auto: docs sync 2026-08-24T12:00:05+00:00

Files changed: engine/.embcache.json engine/changelog.md engine/lint-report.md vault/.obsidian/workspace.json vault/docs/services/services.md vault/docs/software/caddy.md vault/docs/software/dns.md vault/runbooks/expose-service-edge2.md vault/runbooks/expose-service-home.md
This commit is contained in:
echo6-autocommit 2026-08-24 12:00:05 +00:00
commit 4526e1843b
9 changed files with 32 additions and 26 deletions

View file

@ -199,6 +199,7 @@
},
"active": "17bd4a6166f789d0",
"lastOpenFiles": [
"docs/software/dns.md.tmp.3790074.04f69e0a9ea6",
"projects/meshtastic-headscale-runbook.md.tmp.3790074.f71d216eecca",
"projects/meshtastic-headscale-runbook.md.tmp.3790074.d94af273bec3",
"runbooks/expose-service-contabo.md.tmp.3790074.70782eb4562c",
@ -210,7 +211,6 @@
"docs/software/dns.md.tmp.3790074.fcdcf768c300",
"docs/software/dns.md.tmp.3790074.404f85bc78a4",
"projects/meshwars.md",
"projects/fleet-storage-memory-upgrade.md.tmp.2730138.81f9975eb3a6",
"runbooks/navi-lift-to-media.md",
"runbooks/edge2-boot-recovery.md",
"runbooks/corescope-ingest-stall-oom.md",

