auto: docs sync 2026-07-16T12:00:15+00:00

Files changed: engine/.embcache.json engine/changelog.md engine/lint-report.md vault/docs/hardware/environment.md vault/docs/hardware/ip-allocation.md vault/docs/software/central.md vault/docs/software/conduit.md vault/runbooks/add-peertube-channel.md vault/runbooks/central-deploy-cutover.md vault/runbooks/conduit-operations.md vault/runbooks/peertube-remote-runner.md
This commit is contained in:
echo6-autocommit 2026-07-16 12:00:15 +00:00
commit 77b4715384
11 changed files with 54 additions and 48 deletions

File diff suppressed because one or more lines are too long

View file

@ -171,3 +171,9 @@
- processed: 1 | written: 1 | flagged: 0 | errors: 0 - processed: 1 | written: 1 | flagged: 0 | errors: 0
## 2026-07-15T09:00:01Z — sweep deferred (competing GPU process: 1479040 /usr/bin/python3 /usr/local/bin/whisper-ctranslate2-real /home/zvx/.cache/peertube-runner-nodejs/default/transcoding/7fd5c3f5-460b-4727-a08c-5cc870990b69 --model medium --word_timestamps True --vad_filter true --vad_min_silence_duration_ms 5000 --output_format all --output_dir /home/zvx/.cache/peertube-runner-nodejs/default/transcription/oHfKgprXtJn5hsvZXNS1pX --model medium --device cpu --compute_type int8 --word_timestamps False --vad_min_silence_duration_ms 500) ## 2026-07-15T09:00:01Z — sweep deferred (competing GPU process: 1479040 /usr/bin/python3 /usr/local/bin/whisper-ctranslate2-real /home/zvx/.cache/peertube-runner-nodejs/default/transcoding/7fd5c3f5-460b-4727-a08c-5cc870990b69 --model medium --word_timestamps True --vad_filter true --vad_min_silence_duration_ms 5000 --output_format all --output_dir /home/zvx/.cache/peertube-runner-nodejs/default/transcription/oHfKgprXtJn5hsvZXNS1pX --model medium --device cpu --compute_type int8 --word_timestamps False --vad_min_silence_duration_ms 500)
## 2026-07-16T09:00:01Z — sweep run
- end: 2026-07-16T09:00:19Z
- mode: incremental
- docs selected: 8
- processed: 8 | written: 8 | flagged: 0 | errors: 0

View file

@ -1,6 +1,6 @@
# Vault Lint Report # Vault Lint Report
Generated: 2026-07-16T00:00:19Z | Docs scanned: 107 | Elapsed: 0.0s Generated: 2026-07-16T09:00:01Z | Docs scanned: 107 | Elapsed: 0.0s
## Summary ## Summary

