auto: docs sync 2026-06-18T18:00:10+00:00
Files changed: .gitignore CLAUDE.md credentials engine/.embcache.json engine/changelog.md engine/config.yaml engine/lib/__pycache__/agent.cpython-312.pyc engine/lib/agent.py engine/lib/lint.py engine/lint-report.md engine/sweep-full.log engine/sweep.sh vault/.obsidian/graph.json vault/.obsidian/workspace.json vault/INDEX.md vault/archive/projects/mmud/last-ember-chronicle.html vault/archive/projects/mmud/last-ember-howto.html vault/archive/projects/mmud/last-ember.html vault/archive/projects/mmud/mmud-phase5-prompt.md vault/archive/projects/mmud/mmud-phase6-prompt.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/01-update-planned.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/02-npc-nodes.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/03-darkcragg.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/04-dcrg-node.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/05-phase5.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/06-phase6.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/README.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/mmud-project.md vault/docs/hardware/environment.md vault/docs/hardware/ip-allocation.md vault/docs/matrix/archivist.md vault/docs/matrix/matrix_host.md vault/docs/matrix/mautrix_signal.md vault/docs/matrix/synapse.md vault/docs/matrix/synapse_retention_discovery.md vault/docs/navi/cc-rules.md vault/docs/navi/deployment.md vault/docs/navi/themes.md vault/docs/services/ots-setup.md vault/docs/services/services.md vault/docs/services/usenet.md vault/docs/software/authentik.md vault/docs/software/caddy.md vault/docs/software/dns.md vault/docs/software/geo-tools.md vault/docs/software/recon.md vault/docs/software/searxng.md vault/glossary.md vault/notes/echo6-landing-page-data-export.md vault/notes/ia-download-queue.md vault/plans/vaultwarden-plan.md vault/projects/advbbs-project.md vault/projects/argus.md vault/projects/deploy-livesync.md vault/projects/matrix-synapse-deployment.md vault/projects/meshtastic-headscale-runbook.md vault/projects/mmud-project.md vault/runbooks/add-peertube-channel.md vault/runbooks/authentik-access-groups.md vault/runbooks/authentik-create-invitation.md vault/runbooks/authentik-oidc-application.md vault/runbooks/authentik-upgrade.md vault/runbooks/ct-runbook.md vault/runbooks/edge2-access-reference.md vault/runbooks/expose-service-contabo.md vault/runbooks/expose-service-edge2.md vault/runbooks/expose-service-home.md vault/runbooks/headscale-onboard-node.md vault/runbooks/ia-cli-reference.md vault/runbooks/ia-download-mirror.md vault/runbooks/idahomesh-bridge-setup.md vault/runbooks/idahomesh-vpn-device-setup.md vault/runbooks/lxc-service-migration.md vault/runbooks/mailcow-create-mailbox.md vault/runbooks/meshmonitor-password-reset.md vault/runbooks/meshtastic-sidecar-node.md vault/runbooks/meshtasticd-sim-nodes-runbook.md vault/runbooks/nordvpn-lxc.md vault/runbooks/peertube-remote-runner.md vault/runbooks/pg-backup.md vault/runbooks/pi-nas-omv-runbook.md vault/runbooks/pipeline-patterns.md vault/runbooks/proxmox-create-ubuntu-vm.md vault/runbooks/proxmox-onboard-node.md vault/runbooks/recon-operations.md vault/runbooks/recon-service-integration.md vault/runbooks/syncthing-add-node.md vault/session-resume/SESSION-HANDOFF-meshai-test.md
This commit is contained in:
parent
c30ce9f1e3
commit
eb7eade7fa
88 changed files with 5469 additions and 6038 deletions
|
|
@ -3,22 +3,20 @@ title: Add PeerTube Channel
|
|||
type: runbook
|
||||
tags:
|
||||
- media
|
||||
- vpn
|
||||
- auth
|
||||
aliases: []
|
||||
related:
|
||||
- [[peertube-remote-runner]]
|
||||
- [[ct-runbook]]
|
||||
- [[recon-operations]]
|
||||
- [[recon-service-integration]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[ct-runbook]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Add PeerTube Channel
|
||||
|
||||
## Overview
|
||||
|
||||
Add a YouTube channel to the PeerTube bulk import pipeline. Creates the PeerTube channel, adds to channel-map.json, and the downloader will begin syncing videos automatically.
|
||||
Add a Youtube channel to the peertube bulk import pipeline. Creates the PeerTube channel, adds to channel-map.json, and the downloader will begin syncing videos automatically.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
|
|
@ -28,7 +26,7 @@ Add a YouTube channel to the PeerTube bulk import pipeline. Creates the PeerTube
|
|||
|
||||
## Method 1: Web UI (Preferred)
|
||||
|
||||
1. Open **RECON Dashboard** → Upload tab: `http://192.168.1.130:8420/upload`
|
||||
1. Open **[[recon]] Dashboard** → Upload tab: `http://192.168.1.130:8420/upload`
|
||||
2. Scroll to **PeerTube Channels** section
|
||||
3. Enter YouTube URL, category, priority
|
||||
4. Click **Add Channel**
|
||||
|
|
|
|||
|
|
@ -3,22 +3,20 @@ title: Authentik Access Groups
|
|||
type: runbook
|
||||
tags:
|
||||
- auth
|
||||
- mesh
|
||||
- matrix
|
||||
aliases: []
|
||||
related:
|
||||
- [[authentik-oidc-application]]
|
||||
- [[authentik-create-invitation]]
|
||||
- [[authentik]]
|
||||
- [[authentik-create-invitation]]
|
||||
- [[deploy-livesync]]
|
||||
- [[proxmox-onboard-node]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Authentik Access Groups
|
||||
|
||||
Manage group-based application access via the Authentik API. No web UI interaction required.
