auto: docs sync 2026-06-19T00:00:09+00:00

Files changed: engine/lint-report.md vault/.obsidian/graph.json vault/.obsidian/workspace.json vault/docs/hardware/environment.md vault/docs/services/services.md vault/docs/software/central.md vault/docs/software/navi.md vault/docs/software/recon.md
This commit is contained in:
echo6-autocommit 2026-06-19 00:00:09 +00:00
commit 75df23b89e
8 changed files with 280 additions and 38 deletions

View file

@ -1,6 +1,6 @@
# Vault Lint Report
Generated: 2026-06-18T17:51:42Z | Docs scanned: 87 | Elapsed: 0.0s
Generated: 2026-06-18T20:57:00Z | Docs scanned: 89 | Elapsed: 0.0s
## Summary
@ -92,13 +92,12 @@ Matt decides whether to create a real doc — when he does, future sweeps will l
| Term | Docs mentioning it |
|------|--------------------|
| `tailscale` | 31 |
| `tailscale` | 32 |
| `docker` | 28 |
| `proxmox` | 28 |
| `docker` | 27 |
| `headscale` | 21 |
| `peertube` | 15 |
| `meshtastic` | 14 |
| `navi` | 14 |
| `mailcow` | 11 |
| `forgejo` | 10 |
| `immich` | 10 |
@ -107,3 +106,4 @@ Matt decides whether to create a real doc — when he does, future sweeps will l
| `jellyfin` | 9 |
| `meshtasticd` | 9 |
| `aida-nebra` | 8 |
| `livesync` | 8 |

View file

@ -60,6 +60,6 @@
"repelStrength": 20,
"linkStrength": 1,
"linkDistance": 500,
"scale": 0.08779149519890246,
"scale": 0.1316872427983537,
"close": false
}

View file

@ -11,10 +11,14 @@
"id": "8d53cdb6c257e685",
"type": "leaf",
"state": {
"type": "graph",
"state": {},
"icon": "lucide-git-fork",
"title": "Graph view"
"type": "markdown",
"state": {
"file": "docs/hardware/environment.md",
"mode": "source",
"source": false
},
"icon": "lucide-file",
"title": "environment"
}
}
]
@ -195,10 +199,15 @@
},
"active": "8d53cdb6c257e685",
"lastOpenFiles": [
"rules/proxmox.md",
"docs/services/services.md",
"docs/software/central.md",
"docs/software/navi.md",
"docs/hardware/environment.md.bak",
"docs/services/services.md.bak",
"archive/projects/mmud/mmud-phase6-prompt.md",
"archive/projects/last-ember-project.md",
"projects/mmud-project.md",
"docs/services/services.md",
"concepts/lxc-container.md",
"concepts/osint.md",
"concepts/split-dns.md",
@ -220,9 +229,6 @@
"entities/mesh-bridge.md",
"entities/meshtastic-hs.md",
"entities/tei.md",
"entities/qdrant.md",
"entities/recon-vm.md",
"entities/utility.md",
"entities",
"credentials.tmp.40509.595364788ca8",
"runbooks/lxc-service-migration.md.tmp.40509.ac2c03680b76",
@ -230,8 +236,6 @@
"runbooks/lxc-service-migration.md.tmp.40509.ae9f0d9aaaea",
"runbooks/lxc-service-migration.md.tmp.40509.f6c568f75061",
"docs/hardware/ip-allocation.md.tmp.40509.03b7ba9c244f",
"docs/hardware/ip-allocation.md.tmp.40509.a068767a4b20",
"docs/hardware/ip-allocation.md.tmp.40509.da0228cd9f66",
"assets/echo6yellow_logo_422x422_square.png",
"assets/echo6yellow_logo_422x81.png",
"assets/echo6_logo.png",