View file

@ -5,12 +5,12 @@ tags:
- proxmox - proxmox
aliases: [] aliases: []
related: related:
- [[ip-allocation]]
- [[fleet-platform-baseline]] - [[fleet-platform-baseline]]
- [[proxmox-create-ubuntu-vm]] - [[ip-allocation]]
- [[headscale-onboard-node]] - [[headscale-onboard-node]]
- [[ct-runbook]] - [[proxmox-create-ubuntu-vm]]
updated: 2026-07-15 - [[toc-cortex-pve9.2-update]]
updated: 2026-07-16
--- ---
# Echo6 Environment Reference # Echo6 Environment Reference
@ -22,7 +22,7 @@ Five nodes running Proxmox VE:
| ------- | ------------- | ----------- | ----------------------------------------------- | -------------- | -------------------------------- | | ------- | ------------- | ----------- | ----------------------------------------------- | -------------- | -------------------------------- |
| data | 192.168.1.240 | 100.64.0.6 | AMD Ryzen 7 PRO 5750GE, 1TB NVMe + 1TB SATA SSD | 32GB DDR4-3200 | Database [[services]] | | data | 192.168.1.240 | 100.64.0.6 | AMD Ryzen 7 PRO 5750GE, 1TB NVMe + 1TB SATA SSD | 32GB DDR4-3200 | Database [[services]] |
| utility | 192.168.1.241 | 100.64.0.5 | AMD Ryzen 7 PRO 5750GE, 512GB NVMe | 32GB DDR4-3200 | Utility [[services]], monitoring | | utility | 192.168.1.241 | 100.64.0.5 | AMD Ryzen 7 PRO 5750GE, 512GB NVMe | 32GB DDR4-3200 | Utility [[services]], monitoring |
| cloud | 192.168.1.242 | 100.64.0.4 | Intel i7-12700T, 512GB NVMe | 32GB DDR4-3200 | Cloud storage, personal services | | cloud | 192.168.1.242 | 100.64.0.4 | Intel i7-12700T, 512GB NVMe | 32GB DDR4-3200 | Cloud storage, personal [[services]] |
| media | 192.168.1.243 | 100.64.0.3 | Intel i7-14700T, 2x 512GB NVMe | 32GB DDR5-5600 | Media server, *arr stack | | media | 192.168.1.243 | 100.64.0.3 | Intel i7-14700T, 2x 512GB NVMe | 32GB DDR5-5600 | Media server, *arr stack |
| toc | 192.168.1.244 | 100.64.0.13 | Workstation (i9-10900X) | 64GB DDR4 | GPU compute, AI/ML workloads | | toc | 192.168.1.244 | 100.64.0.13 | Workstation (i9-10900X) | 64GB DDR4 | GPU compute, AI/ML workloads |
### Node Storage Details ### Node Storage Details
@ -50,7 +50,7 @@ Five nodes running Proxmox VE:
### Network Notes ### Network Notes
- **media NIC:** Original Intel e1000e NIC (`nic0`, MAC `e8:cf:83:20:8b:cb`) crashes under sustained NFS load — present but DOWN/unused. Sole uplink is a USB Realtek RTL8153 GbE dongle (MAC `0c:37:96:0e:e8:53`) on vmbr0. - **media NIC:** Original Intel e1000e NIC (`nic0`, MAC `e8:cf:83:20:8b:cb`) crashes under sustained NFS load — present but DOWN/unused. Sole uplink is a USB Realtek RTL8153 GbE dongle (MAC `0c:37:96:0e:e8:53`) on vmbr0.
- **Tailscale [[dns]] bootstrap:** All LXC containers with Tailscale have a systemd drop-in (`/etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf`) that ensures fallback [[dns]] exists before tailscaled starts, preventing chicken-and-egg DNS resolution failures on reboot - **Tailscale [[dns]] bootstrap:** All LXC containers with Tailscale have a systemd drop-in (`/etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf`) that ensures fallback [[dns]] exists before tailscaled starts, preventing chicken-and-egg [[dns]] resolution failures on reboot
### TOC Node Details ### TOC Node Details
@ -115,7 +115,7 @@ Five nodes running Proxmox VE:
| **edge1** (rebuilt Contabo VPS) | 5.189.158.149 | 100.64.0.40 | Debian 12 + Proxmox 8.4.19, **mail-only** — Mailcow in CT 101; host [[caddy]] + mailcow-dnat.service; rebuilt [[2026-06-19]] | | **edge1** (rebuilt Contabo VPS) | 5.189.158.149 | 100.64.0.40 | Debian 12 + Proxmox 8.4.19, **mail-only** — Mailcow in CT 101; host [[caddy]] + mailcow-dnat.service; rebuilt [[2026-06-19]] |
