docs: migrate Authentik (SSO keystone) to edge2 CT 105

- Authentik -> edge2 CT 105 (Postgres pg_dump/restore; SECRET_KEY carried verbatim; zero-downtime until ~2s cutover)
- Multi-block Caddy cutover: auth.echo6.co + notes.echo6.co outpost/forward_auth -> 100.64.0.36:9000
- runbook: add reboot tailscale-before-docker gotcha; clarify dnsmasq must NOT be repointed (points at Caddy host)
- source left stopped + intact on Contabo as cold rollback

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Matt Johnson 2026-06-18 05:49:07 +00:00
commit 44f0257376
140 changed files with 4013 additions and 24 deletions

100
INDEX.md
View file

@ -1,100 +0,0 @@
---
type: index
title: Echo6 Knowledge Base
updated: 2026-06-17
---
# Echo6 Knowledge Base
The map of this vault — start here. `docs/` is current reference, `runbooks/` is how-to procedures, `projects/` is living context for active work, `notes/` is loose operational notes, and `archive/` is the historical paper trail.
> [!tip] How to use this
> Click any link to jump to that note. Each note shows its **backlinks** (what points to it) at the bottom — including this index — so you can always get back home. The **graph view** (left ribbon) shows how it all connects.
---
## 🧭 Reference — current state (`docs/`)
**Infrastructure**
- [[environment]] — Proxmox cluster, VMs, LXCs, Headscale nodes, SSH access
- [[ip-allocation]] — full 192.168.1.x IP allocation table (LXCs, VMs, hosts, Meshtastic nodes, Tailscale IPs)
- [[services]] — full services inventory by server (ports, compose paths, access URLs)
- [[ots-setup]] — OpenTAKServer on CT 109 (native install, MQTT gateway, Meshtastic integration, troubleshooting)
- [[usenet]] — SABnzbd + Usenet providers & indexers
**Software / platforms** (`docs/software/`)
- [[authentik]] — SSO: OAuth2 providers, groups, flows, branding, enrollment
- [[caddy]] — reverse proxy (Contabo + utility), dnsmasq split DNS, GoDaddy records, port map
- [[dns]] — GoDaddy DNS script, managed domains, common patterns
- [[recon]] — RECON knowledge-extraction pipeline (architecture, stack, API)
- [[searxng]] — Echo6 Search homepage (theme, config, deploy)
- [[geo-tools]] — cortex geo-processing tools (GDAL, tippecanoe, pmtiles)
**Matrix / Signal** (`docs/matrix/`)
- [[synapse]] — Synapse + MAS + Postgres + Caddy deployment reference
- [[mautrix_signal]] — Signal bridge (image, DB, E2BE, commands)
- [[archivist]] — CT 118 Signal/Matrix archive bot
- [[matrix_host]] — Contabo VPS host specs
- [[synapse_retention_discovery]] — retention config, MSC2815, DB sizes, rollback
**navi** (`docs/navi/`)
- [[cc-rules]] — Claude Code rules for working on navi
- [[deployment]] — navi build/deploy (VM 1130, nginx, Caddy route, rollback)
- [[themes]] — navi theme system (registry, namedTheme rule, CSS vars)
---
## 🛠️ Procedures (`runbooks/`)
- **Authentik:** [[authentik-oidc-application]] · [[authentik-access-groups]] · [[authentik-create-invitation]] · [[authentik-upgrade]]
- **Exposing a service:** [[expose-service-contabo]] · [[expose-service-home]]
- **Service migration:** [[lxc-service-migration]] — move a Contabo-Caddy-fronted service to edge2 LXC (Vaultwarden pilot 2026-06-16)
- **Proxmox / hosts:** [[ct-runbook]] · [[proxmox-create-ubuntu-vm]] · [[proxmox-onboard-node]] · [[pi-nas-omv-runbook]] · [[headscale-onboard-node]]
- **RECON:** [[recon-operations]] · [[recon-service-integration]]
- **Mesh / Meshtastic:** [[meshtastic-sidecar-node]] · [[meshtasticd-sim-nodes-runbook]] · [[idahomesh-bridge-setup]] · [[idahomesh-vpn-device-setup]] · [[meshmonitor-password-reset]]
- **PeerTube / media:** [[add-peertube-channel]] · [[peertube-remote-runner]]
- **Internet Archive:** [[ia-cli-reference]] · [[ia-download-mirror]]
- **Patterns & infra:** [[pipeline-patterns]] · [[pg-backup]] · [[nordvpn-lxc]] · [[syncthing-add-node]] · [[mailcow-create-mailbox]]
---
## 📦 Projects (`projects/`)
Living "read-me-first" context for active work:
- [[advbbs-project]] — advBBS Meshtastic federated BBS
- [[mmud-project]] — MMUD mesh dungeon game
- [[argus]] — ARGUS OSINT intelligence platform (in progress)
- [[deploy-livesync]] — Obsidian LiveSync (CouchDB + JWT) reference
- [[matrix-synapse-deployment]] — Matrix Synapse + Element + SSO rebuild reference
- [[meshtastic-headscale-runbook]] — IdahoMesh Headscale + bridge
---
## 🗒️ Notes (`notes/`)
- [[ia-download-queue]] — Internet Archive pull-down queue (operational tracking)
- [[echo6-landing-page-data-export]] — platform/brand/services reference snapshot
---
## ⚙️ Baseline & rules
- [[CLAUDE-baseline]] — the global Claude Code rules (read-only mirror of `~/.claude/CLAUDE.md`)
- `rules/` — per-system conventions (docker, proxmox, caddy, tak, meshtastic, …) — read-only mirror of `~/.claude/rules/`
---
## 🔄 Session resume (`session-resume/`)
Live handoffs for sessions paused on one machine and resumed on another (cross-machine `~/.claude` sync is parked). Tagged `#session-resume`; `status: open` = not yet finished.
- [[SESSION-HANDOFF-meshai-test]] — paused: pulling MeshAI (CT 108) logs to see how it handled the aida-nebra radio drop. Blocked from matt-desktop (no SSH key on utility); resume on cortex. `#open`
---
## 🗄️ Archive
Historical material lives in `archive/` — paper trail, not living docs:
- `archive/projects/` + `archive/reports/` — completed one-time deploy logs and migration reports
- `archive/matrix/` — the Matrix-archive investigation saga: the rejected Hookshot path and the [[PHASE6_DECISION]] decision record
- `archive/AUDIT-2026-02-21.md` — the Feb 2026 doc-vs-infra audit