View file

@ -7,10 +7,10 @@ aliases: []
related:
- [[caddy]]
- [[ip-allocation]]
- [[lxc-service-migration]]
- [[meshtastic-headscale-runbook]]
- [[expose-service-edge2]]
updated: 2026-08-14
- [[lxc-service-migration]]
- [[central]]
updated: 2026-08-24
---
# Current Services Inventory
@ -38,10 +38,10 @@ updated: 2026-08-14
| Headscale | edge2 (CT 107) | 100.64.0.38:8084 | https://vpn.echo6.co | Tailscale coordination (OIDC enabled) — fronted by edge2 host [[caddy]] — **migrated from Contabo [[2026-06-19]]** |
| Headplane | edge2 (CT 107) | 100.64.0.38:3100 | https://vpn.echo6.co/admin | Headscale web UI (OIDC via [[authentik]]) — fronted by edge2 host [[caddy]] — **migrated from Contabo [[2026-06-19]]** |
| Mailcow | **edge1 CT 101** (10.10.10.2) | 5.189.158.149 | https://mail.echo6.co | Email server (privileged LXC on rebuilt Contabo VPS, updated commit 52a41b4d / SOGo 5.12.8) — **rebuilt in-place [[2026-06-19]]** |
| MeshWars Preview | utility (CT 113) | 192.168.1.113 / 100.64.0.39:8090 | https://mwpreview.k7zvx.com | Public preview of the unreleased `feat/places` MeshWars branch, running a periodically-refreshed read-only copy of production (CT 119) data; /admin and /api/admin/* return 404 on the public host, admin reachable only over the tailnet |
| Vaultwarden | edge2 (CT 102) | 100.64.0.33:8086 | https://vault.echo6.co | Password manager 1.37.1 (SSO enabled) — fronted by edge2 host Caddy (reverse_proxy 100.64.0.33:8086) |
| [[meshwars]] Preview | utility (CT 113) | 192.168.1.113 / 100.64.0.39:8090 | https://mwpreview.k7zvx.com | Public preview of the unreleased `feat/places` MeshWars branch, running a periodically-refreshed read-only copy of production (CT 119) data; /admin and /api/admin/* return 404 on the public host, admin reachable only over the tailnet |
| Vaultwarden | edge2 (CT 102) | 100.64.0.33:8086 | https://vault.echo6.co | Password manager 1.37.1 (SSO enabled) — fronted by edge2 host [[caddy]] (reverse_proxy 100.64.0.33:8086) |
| Grav | edge2 (CT 101) | 10.10.10.11:80 | https://idahomesh.com (+www) | Flat-file CMS 2.0.11, no database — Admin2 plugin at /admin; Apache 2.4.67 + mod_php + PHP 8.4.21; migrated from WordPress 2026-07-17 (MariaDB purged from the container); hostname still `wordpress` (unchanged) — fronted by edge2 host Caddy via **internal bridge IP** (reverse_proxy 10.10.10.11:80), unlike other edge2 services which proxy over tailnet |
| Syncthing | cortex | 100.64.0.14:22000 | Internal (Tailscale) | File sync — ~/.claude/, ~/projects/ (Syncthing on Contabo decommissioned 2026-06-19 with edge1 rebuild) |
| Syncthing | cortex | 100.64.0.14:22000 | Internal (Tailscale) | File sync — ~/.claude/, ~/projects/ (Syncthing on Contabo decommissioned [[2026-06-19]] with edge1 rebuild) |
| Proxmox VE | data node | 192.168.1.240:8006 | https://proxmox.echo6.co | Cluster web UI (via Caddy+Tailscale) |
| Immich | cloud (CT 120) | 192.168.1.182:2283 | https://immich.echo6.co | Photo management (Docker, NFS storage on pi-nas) |
| Nextcloud | cloud (CT 121) | 192.168.1.183:11000 | https://nextcloud.echo6.co | Cloud storage (AIO Docker, NFS on pi-nas, SSO) |
@ -59,7 +59,7 @@ updated: 2026-08-14
| navi-config | data (VM 1130) | 192.168.1.130:8422 | Internal | [[recon]] [[navi]] node config API |
| navi-contacts | data (VM 1130) | 192.168.1.130:8423 | Internal | [[recon]] [[navi]] contact enrichment API |
| navi-landclass | data (VM 1130) | 192.168.1.130:8424 | Internal | [[recon]] [[navi]] land classification API |
| navi-places | data (VM 1130) | 192.168.1.130:8425 | Internal | RECON navi OSM place detail/enrichment |
| navi-places | data (VM 1130) | 192.168.1.130:8425 | Internal | [[recon]] [[navi]] OSM place detail/enrichment |
| navi-geo | data (VM 1130) | 192.168.1.130:8426 | Internal | RECON navi geocode/reverse geocode API |
| navi-admin | data (VM 1130) | 192.168.1.130:8427 | Internal | RECON navi fleet admin-info aggregator |
| navi-offroute | data (VM 1130) | 192.168.1.130:8428 | Internal | RECON navi off-network router + MVUM API |
@ -149,7 +149,7 @@ updated: 2026-08-14
- `img/echo6-logo.png` — Echo6 logo (replaces [[searxng]] logo)
- `img/favicon.png` — Echo6 favicon
- Config: `/opt/searxng/searxng-config/settings.yml` (instance_name: "Echo6", dark theme, center_alignment: false)
- [[searxng]] version: 2026.2.6 (Docker image: searxng/searxng:latest)
- [[searxng]] version: 2026.2.6 (Docker image: [[searxng]]/searxng:latest)
### utility - CT 104 (192.168.1.104 / Tailscale: 100.64.0.12)
- [[central]] data-hub spine (3 systemd units: central-supervisor, central-archive, central-gui)
@ -202,7 +202,7 @@ updated: 2026-08-14
- Nextcloud AIO (https://nextcloud.echo6.co)
- Apache port 11000, AIO management on 8080
- NFS storage from pi-nas (/mnt/nextcloud)
- SSO via Authentik OIDC
- SSO via [[authentik]] OIDC
### media - VM 105 (192.168.1.160 / Tailscale: 100.64.0.18)
- ARR media automation stack (Docker)
@ -293,7 +293,7 @@ updated: 2026-08-14
- Port: 4403 (default), firmware 2.7.19 (PORTDUINO/native)
- Role: CLIENT_BASE, position: 42.574, -114.607 (manual)
- MAC source: eth0 (derived MAC `00:bd:27:78:0c:47`)
- MeshAI bot (CT 108) connects to this node via TCP `localhost:4403` (Docker network)
- [[meshai]] bot (CT 108) connects to this node via TCP `localhost:4403` (Docker network)
- Service: `meshtasticd.service` (single instance, runs as user meshtastic)
- Config: `/etc/meshtasticd/config.yaml` + `/etc/meshtasticd/config.d/ZebraHat_2W.yaml`
- User: zvx, password auth (`sshpass -p '7redditGold' ssh zvx@aida-nebra`)