|
||||
Manage group-based application access via the [[authentik]] API. No web UI interaction required.
|
||||
|
||||
**Authentik instance:** https://auth.echo6.co (Contabo, 100.64.0.1)
|
||||
**[[authentik]] instance:** https://auth.echo6.co (Contabo, 100.64.0.1)
|
||||
|
||||
**Key behavior:** Users in `authentik Admins` (is_superuser=true) bypass ALL policy checks automatically. Group bindings only restrict non-superuser access.
|
||||
|
||||
|
|
|
|||
|
|
@ -1,6 +1,20 @@
|
|||
---
|
||||
title: "Authentik: Create Invitation"
|
||||
type: runbook
|
||||
tags:
|
||||
- auth
|
||||
aliases: []
|
||||
related:
|
||||
- [[authentik-access-groups]]
|
||||
- [[authentik]]
|
||||
- [[authentik-oidc-application]]
|
||||
- [[authentik-upgrade]]
|
||||
- [[mailcow-create-mailbox]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Authentik: Create Invitation
|
||||
|
||||
Create user invitations via the Authentik Admin UI. Supports two modes: email (automatic delivery) and link-sharing (manual delivery).
|
||||
Create user invitations via the [[authentik]] Admin UI. Supports two modes: email (automatic delivery) and link-sharing (manual delivery).
|
||||
|
||||
---
|
||||
|
||||
|
|
@ -119,7 +133,7 @@ Use `firstname-lastname-YYYY-MM` or `purpose-YYYY-MM` for easy identification:
|
|||
|
||||
## After Enrollment
|
||||
|
||||
New users are created under the `users/enrolled` path. To grant them access to services:
|
||||
New users are created under the `users/enrolled` path. To grant them access to [[services]]:
|
||||
|
||||
1. Navigate to **Directory → Groups**
|
||||
2. Add the user to the appropriate group(s):
|
||||
|
|
|
|||
|
|
@ -1,8 +1,22 @@
|
|||
---
|
||||
title: Add Authentik OIDC to an Application
|
||||
type: runbook
|
||||
tags:
|
||||
- auth
|
||||
aliases: []
|
||||
related:
|
||||
- [[authentik]]
|
||||
- [[authentik-access-groups]]
|
||||
- [[authentik-upgrade]]
|
||||
- [[mailcow-create-mailbox]]
|
||||
- [[expose-service-home]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Add Authentik OIDC to an Application
|
||||
|
||||
Fully automated via Authentik API. No web UI interaction required.
|
||||
Fully automated via [[authentik]] API. No web UI interaction required.
|
||||
|
||||
**Prerequisite:** DNS must already exist for the service (run expose-service-contabo.md or expose-service-home.md first).
|
||||
**Prerequisite:** [[dns]] must already exist for the service (run expose-service-contabo.md or expose-service-home.md first).
|
||||
|
||||
**Authentik instance:** https://auth.echo6.co (Contabo, 100.64.0.1)
|
||||
|
||||
|
|
@ -214,7 +228,7 @@ Most apps only need the **Issuer** (or Discovery URL) plus Client ID and Client
|
|||
|
||||
### Common config patterns
|
||||
|
||||
**Environment variables (Docker):**
|
||||
**[[environment]] variables (Docker):**
|
||||
|
||||
```bash
|
||||
OIDC_ISSUER=https://auth.echo6.co/application/o/$SERVICE_SLUG/
|
||||
|
|
|
|||
|
|
@ -1,6 +1,20 @@
|
|||
---
|
||||
title: "Authentik: Major Version Upgrade"
|
||||
type: runbook
|
||||
tags:
|
||||
- auth
|
||||
aliases: []
|
||||
related:
|
||||
- [[authentik-oidc-application]]
|
||||
- [[lxc-service-migration]]
|
||||
- [[authentik]]
|
||||
- [[authentik-create-invitation]]
|
||||
- [[ct-runbook]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Authentik: Major Version Upgrade
|
||||
|
||||
Upgrade Authentik between major versions on Contabo. Covers backup, upgrade, verification, and rollback.
|
||||
Upgrade [[authentik]] between major versions on Contabo. Covers backup, upgrade, verification, and rollback.