| edge2 | 184.174.35.153 | 100.64.0.26 | Contabo Cloud VPS 30 NVMe — Proxmox VE 8.4.19 (LXC-only), 8c/24GB/400GB — **permanent front door** for vault/forge/notes/auth/matrix/element/vpn/proxmox.echo6.co + idahomesh/intermountainmesh | | edge2 | 184.174.35.153 | 100.64.0.26 | Contabo Cloud VPS 30 NVMe — Proxmox VE 8.4.19 (LXC-only), 8c/24GB/400GB — **permanent front door** for vault/forge/notes/auth/matrix/element/vpn/proxmox.echo6.co + idahomesh/intermountainmesh |
*Last updated: 2026-06-19 — Contabo VPS rebuilt as edge1 (mail-only, Debian 12 + Proxmox 8.4.19, 5.189.158.149 / tailnet 100.64.0.40); Mailcow CT 101 (10.10.10.2) on edge1; edge2 is now the permanent front door for all other services; Headscale node `contabo` moved to 100.64.0.40; previously added edge2 CT 107 (headscale), CT 106 (matrix), CT 105 ([[authentik]]), CT 104 (livesync), CT 103 (forgejo), CT 102 (vaultwarden)* *Last updated: [[2026-06-19]] — Contabo VPS rebuilt as edge1 (mail-only, Debian 12 + Proxmox 8.4.19, 5.189.158.149 / tailnet 100.64.0.40); Mailcow CT 101 (10.10.10.2) on edge1; edge2 is now the permanent front door for all other services; Headscale node `contabo` moved to 100.64.0.40; previously added edge2 CT 107 (headscale), CT 106 (matrix), CT 105 ([[authentik]]), CT 104 (livesync), CT 103 (forgejo), CT 102 (vaultwarden)*
## LXC Containers ## LXC Containers
@ -128,19 +128,19 @@ Five nodes running Proxmox VE:
| nextcloud | cloud (CT 121) | 192.168.1.183 | 100.64.0.11 | Nextcloud AIO | | nextcloud | cloud (CT 121) | 192.168.1.183 | 100.64.0.11 | Nextcloud AIO |
| meshtastic-hs | utility (CT 106) | 192.168.1.106 | — | IdahoMesh Headscale VPN coordination | | meshtastic-hs | utility (CT 106) | 192.168.1.106 | — | IdahoMesh Headscale VPN coordination |
| mesh-bridge | utility (CT 107) | 192.168.1.107 | 100.64.0.22 | Dual-tailscaled bridge (echo6 ↔ idahomesh) | | mesh-bridge | utility (CT 107) | 192.168.1.107 | 100.64.0.22 | Dual-tailscaled bridge (echo6 ↔ idahomesh) |
| meshai | utility (CT 108) | 192.168.1.144 | 100.64.0.32 | MeshAI - LLM-powered Meshtastic assistant | | [[meshai]] | utility (CT 108) | 192.168.1.144 | 100.64.0.32 | MeshAI - LLM-powered Meshtastic assistant |
| [[archivist]] | utility (CT 118) | 192.168.1.118 | — | [[archivist]] knowledge pipeline | | [[archivist]] | utility (CT 118) | 192.168.1.118 | — | [[archivist]] knowledge pipeline |
| [[argus]] | utility (CT 103) | 192.168.1.103 | 100.64.0.25 | [[argus]] - OSINT intelligence gathering platform | | [[argus]] | utility (CT 103) | 192.168.1.103 | 100.64.0.25 | [[argus]] - OSINT intelligence gathering platform |
| [[central]] | utility (CT 104) | 192.168.1.104 | 100.64.0.12 | Data-hub spine (central.echo6.mesh) — ~25 adapters, NATS/JetStream, TimescaleDB/PostGIS — see [[central]] | | [[central]] | utility (CT 104) | 192.168.1.104 | 100.64.0.12 | Data-hub spine (central.echo6.mesh) — ~25 adapters, NATS/JetStream, TimescaleDB/PostGIS — see [[central]] |
| peertube | media (CT 110) | 192.168.1.170 | 100.64.0.17 | PeerTube video streaming — Tailscale identity is `peertube-4hve9pdr` (collision-suffixed) since ~2026-06-22; `.23` is stale/gone | | peertube | media (CT 110) | 192.168.1.170 | 100.64.0.17 | PeerTube video streaming — Tailscale identity is `peertube-4hve9pdr` (collision-suffixed) since ~2026-06-22; `.23` is stale/gone |
| mcc | media (CT 111) | 192.168.1.111 | 100.64.0.19 | pymc console web app (Caddy + Postfix, /api+/auth+/ws → aida-nebra :8000) | | mcc | media (CT 111) | 192.168.1.111 | 100.64.0.19 | pymc console web app ([[caddy]] + Postfix, /api+/auth+/ws → aida-nebra :8000) |
