auto: docs sync 2026-06-20T06:00:08+00:00

Files changed: credentials engine/lint-report.md vault/.obsidian/workspace.json vault/projects/fleet-patch-audit.md
This commit is contained in:
echo6-autocommit 2026-06-20 06:00:08 +00:00
commit 76cf8893ef
4 changed files with 42 additions and 26 deletions

View file

@ -375,3 +375,10 @@ WP_IMESH_DB_USER=wp_user
WP_IMESH_DB_PASSWORD=9cnwfhQzkdyfU8C3yodIXu_IA1PUOawr WP_IMESH_DB_PASSWORD=9cnwfhQzkdyfU8C3yodIXu_IA1PUOawr
WP_IMESH_DB_NAME=wordpress WP_IMESH_DB_NAME=wordpress
# WordPress admin credentials: set during browser setup wizard at https://intermountainmesh.com # WordPress admin credentials: set during browser setup wizard at https://intermountainmesh.com
# Proxmox Datacenter Manager (PDM) — Break-glass local admin (edge2 CT 100, 100.64.0.28:8443)
# PAM realm: Linux user on CT100, independent of Authentik SSO
# Backup taken: /root/access.bak-2026-06-20 (inside CT100)
PDM_URL="https://pdm.echo6.co"
PDM_BREAKGLASS_USER="admin@pam"
PDM_BREAKGLASS_PASS="7redditGold"

View file

@ -1,6 +1,6 @@
# Vault Lint Report # Vault Lint Report
Generated: 2026-06-19T18:00:06Z | Docs scanned: 90 | Elapsed: 0.0s Generated: 2026-06-20T00:00:07Z | Docs scanned: 92 | Elapsed: 0.0s
## Summary ## Summary
@ -8,7 +8,7 @@ Generated: 2026-06-19T18:00:06Z | Docs scanned: 90 | Elapsed: 0.0s
|----------|-------| |----------|-------|
| ERROR (dead links) | 0 | | ERROR (dead links) | 0 |
| WARN (schema) | 1 | | WARN (schema) | 1 |
| INFO (orphans) | 39 | | INFO (orphans) | 40 |
### WARN breakdown ### WARN breakdown
- Missing frontmatter block: 1 - Missing frontmatter block: 1
@ -21,10 +21,11 @@ _None. All wikilinks resolve._
## WARN — Schema & Tag Violations ## WARN — Schema & Tag Violations
- `CLAUDE-baseline.md` — missing frontmatter block entirely - `.trash/2026-06-19.md` — missing frontmatter block entirely
## INFO — Orphan Notes (no incoming links, capped at 40) ## INFO — Orphan Notes (no incoming links, capped at 40)
- no incoming links: .trash/2026-06-19.md
- no incoming links: runbooks/add-peertube-channel.md - no incoming links: runbooks/add-peertube-channel.md
- no incoming links: runbooks/authentik-access-groups.md - no incoming links: runbooks/authentik-access-groups.md
- no incoming links: runbooks/authentik-create-invitation.md - no incoming links: runbooks/authentik-create-invitation.md
@ -37,7 +38,6 @@ _None. All wikilinks resolve._
- no incoming links: runbooks/expose-service-contabo.md - no incoming links: runbooks/expose-service-contabo.md
- no incoming links: runbooks/expose-service-edge2.md - no incoming links: runbooks/expose-service-edge2.md
- no incoming links: runbooks/expose-service-home.md - no incoming links: runbooks/expose-service-home.md
- no incoming links: projects/fleet-patch-audit.md
- no incoming links: docs/software/geo-tools.md - no incoming links: docs/software/geo-tools.md
- no incoming links: glossary.md - no incoming links: glossary.md
- no incoming links: runbooks/headscale-onboard-node.md - no incoming links: runbooks/headscale-onboard-node.md
@ -52,6 +52,7 @@ _None. All wikilinks resolve._
- no incoming links: runbooks/meshmonitor-password-reset.md - no incoming links: runbooks/meshmonitor-password-reset.md
- no incoming links: runbooks/meshtastic-sidecar-node.md - no incoming links: runbooks/meshtastic-sidecar-node.md
- no incoming links: runbooks/meshtasticd-sim-nodes-runbook.md - no incoming links: runbooks/meshtasticd-sim-nodes-runbook.md
- no incoming links: projects/nominatim-v5-reimport.md
- no incoming links: runbooks/nordvpn-lxc.md - no incoming links: runbooks/nordvpn-lxc.md
- no incoming links: runbooks/pg-backup.md - no incoming links: runbooks/pg-backup.md
- no incoming links: runbooks/pi-nas-omv-runbook.md - no incoming links: runbooks/pi-nas-omv-runbook.md
@ -69,12 +70,12 @@ _None. All wikilinks resolve._
### Docs with no tags ### Docs with no tags
- `CLAUDE-baseline.md` - `.trash/2026-06-19.md`
- `runbooks/pipeline-patterns.md` - `runbooks/pipeline-patterns.md`
### True orphans (no inbound link, no shared tag) ### True orphans (no inbound link, no shared tag)
- `CLAUDE-baseline.md` - `.trash/2026-06-19.md`
- `runbooks/nordvpn-lxc.md` - `runbooks/nordvpn-lxc.md`
- `runbooks/pipeline-patterns.md` - `runbooks/pipeline-patterns.md`
@ -94,13 +95,13 @@ Matt decides whether to create a real doc — when he does, future sweeps will l
| Term | Docs mentioning it | | Term | Docs mentioning it |
|------|--------------------| |------|--------------------|
| `tailscale` | 33 | | `tailscale` | 33 |
| `docker` | 30 |
| `proxmox` | 30 | | `proxmox` | 30 |
| `docker` | 29 |
| `headscale` | 22 | | `headscale` | 22 |
| `peertube` | 16 | | `peertube` | 16 |
| `meshtastic` | 15 | | `meshtastic` | 15 |
| `mailcow` | 14 | | `mailcow` | 15 |
| `element` | 12 | | `element` | 13 |
| `forgejo` | 11 | | `forgejo` | 11 |
| `immich` | 11 | | `immich` | 11 |
| `nextcloud` | 11 | | `nextcloud` | 11 |