|
||||
|
||||
---
|
||||
|
||||
|
|
@ -37,7 +51,7 @@ https://docs.goauthentik.io/docs/releases/
|
|||
|
||||
Look for:
|
||||
- **Breaking changes** — removed features, changed defaults, API changes
|
||||
- **Dependency changes** — added/removed services (e.g., Redis removed in 2025.10)
|
||||
- **Dependency changes** — added/removed [[services]] (e.g., Redis removed in 2025.10)
|
||||
- **Configuration changes** — new required env vars, changed mount paths
|
||||
- **Database migrations** — large migrations that may take time
|
||||
|
||||
|
|
|
|||
|
|
@ -5,11 +5,11 @@ tags:
|
|||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[headscale-onboard-node]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[proxmox-create-ubuntu-vm]]
|
||||
- [[nordvpn-lxc]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[meshtasticd-sim-nodes-runbook]]
|
||||
- [[proxmox-create-ubuntu-vm]]
|
||||
- [[ots-setup]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Proxmox CT/LXC Provisioning Runbook
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: edge2 Access Reference
|
||||
type: runbook
|
||||
tags:
|
||||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[expose-service-edge2]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[vaultwarden-plan]]
|
||||
- [[lxc-service-migration]]
|
||||
- [[headscale-onboard-node]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# edge2 Access Reference
|
||||
|
||||
## SSH Access
|
||||
|
|
@ -84,7 +98,7 @@ ssh edge2 'sudo pct stop <CTID>'
|
|||
**Why it was confusing:**
|
||||
1. The SSH error shows `publickey,password` as available methods — this is misleading because `PasswordAuthentication no` is enforced, but the SSH banner still lists both
|
||||
2. We tried `root@` (wrong user) and the default `id_ed25519` (wrong key)
|
||||
3. The environment docs didn't document the `admin` user or the specific key requirement
|
||||
3. The [[environment]] docs didn't document the `admin` user or the specific key requirement
|
||||
|
||||
**Resolution:** Added cortex's default `id_ed25519`, WSL2 key, and Windows key to admin's `authorized_keys`. Added SSH config alias `edge2` → `admin@100.64.0.26`.
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: Expose Service on Contabo
|
||||
type: runbook
|
||||
tags:
|
||||
- dns
|
||||
aliases: []
|
||||
related:
|
||||
- [[expose-service-edge2]]
|
||||
- [[expose-service-home]]
|
||||
- [[lxc-service-migration]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[caddy]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Expose Service on Contabo
|
||||
|
||||
## Prerequisites
|
||||
|
|
|
|||
|
|
@ -1,14 +1,28 @@
|
|||
---
|
||||
title: Expose Service on edge2 (Contabo Cloud VPS)
|
||||
type: runbook
|
||||
tags:
|
||||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[lxc-service-migration]]
|
||||
- [[edge2-access-reference]]
|
||||
- [[expose-service-contabo]]
|
||||
- [[expose-service-home]]
|
||||
- [[vaultwarden-plan]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Expose Service on edge2 (Contabo Cloud VPS)
|
||||
|
||||
## Context
|
||||
|
||||
edge2 is a Proxmox VE 8 node (184.174.35.153 / 100.64.0.26) running LXC containers on an internal bridge (`vmbr0`, subnet `10.10.10.0/24`, gateway `10.10.10.1`). Services run inside unprivileged LXC containers. Caddy on the edge2 host terminates TLS and reverse-proxies to the container's internal IP.
|
||||
edge2 is a Proxmox VE 8 node (184.174.35.153 / 100.64.0.26) running LXC containers on an internal bridge (`vmbr0`, subnet `10.10.10.0/24`, gateway `10.10.10.1`). [[services]] run inside unprivileged LXC containers. [[caddy]] on the edge2 host terminates TLS and reverse-proxies to the container's internal IP.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- SSH access to edge2: `ssh edge2` (admin@100.64.0.26, key auth, passwordless sudo)
|
||||
- Debian 13 CT template cached: `local:vztmpl/debian-13-standard_13.1-2_amd64.tar.zst`
|
||||
- DNS provider access (Cloudflare, GoDaddy, etc.)
|
||||
- [[dns]] provider access (Cloudflare, GoDaddy, etc.)
|
||||
|
||||
## Steps
|
||||
|
||||
|
|
|
|||
|
|
@ -1,9 +1,23 @@
|
|||
---
|
||||
title: Expose Service on Home Network
|
||||
type: runbook
|
||||
tags:
|
||||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[expose-service-edge2]]
|
||||
- [[expose-service-contabo]]
|
||||
- [[caddy]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[ct-runbook]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Expose Service on Home Network
|
||||
|
||||
## Prerequisites
|
||||
- Service running on a Proxmox CT/VM or bare metal
|
||||
- Router forwards 80/443 to Utility Caddy (192.168.1.101) — one-time setup
|
||||
- Determine pattern: does the service have Authentik OIDC?
|
||||
- Router forwards 80/443 to Utility [[caddy]] (192.168.1.101) — one-time setup
|
||||
- Determine pattern: does the service have [[authentik]] OIDC?
|
||||
|
||||
## Steps
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: Headscale / Tailscale — Onboard a New Node
|
||||
type: runbook
|
||||
tags:
|
||||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[ct-runbook]]
|
||||
- [[caddy]]
|
||||
- [[meshtastic-headscale-runbook]]
|
||||
- [[lxc-service-migration]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Headscale / Tailscale — Onboard a New Node
|
||||
|
||||
Standard procedure to bring any new system (Proxmox host, bare-metal, VM, or LXC) onto the Echo6 tailnet.
|
||||
|
|
@ -77,7 +91,7 @@ Most nodes use `User root`. Per-node exceptions exist — e.g. **edge2** uses `U
|
|||
- `docs/hardware/environment.md` — Key Servers table **and** Headscale Node List (bump count + "updated" line).
|
||||
- `docs/hardware/ip-allocation.md` — Tailscale IPs section.
|
||||
- `CLAUDE.md` cluster cheat-sheet — Proxmox hosts only.
|
||||
- `docs/services/services.md` — once services are deployed on the node.
|
||||
- `docs/services/services.md` — once [[services]] are deployed on the node.
|
||||
|
||||
## Worked example — edge2 (2026-06-16)
|
||||
Proxmox host on Contabo. Preauth key → `tailscale up --login-server=https://vpn.echo6.co --auth-key=<KEY> --hostname=edge2` → assigned **100.64.0.26** (Headscale node 42). SSH aliases `edge2` / `ts-edge2` use `User admin` + `~/.ssh/contabo2_ed25519`.