| mailcow | edge1 (CT 101) | 10.10.10.2 | — | Mailcow email server (privileged LXC, mail-only host; reached via host DNAT + Caddy) | | mailcow | edge1 (CT 101) | 10.10.10.2 | — | Mailcow email server (privileged LXC, mail-only host; reached via host DNAT + Caddy) |
| pdm | edge2 (CT 100) | 10.10.10.10 | 100.64.0.28 | Proxmox Datacenter Manager | | pdm | edge2 (CT 100) | 10.10.10.10 | 100.64.0.28 | Proxmox Datacenter Manager |
| wordpress | edge2 (CT 101) | 10.10.10.11 | 100.64.0.31 | WordPress for intermountainmesh.com | | wordpress | edge2 (CT 101) | 10.10.10.11 | 100.64.0.31 | WordPress for intermountainmesh.com |
| vaultwarden | edge2 (CT 102) | 10.10.10.20 | 100.64.0.33 | Vaultwarden password manager (migrated from Contabo 2026-06-16) | | vaultwarden | edge2 (CT 102) | 10.10.10.20 | 100.64.0.33 | Vaultwarden password manager (migrated from Contabo 2026-06-16) |
| forgejo | edge2 (CT 103) | 10.10.10.21 | 100.64.0.34 | Forgejo git server (migrated from Contabo 2026-06-16) | | forgejo | edge2 (CT 103) | 10.10.10.21 | 100.64.0.34 | Forgejo git server (migrated from Contabo 2026-06-16) |
| livesync | edge2 (CT 104) | 10.10.10.22 | 100.64.0.35 | LiveSync Obsidian sync (CouchDB + provisioner; migrated from Contabo 2026-06-16) | | livesync | edge2 (CT 104) | 10.10.10.22 | 100.64.0.35 | LiveSync Obsidian sync (CouchDB + provisioner; migrated from Contabo 2026-06-16) |
| authentik | edge2 (CT 105) | 10.10.10.23 | 100.64.0.36 | Authentik SSO platform (migrated from Contabo 2026-06-18) | | [[authentik]] | edge2 (CT 105) | 10.10.10.23 | 100.64.0.36 | Authentik SSO platform (migrated from Contabo 2026-06-18) |
| matrix | edge2 (CT 106) | 10.10.10.24 | 100.64.0.37 | Matrix stack ([[synapse]] + MAS + Element + [[mautrix_signal]]; migrated from Contabo 2026-06-18) | | matrix | edge2 (CT 106) | 10.10.10.24 | 100.64.0.37 | Matrix stack ([[synapse]] + MAS + Element + [[mautrix_signal]]; migrated from Contabo 2026-06-18) |
| headscale | edge2 (CT 107) | 10.10.10.25 | 100.64.0.38 | Headscale + Headplane tailnet control plane (migrated from Contabo 2026-06-19) | | headscale | edge2 (CT 107) | 10.10.10.25 | 100.64.0.38 | Headscale + Headplane tailnet control plane (migrated from Contabo 2026-06-19) |
@ -178,14 +178,14 @@ Current registered nodes (25 total):
| nextcloud | 100.64.0.11 | LXC | | nextcloud | 100.64.0.11 | LXC |
| toc | 100.64.0.13 | Proxmox | | toc | 100.64.0.13 | Proxmox |
| cortex | 100.64.0.14 | VM | | cortex | 100.64.0.14 | VM |
| searxng | 100.64.0.15 | LXC | | [[searxng]] | 100.64.0.15 | LXC |
| ha | 100.64.0.16 | VM (cloud VM 151 — node id 54, user echo6; home automation) | | ha | 100.64.0.16 | VM (cloud VM 151 — node id 54, user echo6; home automation) |
| arr | 100.64.0.18 | VM | | arr | 100.64.0.18 | VM |
| pi-nas | 100.64.0.21 | Pi | | pi-nas | 100.64.0.21 | Pi |
| mesh-bridge | 100.64.0.22 | LXC | | mesh-bridge | 100.64.0.22 | LXC |
| peertube-4hve9pdr | 100.64.0.17 | LXC (collision-suffixed identity since ~2026-06-22; formerly `peertube` at 100.64.0.23, now stale/gone) | | peertube-4hve9pdr | 100.64.0.17 | LXC (collision-suffixed identity since ~2026-06-22; formerly `peertube` at 100.64.0.23, now stale/gone) |
| recon | 100.64.0.24 | VM | | [[recon]] | 100.64.0.24 | VM |
| argus | 100.64.0.25 | LXC | | [[argus]] | 100.64.0.25 | LXC |
| [[central]] | 100.64.0.12 | LXC (utility CT 104 — central.echo6.mesh) | | [[central]] | 100.64.0.12 | LXC (utility CT 104 — central.echo6.mesh) |
| edge2 | 100.64.0.26 | Proxmox/Contabo VPS | | edge2 | 100.64.0.26 | Proxmox/Contabo VPS |
| gl-a1300 | 100.64.0.29 | Router | | gl-a1300 | 100.64.0.29 | Router |

View file

@ -5,12 +5,12 @@ tags:
- proxmox - proxmox
aliases: [] aliases: []
related: related:
- [[services]]
- [[caddy]] - [[caddy]]
- [[services]]
- [[environment]] - [[environment]]
- [[glossary]] - [[glossary]]
- [[headscale-onboard-node]] - [[headscale-onboard-node]]
updated: 2026-07-14 updated: 2026-07-16
--- ---
# Echo6 Network IP Allocation # Echo6 Network IP Allocation
@ -56,7 +56,7 @@ updated: 2026-07-14
| .116 | mmud-wspr (CT 116) | utility | MMUD SIM: WSPR (Whisper sage) | | .116 | mmud-wspr (CT 116) | utility | MMUD SIM: WSPR (Whisper sage) |
| .118 | [[archivist]] (CT 118) | utility | Signal/Matrix archive bot | | .118 | [[archivist]] (CT 118) | utility | Signal/Matrix archive bot |
| .130 | [[recon]] (VM 1130) | data | [[recon]] pipeline (migrated from CT 130) | | .130 | [[recon]] (VM 1130) | data | [[recon]] pipeline (migrated from CT 130) |
| .144 | [[meshai]] (CT 108) | utility | MeshAI assistant | | .144 | [[meshai]] (CT 108) | utility | [[meshai]] assistant |
| .170 | peertube (CT 110) | media | PeerTube streaming | | .170 | peertube (CT 110) | media | PeerTube streaming |
| .182 | immich (CT 120) | cloud | Immich photos | | .182 | immich (CT 120) | cloud | Immich photos |
| .183 | nextcloud (CT 121) | cloud | Nextcloud AIO | | .183 | nextcloud (CT 121) | cloud | Nextcloud AIO |
@ -125,7 +125,7 @@ edge2 (Contabo Cloud VPS 184.174.35.153 / Tailscale 100.64.0.26) uses a separate
| Tailscale IP | Device | Local IP | | Tailscale IP | Device | Local IP |
|--------------|--------|----------| |--------------|--------|----------|
| 100.64.0.13 | echo6-toc | 192.168.1.244 | | 100.64.0.13 | echo6-toc | 192.168.1.244 |
| 100.64.0.40 | contabo / edge1 (rebuilt 2026-06-19, mail-only) | 5.189.158.149 (external) | | 100.64.0.40 | contabo / edge1 (rebuilt [[2026-06-19]], mail-only) | 5.189.158.149 (external) |
| 100.64.0.9 | aida-nebra | 192.168.1.253 | | 100.64.0.9 | aida-nebra | 192.168.1.253 |
| 100.64.0.5 | utility | 192.168.1.241 | | 100.64.0.5 | utility | 192.168.1.241 |
| 100.64.0.6 | data | 192.168.1.240 | | 100.64.0.6 | data | 192.168.1.240 |
@ -136,7 +136,7 @@ edge2 (Contabo Cloud VPS 184.174.35.153 / Tailscale 100.64.0.26) uses a separate
| 100.64.0.33 | vaultwarden (CT 102 on edge2) — node id 45 | 10.10.10.20 (vmbr0) | | 100.64.0.33 | vaultwarden (CT 102 on edge2) — node id 45 | 10.10.10.20 (vmbr0) |
| 100.64.0.34 | forgejo (CT 103 on edge2) — node id 46 | 10.10.10.21 (vmbr0) | | 100.64.0.34 | forgejo (CT 103 on edge2) — node id 46 | 10.10.10.21 (vmbr0) |
| 100.64.0.35 | livesync (CT 104 on edge2) — hostname `livesync` | 10.10.10.22 (vmbr0) | | 100.64.0.35 | livesync (CT 104 on edge2) — hostname `livesync` | 10.10.10.22 (vmbr0) |
| 100.64.0.36 | authentik (CT 105 on edge2) — node id 48 | 10.10.10.23 (vmbr0) | | 100.64.0.36 | [[authentik]] (CT 105 on edge2) — node id 48 | 10.10.10.23 (vmbr0) |
| 100.64.0.37 | matrix (CT 106 on edge2) — hostname `matrix` | 10.10.10.24 (vmbr0) | | 100.64.0.37 | matrix (CT 106 on edge2) — hostname `matrix` | 10.10.10.24 (vmbr0) |
| 100.64.0.38 | headscale (CT 107 on edge2) — hostname `headscale` | 10.10.10.25 (vmbr0) | | 100.64.0.38 | headscale (CT 107 on edge2) — hostname `headscale` | 10.10.10.25 (vmbr0) |
| 100.64.0.16 | ha (VM 151 on cloud) — node id 54 | 192.168.1.151 | | 100.64.0.16 | ha (VM 151 on cloud) — node id 54 | 192.168.1.151 |

