 1.13 → 1.19 + Mumble on CT109 (OTS companions, separate from the OTS app) +**Low-urgency batch — DONE:** +- Caddy (utility CT101): 2.10.2 → 2.11.4 +- CouchDB (edge2 CT104 livesync): 3.4 → 3.5.2 — all 5 DBs intact +- valkey-8 sidecar (utility CT102 searxng): bumped to latest 8.x +- NATS (utility CT104 central): 2.14.0 → 2.14.2 — all 12 JetStream streams intact +- MediaMTX (CT109): 1.13.0 → 1.19.1 +- Mumble (CT109): already latest in Ubuntu repo (1.5.517 — no upstream action possible without going off-distro) -**Protected host — own deliberate window:** -- cortex AI stack: ollama 0.16 → 0.30, open-webui, qdrant, TEI +**cortex AI stack — DONE** (protected host; containers only; NO reboot, NO driver touch): +- qdrant: 1.16.3 → 1.18.2 +- tei: 1.7 → 1.9 (bge-m3 on GPU) +- ollama: 0.16.1 → 0.30.10 (vault-tagger 100% GPU) +- open-webui: 0.8.1 → 0.9.6 +- Both `.ref` vault-engine deps (ollama vault-tagger + tei bge-m3) confirmed working on GPU. + +### Minor follow-ups noted (non-urgent) + +- **Caddy expired cert:** Caddy flagged an EXPIRED unmanaged cert for `navidrome.echo6.co` (pre-existing condition, not caused by the upgrade) — fix if that hostname matters. +- **MediaMTX deprecated config params:** 1.19 uses deprecated param names (`protocols` → `rtspTransports`, `encryption` → `rtspEncryption`) — works now (warnings only); rename before a future MediaMTX release removes them. +- **Rollback artifact cleanup:** retained rollback artifacts to clean once comfortable: `/root` DB dumps on their respective CTs (authentik hop1/2/3, forgejo, headscale107, immich, peertube, OTS), binary backups (caddy.bak, nats-server.bak, mediamtx.bak on their CTs), and openwebui DB backup on cortex (`/home/zvx/openwebui-webui.db.bak-20260621`). +- **Vestigial utility exit-node route:** stale 0.0.0.0/0 exit-node route on utility — optional cleanup (harmless post-0.29 Headscale). + +### Separate deferred projects -**Separate deferred projects:** - Nominatim v5 re-import — see [[nominatim-v5-reimport]] -- Optional: clean up retained `/root` DB dumps (authentik hop1/2/3, forgejo, headscale, OTS, immich, peertube, etc.) once upgrades are confirmed stable ---