diff --git a/.obsidian/workspace.json b/.obsidian/workspace.json index 50e973b..f4671aa 100644 --- a/.obsidian/workspace.json +++ b/.obsidian/workspace.json @@ -189,12 +189,22 @@ }, "active": "ea4cc678c44e8b67", "lastOpenFiles": [ - "credentials.tmp.3861660.701c90c30e54", + "INDEX.md.tmp.40509.2a05e7708182", + "runbooks/lxc-service-migration.md", + "runbooks/lxc-service-migration.md.tmp.40509.38316817de79", + "archive/projects/vaultwarden-deployment.md.tmp.40509.88bb66425f5e", + "docs/hardware/ip-allocation.md.tmp.40509.b03329ad68b8", + "docs/hardware/ip-allocation.md.tmp.40509.008cf455ddde", + "docs/hardware/ip-allocation.md.tmp.40509.8b2ec85a60b8", + "docs/hardware/environment.md.tmp.40509.ad3a0bc1d9bf", + "docs/hardware/environment.md.tmp.40509.e90afdbac998", + "docs/hardware/environment.md.tmp.40509.727e35e81611", + "docs/services/services.md.tmp.40509.e97391cd330d", + "docs/services/services.md.tmp.40509.3adb6587d024", "runbooks/edge2-access-reference.md", "runbooks/expose-service-edge2.md", "plans/vaultwarden-plan.md", "plans/vaultwarden-migration.md", - "plans", "rules/radio.md", "rules/tak.md", "archive/matrix/PHASE6_DECISION.md", @@ -211,20 +221,10 @@ "rules/watchtower.md", "rules/argus.md", "rules/aurora.md", - "Untitled.base", - "docs/matrix/synapse_homeserver.yaml.sanitized", - "Untitled 1.base", "projects/argus.md", "archive/matrix/PLAN.md", "archive/matrix/archivist_discovery.md", "archive/matrix/appservices.md", - "archive/matrix/archive_receiver_discovery.md", - "notes", - "archive/matrix", - "docs/matrix", - "archive/projects/mmud/mmud-prompts/mmud-prompts", - "archive/projects/mmud/mmud-prompts.tar.gz", - "archive/projects/mmud/mmud-prompts", "assets/echo6yellow_logo_422x422_square.png", "assets/echo6yellow_logo_422x81.png", "assets/echo6_logo.png", diff --git a/INDEX.md b/INDEX.md index ea189e4..ee35eed 100644 --- a/INDEX.md +++ b/INDEX.md @@ -48,6 +48,7 @@ The map of this vault — start here. `docs/` is current reference, `runbooks/` - **Authentik:** [[authentik-oidc-application]] · [[authentik-access-groups]] · [[authentik-create-invitation]] · [[authentik-upgrade]] - **Exposing a service:** [[expose-service-contabo]] · [[expose-service-home]] +- **Service migration:** [[lxc-service-migration]] — move a Contabo-Caddy-fronted service to edge2 LXC (Vaultwarden pilot 2026-06-16) - **Proxmox / hosts:** [[ct-runbook]] · [[proxmox-create-ubuntu-vm]] · [[proxmox-onboard-node]] · [[pi-nas-omv-runbook]] · [[headscale-onboard-node]] - **RECON:** [[recon-operations]] · [[recon-service-integration]] - **Mesh / Meshtastic:** [[meshtastic-sidecar-node]] · [[meshtasticd-sim-nodes-runbook]] · [[idahomesh-bridge-setup]] · [[idahomesh-vpn-device-setup]] · [[meshmonitor-password-reset]] diff --git a/archive/projects/vaultwarden-deployment.md b/archive/projects/vaultwarden-deployment.md index d2cb596..56d22a0 100644 --- a/archive/projects/vaultwarden-deployment.md +++ b/archive/projects/vaultwarden-deployment.md @@ -1,7 +1,19 @@ +> [!warning] STALE / SUPERSEDED — DO NOT USE AS REFERENCE +> +> **This document describes the original Contabo deployment (2026-02-05) and is no longer accurate.** +> +> - The service was **migrated to edge2 CT 102** (10.10.10.20 / Tailscale 100.64.0.33) on **2026-06-16**. +> - The `:3012` websocket port, `/notifications/hub` Caddy route, dnsmasq split-DNS entry, and `/oidc-signin` redirect URI described below **do not exist** in the live deployment. +> - **Current reference:** `docs/services/services.md` (Vaultwarden entry) and `runbooks/lxc-service-migration.md`. +> - **Rollback info:** Contabo source is stopped-but-intact; `/etc/caddy/Caddyfile.bak-prevault` exists on Contabo for instant rollback. + +--- + # Vaultwarden Deployment **Deployed:** 2026-02-05 -**Location:** Contabo VPS (5.189.158.149 / 100.64.0.1) +**Superseded:** 2026-06-16 (migrated to edge2 CT 102 — see services.md) +**Location (historical):** Contabo VPS (5.189.158.149 / 