View file

@ -7,15 +7,14 @@ aliases: []
related: related:
- [[central-deploy-cutover]] - [[central-deploy-cutover]]
- [[services]] - [[services]]
- [[navi]]
- [[fleet-platform-baseline]]
- [[caddy]] - [[caddy]]
- [[conduit]] - [[fleet-platform-baseline]]
updated: 2026-07-15 - [[fleet-patch-audit]]
updated: 2026-07-16
--- ---
# central — Data-Hub Spine # central — Data-Hub Spine
> **RETIRED + DROPPED (2026-07-15).** Central has been replaced by [[conduit]]. Its app services were stopped and disabled 2026-07-14 (zero live consumers remained); on 2026-07-15 its database was archived to pi-nas (sha256-verified) and dropped (`DROP DATABASE central`, ~41 GB reclaimed), and the shared Postgres instance was cleaned back to plain (TimescaleDB removed). Central is recoverable only from the pi-nas archive. **Everything below this point is historical** — it describes how central worked while it was live, and is kept for reference only. > **RETIRED + DROPPED (2026-07-15).** Central has been replaced by [[conduit]]. Its app [[services]] were stopped and disabled 2026-07-14 (zero live consumers remained); on 2026-07-15 its database was archived to pi-nas (sha256-verified) and dropped (`DROP DATABASE central`, ~41 GB reclaimed), and the shared Postgres instance was cleaned back to plain (TimescaleDB removed). Central is recoverable only from the pi-nas archive. **Everything below this point is historical** — it describes how central worked while it was live, and is kept for reference only.
## Overview ## Overview
@ -76,7 +75,7 @@ All three units are **enabled and active**; [[deployment]] survives reboot. Deps
Authenticated app with login/sessions/CSRF, first-run setup wizard, operator management, adapter configuration (incl. **no-code creation of generic REST/GeoJSON sources**, v0.15.0), stream viewer, **JetStream consumer management** (`/consumers` — view + delete consumers; central's own `archive-*` durable consumers are protected/non-deletable; CSRF + audit-logged), enrichment pipeline, monitoring-area management, API key management, audit log, and manual resend. Authenticated app with login/sessions/CSRF, first-run setup wizard, operator management, adapter configuration (incl. **no-code creation of generic REST/GeoJSON sources**, v0.15.0), stream viewer, **JetStream consumer management** (`/consumers` — view + delete consumers; central's own `archive-*` durable consumers are protected/non-deletable; CSRF + audit-logged), enrichment pipeline, monitoring-area management, API key management, audit log, and manual resend.
**Auth-exempt tile endpoints** (used by navi, verified HTTP 200): **Auth-exempt tile endpoints** (used by [[navi]], verified HTTP 200):
| Endpoint | Format | | Endpoint | Format |
|----------|--------| |----------|--------|
@ -89,7 +88,7 @@ Authenticated app with login/sessions/CSRF, first-run setup wizard, operator man
navi-traffic (navi's in-VM :8421 extraction service) was **retired on 2026-05-26** and cut over to central. recon-vm's nginx (`/etc/nginx/sites-available/navi.echo6.co`, port 8440) proxied `^~ /api/traffic/``central.echo6.mesh:8000` with a 120s tile cache. navi-traffic:8421 is confirmed dead and disabled. navi-traffic (navi's in-VM :8421 extraction service) was **retired on 2026-05-26** and cut over to central. recon-vm's nginx (`/etc/nginx/sites-available/navi.echo6.co`, port 8440) proxied `^~ /api/traffic/``central.echo6.mesh:8000` with a 120s tile cache. navi-traffic:8421 is confirmed dead and disabled.
**As of 2026-07-14, navi's `/api/traffic/` tiles were repointed to [[conduit]]:** recon-vm's nginx now rewrites `^~ /api/traffic/``/up/tomtom_flow_tiles/...` and proxies to `central.echo6.mesh:8010` (Conduit, co-resident on the same CT 104 host). Central's own tile endpoint (`:8000/api/traffic/...`) still exists and still works, but is no longer on navi's hot path — it remains the rollback target if the Conduit cutover needs to be reverted. See [[conduit-operations]] for the cutover and rollback procedure. **As of 2026-07-14, navi's `/api/traffic/` tiles were repointed to [[conduit]]:** recon-vm's nginx now rewrites `^~ /api/traffic/``/up/tomtom_flow_tiles/...` and proxies to `central.echo6.mesh:8010` ([[conduit]], co-resident on the same CT 104 host). Central's own tile endpoint (`:8000/api/traffic/...`) still exists and still works, but is no longer on navi's hot path — it remains the rollback target if the Conduit cutover needs to be reverted. See [[conduit-operations]] for the cutover and rollback procedure.
## Dependencies ## Dependencies

