From 75df23b89e72d831264c8a049b68094a75f92ba1 Mon Sep 17 00:00:00 2001 From: echo6-autocommit Date: Fri, 19 Jun 2026 00:00:09 +0000 Subject: [PATCH] auto: docs sync 2026-06-19T00:00:09+00:00 Files changed: engine/lint-report.md vault/.obsidian/graph.json vault/.obsidian/workspace.json vault/docs/hardware/environment.md vault/docs/services/services.md vault/docs/software/central.md vault/docs/software/navi.md vault/docs/software/recon.md --- engine/lint-report.md | 8 +-- vault/.obsidian/graph.json | 2 +- vault/.obsidian/workspace.json | 24 ++++--- vault/docs/hardware/environment.md | 21 ++++-- vault/docs/services/services.md | 58 +++++++++++++---- vault/docs/software/central.md | 100 +++++++++++++++++++++++++++++ vault/docs/software/navi.md | 94 +++++++++++++++++++++++++++ vault/docs/software/recon.md | 11 ++-- 8 files changed, 280 insertions(+), 38 deletions(-) create mode 100644 vault/docs/software/central.md create mode 100644 vault/docs/software/navi.md diff --git a/engine/lint-report.md b/engine/lint-report.md index e0379dd..d6a8efa 100644 --- a/engine/lint-report.md +++ b/engine/lint-report.md @@ -1,6 +1,6 @@ # Vault Lint Report -Generated: 2026-06-18T17:51:42Z | Docs scanned: 87 | Elapsed: 0.0s +Generated: 2026-06-18T20:57:00Z | Docs scanned: 89 | Elapsed: 0.0s ## Summary @@ -92,13 +92,12 @@ Matt decides whether to create a real doc — when he does, future sweeps will l | Term | Docs mentioning it | |------|--------------------| -| `tailscale` | 31 | +| `tailscale` | 32 | +| `docker` | 28 | | `proxmox` | 28 | -| `docker` | 27 | | `headscale` | 21 | | `peertube` | 15 | | `meshtastic` | 14 | -| `navi` | 14 | | `mailcow` | 11 | | `forgejo` | 10 | | `immich` | 10 | @@ -107,3 +106,4 @@ Matt decides whether to create a real doc — when he does, future sweeps will l | `jellyfin` | 9 | | `meshtasticd` | 9 | | `aida-nebra` | 8 | +| `livesync` | 8 | diff --git a/vault/.obsidian/graph.json b/vault/.obsidian/graph.json index 9ff03c0..4d02633 100644 --- a/vault/.obsidian/graph.json +++ b/vault/.obsidian/graph.json @@ -60,6 +60,6 @@ "repelStrength": 20, "linkStrength": 1, "linkDistance": 500, - "scale": 0.08779149519890246, + "scale": 0.1316872427983537, "close": false } \ No newline at end of file diff --git a/vault/.obsidian/workspace.json b/vault/.obsidian/workspace.json index 8cc417b..7e0738b 100644 --- a/vault/.obsidian/workspace.json +++ b/vault/.obsidian/workspace.json @@ -11,10 +11,14 @@ "id": "8d53cdb6c257e685", "type": "leaf", "state": { - "type": "graph", - "state": {}, - "icon": "lucide-git-fork", - "title": "Graph view" + "type": "markdown", + "state": { + "file": "docs/hardware/environment.md", + "mode": "source", + "source": false + }, + "icon": "lucide-file", + "title": "environment" } } ] @@ -195,10 +199,15 @@ }, "active": "8d53cdb6c257e685", "lastOpenFiles": [ + "rules/proxmox.md", + "docs/services/services.md", + "docs/software/central.md", + "docs/software/navi.md", + "docs/hardware/environment.md.bak", + "docs/services/services.md.bak", "archive/projects/mmud/mmud-phase6-prompt.md", "archive/projects/last-ember-project.md", "projects/mmud-project.md", - "docs/services/services.md", "concepts/lxc-container.md", "concepts/osint.md", "concepts/split-dns.md", @@ -220,9 +229,6 @@ "entities/mesh-bridge.md", "entities/meshtastic-hs.md", "entities/tei.md", - "entities/qdrant.md", - "entities/recon-vm.md", - "entities/utility.md", "entities", "credentials.tmp.40509.595364788ca8", "runbooks/lxc-service-migration.md.tmp.40509.ac2c03680b76", @@ -230,8 +236,6 @@ "runbooks/lxc-service-migration.md.tmp.40509.ae9f0d9aaaea", "runbooks/lxc-service-migration.md.tmp.40509.f6c568f75061", "docs/hardware/ip-allocation.md.tmp.40509.03b7ba9c244f", - "docs/hardware/ip-allocation.md.tmp.40509.a068767a4b20", - "docs/hardware/ip-allocation.md.tmp.40509.da0228cd9f66", "assets/echo6yellow_logo_422x422_square.png", "assets/echo6yellow_logo_422x81.png", "assets/echo6_logo.png", diff --git a/vault/docs/hardware/environment.md b/vault/docs/hardware/environment.md index 65c4a60..3900471 100644 --- a/vault/docs/hardware/environment.md +++ b/vault/docs/hardware/environment.md @@ -20,7 +20,7 @@ Five nodes running Proxmox VE: | Node | Local IP | Tailscale | Hardware | RAM | Purpose | | ------- | ------------- | ----------- | ----------------------------------------------- | -------------- | -------------------------------- | -| data | 192.168.1.240 | 100.64.0.6 | AMD Ryzen 7 PRO 5750GE, 1TB NVMe + 1TB SATA SSD | 32GB DDR4-3200 | Database [[services]] | +| data | 192.168.1.240 | 100.64.0.6 | AMD Ryzen 7 PRO 5750GE, 1TB NVMe + 1TB SATA SSD | 32GB DDR4-3200 | Database [[services]] | | utility | 192.168.1.241 | 100.64.0.5 | AMD Ryzen 7 PRO 5750GE, 512GB NVMe | 32GB DDR4-3200 | Utility services, monitoring | | cloud | 192.168.1.242 | 100.64.0.4 | Intel i7-12700T, 512GB NVMe | 32GB DDR4-3200 | Cloud storage, personal services | | media | 192.168.1.243 | 100.64.0.3 | Intel i7-14700T, 2x 512GB NVMe | 32GB DDR5-5600 | Media server, *arr stack | @@ -52,7 +52,7 @@ Five nodes running Proxmox VE: | VM | Host | VMID | Local IP | Tailscale | Purpose | |----|------|------|----------|-----------|---------| | cortex | toc | 150 | 192.168.1.150 | 100.64.0.14 | GPU compute — Open WebUI, Ollama, Qdrant, TEI, Claude Code | -| recon-vm | data | 1130 | 192.168.1.130 | 100.64.0.24 | [[recon]] knowledge extraction pipeline, Files, Kiwix | +| recon-vm | data | 1130 | 192.168.1.130 | 100.64.0.24 | [[recon]] + [[navi]] platforms, Files, Kiwix, geo backends | | arr | media | 105 | 192.168.1.160 | 100.64.0.18 | ARR media automation stack (Jellyfin, Sonarr, Radarr, etc.) | ### cortex VM Details @@ -69,8 +69,9 @@ Five nodes running Proxmox VE: ### recon-vm Details - **OS:** Ubuntu 24.04.4 LTS (cloud-init), kernel 6.8.0-110-generic -- **Resources:** 4 cores, 16GB RAM, 100GB disk +- **Resources:** 4 cores, 24GB RAM, 180GB disk - **Software:** Docker 29.4.0, Python 3.12.3, nginx, sqlite3, Tailscale +- **Platforms:** [[recon]] (knowledge extraction pipeline, :8420) and [[navi]] (offline navigation, navi.echo6.co, :8440) with geo backends (Valhalla :8002, Nominatim :8010, Photon :2322, PostgreSQL/PostGIS :5432) - **Systemd services:** recon (8420), recon-watchdog, kiwix (8430), nginx (8888) - **NFS mounts:** pi-nas:/export/library → /mnt/library, /mnt/nav, /mnt/kiwix - **User:** zvx (sudo, SSH key auth) @@ -96,11 +97,12 @@ Five nodes running Proxmox VE: | mt-isr | 192.168.1.141 | 100.100.0.5 (IdahoMesh) | Meshtastic sidecar Pi (G2 WiFi bridge, meshtasticd, CLI) | | mt-burleybutte | 192.168.1.185 | — | Meshtastic node (meshtasticd, Nebra 2W hat, IdahoMesh VPN) | | pi-nas | 192.168.1.245 | 100.64.0.21 | Raspberry Pi NAS | -| matt-desktop | 192.168.1.111 | 100.64.0.10 | Personal workstation (Windows, your PC) | +| matt-desktop | 192.168.1.254 | 100.64.0.10 | Personal workstation (Windows, your PC) | + | Contabo Server | 5.189.158.149 | 100.64.0.1 | External VPS: Mail, [[authentik]], Headscale, Forge, Matrix | | edge2 | 184.174.35.153 | 100.64.0.26 | Contabo Cloud VPS 30 NVMe — Proxmox VE 8.4.19 (LXC-only), 8c/24GB/400GB | -*Last updated: 2026-06-18 — Added edge2 CT 105 (authentik, 10.10.10.23, 100.64.0.36, node 48, migrated 2026-06-18); previously added CT 104 (livesync), CT 103 (forgejo), CT 102 (vaultwarden), pdm CT 100, wordpress CT 101* +*Last updated: 2026-06-18 — Added central (utility CT 104, 192.168.1.104, 100.64.0.12); also added edge2 CT 105 (authentik, 10.10.10.23, 100.64.0.36, node 48, migrated 2026-06-18); previously added edge2 CT 104 (livesync), CT 103 (forgejo), CT 102 (vaultwarden), pdm CT 100, wordpress CT 101* ## LXC Containers @@ -116,7 +118,9 @@ Five nodes running Proxmox VE: | meshai | utility (CT 108) | 192.168.1.144 | 100.64.0.32 | MeshAI - LLM-powered Meshtastic assistant | | [[archivist]] | utility (CT 118) | 192.168.1.118 | — | Archivist knowledge pipeline | | [[argus]] | utility (CT 103) | 192.168.1.103 | 100.64.0.25 | ARGUS - OSINT intelligence gathering platform | +| [[central]] | utility (CT 104) | 192.168.1.104 | 100.64.0.12 | Data-hub spine (central.echo6.mesh) — ~25 adapters, NATS/JetStream, TimescaleDB/PostGIS — see [[central]] | | peertube | media (CT 110) | 192.168.1.170 | 100.64.0.23 | PeerTube video streaming | +| mcc | media (CT 111) | 192.168.1.111 | — | pymc console web app (Caddy + Postfix, /api+/auth+/ws → aida-nebra :8000) | | pdm | edge2 (CT 100) | 10.10.10.10 | 100.64.0.28 | Proxmox Datacenter Manager | | wordpress | edge2 (CT 101) | 10.10.10.11 | 100.64.0.31 | WordPress for intermountainmesh.com | | vaultwarden | edge2 (CT 102) | 10.10.10.20 | 100.64.0.33 | Vaultwarden password manager (migrated from Contabo 2026-06-16) | @@ -124,6 +128,8 @@ Five nodes running Proxmox VE: | livesync | edge2 (CT 104) | 10.10.10.22 | 100.64.0.35 | LiveSync Obsidian sync (CouchDB + provisioner; migrated from Contabo 2026-06-16) | | authentik | edge2 (CT 105) | 10.10.10.23 | 100.64.0.36 | Authentik SSO platform (migrated from Contabo 2026-06-18) | +> **Note (2026-06-18):** edge2 CT placements above (CT 102–105) are sourced from migration git log. edge2 was not directly SSH-reachable during the 2026-06-18 fleet audit — placements pending live confirmation. + ## IP Allocation Scheme | Range | Purpose | @@ -164,6 +170,7 @@ Current registered nodes (26 total): | peertube | 100.64.0.23 | LXC | | recon | 100.64.0.24 | VM | | argus | 100.64.0.25 | LXC | +| central | 100.64.0.12 | LXC (utility CT 104 — central.echo6.mesh) | | edge2 | 100.64.0.26 | Proxmox/Contabo VPS | | meshmonitor-dev | 100.64.0.27 | LXC | | gl-a1300 | 100.64.0.29 | Router | @@ -227,12 +234,12 @@ These require password authentication (no SSH keys installed): | aida-nebra | zvx | 7redditGold | `sshpass -p '7redditGold' ssh zvx@aida-nebra` | | mt-isr | isr | UfPsfwyMIUIKb1 | `sshpass -p 'UfPsfwyMIUIKb1' ssh isr@192.168.1.141` | | mt-burleybutte | bb | (see credentials) | `sshpass -p '' ssh bb@192.168.1.185` | -| matt-desktop | administrator | Qw1290opzx | `ssh -o PreferredAuthentications=password -o PubkeyAuthentication=no administrator@192.168.1.111` | +| matt-desktop | administrator | Qw1290opzx | `ssh -o PreferredAuthentications=password -o PubkeyAuthentication=no administrator@192.168.1.254` | | toc | root | 7redditGold | `sshpass -p '7redditGold' ssh -o PubkeyAuthentication=no root@100.64.0.13` | Use the Tailscale hostname (`aida-nebra`) or local IP (`192.168.1.253`) — both work for aida-nebra. mt-isr is on IdahoMesh tailnet (100.100.0.5) — reachable from echo6 via bridge. -matt-desktop is accessible via local IP (192.168.1.111) or Tailscale (100.64.0.10) — requires explicit password auth flags. +matt-desktop is accessible via local IP (192.168.1.254) or Tailscale (100.64.0.10) — requires explicit password auth flags. ## Key External IPs diff --git a/vault/docs/services/services.md b/vault/docs/services/services.md index c02d11e..400a9fd 100644 --- a/vault/docs/services/services.md +++ b/vault/docs/services/services.md @@ -18,7 +18,7 @@ updated: 2026-06-18 | Service | Location | IP:Port | Access | Notes | |---------|----------|---------|--------|-------| -| MeshMonitor | utility (CT 100) | 192.168.1.100:8080 | https://mesh.echo6.co | Meshtastic mesh monitoring (zvx-echo6/meshmonitor fork, multi-channel AutoAnnounce/AutoResponder) | +| MeshMonitor | utility (CT 100) | 192.168.1.100:8080 / :4404 | https://mesh.echo6.co | Meshtastic mesh monitoring (upstream ghcr.io/yeraze/meshmonitor:latest, multi-channel AutoAnnounce/AutoResponder) | | Utility [[caddy]] | utility (CT 101) | 192.168.1.101 / 100.64.0.8 | 199.6.36.163 (ports 80/443) | Reverse proxy for home services | | Echo6 Search ([[searxng]]) | utility (CT 102) | 192.168.1.102:8080 | https://echo6.co | Branded search homepage (Docker, custom theme) | | meshtasticd (AIDA-N2) | aida-nebra | 192.168.1.253:4403 | Internal | AIDA-N2(RPT,LLM) node !27780c47, Nebra 2W hat (ZebraHat), CLIENT_BASE role, fw 2.7.19. MeshAI (CT 108) connects via TCP localhost:4403 | @@ -26,8 +26,11 @@ updated: 2026-06-18 | meshtasticd | mt-burleybutte | 192.168.1.185:4403 | Internal | Software Meshtastic node (Nebra 2W hat) | | IdahoMesh Headscale | utility (CT 106) | 192.168.1.106:8080 | https://vpn.idahomesh.com | Meshtastic mesh VPN coordination | | mesh-bridge | utility (CT 107) | 192.168.1.107 | Internal | Dual-tailscaled bridge (echo6 ↔ idahomesh) | -| MeshAI | utility (CT 108) | 192.168.1.144:4403 | Internal | LLM-powered Meshtastic assistant (Docker, Gemini Flash, Google grounding) | -| [[argus]] | utility (CT 103) | 192.168.1.103 | Internal | OSINT intelligence gathering platform (Docker, SearXNG + local LLM analysis) | +| MeshAI | utility (CT 108) | 192.168.1.144:4403 / :8080 | Internal | LLM-powered Meshtastic assistant (Docker, work-meshai local build, Gemini Flash, Google grounding) | +| [[argus]] | utility (CT 103) | 192.168.1.103:8080 | Internal | Python app on :8080 — OSINT intelligence gathering platform | +| [[central]] | utility (CT 104) | 192.168.1.104:8000 / 100.64.0.12 | central.echo6.mesh (mesh) | Data-hub spine — ~25 adapters → NATS/JetStream → TimescaleDB; serves traffic