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: Internet Archive CLI Reference
|
||||
type: runbook
|
||||
tags:
|
||||
- auth
|
||||
aliases: []
|
||||
related:
|
||||
- [[ia-download-mirror]]
|
||||
- [[ia-download-queue]]
|
||||
- [[idahomesh-vpn-device-setup]]
|
||||
- [[archivist]]
|
||||
- [[usenet]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Internet Archive CLI Reference
|
||||
|
||||
Quick reference for the `ia` command-line tool on pi-nas.
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: "Download & Mirror from Internet Archive"
|
||||
type: runbook
|
||||
tags:
|
||||
- storage
|
||||
aliases: []
|
||||
related:
|
||||
- [[ia-cli-reference]]
|
||||
- [[ia-download-queue]]
|
||||
- [[pipeline-patterns]]
|
||||
- [[syncthing-add-node]]
|
||||
- [[idahomesh-vpn-device-setup]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Download & Mirror from Internet Archive
|
||||
|
||||
Procedures for downloading items, filtering by format/pattern, bulk downloading from collections, and mirroring entire collections via the `ia` CLI on pi-nas.
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: IdahoMesh Bridge Setup
|
||||
type: runbook
|
||||
tags:
|
||||
- mesh
|
||||
aliases: []
|
||||
related:
|
||||
- [[meshtastic-headscale-runbook]]
|
||||
- [[idahomesh-vpn-device-setup]]
|
||||
- [[meshtastic-sidecar-node]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[caddy]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# IdahoMesh Bridge Setup
|
||||
|
||||
Build a one-way bridge between your tailnet and the IdahoMesh Meshtastic network. This lets your devices reach Nebra gateways through IdahoMesh, while preventing IdahoMesh from reaching back into your network.
|
||||
|
|
@ -288,7 +302,7 @@ From an IdahoMesh device or ask the admin to test — pinging your tailnet IPs f
|
|||
|
||||
### After reboot, only one tailscaled reconnects
|
||||
|
||||
- Check both services: `systemctl status tailscaled` and `systemctl status tailscaled-meshtastic`
|
||||
- Check both [[services]]: `systemctl status tailscaled` and `systemctl status tailscaled-meshtastic`
|
||||
- Verify iptables rules survived: `iptables -L FORWARD -v -n`
|
||||
- If the second instance lost state, re-join IdahoMesh with a new preauthkey
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: IdahoMesh VPN — Device Setup
|
||||
type: runbook
|
||||
tags:
|
||||
- mesh
|
||||
aliases: []
|
||||
related:
|
||||
- [[idahomesh-bridge-setup]]
|
||||
- [[meshtastic-headscale-runbook]]
|
||||
- [[meshtastic-sidecar-node]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[caddy]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# IdahoMesh VPN — Device Setup
|
||||
|
||||
Join a device to the IdahoMesh tailnet (Meshtastic mesh network VPN).
|
||||
|
|
@ -255,7 +269,7 @@ tailscale logout
|
|||
### "connection refused" or timeout on join
|
||||
|
||||
- Confirm the device has internet access: `curl -I https://vpn.idahomesh.com`
|
||||
- Check DNS resolution: `dig vpn.idahomesh.com`
|
||||
- Check [[dns]] resolution: `dig vpn.idahomesh.com`
|
||||
- Verify the preauthkey hasn't expired
|
||||
|
||||
### "key expired" or "invalid key"
|
||||
|
|
|
|||
|
|
@ -1,12 +1,26 @@
|
|||
---
|
||||
title: LXC Service Migration — Contabo → edge2
|
||||
type: runbook
|
||||
tags:
|
||||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[expose-service-edge2]]
|
||||
- [[vaultwarden-plan]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[caddy]]
|
||||
- [[expose-service-contabo]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# LXC Service Migration — Contabo → edge2
|
||||
|
||||
> Proven pilots: **Vaultwarden → edge2 CT 102** (SQLite, 2026-06-16), **Forgejo → edge2 CT 103** (PostgreSQL + non-Caddy SSH port, 2026-06-16), **LiveSync (CouchDB) → edge2 CT 104** (cold named-volume tar + bind-mounted config, 2026-06-16), and **Authentik (PostgreSQL keystone) → edge2 CT 105** (SECRET_KEY-must-travel, multi-block Caddy cutover across 2 site blocks, reboot tailscale-before-docker race, 2026-06-18). This runbook generalizes these patterns into a reusable template for evacuating any Contabo-Caddy-fronted service to an edge2 LXC.
|
||||
> Proven pilots: **Vaultwarden → edge2 CT 102** (SQLite, 2026-06-16), **Forgejo → edge2 CT 103** (PostgreSQL + non-Caddy SSH port, 2026-06-16), **LiveSync (CouchDB) → edge2 CT 104** (cold named-volume tar + bind-mounted config, 2026-06-16), and **[[authentik]] (PostgreSQL keystone) → edge2 CT 105** (SECRET_KEY-must-travel, multi-block [[caddy]] cutover across 2 site blocks, reboot tailscale-before-docker race, 2026-06-18). This runbook generalizes these patterns into a reusable template for evacuating any Contabo-Caddy-fronted service to an edge2 LXC.