View file

@ -6,11 +6,11 @@ tags:
aliases: [] aliases: []
related: related:
- [[conduit-operations]] - [[conduit-operations]]
- [[recon-operations]]
- [[recon]]
- [[central]] - [[central]]
- [[navi]] - [[fleet-patch-audit]]
- [[caddy]] updated: 2026-07-16
- [[meshai]]
updated: 2026-07-15
--- ---
# Conduit — Raw-API Broker # Conduit — Raw-API Broker
@ -63,11 +63,11 @@ Everything Conduit brokers is a **source** — an addressable API identity, whet
- **Single-flight coalescing** — concurrent misses for the same `(source, request_key)` → one upstream call. - **Single-flight coalescing** — concurrent misses for the same `(source, request_key)` → one upstream call.
- **Quota guard** (`quota.py`) — per-source day/minute/month caps enforced against a durable `upstream_calls` log, atomic per-source `asyncio.Lock` (single-process). Protects free-tier upstreams (e.g. TomTom's free plan). - **Quota guard** (`quota.py`) — per-source day/minute/month caps enforced against a durable `upstream_calls` log, atomic per-source `asyncio.Lock` (single-process). Protects free-tier upstreams (e.g. TomTom's free plan).
- **Serve-stale** — on quota-block, upstream 429, or 5xx/transport failure, Conduit serves the last-known-good cached copy instead of failing the caller (`X-Conduit-Stale: 1`). - **Serve-stale** — on quota-block, upstream 429, or 5xx/transport failure, Conduit serves the last-known-good cached copy instead of failing the caller (`X-Conduit-Stale: 1`).
- **Faithful 4xx passthrough** (PR #16, 2026-07-15) — a genuine upstream 4xx *except* 429 (e.g. TomTom flow's `400 "Point too far from nearest existing segment"`) is returned to the caller with its real status + body, uncached, not wrapped as a 502. Only 429/5xx/transport failures fall back to serve-stale-or-502. This unblocked the last meshai adapter (traffic) to migrate. - **Faithful 4xx passthrough** (PR #16, 2026-07-15) — a genuine upstream 4xx *except* 429 (e.g. TomTom flow's `400 "Point too far from nearest existing segment"`) is returned to the caller with its real status + body, uncached, not wrapped as a 502. Only 429/5xx/transport failures fall back to serve-stale-or-502. This unblocked the last [[meshai]] adapter (traffic) to migrate.
- **Hot-reload of sources** — a source add/edit/delete made through the GUI calls `Broker.set_sources()` and takes effect with no restart. A direct out-of-band SQL change to `sources` still needs `systemctl restart conduit` — the GUI path is the live one. - **Hot-reload of sources** — a source add/edit/delete made through the GUI calls `Broker.set_sources()` and takes effect with no restart. A direct out-of-band SQL change to `sources` still needs `systemctl restart conduit` — the GUI path is the live one.
- **Retention engine** (`poller.py` + `store/history.py`) — opt-in per source (`retain=true`). A background `Poller` fetches retained sources on their `poll_interval_seconds` and appends changed raw payloads to `payload_history` (append-on-change, sha256-dedup). Idle by construction when nothing is retained. Read back via `GET /history/{source}` and `/history/{source}/{id}/body` (unauthenticated, mesh-internal). Purpose: accumulate raw feeds for later forecast/trend models. - **Retention engine** (`poller.py` + `store/history.py`) — opt-in per source (`retain=true`). A background `Poller` fetches retained sources on their `poll_interval_seconds` and appends changed raw payloads to `payload_history` (append-on-change, sha256-dedup). Idle by construction when nothing is retained. Read back via `GET /history/{source}` and `/history/{source}/{id}/body` (unauthenticated, mesh-internal). Purpose: accumulate raw feeds for later forecast/trend models.
- **Management GUI** (`gui/`) — built in meshai's visual language. argon2 operator auth + two-tier CSRF + schema-reflection forms harvested from central. Pages: sources CRUD (incl. headers/quota/retention fields), API keys, a Cmd-K command palette. Admin operator provisioned. `/up` and `/history` stay unauthenticated (mesh-internal, tiles-trust model); the GUI is the authenticated surface. - **Management GUI** (`gui/`) — built in meshai's visual language. argon2 operator auth + two-tier CSRF + schema-reflection forms harvested from central. Pages: sources CRUD (incl. headers/quota/retention fields), API keys, a Cmd-K command palette. Admin operator provisioned. `/up` and `/history` stay unauthenticated (mesh-internal, tiles-trust model); the GUI is the authenticated surface.
- **Keystore** (`keystore.py`, `crypto.py`) — AES-256-GCM `api_keys` by alias, under Conduit's own master key. Holds `tomtom`, `roads511`, and `firms` keys (harvested from central / provisioned) — meshai no longer holds any of these itself. - **Keystore** (`keystore.py`, `crypto.py`) — AES-256-GCM `api_keys` by alias, under Conduit's own master key. Holds `tomtom`, `roads511`, and `firms` keys (harvested from [[central]] / provisioned) — meshai no longer holds any of these itself.
## Modules (`src/conduit/`) ## Modules (`src/conduit/`)
@ -99,7 +99,7 @@ Pull-based deploy: authored/pushed from a cortex clone, CT 104 pulls via a **rea
## Relationship to [[central]] ## Relationship to [[central]]
**Central is retired and dropped (2026-07-15) — Conduit replaced it.** Central's app services were stopped and disabled 2026-07-14 (zero live consumers remained), then on 2026-07-15 its database was archived to pi-nas (sha256-verified) and dropped (`DROP DATABASE central`, ~41 GB reclaimed); the shared Postgres instance was cleaned back to plain (TimescaleDB removed from `shared_preload_libraries`). Central is recoverable only from the pi-nas archive. Conduit's own `conduit` DB shares that same Postgres instance, which was never stopped. **Central is retired and dropped (2026-07-15) — Conduit replaced it.** Central's app [[services]] were stopped and disabled 2026-07-14 (zero live consumers remained), then on 2026-07-15 its database was archived to pi-nas (sha256-verified) and dropped (`DROP DATABASE central`, ~41 GB reclaimed); the shared Postgres instance was cleaned back to plain (TimescaleDB removed from `shared_preload_libraries`). Central is recoverable only from the pi-nas archive. Conduit's own `conduit` DB shares that same Postgres instance, which was never stopped.
Conduit was born by harvesting central's proven, decoupled pieces — the AES-256-GCM encrypted key store, the GUI auth/CSRF + schema-reflection form patterns, and the aiohttp+tenacity fetch idiom — while deliberately shedding central's NATS/JetStream, CloudEvents normalization, and enrichment pipeline. Conduit was born by harvesting central's proven, decoupled pieces — the AES-256-GCM encrypted key store, the GUI auth/CSRF + schema-reflection form patterns, and the aiohttp+tenacity fetch idiom — while deliberately shedding central's NATS/JetStream, CloudEvents normalization, and enrichment pipeline.