View file

@ -199,6 +199,8 @@
}, },
"active": "8d53cdb6c257e685", "active": "8d53cdb6c257e685",
"lastOpenFiles": [ "lastOpenFiles": [
"projects/fleet-patch-audit.md.tmp.1493418.e48160886375",
"projects/fleet-patch-audit.md.tmp.1493418.e4f1f5df5445",
"projects/nominatim-v5-reimport.md", "projects/nominatim-v5-reimport.md",
"projects/nominatim-v5-reimport.md.tmp.1493418.334c5df83cc6", "projects/nominatim-v5-reimport.md.tmp.1493418.334c5df83cc6",
"projects/fleet-patch-audit.md.tmp.1493418.c5907f7438c0", "projects/fleet-patch-audit.md.tmp.1493418.c5907f7438c0",
@ -209,7 +211,6 @@
"projects/fleet-patch-audit.md.tmp.1493418.dff12cfa9a42", "projects/fleet-patch-audit.md.tmp.1493418.dff12cfa9a42",
"projects/fleet-patch-audit.md.tmp.1493418.73d7194d7615", "projects/fleet-patch-audit.md.tmp.1493418.73d7194d7615",
"projects/fleet-patch-audit.md.tmp.1493418.b6f7dc14e8ae", "projects/fleet-patch-audit.md.tmp.1493418.b6f7dc14e8ae",
"projects/fleet-patch-audit.md.tmp.1493418.a531165239ca",
"2026-06-19.md", "2026-06-19.md",
"Untitled.canvas", "Untitled.canvas",
"docs/hardware/environment.md", "docs/hardware/environment.md",
@ -235,7 +236,6 @@
"concepts/reverse-proxy.md", "concepts/reverse-proxy.md",
"concepts/raspberry-pi.md", "concepts/raspberry-pi.md",
"concepts/lora.md", "concepts/lora.md",
"concepts/knowledge-extraction.md",
"assets/echo6yellow_logo_422x422_square.png", "assets/echo6yellow_logo_422x422_square.png",
"assets/echo6yellow_logo_422x81.png", "assets/echo6yellow_logo_422x81.png",
"assets/echo6_logo.png", "assets/echo6_logo.png",