|
||||
|
||||
---
|
||||
|
||||
## Overview
|
||||
|
||||
Move a Docker service from the main Contabo VPS into an LXC on edge2, with the Contabo Caddy frontend unchanged (public DNS never moves; only the upstream token in the Caddyfile changes). Rollback is a single line.
|
||||
Move a Docker service from the main Contabo VPS into an LXC on edge2, with the Contabo Caddy frontend unchanged (public [[dns]] never moves; only the upstream token in the Caddyfile changes). Rollback is a single line.
|
||||
|
||||
**Architecture after migration:**
|
||||
|
||||
|
|
@ -428,14 +442,14 @@ ssh root@100.64.0.1 'systemctl disable --now <service>-ssh-dnat.service && rm /e
|
|||
| G13 | iptables DNAT must be made reboot-persistent via a systemd `oneshot`/`RemainAfterExit` unit (Phase 7a). Do NOT rely on iptables-persistent packages or manual rules — they require package installs (forbidden) or do not survive all reboot paths. Do NOT apply by rebooting the Contabo host (production). Create the unit file, `daemon-reload`, `enable --now`. |
|
||||
| G14 | **Reboot race — Docker binding to the tailnet IP can start before Tailscale is online, failing the bind and leaving the service unreachable after a reboot.** Fix: create a systemd unit on the CT that runs `docker compose up` and has `After=tailscale-online.target` + `Requires=tailscale-online.target` (or equivalent `tailscale status --wait` pre-check). Alternatively, `restart: unless-stopped` in the compose file will cause Docker to self-heal via restarts, but the service will be unreachable for the first ~10–30 s after reboot. Verify reboot survival explicitly (Phase 8). Proven required for Authentik (CT 105, 2026-06-18). |
|
||||
| G15 | **Do NOT change the dnsmasq split-DNS entry during cutover.** The dnsmasq entry for `<service>.echo6.co` points at the Caddy/TLS host (100.64.0.1 = Contabo), NOT the backend. Only the Caddy upstream changes. Repointing dnsmasq to the backend tailnet IP would break internal HTTPS (no cert, no TLS termination). The Caddy host is always the internal DNS target; the backend IP only appears in the Caddy `reverse_proxy` directive. |
|
||||
| G16 | **SECRET_KEY and session-signing material must travel byte-for-byte for keystone/session-bearing services** (e.g. Authentik `AUTHENTIK_SECRET_KEY`, Vaultwarden `rsa_key.pem`). Carrying them verbatim means existing browser sessions survive the cutover — users drop straight in with no forced re-login. If the key is regenerated on the target, all active sessions are invalidated immediately. Confirm from startup logs that no new key was generated. |
|
||||
| G16 | **SECRET_KEY and session-signing material must travel byte-for-byte for keystone/session-bearing [[services]]** (e.g. Authentik `AUTHENTIK_SECRET_KEY`, Vaultwarden `rsa_key.pem`). Carrying them verbatim means existing browser sessions survive the cutover — users drop straight in with no forced re-login. If the key is regenerated on the target, all active sessions are invalidated immediately. Confirm from startup logs that no new key was generated. |
|
||||
| N | The composed **Contabo-Caddy → edge2-LXC tailnet** path is unexercised for each new service. Keep the Phase 6 HTTP `/alive` 200 gate as a HARD pre-cutover requirement (use `curl`, not ICMP). |
|
||||
|
||||
---
|
||||
|
||||
## Template Summary
|
||||
|
||||
**Generic phases (identical for every service):** 0 (recon) → 1 (LXC provision) → 2 (Docker) → 3 (Tailscale + DNS-bootstrap + reachability pre-gate) → 7 (one-token Caddy cutover + backup + validate + restart) → 7a (if service exposes non-Caddy TCP port: iptables DNAT systemd unit on Contabo) → 8 (end-to-end + reboot survival) → 9 (deferred decommission).
|
||||
**Generic phases (identical for every service):** 0 ([[recon]]) → 1 (LXC provision) → 2 (Docker) → 3 (Tailscale + DNS-bootstrap + reachability pre-gate) → 7 (one-token Caddy cutover + backup + validate + restart) → 7a (if service exposes non-Caddy TCP port: iptables DNAT systemd unit on Contabo) → 8 (end-to-end + reboot survival) → 9 (deferred decommission).
|
||||
|
||||
**Service-specific phases:** 0a (pre-migration gate), 4 (compose/config — copy from live host), 5 (data migration method depends on storage type), 6 (health gates — service-specific checks before cutover).
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: "Mailcow: Create Mailbox"
|
||||
type: runbook
|
||||
tags:
|
||||
- auth
|
||||
aliases: []
|
||||
related:
|
||||
- [[authentik]]
|
||||
- [[authentik-oidc-application]]
|
||||
- [[caddy]]
|
||||
- [[authentik-create-invitation]]
|
||||
- [[proxmox-onboard-node]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Mailcow: Create Mailbox
|
||||
|
||||
Create a new mailbox in Mailcow on the Contabo VPS. Covers both interactive (UI) and API-driven creation, with the critical authsource fix for service accounts.
|
||||
|
|
@ -6,7 +20,7 @@ Create a new mailbox in Mailcow on the Contabo VPS. Covers both interactive (UI)
|
|||
|
||||
## When to Use This
|
||||
|
||||
Any time a new mailbox is created in Mailcow, but **especially** for service/system accounts that authenticate via SMTP to send mail programmatically (e.g., `no-reply@echo6.co` used by Authentik, `recon@echo6.co` used by the RECON pipeline). These accounts don't log in through the Mailcow web UI or SSO — they pass credentials directly to Postfix over SMTP, so they **must** use local password authentication.