View file

@ -10,7 +10,7 @@ related:
- [[recon-service-integration]] - [[recon-service-integration]]
- [[proxmox-onboard-node]] - [[proxmox-onboard-node]]
- [[ct-runbook]] - [[ct-runbook]]
updated: 2026-07-15 updated: 2026-07-16
--- ---
# Add PeerTube Channel # Add PeerTube Channel

View file

@ -5,17 +5,17 @@ tags:
- mesh - mesh
aliases: [] aliases: []
related: related:
- [[conduit-operations]]
- [[central]] - [[central]]
- [[recon-operations]] - [[recon-operations]]
- [[lxc-service-migration]] - [[lxc-service-migration]]
- [[deployment]]
- [[syncthing-add-node]] - [[syncthing-add-node]]
updated: 2026-07-15 updated: 2026-07-16
--- ---
# central — Deploy & Cutover Runbook # central — Deploy & Cutover Runbook
> **HISTORICAL** — central was retired + dropped 2026-07-15 (see [[central]] / [[conduit]]); this runbook is kept for reference only. > **HISTORICAL**[[central]] was retired + dropped 2026-07-15 (see [[central]] / [[conduit]]); this runbook is kept for reference only.
## Overview / when to use ## Overview / when to use

View file

@ -1,22 +1,23 @@
--- ---
title: "Conduit — Operations Runbook" title: Conduit — Operations Runbook
type: runbook type: runbook
tags: tags:
- mesh - mesh
aliases: [] aliases: []
related: related:
- [[central-deploy-cutover]]
- [[conduit]] - [[conduit]]
- [[central]] - [[recon-operations]]
- [[navi]] - [[deployment]]
- [[meshai]] - [[ct-runbook]]
updated: 2026-07-15 updated: 2026-07-16
--- ---
# Conduit — Operations Runbook # Conduit — Operations Runbook
## When to use ## When to use
Deploying a change, adding a pull source, provisioning an API key, or reviewing the navi/meshai migration history for [[conduit]]. See [[conduit]] for architecture and current state. Deploying a change, adding a pull source, provisioning an API key, or reviewing the [[navi]]/[[meshai]] migration history for [[conduit]]. See [[conduit]] for architecture and current state.
## Key facts ## Key facts
@ -67,7 +68,7 @@ Note: **code and schema changes still need this deploy + restart cycle.** Only *
## Fresh deploy from scratch ## Fresh deploy from scratch
`scripts/provision.sh` (repo root) is the canonical from-scratch installer — it stands up one Conduit instance from nothing: Postgres role + database (plain Postgres, no timescaledb/postgis), generated secrets (AES-256 master key + session secret), a uv-managed venv with an editable install, schema migrations, an optional GUI operator, and (optionally) a systemd unit. It takes every name/path/port as an env var or flag — no Matt-specific values are hardcoded, so it's the same script for the live deploy and for a disposable test instance. `scripts/provision.sh` (repo root) is the canonical from-scratch installer — it stands up one [[conduit]] instance from nothing: Postgres role + database (plain Postgres, no timescaledb/postgis), generated secrets (AES-256 master key + session secret), a uv-managed venv with an editable install, schema migrations, an optional GUI operator, and (optionally) a systemd unit. It takes every name/path/port as an env var or flag — no Matt-specific values are hardcoded, so it's the same script for the live deploy and for a disposable test instance.
Example (adjust for a real deploy — this example matches the throwaway shape used to prove the script works): Example (adjust for a real deploy — this example matches the throwaway shape used to prove the script works):
@ -124,7 +125,7 @@ For UA-sensitive upstreams (NWS contact header, Idaho Power WAF, avalanche.org U
## Provision an API key ## Provision an API key
API keys live in Conduit's own AES-256-GCM encrypted keystore (`api_keys` table), addressed by the `alias` a source's `api_key_alias` references. Encrypted under Conduit's own master key (`/etc/conduit/master.key`) — this store is separate from central's (central no longer exists to have one). API keys live in Conduit's own AES-256-GCM encrypted keystore (`api_keys` table), addressed by the `alias` a source's `api_key_alias` references. Encrypted under Conduit's own master key (`/etc/conduit/master.key`) — this store is separate from [[central]]'s (central no longer exists to have one).
Keys currently held: `tomtom`, `roads511`, `firms` — all harvested from central before its retirement or provisioned directly. For a brand-new key, insert it directly through the keystore's encrypt path (no plaintext in shell history or logs), or use the GUI's API Keys page. Keys currently held: `tomtom`, `roads511`, `firms` — all harvested from central before its retirement or provisioned directly. For a brand-new key, insert it directly through the keystore's encrypt path (no plaintext in shell history or logs), or use the GUI's API Keys page.

View file

@ -9,8 +9,8 @@ related:
- [[headless-browser-page-verification]] - [[headless-browser-page-verification]]
- [[nordvpn-lxc]] - [[nordvpn-lxc]]
- [[proxmox-onboard-node]] - [[proxmox-onboard-node]]
- [[recon-service-integration]] - [[toc-cortex-pve9.2-update]]
updated: 2026-07-15 updated: 2026-07-16
--- ---
# PeerTube Remote Runner — GPU Transcoding # PeerTube Remote Runner — GPU Transcoding