auto: docs sync 2026-06-18T18:00:10+00:00

Files changed: .gitignore CLAUDE.md credentials engine/.embcache.json engine/changelog.md engine/config.yaml engine/lib/__pycache__/agent.cpython-312.pyc engine/lib/agent.py engine/lib/lint.py engine/lint-report.md engine/sweep-full.log engine/sweep.sh vault/.obsidian/graph.json vault/.obsidian/workspace.json vault/INDEX.md vault/archive/projects/mmud/last-ember-chronicle.html vault/archive/projects/mmud/last-ember-howto.html vault/archive/projects/mmud/last-ember.html vault/archive/projects/mmud/mmud-phase5-prompt.md vault/archive/projects/mmud/mmud-phase6-prompt.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/01-update-planned.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/02-npc-nodes.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/03-darkcragg.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/04-dcrg-node.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/05-phase5.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/06-phase6.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/README.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/mmud-project.md vault/docs/hardware/environment.md vault/docs/hardware/ip-allocation.md vault/docs/matrix/archivist.md vault/docs/matrix/matrix_host.md vault/docs/matrix/mautrix_signal.md vault/docs/matrix/synapse.md vault/docs/matrix/synapse_retention_discovery.md vault/docs/navi/cc-rules.md vault/docs/navi/deployment.md vault/docs/navi/themes.md vault/docs/services/ots-setup.md vault/docs/services/services.md vault/docs/services/usenet.md vault/docs/software/authentik.md vault/docs/software/caddy.md vault/docs/software/dns.md vault/docs/software/geo-tools.md vault/docs/software/recon.md vault/docs/software/searxng.md vault/glossary.md vault/notes/echo6-landing-page-data-export.md vault/notes/ia-download-queue.md vault/plans/vaultwarden-plan.md vault/projects/advbbs-project.md vault/projects/argus.md vault/projects/deploy-livesync.md vault/projects/matrix-synapse-deployment.md vault/projects/meshtastic-headscale-runbook.md vault/projects/mmud-project.md vault/runbooks/add-peertube-channel.md vault/runbooks/authentik-access-groups.md vault/runbooks/authentik-create-invitation.md vault/runbooks/authentik-oidc-application.md vault/runbooks/authentik-upgrade.md vault/runbooks/ct-runbook.md vault/runbooks/edge2-access-reference.md vault/runbooks/expose-service-contabo.md vault/runbooks/expose-service-edge2.md vault/runbooks/expose-service-home.md vault/runbooks/headscale-onboard-node.md vault/runbooks/ia-cli-reference.md vault/runbooks/ia-download-mirror.md vault/runbooks/idahomesh-bridge-setup.md vault/runbooks/idahomesh-vpn-device-setup.md vault/runbooks/lxc-service-migration.md vault/runbooks/mailcow-create-mailbox.md vault/runbooks/meshmonitor-password-reset.md vault/runbooks/meshtastic-sidecar-node.md vault/runbooks/meshtasticd-sim-nodes-runbook.md vault/runbooks/nordvpn-lxc.md vault/runbooks/peertube-remote-runner.md vault/runbooks/pg-backup.md vault/runbooks/pi-nas-omv-runbook.md vault/runbooks/pipeline-patterns.md vault/runbooks/proxmox-create-ubuntu-vm.md vault/runbooks/proxmox-onboard-node.md vault/runbooks/recon-operations.md vault/runbooks/recon-service-integration.md vault/runbooks/syncthing-add-node.md vault/session-resume/SESSION-HANDOFF-meshai-test.md
This commit is contained in:
echo6-autocommit 2026-06-18 18:00:10 +00:00
commit eb7eade7fa
88 changed files with 5469 additions and 6038 deletions

View file

@ -1,3 +1,17 @@
---
title: advBBS — Claude Code Project Context
type: project
tags:
- mesh
aliases: []
related:
- [[meshtastic-sidecar-node]]
- [[meshtasticd-sim-nodes-runbook]]
- [[mautrix_signal]]
- [[meshtastic-headscale-runbook]]
- [[services]]
updated: 2026-06-18
---
# advBBS — Claude Code Project Context
## Source of Truth

