From 76cf8893efc9d91f2aa305af27f09e327766e5ef Mon Sep 17 00:00:00 2001 From: echo6-autocommit Date: Sat, 20 Jun 2026 06:00:08 +0000 Subject: [PATCH] auto: docs sync 2026-06-20T06:00:08+00:00 Files changed: credentials engine/lint-report.md vault/.obsidian/workspace.json vault/projects/fleet-patch-audit.md --- credentials | 7 ++++++ engine/lint-report.md | 19 ++++++++------- vault/.obsidian/workspace.json | 4 +-- vault/projects/fleet-patch-audit.md | 38 +++++++++++++++++------------ 4 files changed, 42 insertions(+), 26 deletions(-) diff --git a/credentials b/credentials index 815ea86..28a7f2e 100755 --- a/credentials +++ b/credentials @@ -375,3 +375,10 @@ WP_IMESH_DB_USER=wp_user WP_IMESH_DB_PASSWORD=9cnwfhQzkdyfU8C3yodIXu_IA1PUOawr WP_IMESH_DB_NAME=wordpress # WordPress admin credentials: set during browser setup wizard at https://intermountainmesh.com + +# Proxmox Datacenter Manager (PDM) — Break-glass local admin (edge2 CT 100, 100.64.0.28:8443) +# PAM realm: Linux user on CT100, independent of Authentik SSO +# Backup taken: /root/access.bak-2026-06-20 (inside CT100) +PDM_URL="https://pdm.echo6.co" +PDM_BREAKGLASS_USER="admin@pam" +PDM_BREAKGLASS_PASS="7redditGold" diff --git a/engine/lint-report.md b/engine/lint-report.md index a65aa38..947b14a 100644 --- a/engine/lint-report.md +++ b/engine/lint-report.md @@ -1,6 +1,6 @@ # Vault Lint Report -Generated: 2026-06-19T18:00:06Z | Docs scanned: 90 | Elapsed: 0.0s +Generated: 2026-06-20T00:00:07Z | Docs scanned: 92 | Elapsed: 0.0s ## Summary @@ -8,7 +8,7 @@ Generated: 2026-06-19T18:00:06Z | Docs scanned: 90 | Elapsed: 0.0s |----------|-------| | ERROR (dead links) | 0 | | WARN (schema) | 1 | -| INFO (orphans) | 39 | +| INFO (orphans) | 40 | ### WARN breakdown - Missing frontmatter block: 1 @@ -21,10 +21,11 @@ _None. All wikilinks resolve._ ## WARN — Schema & Tag Violations -- `CLAUDE-baseline.md` — missing frontmatter block entirely +- `.trash/2026-06-19.md` — missing frontmatter block entirely ## INFO — Orphan Notes (no incoming links, capped at 40) +- no incoming links: .trash/2026-06-19.md - no incoming links: runbooks/add-peertube-channel.md - no incoming links: runbooks/authentik-access-groups.md - no incoming links: runbooks/authentik-create-invitation.md @@ -37,7 +38,6 @@ _None. All wikilinks resolve._ - no incoming links: runbooks/expose-service-contabo.md - no incoming links: runbooks/expose-service-edge2.md - no incoming links: runbooks/expose-service-home.md -- no incoming links: projects/fleet-patch-audit.md - no incoming links: docs/software/geo-tools.md - no incoming links: glossary.md - no incoming links: runbooks/headscale-onboard-node.md @@ -52,6 +52,7 @@ _None. All wikilinks resolve._ - no incoming links: runbooks/meshmonitor-password-reset.md - no incoming links: runbooks/meshtastic-sidecar-node.md - no incoming links: runbooks/meshtasticd-sim-nodes-runbook.md +- no incoming links: projects/nominatim-v5-reimport.md - no incoming links: runbooks/nordvpn-lxc.md - no incoming links: runbooks/pg-backup.md - no incoming links: runbooks/pi-nas-omv-runbook.md @@ -69,12 +70,12 @@ _None. All wikilinks resolve._ ### Docs with no tags -- `CLAUDE-baseline.md` +- `.trash/2026-06-19.md` - `runbooks/pipeline-patterns.md` ### True orphans (no inbound link, no shared tag) -- `CLAUDE-baseline.md` +- `.trash/2026-06-19.md` - `runbooks/nordvpn-lxc.md` - `runbooks/pipeline-patterns.md` @@ -94,13 +95,13 @@ Matt decides whether to create a real doc — when he does, future sweeps will l | Term | Docs mentioning it | |------|--------------------| | `tailscale` | 33 | +| `docker` | 30 | | `proxmox` | 30 | -| `docker` | 29 | | `headscale` | 22 | | `peertube` | 16 | | `meshtastic` | 15 | -| `mailcow` | 14 | -| `element` | 12 | +| `mailcow` | 15 | +| `element` | 13 | | `forgejo` | 11 | | `immich` | 11 | | `nextcloud` | 11 | diff --git a/vault/.obsidian/workspace.json b/vault/.obsidian/workspace.json