View file

@ -20,7 +20,7 @@ Five nodes running Proxmox VE:
| Node | Local IP | Tailscale | Hardware | RAM | Purpose |
| ------- | ------------- | ----------- | ----------------------------------------------- | -------------- | -------------------------------- |
| data | 192.168.1.240 | 100.64.0.6 | AMD Ryzen 7 PRO 5750GE, 1TB NVMe + 1TB SATA SSD | 32GB DDR4-3200 | Database [[services]] |
| data | 192.168.1.240 | 100.64.0.6 | AMD Ryzen 7 PRO 5750GE, 1TB NVMe + 1TB SATA SSD | 32GB DDR4-3200 | Database [[services]] |
| utility | 192.168.1.241 | 100.64.0.5 | AMD Ryzen 7 PRO 5750GE, 512GB NVMe | 32GB DDR4-3200 | Utility services, monitoring |
| cloud | 192.168.1.242 | 100.64.0.4 | Intel i7-12700T, 512GB NVMe | 32GB DDR4-3200 | Cloud storage, personal services |
| media | 192.168.1.243 | 100.64.0.3 | Intel i7-14700T, 2x 512GB NVMe | 32GB DDR5-5600 | Media server, *arr stack |
@ -52,7 +52,7 @@ Five nodes running Proxmox VE:
| VM | Host | VMID | Local IP | Tailscale | Purpose |
|----|------|------|----------|-----------|---------|
| cortex | toc | 150 | 192.168.1.150 | 100.64.0.14 | GPU compute — Open WebUI, Ollama, Qdrant, TEI, Claude Code |
| recon-vm | data | 1130 | 192.168.1.130 | 100.64.0.24 | [[recon]] knowledge extraction pipeline, Files, Kiwix |
| recon-vm | data | 1130 | 192.168.1.130 | 100.64.0.24 | [[recon]] + [[navi]] platforms, Files, Kiwix, geo backends |
| arr | media | 105 | 192.168.1.160 | 100.64.0.18 | ARR media automation stack (Jellyfin, Sonarr, Radarr, etc.) |
### cortex VM Details
@ -69,8 +69,9 @@ Five nodes running Proxmox VE:
### recon-vm Details
- **OS:** Ubuntu 24.04.4 LTS (cloud-init), kernel 6.8.0-110-generic
- **Resources:** 4 cores, 16GB RAM, 100GB disk
- **Resources:** 4 cores, 24GB RAM, 180GB disk
- **Software:** Docker 29.4.0, Python 3.12.3, nginx, sqlite3, Tailscale
- **Platforms:** [[recon]] (knowledge extraction pipeline, :8420) and [[navi]] (offline navigation, navi.echo6.co, :8440) with geo backends (Valhalla :8002, Nominatim :8010, Photon :2322, PostgreSQL/PostGIS :5432)
- **Systemd services:** recon (8420), recon-watchdog, kiwix (8430), nginx (8888)
- **NFS mounts:** pi-nas:/export/library → /mnt/library, /mnt/nav, /mnt/kiwix
- **User:** zvx (sudo, SSH key auth)
@ -96,11 +97,12 @@ Five nodes running Proxmox VE:
| mt-isr | 192.168.1.141 | 100.100.0.5 (IdahoMesh) | Meshtastic sidecar Pi (G2 WiFi bridge, meshtasticd, CLI) |
| mt-burleybutte | 192.168.1.185 | — | Meshtastic node (meshtasticd, Nebra 2W hat, IdahoMesh VPN) |
| pi-nas | 192.168.1.245 | 100.64.0.21 | Raspberry Pi NAS |
| matt-desktop | 192.168.1.111 | 100.64.0.10 | Personal workstation (Windows, your PC) |
| matt-desktop | 192.168.1.254 | 100.64.0.10 | Personal workstation (Windows, your PC) |
| Contabo Server | 5.189.158.149 | 100.64.0.1 | External VPS: Mail, [[authentik]], Headscale, Forge, Matrix |
| edge2 | 184.174.35.153 | 100.64.0.26 | Contabo Cloud VPS 30 NVMe — Proxmox VE 8.4.19 (LXC-only), 8c/24GB/400GB |
*Last updated: 2026-06-18 — Added edge2 CT 105 (authentik, 10.10.10.23, 100.64.0.36, node 48, migrated 2026-06-18); previously added CT 104 (livesync), CT 103 (forgejo), CT 102 (vaultwarden), pdm CT 100, wordpress CT 101*
*Last updated: 2026-06-18 — Added central (utility CT 104, 192.168.1.104, 100.64.0.12); also added edge2 CT 105 (authentik, 10.10.10.23, 100.64.0.36, node 48, migrated 2026-06-18); previously added edge2 CT 104 (livesync), CT 103 (forgejo), CT 102 (vaultwarden), pdm CT 100, wordpress CT 101*
## LXC Containers
@ -116,7 +118,9 @@ Five nodes running Proxmox VE:
| meshai | utility (CT 108) | 192.168.1.144 | 100.64.0.32 | MeshAI - LLM-powered Meshtastic assistant |
| [[archivist]] | utility (CT 118) | 192.168.1.118 | — | Archivist knowledge pipeline |
| [[argus]] | utility (CT 103) | 192.168.1.103 | 100.64.0.25 | ARGUS - OSINT intelligence gathering platform |
| [[central]] | utility (CT 104) | 192.168.1.104 | 100.64.0.12 | Data-hub spine (central.echo6.mesh) — ~25 adapters, NATS/JetStream, TimescaleDB/PostGIS — see [[central]] |
| peertube | media (CT 110) | 192.168.1.170 | 100.64.0.23 | PeerTube video streaming |
| mcc | media (CT 111) | 192.168.1.111 | — | pymc console web app (Caddy + Postfix, /api+/auth+/ws → aida-nebra :8000) |
| pdm | edge2 (CT 100) | 10.10.10.10 | 100.64.0.28 | Proxmox Datacenter Manager |
| wordpress | edge2 (CT 101) | 10.10.10.11 | 100.64.0.31 | WordPress for intermountainmesh.com |
| vaultwarden | edge2 (CT 102) | 10.10.10.20 | 100.64.0.33 | Vaultwarden password manager (migrated from Contabo 2026-06-16) |
@ -124,6 +128,8 @@ Five nodes running Proxmox VE:
| livesync | edge2 (CT 104) | 10.10.10.22 | 100.64.0.35 | LiveSync Obsidian sync (CouchDB + provisioner; migrated from Contabo 2026-06-16) |
| authentik | edge2 (CT 105) | 10.10.10.23 | 100.64.0.36 | Authentik SSO platform (migrated from Contabo 2026-06-18) |
> **Note (2026-06-18):** edge2 CT placements above (CT 102105) are sourced from migration git log. edge2 was not directly SSH-reachable during the 2026-06-18 fleet audit — placements pending live confirmation.
## IP Allocation Scheme
| Range | Purpose |
@ -164,6 +170,7 @@ Current registered nodes (26 total):
| peertube | 100.64.0.23 | LXC |
| recon | 100.64.0.24 | VM |
| argus | 100.64.0.25 | LXC |
| central | 100.64.0.12 | LXC (utility CT 104 — central.echo6.mesh) |
| edge2 | 100.64.0.26 | Proxmox/Contabo VPS |
| meshmonitor-dev | 100.64.0.27 | LXC |
| gl-a1300 | 100.64.0.29 | Router |
@ -227,12 +234,12 @@ These require password authentication (no SSH keys installed):
| aida-nebra | zvx | 7redditGold | `sshpass -p '7redditGold' ssh zvx@aida-nebra` |
| mt-isr | isr | UfPsfwyMIUIKb1 | `sshpass -p 'UfPsfwyMIUIKb1' ssh isr@192.168.1.141` |
| mt-burleybutte | bb | (see credentials) | `sshpass -p '<pw>' ssh bb@192.168.1.185` |
| matt-desktop | administrator | Qw1290opzx | `ssh -o PreferredAuthentications=password -o PubkeyAuthentication=no administrator@192.168.1.111` |
| matt-desktop | administrator | Qw1290opzx | `ssh -o PreferredAuthentications=password -o PubkeyAuthentication=no administrator@192.168.1.254` |
| toc | root | 7redditGold | `sshpass -p '7redditGold' ssh -o PubkeyAuthentication=no root@100.64.0.13` |
Use the Tailscale hostname (`aida-nebra`) or local IP (`192.168.1.253`) — both work for aida-nebra.
mt-isr is on IdahoMesh tailnet (100.100.0.5) — reachable from echo6 via bridge.
matt-desktop is accessible via local IP (192.168.1.111) or Tailscale (100.64.0.10) — requires explicit password auth flags.
matt-desktop is accessible via local IP (192.168.1.254) or Tailscale (100.64.0.10) — requires explicit password auth flags.
## Key External IPs