100.64.0.1) **URL:** https://vault.echo6.co --- diff --git a/docs/hardware/environment.md b/docs/hardware/environment.md index 31b6d94..72c2739 100644 --- a/docs/hardware/environment.md +++ b/docs/hardware/environment.md @@ -87,7 +87,7 @@ Five nodes running Proxmox VE: | Contabo Server | 5.189.158.149 | 100.64.0.1 | External VPS: Mail, Authentik, Headscale, Forge, Matrix | | edge2 | 184.174.35.153 | 100.64.0.26 | Contabo Cloud VPS 30 NVMe — Proxmox VE 8.4.19 (LXC-only), 8c/24GB/400GB | -*Last updated: 2026-06-16 — Added edge2 CTs (pdm CT 100, wordpress CT 101), Caddy reverse proxy on edge2 host* +*Last updated: 2026-06-17 — Added edge2 CT 102 (vaultwarden), Headscale node 45 (100.64.0.33); previously added edge2 CTs pdm CT 100 / wordpress CT 101* ## LXC Containers @@ -106,6 +106,7 @@ Five nodes running Proxmox VE: | peertube | media (CT 110) | 192.168.1.170 | 100.64.0.23 | PeerTube video streaming | | pdm | edge2 (CT 100) | 10.10.10.10 | 100.64.0.28 | Proxmox Datacenter Manager | | wordpress | edge2 (CT 101) | 10.10.10.11 | 100.64.0.31 | WordPress for intermountainmesh.com | +| vaultwarden | edge2 (CT 102) | 10.10.10.20 | 100.64.0.33 | Vaultwarden password manager (migrated from Contabo 2026-06-16) | ## IP Allocation Scheme @@ -153,6 +154,7 @@ Current registered nodes (26 total): | bluefin | 100.64.0.30 | Desktop | | wordpress | 100.64.0.31 | LXC | | meshai | 100.64.0.32 | LXC | +| vaultwarden | 100.64.0.33 | LXC (edge2 CT 102) | ## IdahoMesh Headscale Node List diff --git a/docs/hardware/ip-allocation.md b/docs/hardware/ip-allocation.md index deeda9d..deddd5d 100755 --- a/docs/hardware/ip-allocation.md +++ b/docs/hardware/ip-allocation.md @@ -47,6 +47,16 @@ | .182 | immich (CT 120) | cloud | Immich photos | | .183 | nextcloud (CT 121) | cloud | Nextcloud AIO | +### edge2 LXC Containers (10.10.10.x, vmbr0) + +edge2 (Contabo Cloud VPS 184.174.35.153 / Tailscale 100.64.0.26) uses a separate 10.10.10.0/24 subnet on vmbr0 (gw 10.10.10.1). No DHCP — all IPs are static. Storage: `local` (dir, no local-lvm). + +| IP | Container | CTID | Tailscale | Purpose | +|----|-----------|------|-----------|---------| +| 10.10.10.10 | pdm | CT 100 | 100.64.0.28 | Proxmox Datacenter Manager | +| 10.10.10.11 | wordpress | CT 101 | 100.64.0.31 | WordPress for intermountainmesh.com | +| 10.10.10.20 | vaultwarden | CT 102 | 100.64.0.33 | Vaultwarden password manager (migrated from Contabo 2026-06-16) | + ### VMs (.150-.199) | IP | VM | Host | Purpose | |----|-----|------|---------| @@ -95,6 +105,7 @@ | 100.64.0.22 | cloud | 192.168.1.242 | | 100.64.0.26 | edge2 | 184.174.35.153 (external) | | 100.64.0.28 | pdm (CT 100 on edge2) | 10.10.10.10 (vmbr0) | +| 100.64.0.33 | vaultwarden (CT 102 on edge2) — node id 45 | 10.10.10.20 (vmbr0) | --- @@ -107,4 +118,4 @@ --- -*Last updated: 2026-06-16* +*Last updated: 2026-06-17 — Added edge2 CT 102 (vaultwarden) at 10.10.10.20 / 100.64.0.33 (Headscale node 45)* diff --git a/docs/services/services.md b/docs/services/services.md index e7496cb..8698d74 100644 --- a/docs/services/services.md +++ b/docs/services/services.md @@ -19,7 +19,7 @@ | Headscale | Contabo | 5.189.158.149 | https://vpn.echo6.co | Tailscale coordination (OIDC enabled) | | Headplane | Contabo | 127.0.0.1:3100 | https://vpn.echo6.co/admin | Headscale web UI (OIDC via Authentik) | | Mailcow | Contabo | 5.189.158.149 | https://mail.echo6.co | Email server | -| Vaultwarden | Contabo | 127.0.0.1:8086 | https://vault.echo6.co | Password manager (SSO enabled) | +| Vaultwarden | edge2 (CT 102) | 100.64.0.33:8086 | https://vault.echo6.co | Password manager (SSO enabled) — fronted by Contabo Caddy (reverse_proxy 100.64.0.33:8086) | | Syncthing | Contabo | 100.64.0.1:22000 | Internal (Tailscale) | File sync — ~/.claude/, ~/projects/ | | Syncthing | cortex | 100.64.0.14:22000 | Internal (Tailscale) | File sync — ~/.claude/, ~/projects/ | | Proxmox VE | data node | 192.168.1.240:8006 | https://proxmox.echo6.co | Cluster web UI (via Caddy+Tailscale) | @@ -254,12 +254,21 @@ - Static MAC: A7:A1:30:79:BB:BB - Tailscale registered on IdahoMesh Headscale (vpn.idahomesh.com) under malice user +### edge2 - CT 102 (10.10.10.20 / Tailscale: 100.64.0.33, node 45 `vaultwarden`) +- Vaultwarden password manager (port 8086, https://vault.echo6.co, Docker) + - Headscale node id 45, name `vaultwarden`, user `echo6` + - Compose path: `/opt/vaultwarden/docker-compose.yml`; data: `./data/` + - Binds to tailnet IP `100.64.0.33:8086:80`; Contabo Caddy proxies here over tailnet + - SSO via Authentik (`SSO_ONLY=false` — local email+master-password login also works) + - Source (Contabo `/opt/vaultwarden`) STOPPED but intact as cold rollback; rollback = restore `/etc/caddy/Caddyfile.bak-prevault` + `systemctl restart caddy` + `docker compose up -d` on Contabo + - **Migrated from Contabo to edge2 CT 102 on 2026-06-16** + ### Contabo VPS (5.189.158.149 / Tailscale: 100.64.0.1) - Authentik (SSO, Echo6 branded — custom CSS, dark theme, logo, favicon, flow titles) - Forge (Git) - Headscale (mesh VPN) - Mailcow (email) -- Vaultwarden (passwords) +- Vaultwarden — **migrated to edge2 CT 102 on 2026-06-16** (Caddy now proxies to 100.64.0.33:8086) - Syncthing (syncs with cortex) - WATCHTOWER (ops dashboard, port 8099, https://wt.echo6.co) - Matrix Synapse homeserver (port 8008, https://matrix.echo6.co, Docker, SSO via Authentik) diff --git a/runbooks/lxc-service-migration.md b/runbooks/lxc-service-migration.md new file mode 100644 index 0000000..0c74683 --- /dev/null +++ b/runbooks/lxc-service-migration.md @@ -0,0 +1,290 @@ +# LXC Service Migration — Contabo → edge2 + +> Proven pilot: **Vaultwarden → edge2 CT 102** (2026-06-16). This runbook generalizes that pattern into a reusable template for evacuating any Contabo-Caddy-fronted service to an edge2 LXC. + +--- + +## Overview + +Move a Docker service from the main Contabo VPS into an LXC on edge2, with the Contabo Caddy frontend unchanged (public DNS never moves; only the upstream token in the Caddyfile changes). Rollback is a single line. + +**Architecture after migration:** + +``` +Internet → 5.189.158.149 (Contabo Caddy) → 100.64.0.XX:PORT (edge2 LXC, via tailnet) +``` + +**edge2 access (always):** `ssh admin@184.174.35.153` (alias `edge2`, key `~/.ssh/contabo2_ed25519`), then `sudo` for every `pct`/`pvesm`/`pveam` command. `root@100.64.0.26` is refused — do not use it. + +--- + +## Phases + +### Phase 0 — Recon & baseline `[G]` + +- On Contabo (`ssh root@100.64.0.1`): capture the **verbatim** `.echo6.co` Caddy block (this is your rollback baseline). Grep the whole Caddyfile for any sub-routes related to the service. +- Read the live compose file + `.env` + data directory listing **from the running host**. Never use `.ref/archive` docs — they may be stale. +- On edge2 (`ssh edge2`): + - Confirm the next free CT ID: `sudo pvesh get /cluster/nextid` + - Confirm chosen IP is free: check `sudo pct list` and the `10.10.10.x` allocation table in `ip-allocation.md` + - Check for needed template: `sudo pvesm list local | grep `. If absent: `sudo pveam download local ` + - Confirm storage free space: `sudo pvesm status` +- **Rollback:** n/a (read-only except optional template download). + +**Service-specific (example: Vaultwarden):** greppeed for `:3012`/`notifications/hub` sub-routes — none existed. Confirmed CT 102 and 10.10.10.20 free. + +--- + +### Phase 0a — Pre-migration gate `[S]` + +Confirm any service-specific preconditions before provisioning (e.g., local login works, data is sane, credentials are recorded). + +**Service-specific (example: Vaultwarden):** Verified ≥1 account has a non-empty `password_hash` (local login works without SSO). Recorded `ADMIN_TOKEN` to credentials file. + +--- + +### Phase 1 — Provision the LXC `[G]` + +Pick right-sized resources for the service (not a copy of another CT's sizing). + +```bash +ssh edge2 "sudo pct create local:vztmpl/