tiles to navi — see [[central]] | +| NATS/JetStream (central) | utility (CT 104) | 192.168.1.104:4222 / :8222 | Internal | Central backend message bus (NATS :4222 client, :8222 monitoring) | +| TimescaleDB/PostGIS (central) | utility (CT 104) | 192.168.1.104:5432 | Internal | Central backend time-series + geospatial database (PostgreSQL 16 + TimescaleDB + PostGIS) | | [[authentik]] | edge2 (CT 105) | 100.64.0.36:9000 | https://auth.echo6.co | SSO provider (Echo6 branded, custom CSS, dark theme) — fronted by Contabo Caddy (reverse_proxy 100.64.0.36:9000); **migrated from Contabo 2026-06-18** | | Forge (Forgejo) | edge2 (CT 103) | 100.64.0.34:3001 HTTP / :2222 SSH (via Contabo DNAT) | https://forge.echo6.co | Git server — fronted by Contabo Caddy (reverse_proxy 100.64.0.34:3001); git SSH via iptables DNAT on Contabo (forgejo-ssh-dnat.service) — **migrated from Contabo 2026-06-16** | | Headscale | Contabo | 5.189.158.149 | https://vpn.echo6.co | Tailscale coordination (OIDC enabled) | @@ -46,28 +49,39 @@ updated: 2026-06-18 | Prowlarr | media (VM 105) | 192.168.1.160:9696 | Internal | Indexer manager (Docker) | | SABnzbd | media (VM 105) | 192.168.1.160:8080 | Internal | [[usenet]] download client (Docker) | | PeerTube | media (CT 110) | 192.168.1.170:9000 | https://stream.echo6.co | Video streaming (native, NFS on pi-nas, SSO) | -| WATCHTOWER | **Decommissioned (2026-06-16)** | — | ~~wt.echo6.co~~ | Was Docker on Contabo `/opt/watchtower`; stopped & archived to forge.echo6.co/matt/archive-watchtower | | Open WebUI | cortex (VM 150) | 192.168.1.150:8080 | https://ai.echo6.co | AI chat interface (Docker, Ollama backend, SSO) | | Qdrant | cortex (VM 150) | 192.168.1.150:6333 | Internal | Vector database (Docker, [[recon]] knowledge store) | | TEI | cortex (VM 150) | 192.168.1.150:8090 | Internal | Text embeddings (Docker, bge-m3 1024-dim) | | RECON | data (VM 1130) | 192.168.1.130:8420 | https://recon.echo6.co | Knowledge extraction pipeline (systemd, dashboard+API) | +| navi-config | data (VM 1130) | 192.168.1.130:8422 | Internal | RECON navi node config API | +| navi-contacts | data (VM 1130) | 192.168.1.130:8423 | Internal | RECON navi contact enrichment API | +| navi-landclass | data (VM 1130) | 192.168.1.130:8424 | Internal | RECON navi land classification API | +| navi-places | data (VM 1130) | 192.168.1.130:8425 | Internal | RECON navi OSM place detail/enrichment | +| navi-geo | data (VM 1130) | 192.168.1.130:8426 | Internal | RECON navi geocode/reverse geocode API | +| navi-admin | data (VM 1130) | 192.168.1.130:8427 | Internal | RECON navi fleet admin-info aggregator | +| navi-offroute | data (VM 1130) | 192.168.1.130:8428 | Internal | RECON navi off-network router + MVUM API | +| navi (navi.echo6.co) | data (VM 1130) | 192.168.1.130:8440 | https://navi.echo6.co | Offline navigation platform — see [[navi]] | +| dem-origin | data (VM 1130) | 127.0.0.1:8441 | Internal | Local DEM tile origin for navi (658 GB planet-dem.pmtiles) | +| Valhalla | data (VM 1130) | 192.168.1.130:8002 | Internal | navi geo backend (routing) — see [[navi]] | +| Nominatim | data (VM 1130) | 192.168.1.130:8010 | Internal | navi geo backend (geocoder) — see [[navi]] | +| Photon | data (VM 1130) | 192.168.1.130:2322 | Internal | navi geo backend (geocoder + Elasticsearch :9201) — see [[navi]] | +| PostgreSQL/PostGIS | data (VM 1130) | 192.168.1.130:5432 | Internal | navi geo backend (padus, overture DBs) — see [[navi]] | | Files | data (VM 1130) | 192.168.1.130:8888 | https://files.echo6.co | PDF library (nginx, Authentik forward auth) | | Samba | data | 192.168.1.240:445 | Internal | SMB file sharing — `//data/library` → /mnt/data/library (guest access) | | Matrix [[synapse]] | Contabo | 127.0.0.1:8008 | https://matrix.echo6.co | Matrix homeserver (Docker, SSO) | | Element Web | Contabo | 127.0.0.1:8088 | https://element.echo6.co | Matrix web client (Docker) | | [[mautrix_signal]] | Contabo | internal (29328) | DM @signalbot:echo6.co | Signal bridge (Docker, E2BE, MSC4190, double puppeting) | | LiveSync | edge2 (CT 104) | 100.64.0.35:5984 (CouchDB) / :5985 (provisioner) | https://notes.echo6.co | Obsidian sync (CouchDB + provisioner, Docker, JWT auth) — fronted by Contabo Caddy (reverse_proxy 100.64.0.35:5984 / :5985); **migrated from Contabo 2026-06-16** | -| TAK Server | **Decommissioned (2026-06-16)** | — | ~~tak.echo6.co~~ | Was Docker on Contabo `/opt/tak-server-deploy`; stopped & archived to forge.echo6.co/matt/archive-tak-server | -| SIGIL | **Decommissioned (2026-06-16)** | — | ~~tak.echo6.co/sigil~~ | Was Docker on Contabo `/opt/sigil`; stopped & archived to forge.echo6.co/matt/archive-tak-server | | OpenTAKServer (OTS) | utility (CT 109) | 192.168.1.109:443 | https://ots.k7zvx.com | Live TAK server (native install, nginx+RabbitMQ+PostgreSQL, Meshtastic MQTT gateway on port 8883) — see [[ots-setup]] | | Echo6 Cortex Agent | cortex (VM 150) | N/A (Matrix bot) | #cortex:echo6.co in echo6-ops space | Claude Code bridge — @cortex:echo6.co, session continuity, E2EE (systemd) | -| Echo6 Contabo Agent | Contabo | N/A (Matrix bot) | #contabo:echo6.co in echo6-ops space | Claude Code bridge — @contabo:echo6.co, session continuity, E2EE (systemd) | | mautrix-signal | Contabo | 29328 (internal) | Internal (matrix-net) | Signal bridge — @signalbot:echo6.co, E2BE, MSC4190, auto-portals | | Matrix MAS | Contabo | 127.0.0.1:8085 | Internal (via Caddy) | Matrix Authentication Service (Docker, handles login/logout/OIDC for Synapse) | | Termix | Contabo | 0.0.0.0:8083 | Internal (no Caddy block) | Terminal sharing tool (Docker, ghcr.io/lukegus/termix:latest) | | [[archivist]] | utility (CT 118) | 192.168.1.118 | Internal | Signal/Matrix room archive bot (systemd) — see archivist.md for details | | pt-transcoder | cortex (VM 150) | N/A | Internal | PeerTube H.265 NVENC transcoder (systemd, /opt/bulk-import/transcoder.py) | | recon-sparse | cortex (VM 150) | 192.168.1.150:8091 | Internal | RECON sparse embedding service (systemd, bge-m3 model, port 8091) | +| obsidian-remote | cortex (VM 150) | 100.64.0.14:8082 → :3001 | Internal (Tailscale) | Headless web Obsidian (lscr.io/linuxserver/obsidian:latest, Docker) | +| mcc | media (CT 111) | 192.168.1.111:80/443 | Internal | Caddy + Postfix, pymc console web app; reverse-proxies /api,/auth,/ws → 192.168.1.253:8000 (aida-nebra) | | Samba | cortex (VM 150) | 192.168.1.150:445 | Internal | SMB file sharing — `//cortex/projects` → /home/zvx/projects (guest access) | ## Services by Server @@ -110,9 +124,9 @@ updated: 2026-06-18 - MAS user ID: 01KKX88ARGK0BTA1JMB2QVAW4C ### utility - CT 100 (192.168.1.100 / Tailscale: 100.64.0.7) -- MeshMonitor (port 8080, https://mesh.echo6.co) -- Image: `meshmonitor:multichannel-new` (local build from zvx-echo6/meshmonitor fork, branch `feature/multi-channel-automation`) -- Fork of Yeraze/meshmonitor with multi-channel AutoAnnounce and AutoResponder support (PR #2078 open upstream) +- MeshMonitor (port 8080 + 4404, https://mesh.echo6.co) +- Image: ghcr.io/yeraze/meshmonitor:latest (upstream image, not local fork build) +- Multi-channel AutoAnnounce and AutoResponder support ### utility - CT 101 (192.168.1.101 / Tailscale: 100.64.0.8) - Utility Caddy (reverse proxy for VPN-only services) @@ -135,12 +149,20 @@ updated: 2026-06-18 - Config: `/opt/searxng/searxng-config/settings.yml` (instance_name: "Echo6", dark theme, center_alignment: false) - SearXNG version: 2026.2.6 (Docker image: searxng/searxng:latest) +### utility - CT 104 (192.168.1.104 / Tailscale: 100.64.0.12) +- [[central]] data-hub spine (3 systemd units: central-supervisor, central-archive, central-gui) +- API/GUI on port 8000 (0.0.0.0), NATS :4222/:8222, PostgreSQL/TimescaleDB :5432 +- ~25 domain adapters (traffic, wildfire, weather, hydro, earthquakes, avalanche, disasters, satellite) +- Serves navi traffic tiles at auth-exempt /api/traffic/flow/{z}/{x}/{y}.png|pbf +- Tailscale hostname: central.echo6.mesh + ### utility - CT 108 (192.168.1.144 / Tailscale: 100.64.0.32) - MeshAI — LLM-powered Meshtastic mesh assistant (Docker) - Bot name: AIDA, node ID !27780c47, channel 8 whitelist -- Image: ghcr.io/zvx-echo6/meshai:latest (GitHub Actions multi-arch build) +- Image: work-meshai (local build, not ghcr.io/zvx-echo6/meshai:latest) - Backend: Gemini 2.5 Flash with Google Search grounding - Connects to meshtasticd **on aida-nebra** (192.168.1.253:4403) — the AIDA-N2 node !27780c47 +- Exposes port 8080 (web UI) - Config TUI on port 7682 (`meshai --config`) - Commands: !help, !ping, !status, !weather, !reset, !clear - 7-day rolling conversation memory (SQLite), full history sent to LLM @@ -202,13 +224,23 @@ updated: 2026-06-18 ### data - VM 1130 "recon-vm" (192.168.1.130 / Tailscale: 100.64.0.24) - **Migrated from CT 130 (LXC) on 2026-04-19** - OS: Ubuntu 24.04.4 LTS, kernel 6.8.0-110-generic -- Resources: 4 cores, 16GB RAM, 100GB disk +- Resources: 4 cores, 24GB RAM, 180GB disk - Software: Docker 29.4.0, Python 3.12.3 (venv), Tailscale, nginx, sqlite3 - RECON knowledge extraction pipeline - systemd services: `recon.service`, `recon-watchdog.service`, `kiwix.service` - Dashboard + API on port 8420 (https://recon.echo6.co) +- navi-config on port 8422 (node config API) +- navi-contacts on port 8423 (contact enrichment API) +- navi-landclass on port 8424 (land classification API) +- navi-places on port 8425 (OSM place detail/enrichment) +- navi-geo on port 8426 (geocode/reverse geocode API) +- navi-admin on port 8427 (fleet admin-info aggregator) +- navi-offroute on port 8428 (off-network router + MVUM API) - nginx file server on port 8888 (https://files.echo6.co, Authentik forward auth) - Kiwix-serve on port 8430 (ZIM library, 10 sources) +- navi (navi.echo6.co) on port :8440 — offline navigation platform front door (nginx SPA + API gateway); see [[navi]] +- dem-origin on port :8441 (localhost only) — DEM tile origin serving 658 GB planet-dem.pmtiles +- Geo backends (Docker + system): Valhalla :8002 (routing), Nominatim :8010 (geocoder), Photon :2322 (geocoder + Elasticsearch :9201), PostgreSQL/PostGIS :5432 (padus, overture DBs) - Install: `/opt/recon/` (Python 3, Flask, venv) - NFS mounts: pi-nas:/export/library → /mnt/library (PDF source), /mnt/nav, /mnt/kiwix - Pipeline: Extract (PyPDF2→pdftotext→Tesseract→Gemini Vision) → Enrich (Gemini) → Embed (TEI/Qdrant) @@ -268,6 +300,8 @@ updated: 2026-06-18 - Static MAC: A7:A1:30:79:BB:BB - Tailscale registered on IdahoMesh Headscale (vpn.idahomesh.com) under malice user + +> **Note (2026-06-18):** edge2 CT placements (CT 102–05) are sourced from the migration git log. edge2 was not directly SSH-reachable during the 2026-06-18 fleet audit — placements pending live confirmation. ### edge2 - CT 103 (10.10.10.21 / Tailscale: 100.64.0.34, node 46 `forgejo`) - Forgejo git server (https://forge.echo6.co — **migrated from Contabo 2026-06-16**) - Headscale node id 46, name `forgejo`, user `echo6` diff --git a/vault/docs/software/central.md b/vault/docs/software/central.md new file mode 100644 index 0000000..5809a9f --- /dev/null +++ b/vault/docs/software/central.md @@ -0,0 +1,100 @@ +--- +title: central — Data-Hub Spine +type: reference +tags: [recon] +related: ["[[navi]]", "[[services]]", "[[environment]]"] +updated: 2026-06-18 +--- +# central — Data-Hub Spine + +## Overview + +central is a multi-domain real-time data-hub spine. Adapters normalize upstream sources, publish CloudEvents to **NATS/JetStream**, and archive to **TimescaleDB/PostGIS** for historical and geospatial query. It is the live data backbone for navi traffic tiles and related situational-awareness feeds. + +- **URL (internal):** http://central.echo6.mesh:8000 (mesh-only, no public exposure) +- **Host:** utility CT 104 (unprivileged Ubuntu LXC) +- **Repo:** github.com/zvx-echo6/central (public, Python, branch ) +- **Deploy path:** (Python venv, system user) + +## Host + +| Attribute | Value | +|-----------|-------| +| Container | utility CT 104 | +| Local IP | 192.168.1.104 | +| Tailscale / mesh | 100.64.0.12 → | +| Resources | 4 cores / 12 GB RAM / 100 GB disk | +| OS | Ubuntu LXC (unprivileged) | + +## Architecture + +The data flow is: upstream APIs → adapters (central-supervisor) → NATS/JetStream :4222 → central-archive (TimescaleDB/PostGIS :5432). The central-gui (FastAPI + HTMX, :8000) exposes the API consumed by navi via . + +## Systemd Services + +All three units are **enabled and active**; deployment survives reboot. + +| Unit | Role | +|------|------| +| | Adapter scheduler + CloudEvents publisher | +| | JetStream → TimescaleDB consumer | +| | FastAPI + HTMX web app + API (the :8000 listener) | + +## Ports + +| Port | Protocol | Purpose | +|------|----------|---------| +| :8000 | HTTP | GUI / API (bound 0.0.0.0) | +| :4222 | TCP | NATS client connections | +| :8222 | HTTP | NATS monitoring | +| :5432 | TCP | PostgreSQL 16 + TimescaleDB/PostGIS | + +## Adapters (~25 active) + +| Domain | Sources | +|--------|---------| +| Traffic | ITD 511, WZDX, TomTom flow/incidents, 511 cameras | +| Wildfire | WFIGS incidents/perimeters, InciWeb, FIRMS | +| Weather / Space-weather | NWS, SWPC k-index/protons/alerts | +| Hydro | NWIS | +| Earthquakes | USGS | +| Avalanche | avalanche.org | +| Disasters | GDACS, EONET | +| Satellite | CelesTrak TLE, sat positions/orbits, N2YO passes, satpass predict | + +## GUI / API Surface + +Authenticated app with login/sessions/CSRF, first-run setup wizard, operator management, adapter configuration, stream viewer, enrichment pipeline, monitoring-area management, API key management, audit log, and manual resend. + +**Auth-exempt tile endpoints** (used by navi, verified HTTP 200): + +| Endpoint | Format | +|----------|--------| +| | PNG tile (raster) | +| | PBF tile (vector) | + +All other endpoints are auth-gated. + +## Consumer — navi Integration + +navi-traffic (navi's in-VM :8421 extraction service) was **retired on 2026-05-26** and cut over to central. recon-vm's nginx () now proxies → . Tile endpoints verified returning HTTP 200. + +## Dependencies + +| Component | Location | +|-----------|----------| +| NATS / JetStream | Local (central CT 104) | +| PostgreSQL 16 + TimescaleDB + PostGIS | Local (central CT 104) | +| Upstream APIs | ~20 external sources (see Adapters table) | + +## Deploy / Drift Notes (as of 2026-06-18 audit) + +- **Deployed HEAD:** v0.14.4 +- **Repo :** v0.14.5 — deployment is **1 release behind** +- **Uncommitted local migration:** exists on disk in the deployment but was **never committed to the repo** +- **Stale README:** repo README still reads *"Phase 0 — scaffold, not yet operational"* — central is fully operational +- **Stale :** version field shows 0.3.0; real version is the git tag (v0.14.x) + +--- + +*Last updated: 2026-06-18 — Initial documentation; central was previously undocumented. Deployment confirmed live, all three systemd units active.* diff --git a/vault/docs/software/navi.md b/vault/docs/software/navi.md new file mode 100644 index 0000000..c9444fb --- /dev/null +++ b/vault/docs/software/navi.md @@ -0,0 +1,94 @@ +--- +title: navi — Offline Navigation Platform +type: reference +tags: [recon] +related: ["[[recon]]", "[[services]]", "[[environment]]"] +updated: 2026-06-18 +--- +# navi — Offline Navigation Platform + +## Overview + +navi is an offline-capable navigation web app served from **recon-vm** (VM 1130, 192.168.1.130). It provides geocoding, routing, land classification, fleet admin, and DEM-backed elevation data — all from self-hosted geo backends. Frontend is a Vite SPA; backend is a suite of 8 Python microservices behind nginx. + +- **URL:** https://navi.echo6.co (fronted by utility Caddy + Authentik) +- **Host:** recon-vm (data node, VM 1130) +- **Repos:** `github.com/zvx-echo6/navi` (canonical), Forge mirror `matt/navi` +- **Layout:** monorepo — `backend/` (Python) + `frontend/` (Vite) +- **Deploy path:** `/home/zvx/projects/repos/navi-mono` (branch `main`, in sync with origin) + +## Architecture + +``` +Internet → Caddy (utility CT 101) → Authentik → nginx :8440 (navi-mono frontend) + ├─ /api/* → navi-* backends :8421-:8428 + ├─ /tiles/* → tile proxy + └─ /dem/* → dem-origin :8441 (range-cached) + └─ /mnt/nas/nav/planet-dem.pmtiles (658 GB) +``` + +## nginx Vhosts + +| Port | Vhost | Role | +|------|-------|------| +| :8440 | navi.echo6.co | Public front door — SPA from `/mnt/nav/frontend`, API gateway (`/api/*` → backends), tile/DEM proxies; range-caches DEM requests from :8441 | +| :8441 | dem-origin (localhost only) | Serves 658 GB `planet-dem.pmtiles` from `/mnt/nas/nav/`; never exposed directly | + +## Backend Services + +All 8 are gunicorn processes, bound to `127.0.0.1`, working directory `navi-mono/backend`, env files in `/etc/navi-backend/*.env`. + +| # | Service | Port | Status | Purpose | +|---|---------|------|--------|---------| +| 1 | navi-traffic | :8421 | **DISABLED** | Traffic — now proxied externally to `central.echo6.mesh:8000` | +| 2 | navi-config | :8422 | Active | Deployment profile API | +| 3 | navi-contacts | :8423 | Active | Contacts + address book | +| 4 | navi-landclass | :8424 | Active | PAD-US land classification (Postgres `padus` DB) | +| 5 | navi-places | :8425 | Active | OSM place detail/enrichment (Postgres `overture` DB) | +| 6 | navi-geo | :8426 | Active | Geocode + reverse geocode (Photon + DEM + timezone) | +| 7 | navi-admin | :8427 | Active | Fleet admin-info aggregator (auth-gated) | +| 8 | navi-offroute | :8428 | Active | Off-network router + MVUM (Valhalla + PostGIS) | + +Shared backend modules: `shared/auth.py` (Authentik header validation), `shared/admin_info.py`. + +## Geo Backends (co-resident on recon-vm) + +| Service | Port | Runtime | Purpose | +|---------|------|---------|---------| +| Valhalla | :8002 | Docker | Routing engine | +| Nominatim | :8010 | Docker | Geocoder | +| Photon | :2322 | Direct | Geocoder (embedded Elasticsearch :9201) | +| PostgreSQL/PostGIS | :5432 | System | DBs: `padus` (land classification), `overture` (OSM enrichment) | + +## Data + +| Path | Contents | +|------|---------| +| `/mnt/nav/` | Addresses, timezones, OSM PBF, worldcover friction/barriers/trails, HPA, Photon data, frontend SPA build | +| `/mnt/nas/nav/planet-dem.pmtiles` | 658 GB global DEM tile archive | +| `/var/lib/navi-backend/` | Writable runtime state: `contacts.db`, `place_cache.db`, `wiki_index.db` | + +NFS: pi-nas exports `/mnt/nav` and `/mnt/nas` to recon-vm. + +## Deployment + +The repo ships its own deploy templates under `backend/deploy/`: + +- `deploy/systemd/` — all 8 unit files (match live) +- `deploy/nginx/` — nginx vhost snippets (match live) +- `deploy/env/` — env file templates (instances in `/etc/navi-backend/`) +- `deploy/caddy/` — Caddy upstream fragment + +## Gotchas / Operational Notes + +**Three checkouts exist** under `~/projects/repos/`: + +| Checkout | Status | +|----------|--------| +| `navi-mono/` | **Live — this is what runs** | +| `navi/` | Stale — do not use | +| `navi-backend/` | Stale — **do not delete without auditing** (see below) | + +**`navi-backend/` cannot be deleted yet:** several live env files (`navi-config`, `navi-contacts`, `navi-places`, `navi-geo`, `navi-offroute`) reference config, profile, and address-book files under `/home/zvx/projects/repos/navi-backend/config/...`. Document those paths before any cleanup. + +**Stale README:** `backend/README.md` in the monorepo still refers to "extraction #1: navi-traffic" and predates the full monorepo consolidation. Treat `backend/deploy/` as the authoritative source. diff --git a/vault/docs/software/recon.md b/vault/docs/software/recon.md index e773ecd..9f576d8 100644 --- a/vault/docs/software/recon.md +++ b/vault/docs/software/recon.md @@ -22,9 +22,11 @@ RECON extracts knowledge from PDFs and web content into a searchable vector data - **Host:** recon-vm (VM 1130 on data node, 192.168.1.240) — migrated from CT 130 on 2026-04-19 - **IP:** 192.168.1.130 / 100.64.0.24 (Tailscale) -- **Install:** `/opt/recon/` +- **Repo:** github.com/zvx-echo6/recon (branch `master`; Forge mirror `matt/recon`) +- **Install:** `/opt/recon/` (Python venv, in sync with origin) - **User:** zvx - **Service:** `recon.service`, `recon-watchdog.service`, `kiwix.service` (systemd) +- **Entrypoints:** `recon.py service` (dashboard/API :8420) + `recon.py pipeline watch` (watchdog, auto-ingests new PDFs in `/mnt/library`) - **Dashboard:** https://recon.echo6.co (internal: http://100.64.0.24:8420) - **Health:** https://recon.echo6.co/api/health @@ -37,7 +39,8 @@ RECON extracts knowledge from PDFs and web content into a searchable vector data | Status DB | SQLite (WAL mode) | /opt/recon/data/recon.db | | Vector DB | Qdrant | cortex:6333 (Docker) | | Embeddings | TEI (bge-m3, 1024-dim) | cortex:8090 (Docker) | -| Enrichment | Gemini 2.5 Flash Lite | Google API (4 keys) | +| Sparse embeddings | recon-sparse (bge-m3 SPLADE) | cortex:8091 (systemd) | +| Enrichment | Gemini `gemini-2.5-flash-lite` (enforced) | Google API (4 keys) | | Vision Ocr | Gemini 2.5 Flash Lite | Google API (shared keys) | | Text extraction | PyPDF2, poppler-utils, Tesseract | Local | | PDF source | NFS | pi-nas:/export/library → /mnt/library | @@ -67,7 +70,7 @@ Method tracking saved in `data/text/{hash}/meta.json` as `ocr_methods` dict. - ~10,162 documents in pipeline - ~95,000+ vectors in Qdrant (HNSW index, <10ms search latency) -- Collection: `recon_knowledge` +- Collection: `recon_knowledge_hybrid` - ~13,239 PDFs catalogued from NFS library ## Resilience @@ -142,4 +145,4 @@ Key sections: --- -*Last updated: 2026-02-16 — Initial creation* +*Last updated: 2026-06-18 — Updated: repo/branch, recon-sparse :8091, recon_knowledge_hybrid collection, Entrypoints; PROJECT-BIBLE.md dated 2026-02-16 (predates current deployment) — verified against live 2026-06-18*