View file

@ -9,8 +9,8 @@ related:
- [[ip-allocation]]
- [[lxc-service-migration]]
- [[expose-service-edge2]]
- [[authentik]]
updated: 2026-07-13
- [[matrix-synapse-deployment]]
updated: 2026-08-24
---
# Caddy & DNS Reference
@ -69,7 +69,7 @@ journalctl -u caddy -f
| search.echo6.co | — | — | 301 redirect to echo6.co |
| nas.echo6.co | 100.64.0.21:80 | Tailscale | OpenMediaVault (pi-nas) |
| immich.echo6.co | 192.168.1.182:2283 | Local IP | immich (has 2FA) |
| nextcloud.echo6.co | 192.168.1.183:11000 | Local IP | nextcloud AIO (SSO via Authentik) |
| nextcloud.echo6.co | 192.168.1.183:11000 | Local IP | nextcloud AIO (SSO via [[authentik]]) |
| jellyfin.echo6.co | 100.64.0.18:8096 | Tailscale | Jellyfin media server (SSO via Authentik) |
| requests.echo6.co | 100.64.0.18:5055 | Tailscale | Jellyseer request management (SSO via Authentik) |
| stream.echo6.co | 192.168.1.170:80 | Local IP | peertube video streaming (SSO via Authentik) |
@ -79,7 +79,7 @@ journalctl -u caddy -f
| lidarr.echo6.co | 100.64.0.18:8686 | Tailscale | lidarr music automation (Authentik forward auth) |
| navidrome.echo6.co | 100.64.0.18:4533 | Tailscale | navidrome music server (Authentik forward auth, /rest/* exempt for Subsonic API) |
| vpn.idahomesh.com | 192.168.1.106:8080 | Local IP | IdahoMesh Headscale VPN coordination |
| mwpreview.k7zvx.com | 100.64.0.39:8090 | Tailscale | MeshWars public preview (CT 113, feat/places branch; /admin + /api/admin/* blocked -- 404 -- on this public host, reachable only over tailnet) |
| mwpreview.k7zvx.com | 100.64.0.39:8090 | Tailscale | [[meshwars]] public preview (CT 113, feat/places branch; /admin + /api/admin/* blocked -- 404 -- on this public host, reachable only over tailnet) |
### Commands
@ -145,7 +145,7 @@ dig +short forge.echo6.co @100.64.0.1 # Test
| forge | Forgejo Git |
| vpn | Headscale VPN |
| vault | Vaultwarden |
| matrix | Matrix Synapse |
| matrix | Matrix [[synapse]] |
| element | Element Web |
| notes | LiveSync (CouchDB + provisioner) |
| proxmox | Proxmox VE (via Tailscale to data node) |
@ -177,7 +177,7 @@ dig +short forge.echo6.co @100.64.0.1 # Test
| immich | Immich |
| nextcloud | Nextcloud |
| requests | Jellyseer |
| files | RECON PDF library |
| files | [[recon]] PDF library |
| recon | RECON dashboard |
| lidarr | Lidarr music automation |
| navidrome | Navidrome music server |
@ -246,4 +246,4 @@ oidc:
---
*Last updated: 2026-07-11 — Flip off Contabo completed: "Contabo Caddy" section → "edge2 Caddy" (front door for auth/forge/vpn/vault/matrix/element/notes/proxmox, CTs verified against [[ip-allocation]]/[[services]]); Mailcow + autodiscover/autoconfig moved to edge1 (separate mail-only host, not on edge2); WATCHTOWER + TAK/SIGIL marked decommissioned (dead 100.64.0.1 backends removed); Headscale config location + Port Map updated to edge2; `ssh root@100.64.0.1``ssh edge2`. dnsmasq split-DNS section marked HISTORICAL/OBSOLETE (echo6.co split-DNS retired, ran on the dead pre-2026-06-19 Contabo host, not repointed to edge1/edge2 per [[services]]); GoDaddy DNS Records section corrected — edge2 [[services]] (auth/forge/vpn/vault/matrix/element/notes/proxmox) → 184.174.35.153, mail → edge1 5.189.158.149 (unchanged public IP), wt/tak marked as removed records. Prior: 2026-04-13 — Audit sync: added MAS routing on matrix.echo6.co, lidarr/navidrome/vpn.idahomesh.com to utility Caddy, proxmox/tak to GoDaddy, removed ghost docs.echo6.co entries, added dnsmasq lidarr/navidrome*
*Last updated: 2026-07-11 — Flip off Contabo completed: "Contabo Caddy" section → "edge2 Caddy" (front door for auth/forge/vpn/vault/matrix/element/notes/proxmox, CTs verified against [[ip-allocation]]/[[services]]); Mailcow + autodiscover/autoconfig moved to edge1 (separate mail-only host, not on edge2); WATCHTOWER + TAK/SIGIL marked decommissioned (dead 100.64.0.1 backends removed); Headscale config location + Port Map updated to edge2; `ssh root@100.64.0.1``ssh edge2`. dnsmasq split-DNS section marked HISTORICAL/OBSOLETE (echo6.co split-DNS retired, ran on the dead pre-2026-06-19 Contabo host, not repointed to edge1/edge2 per [[services]]); GoDaddy [[dns]] Records section corrected — edge2 [[services]] (auth/forge/vpn/vault/matrix/element/notes/proxmox) → 184.174.35.153, mail → edge1 5.189.158.149 (unchanged public IP), wt/tak marked as removed records. Prior: 2026-04-13 — Audit sync: added MAS routing on matrix.echo6.co, lidarr/navidrome/vpn.idahomesh.com to utility Caddy, proxmox/tak to GoDaddy, removed ghost docs.echo6.co entries, added dnsmasq lidarr/navidrome*