View file

@ -18,7 +18,7 @@ updated: 2026-06-18
| Service | Location | IP:Port | Access | Notes |
|---------|----------|---------|--------|-------|
| MeshMonitor | utility (CT 100) | 192.168.1.100:8080 | https://mesh.echo6.co | Meshtastic mesh monitoring (zvx-echo6/meshmonitor fork, multi-channel AutoAnnounce/AutoResponder) |
| MeshMonitor | utility (CT 100) | 192.168.1.100:8080 / :4404 | https://mesh.echo6.co | Meshtastic mesh monitoring (upstream ghcr.io/yeraze/meshmonitor:latest, multi-channel AutoAnnounce/AutoResponder) |
| Utility [[caddy]] | utility (CT 101) | 192.168.1.101 / 100.64.0.8 | 199.6.36.163 (ports 80/443) | Reverse proxy for home services |
| Echo6 Search ([[searxng]]) | utility (CT 102) | 192.168.1.102:8080 | https://echo6.co | Branded search homepage (Docker, custom theme) |
| meshtasticd (AIDA-N2) | aida-nebra | 192.168.1.253:4403 | Internal | AIDA-N2(RPT,LLM) node !27780c47, Nebra 2W hat (ZebraHat), CLIENT_BASE role, fw 2.7.19. MeshAI (CT 108) connects via TCP localhost:4403 |
@ -26,8 +26,11 @@ updated: 2026-06-18
| meshtasticd | mt-burleybutte | 192.168.1.185:4403 | Internal | Software Meshtastic node (Nebra 2W hat) |
| IdahoMesh Headscale | utility (CT 106) | 192.168.1.106:8080 | https://vpn.idahomesh.com | Meshtastic mesh VPN coordination |
| mesh-bridge | utility (CT 107) | 192.168.1.107 | Internal | Dual-tailscaled bridge (echo6 ↔ idahomesh) |
| MeshAI | utility (CT 108) | 192.168.1.144:4403 | Internal | LLM-powered Meshtastic assistant (Docker, Gemini Flash, Google grounding) |
| [[argus]] | utility (CT 103) | 192.168.1.103 | Internal | OSINT intelligence gathering platform (Docker, SearXNG + local LLM analysis) |
| MeshAI | utility (CT 108) | 192.168.1.144:4403 / :8080 | Internal | LLM-powered Meshtastic assistant (Docker, work-meshai local build, Gemini Flash, Google grounding) |
| [[argus]] | utility (CT 103) | 192.168.1.103:8080 | Internal | Python app on :8080 — OSINT intelligence gathering platform |
| [[central]] | utility (CT 104) | 192.168.1.104:8000 / 100.64.0.12 | central.echo6.mesh (mesh) | Data-hub spine — ~25 adapters → NATS/JetStream → TimescaleDB; serves traffic tiles to navi — see [[central]] |
| NATS/JetStream (central) | utility (CT 104) | 192.168.1.104:4222 / :8222 | Internal | Central backend message bus (NATS :4222 client, :8222 monitoring) |
| TimescaleDB/PostGIS (central) | utility (CT 104) | 192.168.1.104:5432 | Internal | Central backend time-series + geospatial database (PostgreSQL 16 + TimescaleDB + PostGIS) |
| [[authentik]] | edge2 (CT 105) | 100.64.0.36:9000 | https://auth.echo6.co | SSO provider (Echo6 branded, custom CSS, dark theme) — fronted by Contabo Caddy (reverse_proxy 100.64.0.36:9000); **migrated from Contabo 2026-06-18** |
| Forge (Forgejo) | edge2 (CT 103) | 100.64.0.34:3001 HTTP / :2222 SSH (via Contabo DNAT) | https://forge.echo6.co | Git server — fronted by Contabo Caddy (reverse_proxy 100.64.0.34:3001); git SSH via iptables DNAT on Contabo (forgejo-ssh-dnat.service) — **migrated from Contabo 2026-06-16** |
| Headscale | Contabo | 5.189.158.149 | https://vpn.echo6.co | Tailscale coordination (OIDC enabled) |
@ -46,28 +49,39 @@ updated: 2026-06-18
| Prowlarr | media (VM 105) | 192.168.1.160:9696 | Internal | Indexer manager (Docker) |
| SABnzbd | media (VM 105) | 192.168.1.160:8080 | Internal | [[usenet]] download client (Docker) |
| PeerTube | media (CT 110) | 192.168.1.170:9000 | https://stream.echo6.co | Video streaming (native, NFS on pi-nas, SSO) |
| WATCHTOWER | **Decommissioned (2026-06-16)** | — | ~~wt.echo6.co~~ | Was Docker on Contabo `/opt/watchtower`; stopped & archived to forge.echo6.co/matt/archive-watchtower |
| Open WebUI | cortex (VM 150) | 192.168.1.150:8080 | https://ai.echo6.co | AI chat interface (Docker, Ollama backend, SSO) |
| Qdrant | cortex (VM 150) | 192.168.1.150:6333 | Internal | Vector database (Docker, [[recon]] knowledge store) |
| TEI | cortex (VM 150) | 192.168.1.150:8090 | Internal | Text embeddings (Docker, bge-m3 1024-dim) |
| RECON | data (VM 1130) | 192.168.1.130:8420 | https://recon.echo6.co | Knowledge extraction pipeline (systemd, dashboard+API) |
| navi-config | data (VM 1130) | 192.168.1.130:8422 | Internal | RECON navi node config API |
| navi-contacts | data (VM 1130) | 192.168.1.130:8423 | Internal | RECON navi contact enrichment API |