View file

@ -2,31 +2,29 @@
title: ARGUS - OSINT Intelligence Platform
type: project
tags:
- mesh
- auth
- recon
aliases: []
related:
- [[headscale-onboard-node]]
- [[ip-allocation]]
- [[caddy]]
- [[headscale-onboard-node]]
- [[ct-runbook]]
- [[environment]]
- [[ots-setup]]
updated: 2026-06-18
---
# ARGUS - OSINT Intelligence Platform
**Status:** Container provisioned, baseline installed, awaiting application deployment
**Status:** Container provisioned, baseline installed, awaiting application [[deployment]]
**Last Updated:** 2026-06-14
---
## Overview
ARGUS (Automated Reconnaissance & Gathering for Unified Situational-awareness) is an OSINT intelligence gathering platform combining SearXNG with local LLM analysis for automated threat intelligence collection and processing.
ARGUS (Automated Reconnaissance & Gathering for Unified Situational-awareness) is an OSINT intelligence gathering platform combining [[searxng]] with local LLM analysis for automated threat intelligence collection and processing.
**Architecture:**
- Search backend: SearXNG (self-hosted)
- Search backend: [[searxng]] (self-hosted)
- Analysis: Local LLM models (no cloud APIs)
- Scopes: Local, regional, national, global threat levels
- Privacy-first: No PII collection, focus on events/trends/policies
@ -39,7 +37,7 @@ ARGUS (Automated Reconnaissance & Gathering for Unified Situational-awareness) i
|----------|-------|
| **CTID** | 103 |
| **Hostname** | argus |
| **Host** | utility (192.168.1.241 / 100.64.0.5) |
| **Host** | Utility (192.168.1.241 / 100.64.0.5) |
| **Local IP** | 192.168.1.103 (static) |
| **Tailscale IP** | 100.64.0.25 |
| **Gateway** | 192.168.1.1 |
@ -72,8 +70,8 @@ ARGUS (Automated Reconnaissance & Gathering for Unified Situational-awareness) i
**Tailscale IP:** 100.64.0.25
**Registration:** `tailscale up --login-server=https://vpn.echo6.co --authkey=<key> --ssh --accept-routes`
**DNS Bootstrap Fix:**
Systemd drop-in at `/etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf` ensures fallback DNS (1.1.1.1, 8.8.8.8) exists before tailscaled starts, preventing chicken-and-egg DNS resolution failures on reboot.
**[[dns]] Bootstrap Fix:**
Systemd drop-in at `/etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf` ensures fallback [[dns]] (1.1.1.1, 8.8.8.8) exists before tailscaled starts, preventing chicken-and-egg DNS resolution failures on reboot.
```bash
[Service]
@ -263,7 +261,7 @@ lxc.mount.entry: /dev/net dev/net none bind,create=dir
## Next Steps (Application Deployment)
1. **SearXNG deployment:** Docker container for self-hosted search aggregation
1. **[[searxng]] [[deployment]]:** Docker container for self-hosted search aggregation
2. **LLM integration:** Local model for analysis (Ollama on cortex or self-hosted)
3. **Database:** SQLite for processed intel, possibly Qdrant for vector search (cortex:6333 available)
4. **Scheduler:** Cron or systemd timers for automated collection
@ -286,8 +284,8 @@ lxc.mount.entry: /dev/net dev/net none bind,create=dir
- **CT provisioning:** `/home/zvx/projects/.ref/runbooks/ct-runbook.md`
- **ARGUS rules:** `~/.claude/rules/argus.md`
- **Environment:** `/home/zvx/projects/.ref/docs/hardware/environment.md`
- **Services:** `/home/zvx/projects/.ref/docs/services/services.md`
- **[[environment]]:** `/home/zvx/projects/.ref/docs/hardware/environment.md`
- **[[services]]:** `/home/zvx/projects/.ref/docs/services/services.md`
- **Headscale:** `/home/zvx/projects/.ref/docs/software/caddy.md` (dnsmasq split DNS)
---

View file

@ -1,6 +1,20 @@
---
title: Deploying CouchDB with JWT auth for Obsidian LiveSync via Authentik
type: project
tags:
- auth
aliases: []
related:
- [[authentik-oidc-application]]
- [[authentik]]
- [[authentik-access-groups]]
- [[expose-service-home]]
- [[authentik-upgrade]]
updated: 2026-06-18
---
# Deploying CouchDB with JWT auth for Obsidian LiveSync via Authentik
**LiveSync has native client-side JWT support that eliminates the need for a browser-based OIDC flow.** The plugin generates and signs JWTs internally using a stored private key, sending `Authorization: Bearer` headers directly to CouchDB. This fundamentally changes the architecture: instead of proxying OIDC tokens, you provision per-user key pairs, configure CouchDB with the public keys, and distribute setup URIs containing the private keys. Authentik serves as the identity backbone for a provisioning service — not as a runtime token issuer. No one has publicly documented a complete LiveSync + SSO deployment, making this guide a synthesis of the Kishieel Keycloak series, CouchDB JWT internals, Authentik's claim customization, and the LiveSync plugin's JWT implementation.
**LiveSync has native client-side JWT support that eliminates the need for a browser-based OIDC flow.** The plugin generates and signs JWTs internally using a stored private key, sending `Authorization: Bearer` headers directly to CouchDB. This fundamentally changes the architecture: instead of proxying OIDC tokens, you provision per-user key pairs, configure CouchDB with the public keys, and distribute setup URIs containing the private keys. [[authentik]] serves as the identity backbone for a provisioning service — not as a runtime token issuer. No one has publicly documented a complete LiveSync + SSO [[deployment]], making this guide a synthesis of the Kishieel Keycloak series, CouchDB JWT internals, Authentik's claim customization, and the LiveSync plugin's JWT implementation.
---
@ -197,7 +211,7 @@ CouchDB matches the JWT `sub` against `members.names` and `admins.names`, and th
**CORS is the most common failure mode.** Issue #628 documents that LiveSync does not send the `Origin` header on non-preflight requests, causing CouchDB's CORS handler to omit `Access-Control-Allow-Origin` from responses. The fix is configuring CORS in `local.ini` (shown above) rather than relying on the reverse proxy alone. Required origins: `app://obsidian.md`, `capacitor://localhost`, `http://localhost`.
**The Caddy reverse proxy config** for `notes.echo6.co`:
**The [[caddy]] reverse proxy config** for `notes.echo6.co`:
```
notes.echo6.co {