|
||||
Any time a new mailbox is created in Mailcow, but **especially** for service/system accounts that authenticate via SMTP to send mail programmatically (e.g., `no-reply@echo6.co` used by [[authentik]], `recon@echo6.co` used by the [[recon]] pipeline). These accounts don't log in through the Mailcow web UI or SSO — they pass credentials directly to Postfix over SMTP, so they **must** use local password authentication.
|
||||
|
||||
---
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: MeshMonitor Admin Password Reset
|
||||
type: runbook
|
||||
tags:
|
||||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[recon-service-integration]]
|
||||
- [[ct-runbook]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[recon-operations]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# MeshMonitor Admin Password Reset
|
||||
|
||||
## Overview
|
||||
|
|
|
|||
|
|
@ -3,14 +3,13 @@ title: Meshtastic Sidecar Node — Modular Deployment Runbook
|
|||
type: runbook
|
||||
tags:
|
||||
- mesh
|
||||
- vpn
|
||||
aliases: []
|
||||
related:
|
||||
- [[idahomesh-vpn-device-setup]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[meshtastic-headscale-runbook]]
|
||||
- [[idahomesh-bridge-setup]]
|
||||
- [[meshtasticd-sim-nodes-runbook]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[advbbs-project]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Meshtastic Sidecar Node — Modular Deployment Runbook
|
||||
|
|
@ -164,7 +163,7 @@ sudo tailscale up \
|
|||
|
||||
### Install DNS bootstrap drop-in (reboot-safe)
|
||||
|
||||
Prevents chicken-and-egg DNS failure where tailscaled can't resolve the coordination server after reboot:
|
||||
Prevents chicken-and-egg [[dns]] failure where tailscaled can't resolve the coordination server after reboot:
|
||||
|
||||
```bash
|
||||
sudo mkdir -p /etc/systemd/system/tailscaled.service.d
|
||||
|
|
|
|||
|
|
@ -1,8 +1,22 @@
|
|||
---
|
||||
title: Meshtasticd SIM Node Runbook — LXC Deployment
|
||||
type: runbook
|
||||
tags:
|
||||
- mesh
|
||||
aliases: []
|
||||
related:
|
||||
- [[ct-runbook]]
|
||||
- [[meshtastic-sidecar-node]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[ip-allocation]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Meshtasticd SIM Node Runbook — LXC Deployment
|
||||
|
||||
## Overview
|
||||
|
||||
This runbook covers deploying meshtasticd SIM (virtual) nodes inside LXC containers on Proxmox, each paired with a dedicated service (BBS, MeshSense, etc.). SIM nodes communicate with your real radio node over UDP and appear as normal nodes on the mesh — clients, maps, and other services can't tell the difference.
|
||||
This runbook covers deploying meshtasticd SIM (virtual) nodes inside LXC containers on Proxmox, each paired with a dedicated service (BBS, MeshSense, etc.). SIM nodes communicate with your real radio node over UDP and appear as normal nodes on the mesh — clients, maps, and other [[services]] can't tell the difference.
|
||||
|
||||
**Design principle:** One container = one SIM daemon + one service. Clean isolation, easy to snapshot, migrate, or tear down without affecting anything else.
|
||||
|
||||
|
|
@ -135,7 +149,7 @@ General:
|
|||
|
||||
- **Every SIM node must have a unique MAC.** If two nodes share a MAC, you'll get node ID collisions and unpredictable behavior.
|
||||
- The last 3 byte pairs map to a hex color code displayed in client apps.
|
||||
- Pick a scheme that makes sense for your deployment, e.g.:
|
||||
- Pick a scheme that makes sense for your [[deployment]], e.g.:
|
||||
- `DE:AD:00:FF:00:01` — SIM node 1 (BBS)
|
||||
- `DE:AD:00:00:FF:02` — SIM node 2 (MeshSense)
|
||||
- `DE:AD:00:FF:FF:03` — SIM node 3 (bot)
|
||||
|
|
|
|||
|
|
@ -1,6 +1,20 @@
|
|||
---
|
||||
title: NordVPN / WireGuard in LXC
|
||||
type: runbook
|
||||
tags:
|
||||
- vpn
|
||||
aliases: []
|
||||
related:
|
||||
- [[ct-runbook]]
|
||||
- [[meshtasticd-sim-nodes-runbook]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[peertube-remote-runner]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# NordVPN / WireGuard in LXC
|
||||
|
||||
Set up VPN with IP rotation inside an LXC container. Handles the LXC-specific gotchas: TUN device, systemd compatibility, split tunneling so local services stay reachable.
|
||||
Set up VPN with IP rotation inside an LXC container. Handles the LXC-specific gotchas: TUN device, systemd compatibility, split tunneling so local [[services]] stay reachable.
|
||||
|
||||
---
|
||||
|
||||
|
|
@ -327,7 +341,7 @@ Split tunneling not configured. The VPN is routing ALL traffic including LAN. Fi
|
|||
|
||||
### DNS stops working when VPN is up
|
||||
|
||||
NordVPN CLI: `nordvpn set dns off` (use container's DNS, not NordVPN's).
|
||||
NordVPN CLI: `nordvpn set dns off` (use container's [[dns]], not NordVPN's).
|
||||
WireGuard: Remove the `DNS =` line from the `.conf` file.
|
||||
|
||||
### "Cannot open TUN/TAP dev /dev/net/tun: No such file or directory"
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: PeerTube Remote Runner — GPU Transcoding
|
||||
type: runbook
|
||||
tags:
|
||||
- media
|
||||
aliases: []
|
||||
related:
|
||||
- [[add-peertube-channel]]
|
||||
- [[nordvpn-lxc]]
|
||||
- [[ct-runbook]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[headscale-onboard-node]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# PeerTube Remote Runner — GPU Transcoding
|
||||
|
||||
Deploy a PeerTube remote runner with NVENC GPU transcoding. The runner pulls jobs from PeerTube over WebSocket, transcodes with the GPU, and uploads HLS streams back.