View file

@ -6,10 +6,10 @@ tags:
aliases: []
related:
- [[caddy]]
- [[services]]
- [[expose-service-home]]
- [[expose-service-contabo]]
- [[usenet]]
- [[expose-service-edge2]]
- [[services]]
- [[headscale-onboard-node]]
updated: 2026-08-24
---
# GoDaddy DNS Management
@ -29,7 +29,7 @@ GoDaddy's API has two kinds of write endpoints for A records:
- `PUT /v1/domains/<domain>/records/A` and `PUT /v1/domains/<domain>/records`
— **replace every record of that type on the whole domain.**
Both `k7zvx.com` and `echo6.co` front live production services (mail, auth,
Both `k7zvx.com` and `echo6.co` front live production [[services]] (mail, auth,
forge, vpn, vault, matrix, element, and more). Calling one of the record-SET
endpoints to "add" a record would wipe every other A record on the zone.
`godaddy-dns.py` only ever uses the single-record endpoint to write, and does

View file

@ -6,8 +6,8 @@ tags:
aliases: []
related:
- [[lxc-service-migration]]
- [[expose-service-contabo]]
- [[expose-service-home]]
- [[expose-service-contabo]]
- [[edge2-access-reference]]
- [[caddy]]
updated: 2026-08-24

View file

@ -9,7 +9,7 @@ related:
- [[expose-service-contabo]]
- [[proxmox-onboard-node]]
- [[headscale-onboard-node]]
- [[ct-runbook]]
- [[lxc-service-migration]]
updated: 2026-08-24
---
# Expose Service on Home Network