| navi-landclass | data (VM 1130) | 192.168.1.130:8424 | Internal | RECON navi land classification API |
| navi-places | data (VM 1130) | 192.168.1.130:8425 | Internal | RECON navi OSM place detail/enrichment |
| navi-geo | data (VM 1130) | 192.168.1.130:8426 | Internal | RECON navi geocode/reverse geocode API |
| navi-admin | data (VM 1130) | 192.168.1.130:8427 | Internal | RECON navi fleet admin-info aggregator |
| navi-offroute | data (VM 1130) | 192.168.1.130:8428 | Internal | RECON navi off-network router + MVUM API |
| navi (navi.echo6.co) | data (VM 1130) | 192.168.1.130:8440 | https://navi.echo6.co | Offline navigation platform — see [[navi]] |
| dem-origin | data (VM 1130) | 127.0.0.1:8441 | Internal | Local DEM tile origin for navi (658GB planet-dem.pmtiles) |
| Valhalla | data (VM 1130) | 192.168.1.130:8002 | Internal | navi geo backend (routing) — see [[navi]] |
| Nominatim | data (VM 1130) | 192.168.1.130:8010 | Internal | navi geo backend (geocoder) — see [[navi]] |
| Photon | data (VM 1130) | 192.168.1.130:2322 | Internal | navi geo backend (geocoder + Elasticsearch :9201) — see [[navi]] |
| PostgreSQL/PostGIS | data (VM 1130) | 192.168.1.130:5432 | Internal | navi geo backend (padus, overture DBs) — see [[navi]] |
| Files | data (VM 1130) | 192.168.1.130:8888 | https://files.echo6.co | PDF library (nginx, Authentik forward auth) |
| Samba | data | 192.168.1.240:445 | Internal | SMB file sharing — `//data/library` → /mnt/data/library (guest access) |
| Matrix [[synapse]] | Contabo | 127.0.0.1:8008 | https://matrix.echo6.co | Matrix homeserver (Docker, SSO) |
| Element Web | Contabo | 127.0.0.1:8088 | https://element.echo6.co | Matrix web client (Docker) |
| [[mautrix_signal]] | Contabo | internal (29328) | DM @signalbot:echo6.co | Signal bridge (Docker, E2BE, MSC4190, double puppeting) |
| LiveSync | edge2 (CT 104) | 100.64.0.35:5984 (CouchDB) / :5985 (provisioner) | https://notes.echo6.co | Obsidian sync (CouchDB + provisioner, Docker, JWT auth) — fronted by Contabo Caddy (reverse_proxy 100.64.0.35:5984 / :5985); **migrated from Contabo 2026-06-16** |
| TAK Server | **Decommissioned (2026-06-16)** | — | ~~tak.echo6.co~~ | Was Docker on Contabo `/opt/tak-server-deploy`; stopped & archived to forge.echo6.co/matt/archive-tak-server |
| SIGIL | **Decommissioned (2026-06-16)** | — | ~~tak.echo6.co/sigil~~ | Was Docker on Contabo `/opt/sigil`; stopped & archived to forge.echo6.co/matt/archive-tak-server |
| OpenTAKServer (OTS) | utility (CT 109) | 192.168.1.109:443 | https://ots.k7zvx.com | Live TAK server (native install, nginx+RabbitMQ+PostgreSQL, Meshtastic MQTT gateway on port 8883) — see [[ots-setup]] |
| Echo6 Cortex Agent | cortex (VM 150) | N/A (Matrix bot) | #cortex:echo6.co in echo6-ops space | Claude Code bridge — @cortex:echo6.co, session continuity, E2EE (systemd) |
| Echo6 Contabo Agent | Contabo | N/A (Matrix bot) | #contabo:echo6.co in echo6-ops space | Claude Code bridge — @contabo:echo6.co, session continuity, E2EE (systemd) |
| mautrix-signal | Contabo | 29328 (internal) | Internal (matrix-net) | Signal bridge — @signalbot:echo6.co, E2BE, MSC4190, auto-portals |
| Matrix MAS | Contabo | 127.0.0.1:8085 | Internal (via Caddy) | Matrix Authentication Service (Docker, handles login/logout/OIDC for Synapse) |
| Termix | Contabo | 0.0.0.0:8083 | Internal (no Caddy block) | Terminal sharing tool (Docker, ghcr.io/lukegus/termix:latest) |
| [[archivist]] | utility (CT 118) | 192.168.1.118 | Internal | Signal/Matrix room archive bot (systemd) — see archivist.md for details |
| pt-transcoder | cortex (VM 150) | N/A | Internal | PeerTube H.265 NVENC transcoder (systemd, /opt/bulk-import/transcoder.py) |
| recon-sparse | cortex (VM 150) | 192.168.1.150:8091 | Internal | RECON sparse embedding service (systemd, bge-m3 model, port 8091) |
| obsidian-remote | cortex (VM 150) | 100.64.0.14:8082 → :3001 | Internal (Tailscale) | Headless web Obsidian (lscr.io/linuxserver/obsidian:latest, Docker) |
| mcc | media (CT 111) | 192.168.1.111:80/443 | Internal | Caddy + Postfix, pymc console web app; reverse-proxies /api,/auth,/ws → 192.168.1.253:8000 (aida-nebra) |
| Samba | cortex (VM 150) | 192.168.1.150:445 | Internal | SMB file sharing — `//cortex/projects` → /home/zvx/projects (guest access) |
## Services by Server
@ -110,9 +124,9 @@ updated: 2026-06-18