View file

@ -166,21 +166,29 @@ Lowest-risk changes first; everything reboot-bearing deferred to scheduled windo
## Open Decisions ## Open Decisions
1. **Phase 1 scope** — all non-protected guests at once, or staged worst-first? ### Resolved (2026-06-19/20)
2. **Phase 2 host-OS sequencing**~~fold the four cluster hosts' OS-security apt into their Phase 3 reboot window~~**RESOLVED:** folded into Phase 3 per runbook (no mixed-state across Phase 2 app campaign).
3. **Reboot-window scheduling** — maintenance window dates/times in America/Boise; announce user-facing blips (Authentik SSO, home Caddy, matrix, immich/nextcloud, media). 1. **RabbitMQ 3.12→4.x****ACCEPTED** as a decoupled sub-task (Erlang ≥26 → 3.13.x → enable feature-flags → 4.x); the OpenTAKServer bump does NOT cover it. In scope for this campaign.
4. **Tier-2 app upgrade scope sign-off** — which apps to take on in this campaign vs. defer: Forgejo 14→15 branch migration, Matrix/Synapse, Nominatim 4→5. Each is its own task. 2. **Break-glass****VALIDATED**: all 7 LAN SSH paths work independent of the tailnet; every PVE node (incl. edge2) has local `pam`/`pve` realms; Authentik `akadmin`, Forgejo `matt`, Nextcloud `admin` local logins confirmed. ⚠️ **One gap → PDM (edge2 CT100)** has only `openid:authentik` in `domains.cfg`; confirm `root@pam` login at `https://100.64.0.28:8443` (or add a `pam:` stanza) **before** the Authentik upgrade.
5. **data disk at 92%** — remediate before Phase 1; confirm which artifacts are safe to prune (stale vzdump/snapshots/ISOs, Docker layers on recon-vm except pinned `nominatim:4.5`). 3. **Phase scope****ALL PHASES**; no-reboot work (Phase 12) first, platform/reboot (Phase 3) scheduled separately.
6. **CT118 archivist** rpcbind on `0.0.0.0:111` with no Tailscale/firewall — approved remediation option: disable rpcbind / bind localhost+TS / firewall. 4. **Daemon-restart tolerance****DOWNTIME ACCEPTED**; needrestart blips OK on the stateful guests (still take logical DB dumps for safety, but no holding restarts for availability).
7. **Daemon-restart tolerance** — explicit sign-off that needrestart blips are acceptable for: central CT104 (PG16/NATS/JetStream), opentakserver CT109, peertube CT110, matrix Synapse, recon-vm VM1130 PG16 + navi-backend; or lock those guests to `NEEDRESTART_MODE=l` (runbook already carves them out as stateful; this is the approval gate). 5. **edge2 host kernel (DirtyFrag/copy.fail)****NO ACTION / NO REBOOT**: running `6.8.12-30-pve`, the newest its repos offer; no update available, no reboot-required flag. Not actionable without a repo/branch change. edge2 needs no Phase 3 reboot.
8. ~~**edge2 CT108 mailcow is stopped**~~**RESOLVED:** confirmed superseded by edge1. Backup verified at `/opt/mailcow-backup/mailcow-2026-06-19-03-59-45/`. Pending: verify backup stored durably off CT108, then `pct destroy 108` on approval. 6. **CVE verification****NOT GATING**: being behind on versions is sufficient justification; post-cutoff CVE IDs are not chased or relied on for ordering.
9. **edge2 host-kernel CVEs (DirtyFrag / copy.fail)** — verify whether flagged in-the-wild LPEs apply given host shows fully patched; resolves whether edge2 needs a Phase 3 reboot (otherwise none required). 7. **Maintenance windows****NO CONSTRAINT** (single user); disruptive steps may run anytime, no scheduling/announcement needed.
