diff --git a/.obsidian/graph.json b/.obsidian/graph.json index ad9de13..e21a18d 100644 --- a/.obsidian/graph.json +++ b/.obsidian/graph.json @@ -17,6 +17,6 @@ "repelStrength": 10, "linkStrength": 1, "linkDistance": 250, - "scale": 1.5, + "scale": 1, "close": false } \ No newline at end of file diff --git a/.obsidian/workspace.json b/.obsidian/workspace.json index e3417d9..bc8bc60 100644 --- a/.obsidian/workspace.json +++ b/.obsidian/workspace.json @@ -13,12 +13,12 @@ "state": { "type": "markdown", "state": { - "file": "INDEX.md", + "file": "rules/proxmox.md", "mode": "source", "source": false }, "icon": "lucide-file", - "title": "INDEX" + "title": "proxmox" } } ] @@ -189,16 +189,19 @@ }, "active": "ea4cc678c44e8b67", "lastOpenFiles": [ + "rules/radio.md", + "rules/tak.md", + "archive/matrix/PHASE6_DECISION.md", + "INDEX.md", + "runbooks/headscale-onboard-node.md", "docs/services/ots-setup.md", "docs/hardware/ip-allocation.md", "CLAUDE-baseline.md", - "INDEX.md", "notes/ia-download-queue.md", "notes/echo6-landing-page-data-export.md", "projects/matrix-synapse-deployment.md", "projects/meshtastic-headscale-runbook.md", "projects/mmud-project.md", - "rules/tak.md", "rules/watchtower.md", "rules/argus.md", "rules/aurora.md", @@ -206,7 +209,6 @@ "docs/matrix/synapse_homeserver.yaml.sanitized", "Untitled 1.base", "projects/argus.md", - "archive/matrix/PHASE6_DECISION.md", "archive/matrix/PLAN.md", "archive/matrix/archivist_discovery.md", "archive/matrix/appservices.md", @@ -216,8 +218,6 @@ "archive/matrix/hookshot_e2ee_discovery.md", "archive/matrix/hookshot_deployment_discovery.md", "docs/matrix/synapse_retention_discovery.md", - "docs/matrix/matrix_host.md", - "docs/matrix/archivist.md", "notes", "archive/matrix", "docs/matrix", diff --git a/INDEX.md b/INDEX.md index 9d33b6e..ea189e4 100644 --- a/INDEX.md +++ b/INDEX.md @@ -48,7 +48,7 @@ The map of this vault — start here. `docs/` is current reference, `runbooks/` - **Authentik:** [[authentik-oidc-application]] · [[authentik-access-groups]] · [[authentik-create-invitation]] · [[authentik-upgrade]] - **Exposing a service:** [[expose-service-contabo]] · [[expose-service-home]] -- **Proxmox / hosts:** [[ct-runbook]] · [[proxmox-create-ubuntu-vm]] · [[proxmox-onboard-node]] · [[pi-nas-omv-runbook]] +- **Proxmox / hosts:** [[ct-runbook]] · [[proxmox-create-ubuntu-vm]] · [[proxmox-onboard-node]] · [[pi-nas-omv-runbook]] · [[headscale-onboard-node]] - **RECON:** [[recon-operations]] · [[recon-service-integration]] - **Mesh / Meshtastic:** [[meshtastic-sidecar-node]] · [[meshtasticd-sim-nodes-runbook]] · [[idahomesh-bridge-setup]] · [[idahomesh-vpn-device-setup]] · [[meshmonitor-password-reset]] - **PeerTube / media:** [[add-peertube-channel]] · [[peertube-remote-runner]] diff --git a/docs/hardware/environment.md b/docs/hardware/environment.md index 18a71ef..ab9fc47 100644 --- a/docs/hardware/environment.md +++ b/docs/hardware/environment.md @@ -85,8 +85,9 @@ Five nodes running Proxmox VE: | pi-nas | 192.168.1.245 | 100.64.0.21 | Raspberry Pi NAS | | matt-desktop | 192.168.1.111 | 100.64.0.10 | Personal workstation (Windows, your PC) | | Contabo Server | 5.189.158.149 | 100.64.0.1 | External VPS: Mail, Authentik, Headscale, Forge, Matrix | +| edge2 | 184.174.35.153 | 100.64.0.26 | Contabo Cloud VPS 30 NVMe — Proxmox VE 8.4.19 (LXC-only), 8c/24GB/400GB, role TBD | -*Last updated: 2026-06-10 — Destroyed CT 103 (advbbs), removed from Headscale* +*Last updated: 2026-06-16 — Added edge2 (Contabo Cloud VPS 30 NVMe, Proxmox PVE 8.4.19, 100.64.0.26)* ## LXC Containers @@ -119,7 +120,7 @@ Full details: [[ip-allocation]] ## Headscale Node List -Current registered nodes (25 total): +Current registered nodes (26 total): | Node | Tailscale IP | Type | |------|-------------|------| @@ -144,6 +145,7 @@ Current registered nodes (25 total): | peertube | 100.64.0.23 | LXC | | recon | 100.64.0.24 | VM | | argus | 100.64.0.25 | LXC | +| edge2 | 100.64.0.26 | Proxmox/Contabo VPS | | meshmonitor-dev | 100.64.0.27 | LXC | | gl-a1300 | 100.64.0.29 | Router | | bluefin | 100.64.0.30 | Desktop | diff --git a/docs/hardware/ip-allocation.md b/docs/hardware/ip-allocation.md index 712affa..deeda9d 100755 --- a/docs/hardware/ip-allocation.md +++ b/docs/hardware/ip-allocation.md @@ -93,6 +93,8 @@ | 100.64.0.20 | data | 192.168.1.240 | | 100.64.0.21 | media | 192.168.1.243 | | 100.64.0.22 | cloud | 192.168.1.242 | +| 100.64.0.26 | edge2 | 184.174.35.153 (external) | +| 100.64.0.28 | pdm (CT 100 on edge2) | 10.10.10.10 (vmbr0) | --- @@ -105,4 +107,4 @@ --- -*Last updated: 2026-06-14* +*Last updated: 2026-06-16* diff --git a/runbooks/headscale-onboard-node.md