- MAS user ID: 01KKX88ARGK0BTA1JMB2QVAW4C
### utility - CT 100 (192.168.1.100 / Tailscale: 100.64.0.7)
- MeshMonitor (port 8080, https://mesh.echo6.co)
- Image: `meshmonitor:multichannel-new` (local build from zvx-echo6/meshmonitor fork, branch `feature/multi-channel-automation`)
- Fork of Yeraze/meshmonitor with multi-channel AutoAnnounce and AutoResponder support (PR #2078 open upstream)
- MeshMonitor (port 8080 + 4404, https://mesh.echo6.co)
- Image: ghcr.io/yeraze/meshmonitor:latest (upstream image, not local fork build)
- Multi-channel AutoAnnounce and AutoResponder support
### utility - CT 101 (192.168.1.101 / Tailscale: 100.64.0.8)
- Utility Caddy (reverse proxy for VPN-only services)
@ -135,12 +149,20 @@ updated: 2026-06-18
- Config: `/opt/searxng/searxng-config/settings.yml` (instance_name: "Echo6", dark theme, center_alignment: false)
- SearXNG version: 2026.2.6 (Docker image: searxng/searxng:latest)
### utility - CT 104 (192.168.1.104 / Tailscale: 100.64.0.12)
- [[central]] data-hub spine (3 systemd units: central-supervisor, central-archive, central-gui)
- API/GUI on port 8000 (0.0.0.0), NATS :4222/:8222, PostgreSQL/TimescaleDB :5432
- ~25 domain adapters (traffic, wildfire, weather, hydro, earthquakes, avalanche, disasters, satellite)
- Serves navi traffic tiles at auth-exempt /api/traffic/flow/{z}/{x}/{y}.png|pbf
- Tailscale hostname: central.echo6.mesh
### utility - CT 108 (192.168.1.144 / Tailscale: 100.64.0.32)
- MeshAI — LLM-powered Meshtastic mesh assistant (Docker)
- Bot name: AIDA, node ID !27780c47, channel 8 whitelist
- Image: ghcr.io/zvx-echo6/meshai:latest (GitHub Actions multi-arch build)
- Image: work-meshai (local build, not ghcr.io/zvx-echo6/meshai:latest)
- Backend: Gemini 2.5 Flash with Google Search grounding
- Connects to meshtasticd **on aida-nebra** (192.168.1.253:4403) — the AIDA-N2 node !27780c47
- Exposes port 8080 (web UI)
- Config TUI on port 7682 (`meshai --config`)
- Commands: !help, !ping, !status, !weather, !reset, !clear
- 7-day rolling conversation memory (SQLite), full history sent to LLM
@ -202,13 +224,23 @@ updated: 2026-06-18
### data - VM 1130 "recon-vm" (192.168.1.130 / Tailscale: 100.64.0.24)
- **Migrated from CT 130 (LXC) on 2026-04-19**
- OS: Ubuntu 24.04.4 LTS, kernel 6.8.0-110-generic
- Resources: 4 cores, 16GB RAM, 100GB disk
- Resources: 4 cores, 24GB RAM, 180GB disk
- Software: Docker 29.4.0, Python 3.12.3 (venv), Tailscale, nginx, sqlite3
- RECON knowledge extraction pipeline
- systemd services: `recon.service`, `recon-watchdog.service`, `kiwix.service`
- Dashboard + API on port 8420 (https://recon.echo6.co)
- navi-config on port 8422 (node config API)
- navi-contacts on port 8423 (contact enrichment API)
- navi-landclass on port 8424 (land classification API)
- navi-places on port 8425 (OSM place detail/enrichment)
- navi-geo on port 8426 (geocode/reverse geocode API)
- navi-admin on port 8427 (fleet admin-info aggregator)
- navi-offroute on port 8428 (off-network router + MVUM API)
- nginx file server on port 8888 (https://files.echo6.co, Authentik forward auth)
- Kiwix-serve on port 8430 (ZIM library, 10 sources)
- navi (navi.echo6.co) on port :8440 — offline navigation platform front door (nginx SPA + API gateway); see [[navi]]
- dem-origin on port :8441 (localhost only) — DEM tile origin serving 658GB planet-dem.pmtiles
- Geo backends (Docker + system): Valhalla :8002 (routing), Nominatim :8010 (geocoder), Photon :2322 (geocoder + Elasticsearch :9201), PostgreSQL/PostGIS :5432 (padus, overture DBs)
- Install: `/opt/recon/` (Python 3, Flask, venv)
- NFS mounts: pi-nas:/export/library → /mnt/library (PDF source), /mnt/nav, /mnt/kiwix
- Pipeline: Extract (PyPDF2→pdftotext→Tesseract→Gemini Vision) → Enrich (Gemini) → Embed (TEI/Qdrant)
@ -268,6 +300,8 @@ updated: 2026-06-18
- Static MAC: A7:A1:30:79:BB:BB
- Tailscale registered on IdahoMesh Headscale (vpn.idahomesh.com) under malice user
> **Note (2026-06-18):** edge2 CT placements (CT 10205) are sourced from the migration git log. edge2 was not directly SSH-reachable during the 2026-06-18 fleet audit — placements pending live confirmation.
### edge2 - CT 103 (10.10.10.21 / Tailscale: 100.64.0.34, node 46 `forgejo`)
- Forgejo git server (https://forge.echo6.co — **migrated from Contabo 2026-06-16**)
- Headscale node id 46, name `forgejo`, user `echo6`