View file

@ -1,8 +1,22 @@
---
title: Matrix Synapse Deployment
type: project
tags:
- matrix
aliases: []
related:
- [[synapse]]
- [[matrix_host]]
- [[mautrix_signal]]
- [[caddy]]
- [[lxc-service-migration]]
updated: 2026-06-18
---
# Matrix Synapse Deployment
**Status:** Deployed 2026-02-15, migrated to Contabo 2026-02-15
**Target:** Contabo VPS (5.189.158.149 / 100.64.0.1)
**URLs:** https://matrix.echo6.co (Synapse), https://element.echo6.co (Element Web)
**URLs:** https://matrix.echo6.co ([[synapse]]), https://element.echo6.co (Element Web)
**Server Name:** echo6.co (federated identity: @user:echo6.co)
---
@ -12,9 +26,9 @@
| Component | Detail |
|-----------|--------|
| Host | Contabo VPS (5.189.158.149 / 100.64.0.1) |
| Docker services | Synapse (127.0.0.1:8008), Element Web (127.0.0.1:8088), PostgreSQL 16 |
| Reverse proxy | Contabo Caddy (auto ACME certs) |
| SSO | Authentik OIDC → communication-users group |
| Docker [[services]] | Synapse (127.0.0.1:8008), Element Web (127.0.0.1:8088), PostgreSQL 16 |
| Reverse proxy | Contabo [[caddy]] (auto ACME certs) |
| SSO | [[authentik]] OIDC → communication-users group |
| Federation | Well-known delegation on echo6.co base domain (served by utility Caddy) |
| Compose path | `/opt/matrix/docker-compose.yml` |
| Backup | Daily at 3AM, 14-day retention, `/opt/matrix/backups/` |
@ -233,7 +247,7 @@ This service has OIDC, so use local IP per the runbook's decision table.
### matrix.echo6.co
- Backend: `192.168.1.108:8008` (local IP, has OIDC)
- Issue cert, install cert, add Caddy site block, add GoDaddy DNS
- Issue cert, install cert, add Caddy site block, add GoDaddy [[dns]]
Caddy site block (note the path-based routing for Matrix):
@ -456,7 +470,7 @@ MATRIX_ADMIN_USER=matt
## Post-Deploy Updates
After deployment, update these docs:
After [[deployment]], update these docs:
- `docs/services/services.md` — add Matrix entry
- `docs/software/caddy.md` — add matrix.echo6.co and element.echo6.co site blocks

View file

@ -3,12 +3,10 @@ title: IdahoMesh Tailnet Runbook
type: project
tags:
- mesh
- vpn
- auth
aliases: []
related:
- [[idahomesh-vpn-device-setup]]
- [[idahomesh-bridge-setup]]
- [[idahomesh-vpn-device-setup]]
- [[meshtastic-sidecar-node]]
- [[headscale-onboard-node]]
- [[caddy]]
@ -163,7 +161,7 @@ log:
format: text
```
> **Note:** Embedded DERP is disabled — we use Tailscale's public DERP relays. The server is behind Caddy, so TLS termination happens at the reverse proxy.
> **Note:** Embedded DERP is disabled — we use Tailscale's public DERP relays. The server is behind [[caddy]], so TLS termination happens at the reverse proxy.
### 1.4 Create the ACL Policy

View file

@ -1,3 +1,17 @@
---
title: MMUD — Mesh Multi-User Dungeon
type: project
tags:
- mesh
aliases: []
related:
- [[advbbs-project]]
- [[meshtasticd-sim-nodes-runbook]]
- [[ip-allocation]]
- [[services]]
- [[meshtastic-headscale-runbook]]
updated: 2026-06-18
---
# MMUD — Mesh Multi-User Dungeon
Text-based multiplayer dungeon crawler for Meshtastic LoRa mesh networks. BBS door games (LORD, TradeWars) adapted for 150-char mesh radio constraints, async play, 30-day wipe cycles.