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: PostgreSQL Backup (Docker)
|
||||
type: runbook
|
||||
tags:
|
||||
- storage
|
||||
aliases: []
|
||||
related:
|
||||
- [[ct-runbook]]
|
||||
- [[recon-operations]]
|
||||
- [[meshmonitor-password-reset]]
|
||||
- [[matrix-synapse-deployment]]
|
||||
- [[synapse]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# PostgreSQL Backup (Docker)
|
||||
|
||||
Automated pg_dump backups for any Docker-hosted PostgreSQL instance. Retention, integrity check, and restore testing included.
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: Pi 5 NAS — OMV Provisioning Runbook
|
||||
type: runbook
|
||||
tags:
|
||||
- storage
|
||||
aliases: []
|
||||
related:
|
||||
- [[ct-runbook]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[proxmox-create-ubuntu-vm]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[environment]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Pi 5 NAS — OMV Provisioning Runbook
|
||||
|
||||
SSH into the Pi. The Pi should already be booted with Raspberry Pi OS Lite, Ethernet connected, Radxa Penta SATA Hat installed.
|
||||
|
|
@ -111,7 +125,7 @@ Each drive is used individually — no RAID array.
|
|||
|
||||
### Enable SMB (Windows Shares)
|
||||
|
||||
1. **Services → SMB/CIFS → Settings** — toggle **Enabled**, click **Save**
|
||||
1. **[[services]] → SMB/CIFS → Settings** — toggle **Enabled**, click **Save**
|
||||
2. **Services → SMB/CIFS → Shares** — click **Create** for each shared folder you want accessible from Windows:
|
||||
- Select the shared folder
|
||||
- **Public:** No
|
||||
|
|
|
|||
|
|
@ -1,3 +1,16 @@
|
|||
---
|
||||
title: "Pipeline & Wrapper Patterns"
|
||||
type: runbook
|
||||
tags: []
|
||||
aliases: []
|
||||
related:
|
||||
- [[meshtastic-sidecar-node]]
|
||||
- [[meshtastic-headscale-runbook]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[idahomesh-vpn-device-setup]]
|
||||
- [[syncthing-add-node]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Pipeline & Wrapper Patterns
|
||||
|
||||
Three composable patterns for adding pre-flight logic to tools and pipelines you don't fully control:
|
||||
|
|
@ -6,7 +19,7 @@ Three composable patterns for adding pre-flight logic to tools and pipelines you
|
|||
2. **GPU/CPU Fallback Routing** — *logic you inject*. Probe a job, route small→GPU / large→CPU, and gate concurrency with `flock` so excess jobs fail-fast and re-queue instead of OOM-killing each other.
|
||||
3. **Pre-Flight Probe Gate** — *logic you inject*. Cheaply inspect each input and skip the expensive step when the work would be wasted (wrong format, already optimized, corrupt, too large).
|
||||
|
||||
They compose: **Pattern 1 is how you deploy; Patterns 2 and 3 are two kinds of pre-flight logic you put inside the wrapper.** The running example throughout is the Whisper auto-captioning / PeerTube transcoder / RECON extraction stack on cortex.
|
||||
They compose: **Pattern 1 is how you deploy; Patterns 2 and 3 are two kinds of pre-flight logic you put inside the wrapper.** The running example throughout is the Whisper auto-captioning / PeerTube transcoder / [[recon]] extraction stack on cortex.
|
||||
|
||||
## Contents
|
||||
|
||||
|
|
@ -215,7 +228,7 @@ No service restart needed — next invocation hits the real binary directly.
|
|||
|
||||
### Example — Whisper transcription routing (PeerTube runner on cortex)
|
||||
|
||||
The PeerTube remote runner calls `whisper-ctranslate2` for auto-captioning. The smart wrapper intercepts this to route short videos to GPU and long videos to CPU (the routing logic itself is **Pattern 2** below).
|
||||
The [[peertube-remote-runner]] calls `whisper-ctranslate2` for auto-captioning. The smart wrapper intercepts this to route short videos to GPU and long videos to CPU (the routing logic itself is **Pattern 2** below).
|
||||
|
||||
```
|
||||
BINARY_NAME=whisper-ctranslate2
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: Proxmox — Create Ubuntu VM (Cloud-Init)
|
||||
type: runbook
|
||||
tags:
|
||||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[ct-runbook]]
|
||||
- [[environment]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[pi-nas-omv-runbook]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Proxmox — Create Ubuntu VM (Cloud-Init)
|
||||
|
||||
Automated VM creation using Ubuntu cloud images. No interactive installer needed.