index 0ee75fd..750c959 100644 --- a/vault/.obsidian/workspace.json +++ b/vault/.obsidian/workspace.json @@ -199,6 +199,8 @@ }, "active": "8d53cdb6c257e685", "lastOpenFiles": [ + "projects/fleet-patch-audit.md.tmp.1493418.e48160886375", + "projects/fleet-patch-audit.md.tmp.1493418.e4f1f5df5445", "projects/nominatim-v5-reimport.md", "projects/nominatim-v5-reimport.md.tmp.1493418.334c5df83cc6", "projects/fleet-patch-audit.md.tmp.1493418.c5907f7438c0", @@ -209,7 +211,6 @@ "projects/fleet-patch-audit.md.tmp.1493418.dff12cfa9a42", "projects/fleet-patch-audit.md.tmp.1493418.73d7194d7615", "projects/fleet-patch-audit.md.tmp.1493418.b6f7dc14e8ae", - "projects/fleet-patch-audit.md.tmp.1493418.a531165239ca", "2026-06-19.md", "Untitled.canvas", "docs/hardware/environment.md", @@ -235,7 +236,6 @@ "concepts/reverse-proxy.md", "concepts/raspberry-pi.md", "concepts/lora.md", - "concepts/knowledge-extraction.md", "assets/echo6yellow_logo_422x422_square.png", "assets/echo6yellow_logo_422x81.png", "assets/echo6_logo.png", diff --git a/vault/projects/fleet-patch-audit.md b/vault/projects/fleet-patch-audit.md index f94f108..269729b 100644 --- a/vault/projects/fleet-patch-audit.md +++ b/vault/projects/fleet-patch-audit.md @@ -166,21 +166,29 @@ Lowest-risk changes first; everything reboot-bearing deferred to scheduled windo ## Open Decisions -1. **Phase 1 scope** — all non-protected guests at once, or staged worst-first? -2. **Phase 2 host-OS sequencing** — ~~fold the four cluster hosts' OS-security apt into their Phase 3 reboot window~~ — **RESOLVED:** folded into Phase 3 per runbook (no mixed-state across Phase 2 app campaign). -3. **Reboot-window scheduling** — maintenance window dates/times in America/Boise; announce user-facing blips (Authentik SSO, home Caddy, matrix, immich/nextcloud, media). -4. **Tier-2 app upgrade scope sign-off** — which apps to take on in this campaign vs. defer: Forgejo 14→15 branch migration, Matrix/Synapse, Nominatim 4→5. Each is its own task. -5. **data disk at 92%** — remediate before Phase 1; confirm which artifacts are safe to prune (stale vzdump/snapshots/ISOs, Docker layers on recon-vm except pinned `nominatim:4.5`). -6. **CT118 archivist** rpcbind on `0.0.0.0:111` with no Tailscale/firewall — approved remediation option: disable rpcbind / bind localhost+TS / firewall. -7. **Daemon-restart tolerance** — explicit sign-off that needrestart blips are acceptable for: central CT104 (PG16/NATS/JetStream), opentakserver CT109, peertube CT110, matrix Synapse, recon-vm VM1130 PG16 + navi-backend; or lock those guests to `NEEDRESTART_MODE=l` (runbook already carves them out as stateful; this is the approval gate). -8. ~~**edge2 CT108 mailcow is stopped**~~ — **RESOLVED:** confirmed superseded by edge1. Backup verified at `/opt/mailcow-backup/mailcow-2026-06-19-03-59-45/`. Pending: verify backup stored durably off CT108, then `pct destroy 108` on approval. -9. **edge2 host-kernel CVEs (DirtyFrag / copy.fail)** — verify whether flagged in-the-wild LPEs apply given host shows fully patched; resolves whether edge2 needs a Phase 3 reboot (otherwise none required). -10. **App-currency CVE IDs are post-cutoff** — verify specific advisories (Authentik May-2026 waves, Valkey 9.1.0, Immich 2.6/2.7, RabbitMQ 4.x) against primary sources before using to justify urgency; assign owner + primary-source URL per claim. -11. ~~**Headscale location**~~ — **RESOLVED:** main fleet tailnet = edge2 CT107 (Headscale 0.28.0, `vpn.echo6.co`, 34 nodes); IdahoMesh sub-tailnet = utility CT106 (3 nodes, `vpn.idahomesh.com`). No Contabo routing. -12. **RabbitMQ 3.12→4.x scope sign-off** — confirm the separate RabbitMQ decoupled upgrade (Erlang→3.13.x→feature-flags→4.x) is in scope for this campaign, not deferred. -13. **Break-glass proof gate** — log in with akadmin in a private browser session; confirm each protected app (Forgejo, Nextcloud, PDM, Vaultwarden) has