10. **App-currency CVE IDs are post-cutoff** — verify specific advisories (Authentik May-2026 waves, Valkey 9.1.0, Immich 2.6/2.7, RabbitMQ 4.x) against primary sources before using to justify urgency; assign owner + primary-source URL per claim. 8. **Nominatim 4→5****DEFERRED / OUT OF SCOPE**: spun off to [[nominatim-v5-reimport]] as its own project.
11. ~~**Headscale location**~~**RESOLVED:** main fleet tailnet = edge2 CT107 (Headscale 0.28.0, `vpn.echo6.co`, 34 nodes); IdahoMesh sub-tailnet = utility CT106 (3 nodes, `vpn.idahomesh.com`). No Contabo routing. 9. **Headscale location****RESOLVED**: fleet control plane = edge2 CT107 (`vpn.echo6.co`, 34 nodes — high-risk); IdahoMesh sub-tailnet = utility CT106 (`vpn.idahomesh.com`, 3 nodes — low-risk). No Contabo routing.
12. **RabbitMQ 3.12→4.x scope sign-off** — confirm the separate RabbitMQ decoupled upgrade (Erlang→3.13.x→feature-flags→4.x) is in scope for this campaign, not deferred. 10. **mailcow CT108****RESOLVED**: superseded by edge1; safe to decommission (pending backup-off-CT verify below).
13. **Break-glass proof gate** — log in with akadmin in a private browser session; confirm each protected app (Forgejo, Nextcloud, PDM, Vaultwarden) has a working local-admin fallback before Phase 2 starts. 11. **Phase 2 host-OS sequencing****RESOLVED**: folded into Phase 3 reboot window.
14. **Nominatim 4→5 scope** — separate project (full re-import, separate DB/instance, not in this campaign); confirm exclusion from patch campaign scope. 12. **In-scope app campaign** — Forgejo 14→15, Matrix/Synapse, Authentik chain, RabbitMQ, media stack, immich, nextcloud, headscale, cortex AI. (Nominatim excluded per #8.)
15. **edge2 host kernel decision** — pin `uname -r` / `proxmox-boot-tool kernel list`, check no-sub repo kernel vs. CVE-fixed version; decide reboot yes/no before Phase 3 planning.
### Pre-flight gates — status (2026-06-20)
- **PDM break-glass** — ✅ **DONE**: local `admin@pam` (Administrator) created on PDM CT100, login verified via API, Authentik realm untouched; cred in `credentials`, config backup at CT100 `/root/access.bak-2026-06-20`.
- **CT118 archivist rpcbind** — ✅ **DONE**: nftables rule restricts port 111 to source `192.168.1.240` (NFS server) only; NFS mount healthy, ruleset persisted. Now 100% LAN-internal.
- **mailcow CT108** — backup now **durable on pi-nas** (`…/contabo-prewipe-2026-06/mailcow/`, 3 files, sha256-verified); edge1 confirmed live mail. **Pending: `pct destroy 108` on explicit approval** (edge2 `/tmp` sources retained until then).
- **data disk (92%)** — ⏏️ **DE-SCOPED**: not a gate. OS package updates are roll-back-able (reinstall prior version); the migration-heavy apps that need real rollback (Authentik, Forgejo, Nextcloud, PeerTube) live on cloud/edge2, not `data`. Optional cleanup only (~6 GB obviously-safe: stale ISO, zimit temp) if ever wanted.
**Rollback model (corrected):** OS packages → reinstall the prior version (no VM snapshot needed). App DB-migration upgrades (Authentik/Forgejo/Nextcloud/PeerTube) → restore a quiesced DB dump (cheap), since reinstalling the old binary won't unwind a migrated schema.
--- ---