b/runbooks/headscale-onboard-node.md new file mode 100644 index 0000000..31bf1f6 --- /dev/null +++ b/runbooks/headscale-onboard-node.md @@ -0,0 +1,100 @@ +# Headscale / Tailscale — Onboard a New Node + +Standard procedure to bring any new system (Proxmox host, bare-metal, VM, or LXC) onto the Echo6 tailnet. + +## Overview +- **Control server:** Headscale on Contabo — `ssh root@100.64.0.1`, Docker container `headscale`. +- **Login server:** `https://vpn.echo6.co` · **Admin UI (Headplane):** `https://vpn.echo6.co/admin` +- **User/namespace:** all Echo6 nodes join `echo6` (user ID 1). +- **MagicDNS base domain:** `echo6.mesh` (e.g. `ping data.echo6.mesh`). +- **Naming:** lowercase, hyphens OK, no dots/underscores. Matches `--hostname` and the cortex SSH alias. + +## 1. Generate a preauth key (on Contabo) +```bash +ssh root@100.64.0.1 'docker exec headscale headscale preauthkeys create --user echo6 --reusable --expiration 1h' +# If the name form errors, use the user ID: --user 1 +``` + +## 2. Install Tailscale on the node +```bash +curl -fsSL https://tailscale.com/install.sh | sh +systemctl enable --now tailscaled +``` + +## 3. DNS-bootstrap drop-in (REQUIRED on LXCs, recommended everywhere) +Without this, tailscaled can't resolve `vpn.echo6.co` on a cold boot. Makes onboarding survive a reboot. +```bash +mkdir -p /etc/systemd/system/tailscaled.service.d +cat > /etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf <<'EOF' +[Service] +ExecStartPre=/bin/sh -c "grep -q nameserver /etc/resolv.conf || echo nameserver 1.1.1.1 > /etc/resolv.conf" +EOF +systemctl daemon-reload +``` + +## 4. LXC containers only — TUN device prerequisite +On the Proxmox host, before starting the container (needs `nesting=1,keyctl=1` features set): +```bash +pct stop +cat >> /etc/pve/lxc/.conf <<'EOF' +lxc.cgroup2.devices.allow: c 10:200 rwm +lxc.mount.entry: /dev/net/tun dev/net/tun none bind,create=file +EOF +pct start +``` +(Privileged variant: create with `--unprivileged 0`, use `lxc.mount.entry: /dev/net dev/net none bind,create=dir`.) + +## 5. Register with Headscale +```bash +tailscale up --login-server=https://vpn.echo6.co --auth-key= --hostname= +``` +- Standard nodes pass **no** `--advertise-routes` / `--accept-routes` / `--advertise-tags`. +- Add `--ssh` to enable Tailscale SSH. +- **Always include `--login-server=https://vpn.echo6.co`** — without it the node registers against Tailscale's public servers instead of Echo6 Headscale. +- Subnet-router exception: the mesh-bridge advertises `100.100.0.0/16 --accept-routes`, then enable on Headscale (`headscale routes list` / `routes enable -r `). + +## 6. Verify +```bash +tailscale status +tailscale ip -4 +ssh root@100.64.0.1 'docker exec headscale headscale nodes list' # confirm node + assigned 100.64.0.x +``` +Headscale assigns the IP **sequentially at registration** — don't pre-assign; read it back here. + +## 7. SSH config aliases on cortex (`~/.ssh/config`) +``` +Host + HostName + User root + +Host ts- + HostName + User root +``` +Most nodes use `User root`. Per-node exceptions exist — e.g. **edge2** uses `User admin` + `IdentityFile ~/.ssh/contabo2_ed25519` (cloud image, no root login). + +## 8. Update inventory +- `docs/hardware/environment.md` — Key Servers table **and** Headscale Node List (bump count + "updated" line). +- `docs/hardware/ip-allocation.md` — Tailscale IPs section. +- `CLAUDE.md` cluster cheat-sheet — Proxmox hosts only. +- `docs/services/services.md` — once services are deployed on the node. + +## Worked example — edge2 (2026-06-16) +Proxmox host on Contabo. Preauth key → `tailscale up --login-server=https://vpn.echo6.co --auth-key= --hostname=edge2` → assigned **100.64.0.26** (Headscale node 42). SSH aliases `edge2` / `ts-edge2` use `User admin` + `~/.ssh/contabo2_ed25519`. + +## Gotchas +- `environment.md`'s Headscale Node List is the authoritative IP source — `ip-allocation.md`'s table has gone stale before. +- A node deleted from Headscale does not get its old IP auto-reused; confirm the real next IP with `headscale nodes list`. +- The old `ct-runbook` `tailscale up --authkey ... --ssh` form omits `--login-server` — don't copy it blindly. + +## Checklist +``` +[ ] Preauth key generated on Contabo (user echo6) +[ ] Tailscale installed + tailscaled enabled +[ ] DNS-bootstrap drop-in in place (LXC: required) +[ ] (LXC) TUN device added to CT config +[ ] tailscale up with --login-server=https://vpn.echo6.co --hostname= +[ ] Node appears in headscale nodes list; IP captured +[ ] SSH aliases ( + ts-) added on cortex and tested +[ ] Inventory updated (environment.md, ip-allocation.md, CLAUDE.md) +```