a working local-admin fallback before Phase 2 starts. -14. **Nominatim 4→5 scope** — separate project (full re-import, separate DB/instance, not in this campaign); confirm exclusion from patch campaign scope. -15. **edge2 host kernel decision** — pin `uname -r` / `proxmox-boot-tool kernel list`, check no-sub repo kernel vs. CVE-fixed version; decide reboot yes/no before Phase 3 planning. +### Resolved (2026-06-19/20) + +1. **RabbitMQ 3.12→4.x** — **ACCEPTED** as a decoupled sub-task (Erlang ≥26 → 3.13.x → enable feature-flags → 4.x); the OpenTAKServer bump does NOT cover it. In scope for this campaign. +2. **Break-glass** — **VALIDATED**: all 7 LAN SSH paths work independent of the tailnet; every PVE node (incl. edge2) has local `pam`/`pve` realms; Authentik `akadmin`, Forgejo `matt`, Nextcloud `admin` local logins confirmed. ⚠️ **One gap → PDM (edge2 CT100)** has only `openid:authentik` in `domains.cfg`; confirm `root@pam` login at `https://100.64.0.28:8443` (or add a `pam:` stanza) **before** the Authentik upgrade. +3. **Phase scope** — **ALL PHASES**; no-reboot work (Phase 1–2) first, platform/reboot (Phase 3) scheduled separately. +4. **Daemon-restart tolerance** — **DOWNTIME ACCEPTED**; needrestart blips OK on the stateful guests (still take logical DB dumps for safety, but no holding restarts for availability). +5. **edge2 host kernel (DirtyFrag/copy.fail)** — **NO ACTION / NO REBOOT**: running `6.8.12-30-pve`, the newest its repos offer; no update available, no reboot-required flag. Not actionable without a repo/branch change. edge2 needs no Phase 3 reboot. +6. **CVE verification** — **NOT GATING**: being behind on versions is sufficient justification; post-cutoff CVE IDs are not chased or relied on for ordering. +7. **Maintenance windows** — **NO CONSTRAINT** (single user); disruptive steps may run anytime, no scheduling/announcement needed. +8. **Nominatim 4→5** — **DEFERRED / OUT OF SCOPE**: spun off to [[nominatim-v5-reimport]] as its own project. +9. **Headscale location** — **RESOLVED**: fleet control plane = edge2 CT107 (`vpn.echo6.co`, 34 nodes — high-risk); IdahoMesh sub-tailnet = utility CT106 (`vpn.idahomesh.com`, 3 nodes — low-risk). No Contabo routing. +10. **mailcow CT108** — **RESOLVED**: superseded by edge1; safe to decommission (pending backup-off-CT verify below). +11. **Phase 2 host-OS sequencing** — **RESOLVED**: folded into Phase 3 reboot window. +12. **In-scope app campaign** — Forgejo 14→15, Matrix/Synapse, Authentik chain, RabbitMQ, media stack, immich, nextcloud, headscale, cortex AI. (Nominatim excluded per #8.) + +### Pre-flight gates — status (2026-06-20) + +- **PDM break-glass** — ✅ **DONE**: local `admin@pam` (Administrator) created on PDM CT100, login verified via API, Authentik realm untouched; cred in `credentials`, config backup at CT100 `/root/access.bak-2026-06-20`. +- **CT118 archivist rpcbind** — ✅ **DONE**: nftables rule restricts port 111 to source `192.168.1.240` (NFS server) only; NFS mount healthy, ruleset persisted. Now 100% LAN-internal. +- **mailcow CT108** — backup now **durable on pi-nas** (`…/contabo-prewipe-2026-06/mailcow/`, 3 files, sha256-verified); edge1 confirmed live mail. **Pending: `pct destroy 108` on explicit approval** (edge2 `/tmp` sources retained until then). +- **data disk (92%)** — ⏏️ **DE-SCOPED**: not a gate. OS package updates are roll-back-able (reinstall prior version); the migration-heavy apps that need real rollback (Authentik, Forgejo, Nextcloud, PeerTube) live on cloud/edge2, not `data`. Optional cleanup only (~6 GB obviously-safe: stale ISO, zimit temp) if ever wanted. + +**Rollback model (corrected):** OS packages → reinstall the prior version (no VM snapshot needed). App DB-migration upgrades (Authentik/Forgejo/Nextcloud/PeerTube) → restore a quiesced DB dump (cheap), since reinstalling the old binary won't unwind a migrated schema. ---