View file

@ -0,0 +1,100 @@
---
title: central — Data-Hub Spine
type: reference
tags: [recon]
related: ["[[navi]]", "[[services]]", "[[environment]]"]
updated: 2026-06-18
---
# central — Data-Hub Spine
## Overview
central is a multi-domain real-time data-hub spine. Adapters normalize upstream sources, publish CloudEvents to **NATS/JetStream**, and archive to **TimescaleDB/PostGIS** for historical and geospatial query. It is the live data backbone for navi traffic tiles and related situational-awareness feeds.
- **URL (internal):** http://central.echo6.mesh:8000 (mesh-only, no public exposure)
- **Host:** utility CT 104 (unprivileged Ubuntu LXC)
- **Repo:** github.com/zvx-echo6/central (public, Python, branch )
- **Deploy path:** (Python venv, system user)
## Host
| Attribute | Value |
|-----------|-------|
| Container | utility CT 104 |
| Local IP | 192.168.1.104 |
| Tailscale / mesh | 100.64.0.12 → |
| Resources | 4 cores / 12 GB RAM / 100 GB disk |
| OS | Ubuntu LXC (unprivileged) |
## Architecture
The data flow is: upstream APIs → adapters (central-supervisor) → NATS/JetStream :4222 → central-archive (TimescaleDB/PostGIS :5432). The central-gui (FastAPI + HTMX, :8000) exposes the API consumed by navi via .
## Systemd Services
All three units are **enabled and active**; deployment survives reboot.
| Unit | Role |
|------|------|
| | Adapter scheduler + CloudEvents publisher |
| | JetStream → TimescaleDB consumer |
| | FastAPI + HTMX web app + API (the :8000 listener) |
## Ports
| Port | Protocol | Purpose |
|------|----------|---------|
| :8000 | HTTP | GUI / API (bound 0.0.0.0) |
| :4222 | TCP | NATS client connections |
| :8222 | HTTP | NATS monitoring |
| :5432 | TCP | PostgreSQL 16 + TimescaleDB/PostGIS |
## Adapters (~25 active)
| Domain | Sources |
|--------|---------|
| Traffic | ITD 511, WZDX, TomTom flow/incidents, 511 cameras |
| Wildfire | WFIGS incidents/perimeters, InciWeb, FIRMS |
| Weather / Space-weather | NWS, SWPC k-index/protons/alerts |
| Hydro | NWIS |
| Earthquakes | USGS |
| Avalanche | avalanche.org |
| Disasters | GDACS, EONET |
| Satellite | CelesTrak TLE, sat positions/orbits, N2YO passes, satpass predict |
## GUI / API Surface
Authenticated app with login/sessions/CSRF, first-run setup wizard, operator management, adapter configuration, stream viewer, enrichment pipeline, monitoring-area management, API key management, audit log, and manual resend.
**Auth-exempt tile endpoints** (used by navi, verified HTTP 200):
| Endpoint | Format |
|----------|--------|
| | PNG tile (raster) |
| | PBF tile (vector) |
All other endpoints are auth-gated.
## Consumer — navi Integration
navi-traffic (navi's in-VM :8421 extraction service) was **retired on 2026-05-26** and cut over to central. recon-vm's nginx () now proxies → . Tile endpoints verified returning HTTP 200.
## Dependencies
| Component | Location |
|-----------|----------|
| NATS / JetStream | Local (central CT 104) |
| PostgreSQL 16 + TimescaleDB + PostGIS | Local (central CT 104) |
| Upstream APIs | ~20 external sources (see Adapters table) |
## Deploy / Drift Notes (as of 2026-06-18 audit)
- **Deployed HEAD:** v0.14.4
- **Repo :** v0.14.5 — deployment is **1 release behind**
- **Uncommitted local migration:** exists on disk in the deployment but was **never committed to the repo**
- **Stale README:** repo README still reads *"Phase 0 — scaffold, not yet operational"* — central is fully operational
- **Stale :** version field shows 0.3.0; real version is the git tag (v0.14.x)
---
*Last updated: 2026-06-18 — Initial documentation; central was previously undocumented. Deployment confirmed live, all three systemd units active.*

View file

@ -0,0 +1,94 @@
---
title: navi — Offline Navigation Platform
type: reference
tags: [recon]
related: ["[[recon]]", "[[services]]", "[[environment]]"]
updated: 2026-06-18
---
# navi — Offline Navigation Platform
## Overview
navi is an offline-capable navigation web app served from **recon-vm** (VM 1130, 192.168.1.130). It provides geocoding, routing, land classification, fleet admin, and DEM-backed elevation data — all from self-hosted geo backends. Frontend is a Vite SPA; backend is a suite of 8 Python microservices behind nginx.
- **URL:** https://navi.echo6.co (fronted by utility Caddy + Authentik)
- **Host:** recon-vm (data node, VM 1130)
- **Repos:** `github.com/zvx-echo6/navi` (canonical), Forge mirror `matt/navi`
- **Layout:** monorepo — `backend/` (Python) + `frontend/` (Vite)
- **Deploy path:** `/home/zvx/projects/repos/navi-mono` (branch `main`, in sync with origin)
## Architecture
```
Internet → Caddy (utility CT 101) → Authentik → nginx :8440 (navi-mono frontend)
├─ /api/* → navi-* backends :8421-:8428
├─ /tiles/* → tile proxy
└─ /dem/* → dem-origin :8441 (range-cached)
└─ /mnt/nas/nav/planet-dem.pmtiles (658 GB)
```
## nginx Vhosts
| Port | Vhost | Role |
|------|-------|------|
| :8440 | navi.echo6.co | Public front door — SPA from `/mnt/nav/frontend`, API gateway (`/api/*` → backends), tile/DEM proxies; range-caches DEM requests from :8441 |
| :8441 | dem-origin (localhost only) | Serves 658 GB `planet-dem.pmtiles` from `/mnt/nas/nav/`; never exposed directly |
## Backend Services
All 8 are gunicorn processes, bound to `127.0.0.1`, working directory `navi-mono/backend`, env files in `/etc/navi-backend/*.env`.
| # | Service | Port | Status | Purpose |
|---|---------|------|--------|---------|
| 1 | navi-traffic | :8421 | **DISABLED** | Traffic — now proxied externally to `central.echo6.mesh:8000` |
| 2 | navi-config | :8422 | Active | Deployment profile API |
| 3 | navi-contacts | :8423 | Active | Contacts + address book |
| 4 | navi-landclass | :8424 | Active | PAD-US land classification (Postgres `padus` DB) |
| 5 | navi-places | :8425 | Active | OSM place detail/enrichment (Postgres `overture` DB) |
| 6 | navi-geo | :8426 | Active | Geocode + reverse geocode (Photon + DEM + timezone) |
| 7 | navi-admin | :8427 | Active | Fleet admin-info aggregator (auth-gated) |
| 8 | navi-offroute | :8428 | Active | Off-network router + MVUM (Valhalla + PostGIS) |
Shared backend modules: `shared/auth.py` (Authentik header validation), `shared/admin_info.py`.
## Geo Backends (co-resident on recon-vm)
| Service | Port | Runtime | Purpose |
|---------|------|---------|---------|
| Valhalla | :8002 | Docker | Routing engine |
| Nominatim | :8010 | Docker | Geocoder |
| Photon | :2322 | Direct | Geocoder (embedded Elasticsearch :9201) |
| PostgreSQL/PostGIS | :5432 | System | DBs: `padus` (land classification), `overture` (OSM enrichment) |
## Data
| Path | Contents |
|------|---------|
| `/mnt/nav/` | Addresses, timezones, OSM PBF, worldcover friction/barriers/trails, HPA, Photon data, frontend SPA build |
| `/mnt/nas/nav/planet-dem.pmtiles` | 658 GB global DEM tile archive |
| `/var/lib/navi-backend/` | Writable runtime state: `contacts.db`, `place_cache.db`, `wiki_index.db` |
NFS: pi-nas exports `/mnt/nav` and `/mnt/nas` to recon-vm.
## Deployment
The repo ships its own deploy templates under `backend/deploy/`:
- `deploy/systemd/` — all 8 unit files (match live)
- `deploy/nginx/` — nginx vhost snippets (match live)
- `deploy/env/` — env file templates (instances in `/etc/navi-backend/`)
- `deploy/caddy/` — Caddy upstream fragment
## Gotchas / Operational Notes
**Three checkouts exist** under `~/projects/repos/`:
| Checkout | Status |
|----------|--------|
| `navi-mono/` | **Live — this is what runs** |
| `navi/` | Stale — do not use |
| `navi-backend/` | Stale — **do not delete without auditing** (see below) |
**`navi-backend/` cannot be deleted yet:** several live env files (`navi-config`, `navi-contacts`, `navi-places`, `navi-geo`, `navi-offroute`) reference config, profile, and address-book files under `/home/zvx/projects/repos/navi-backend/config/...`. Document those paths before any cleanup.
**Stale README:** `backend/README.md` in the monorepo still refers to "extraction #1: navi-traffic" and predates the full monorepo consolidation. Treat `backend/deploy/` as the authoritative source.

View file

@ -22,9 +22,11 @@ RECON extracts knowledge from PDFs and web content into a searchable vector data
- **Host:** recon-vm (VM 1130 on data node, 192.168.1.240) — migrated from CT 130 on 2026-04-19
- **IP:** 192.168.1.130 / 100.64.0.24 (Tailscale)
- **Install:** `/opt/recon/`
- **Repo:** github.com/zvx-echo6/recon (branch `master`; Forge mirror `matt/recon`)
- **Install:** `/opt/recon/` (Python venv, in sync with origin)
- **User:** zvx
- **Service:** `recon.service`, `recon-watchdog.service`, `kiwix.service` (systemd)
- **Entrypoints:** `recon.py service` (dashboard/API :8420) + `recon.py pipeline watch` (watchdog, auto-ingests new PDFs in `/mnt/library`)
- **Dashboard:** https://recon.echo6.co (internal: http://100.64.0.24:8420)
- **Health:** https://recon.echo6.co/api/health
@ -37,7 +39,8 @@ RECON extracts knowledge from PDFs and web content into a searchable vector data
| Status DB | SQLite (WAL mode) | /opt/recon/data/recon.db |
| Vector DB | Qdrant | cortex:6333 (Docker) |
| Embeddings | TEI (bge-m3, 1024-dim) | cortex:8090 (Docker) |
| Enrichment | Gemini 2.5 Flash Lite | Google API (4 keys) |
| Sparse embeddings | recon-sparse (bge-m3 SPLADE) | cortex:8091 (systemd) |
| Enrichment | Gemini `gemini-2.5-flash-lite` (enforced) | Google API (4 keys) |
| Vision Ocr | Gemini 2.5 Flash Lite | Google API (shared keys) |
| Text extraction | PyPDF2, poppler-utils, Tesseract | Local |
| PDF source | NFS | pi-nas:/export/library → /mnt/library |
@ -67,7 +70,7 @@ Method tracking saved in `data/text/{hash}/meta.json` as `ocr_methods` dict.
- ~10,162 documents in pipeline
- ~95,000+ vectors in Qdrant (HNSW index, <10ms search latency)
- Collection: `recon_knowledge`
- Collection: `recon_knowledge_hybrid`
- ~13,239 PDFs catalogued from NFS library
## Resilience
@ -142,4 +145,4 @@ Key sections:
---
*Last updated: 2026-02-16 — Initial creation*
*Last updated: 2026-06-18 — Updated: repo/branch, recon-sparse :8091, recon_knowledge_hybrid collection, Entrypoints; PROJECT-BIBLE.md dated 2026-02-16 (predates current deployment) — verified against live 2026-06-18*