|
||||
|
|
@ -279,5 +293,5 @@ docker exec headscale headscale nodes list
|
|||
## Post-Creation
|
||||
|
||||
1. Update `/home/zvx/projects/.ref/docs/hardware/environment.md` with the new VM's IP and Tailscale IP
|
||||
2. Update `/home/zvx/projects/.ref/docs/services/services.md` once services are deployed
|
||||
2. Update `/home/zvx/projects/.ref/docs/services/services.md` once [[services]] are deployed
|
||||
3. Remove the cloud image ISO if disk space is tight: `ssh root@$PVE_HOST 'rm /var/lib/vz/template/iso/noble-server-cloudimg-amd64.img'`
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: "Runbook: Onboard a Proxmox Node"
|
||||
type: runbook
|
||||
tags:
|
||||
- proxmox
|
||||
aliases: []
|
||||
related:
|
||||
- [[ct-runbook]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[proxmox-create-ubuntu-vm]]
|
||||
- [[edge2-access-reference]]
|
||||
- [[expose-service-home]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Runbook: Onboard a Proxmox Node
|
||||
|
||||
You install Proxmox. You give CC an IP and a root password. CC does the rest.
|
||||
|
|
@ -209,7 +223,7 @@ Add `-o PreferredAuthentications=password -o IdentitiesOnly=yes`.
|
|||
**Cluster join corosync errors**
|
||||
Check `/etc/hosts` on all nodes includes the new hostname and IP.
|
||||
|
||||
**Authentik realm missing**
|
||||
**[[authentik]] realm missing**
|
||||
Check `systemctl status pve-cluster`. Realm syncs via pmxcfs in `/etc/pve/domains.cfg`.
|
||||
|
||||
**Can't migrate VMs to node**
|
||||
|
|
|
|||
|
|
@ -1,12 +1,26 @@
|
|||
---
|
||||
title: RECON Operations Runbook
|
||||
type: runbook
|
||||
tags:
|
||||
- recon
|
||||
aliases: []
|
||||
related:
|
||||
- [[recon]]
|
||||
- [[deployment]]
|
||||
- [[caddy]]
|
||||
- [[recon-service-integration]]
|
||||
- [[services]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# RECON Operations Runbook
|
||||
|
||||
## Service Info
|
||||
|
||||
- **Host:** recon-vm (VM 1130 on data node) — migrated from CT 130 on 2026-04-19
|
||||
- **IP:** 192.168.1.130 / 100.64.0.24
|
||||
- **Install:** /opt/recon/
|
||||
- **Install:** /opt/[[recon]]/
|
||||
- **User:** zvx
|
||||
- **Services:** `recon.service`, `recon-watchdog.service`, `kiwix.service` (systemd)
|
||||
- **[[services]]:** `recon.service`, `recon-watchdog.service`, `kiwix.service` (systemd)
|
||||
|
||||
## Service Management
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: RECON Dashboard Service Integration
|
||||
type: runbook
|
||||
tags:
|
||||
- recon
|
||||
aliases: []
|
||||
related:
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[recon-operations]]
|
||||
- [[headscale-onboard-node]]
|
||||
- [[lxc-service-migration]]
|
||||
- [[caddy]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# RECON Dashboard Service Integration
|
||||
|
||||
Add a management UI for a remote service to a Flask/FastAPI dashboard. The pattern: SSH key trust between the dashboard host and the target, scoped sudoers for specific commands, a REST API layer (`GET /api/{service}/status` + `POST /api/{service}/{action}`), and a frontend panel with status indicator, action buttons, and live feedback.
|
||||
|
|
@ -8,7 +22,7 @@ Use this when you have a service running on a remote LXC/VM that needs a web man
|
|||
|
||||
## Prerequisites
|
||||
|
||||
- A running Flask or FastAPI dashboard (e.g., RECON on VM 1130, WATCHTOWER on Contabo)
|
||||
- A running Flask or FastAPI dashboard (e.g., [[recon]] on VM 1130, WATCHTOWER on Contabo)
|
||||
- The target service running on a reachable host (LXC, VM, or bare metal)
|
||||
- SSH access from the dashboard host to the target host
|
||||
- The dashboard runs as a known user (e.g., `zvx`, `recon`, `watchtower`)
|
||||
|
|
@ -210,7 +224,7 @@ Must return `success: true`.
|
|||
|
||||
## Step 4: Add Frontend Panel
|
||||
|
||||
Add a service management panel to the dashboard UI. This goes in the appropriate tab (e.g., Upload, Dashboard, or a new Services tab).
|
||||
Add a service management panel to the dashboard UI. This goes in the appropriate tab (e.g., Upload, Dashboard, or a new [[services]] tab).
|
||||
|
||||
```html
|
||||
<!-- Service Management Panel: $SERVICE_DISPLAY_NAME -->
|
||||
|
|
|
|||
|
|
@ -1,3 +1,17 @@
|
|||
---
|
||||
title: "Syncthing: Add a New Node to the Project Sync Cluster"
|
||||
type: runbook
|
||||
tags:
|
||||
- mesh
|
||||
aliases: []
|
||||
related:
|
||||
- [[ct-runbook]]
|
||||
- [[proxmox-onboard-node]]
|
||||
- [[meshtasticd-sim-nodes-runbook]]
|
||||
- [[idahomesh-vpn-device-setup]]
|
||||
- [[headscale-onboard-node]]
|
||||
updated: 2026-06-18
|
||||
---
|
||||
# Syncthing: Add a New Node to the Project Sync Cluster
|
||||
|
||||
## Overview
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue