Compare commits

..

2 commits

Author SHA1 Message Date
echo6-autocommit
4526e1843b auto: docs sync 2026-08-24T12:00:05+00:00
Files changed: engine/.embcache.json engine/changelog.md engine/lint-report.md vault/.obsidian/workspace.json vault/docs/services/services.md vault/docs/software/caddy.md vault/docs/software/dns.md vault/runbooks/expose-service-edge2.md vault/runbooks/expose-service-home.md
2026-08-24 12:00:05 +00:00
0ef9969510 Drop the stale add-cname example from dns.md
The restored godaddy-dns.py implements list, get-a and add-a only, so an
add-cname example was documenting a subcommand that does not exist -- the
same failure mode as the script the doc used to point at.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-24 06:01:10 +00:00
9 changed files with 32 additions and 31 deletions

File diff suppressed because one or more lines are too long

View file

@ -277,3 +277,9 @@
## 2026-08-22T09:00:01Z — sweep deferred (competing GPU process: 1612203 /usr/bin/python3 /usr/local/bin/whisper-ctranslate2-real /home/zvx/.cache/peertube-runner-nodejs/default/transcoding/8930a1ed-816c-4b41-b36e-e7b6d5fe4161 --model medium --word_timestamps True --vad_filter true --vad_min_silence_duration_ms 5000 --output_format all --output_dir /home/zvx/.cache/peertube-runner-nodejs/default/transcription/28yY8e33obZCymsQhGUii8 --model medium --device cuda --compute_type float16 --word_timestamps False --vad_min_silence_duration_ms 500) ## 2026-08-22T09:00:01Z — sweep deferred (competing GPU process: 1612203 /usr/bin/python3 /usr/local/bin/whisper-ctranslate2-real /home/zvx/.cache/peertube-runner-nodejs/default/transcoding/8930a1ed-816c-4b41-b36e-e7b6d5fe4161 --model medium --word_timestamps True --vad_filter true --vad_min_silence_duration_ms 5000 --output_format all --output_dir /home/zvx/.cache/peertube-runner-nodejs/default/transcription/28yY8e33obZCymsQhGUii8 --model medium --device cuda --compute_type float16 --word_timestamps False --vad_min_silence_duration_ms 500)
## 2026-08-23T09:00:01Z — sweep complete (0 docs selected) ## 2026-08-23T09:00:01Z — sweep complete (0 docs selected)
## 2026-08-24T09:00:01Z — sweep run
- end: 2026-08-24T09:00:21Z
- mode: incremental
- docs selected: 7
- processed: 7 | written: 7 | flagged: 0 | errors: 0

View file

@ -1,6 +1,6 @@
# Vault Lint Report # Vault Lint Report
Generated: 2026-08-24T05:59:56Z | Docs scanned: 116 | Elapsed: 0.0s Generated: 2026-08-24T09:00:02Z | Docs scanned: 116 | Elapsed: 0.0s
## Summary ## Summary

View file

@ -199,6 +199,7 @@
}, },
"active": "17bd4a6166f789d0", "active": "17bd4a6166f789d0",
"lastOpenFiles": [ "lastOpenFiles": [
"docs/software/dns.md.tmp.3790074.04f69e0a9ea6",
"projects/meshtastic-headscale-runbook.md.tmp.3790074.f71d216eecca", "projects/meshtastic-headscale-runbook.md.tmp.3790074.f71d216eecca",
"projects/meshtastic-headscale-runbook.md.tmp.3790074.d94af273bec3", "projects/meshtastic-headscale-runbook.md.tmp.3790074.d94af273bec3",
"runbooks/expose-service-contabo.md.tmp.3790074.70782eb4562c", "runbooks/expose-service-contabo.md.tmp.3790074.70782eb4562c",
@ -210,7 +211,6 @@
"docs/software/dns.md.tmp.3790074.fcdcf768c300", "docs/software/dns.md.tmp.3790074.fcdcf768c300",
"docs/software/dns.md.tmp.3790074.404f85bc78a4", "docs/software/dns.md.tmp.3790074.404f85bc78a4",
"projects/meshwars.md", "projects/meshwars.md",
"projects/fleet-storage-memory-upgrade.md.tmp.2730138.81f9975eb3a6",
"runbooks/navi-lift-to-media.md", "runbooks/navi-lift-to-media.md",
"runbooks/edge2-boot-recovery.md", "runbooks/edge2-boot-recovery.md",
"runbooks/corescope-ingest-stall-oom.md", "runbooks/corescope-ingest-stall-oom.md",

View file

@ -7,10 +7,10 @@ aliases: []
related: related:
- [[caddy]] - [[caddy]]
- [[ip-allocation]] - [[ip-allocation]]
- [[lxc-service-migration]]
- [[meshtastic-headscale-runbook]] - [[meshtastic-headscale-runbook]]
- [[expose-service-edge2]] - [[lxc-service-migration]]
updated: 2026-08-14 - [[central]]
updated: 2026-08-24
--- ---
# Current Services Inventory # Current Services Inventory
@ -38,10 +38,10 @@ updated: 2026-08-14
| Headscale | edge2 (CT 107) | 100.64.0.38:8084 | https://vpn.echo6.co | Tailscale coordination (OIDC enabled) — fronted by edge2 host [[caddy]] — **migrated from Contabo [[2026-06-19]]** | | Headscale | edge2 (CT 107) | 100.64.0.38:8084 | https://vpn.echo6.co | Tailscale coordination (OIDC enabled) — fronted by edge2 host [[caddy]] — **migrated from Contabo [[2026-06-19]]** |
| Headplane | edge2 (CT 107) | 100.64.0.38:3100 | https://vpn.echo6.co/admin | Headscale web UI (OIDC via [[authentik]]) — fronted by edge2 host [[caddy]] — **migrated from Contabo [[2026-06-19]]** | | Headplane | edge2 (CT 107) | 100.64.0.38:3100 | https://vpn.echo6.co/admin | Headscale web UI (OIDC via [[authentik]]) — fronted by edge2 host [[caddy]] — **migrated from Contabo [[2026-06-19]]** |
| Mailcow | **edge1 CT 101** (10.10.10.2) | 5.189.158.149 | https://mail.echo6.co | Email server (privileged LXC on rebuilt Contabo VPS, updated commit 52a41b4d / SOGo 5.12.8) — **rebuilt in-place [[2026-06-19]]** | | Mailcow | **edge1 CT 101** (10.10.10.2) | 5.189.158.149 | https://mail.echo6.co | Email server (privileged LXC on rebuilt Contabo VPS, updated commit 52a41b4d / SOGo 5.12.8) — **rebuilt in-place [[2026-06-19]]** |
| MeshWars Preview | utility (CT 113) | 192.168.1.113 / 100.64.0.39:8090 | https://mwpreview.k7zvx.com | Public preview of the unreleased `feat/places` MeshWars branch, running a periodically-refreshed read-only copy of production (CT 119) data; /admin and /api/admin/* return 404 on the public host, admin reachable only over the tailnet | | [[meshwars]] Preview | utility (CT 113) | 192.168.1.113 / 100.64.0.39:8090 | https://mwpreview.k7zvx.com | Public preview of the unreleased `feat/places` MeshWars branch, running a periodically-refreshed read-only copy of production (CT 119) data; /admin and /api/admin/* return 404 on the public host, admin reachable only over the tailnet |
| Vaultwarden | edge2 (CT 102) | 100.64.0.33:8086 | https://vault.echo6.co | Password manager 1.37.1 (SSO enabled) — fronted by edge2 host Caddy (reverse_proxy 100.64.0.33:8086) | | Vaultwarden | edge2 (CT 102) | 100.64.0.33:8086 | https://vault.echo6.co | Password manager 1.37.1 (SSO enabled) — fronted by edge2 host [[caddy]] (reverse_proxy 100.64.0.33:8086) |
| Grav | edge2 (CT 101) | 10.10.10.11:80 | https://idahomesh.com (+www) | Flat-file CMS 2.0.11, no database — Admin2 plugin at /admin; Apache 2.4.67 + mod_php + PHP 8.4.21; migrated from WordPress 2026-07-17 (MariaDB purged from the container); hostname still `wordpress` (unchanged) — fronted by edge2 host Caddy via **internal bridge IP** (reverse_proxy 10.10.10.11:80), unlike other edge2 services which proxy over tailnet | | Grav | edge2 (CT 101) | 10.10.10.11:80 | https://idahomesh.com (+www) | Flat-file CMS 2.0.11, no database — Admin2 plugin at /admin; Apache 2.4.67 + mod_php + PHP 8.4.21; migrated from WordPress 2026-07-17 (MariaDB purged from the container); hostname still `wordpress` (unchanged) — fronted by edge2 host Caddy via **internal bridge IP** (reverse_proxy 10.10.10.11:80), unlike other edge2 services which proxy over tailnet |
| Syncthing | cortex | 100.64.0.14:22000 | Internal (Tailscale) | File sync — ~/.claude/, ~/projects/ (Syncthing on Contabo decommissioned 2026-06-19 with edge1 rebuild) | | Syncthing | cortex | 100.64.0.14:22000 | Internal (Tailscale) | File sync — ~/.claude/, ~/projects/ (Syncthing on Contabo decommissioned [[2026-06-19]] with edge1 rebuild) |
| Proxmox VE | data node | 192.168.1.240:8006 | https://proxmox.echo6.co | Cluster web UI (via Caddy+Tailscale) | | Proxmox VE | data node | 192.168.1.240:8006 | https://proxmox.echo6.co | Cluster web UI (via Caddy+Tailscale) |
| Immich | cloud (CT 120) | 192.168.1.182:2283 | https://immich.echo6.co | Photo management (Docker, NFS storage on pi-nas) | | Immich | cloud (CT 120) | 192.168.1.182:2283 | https://immich.echo6.co | Photo management (Docker, NFS storage on pi-nas) |
| Nextcloud | cloud (CT 121) | 192.168.1.183:11000 | https://nextcloud.echo6.co | Cloud storage (AIO Docker, NFS on pi-nas, SSO) | | Nextcloud | cloud (CT 121) | 192.168.1.183:11000 | https://nextcloud.echo6.co | Cloud storage (AIO Docker, NFS on pi-nas, SSO) |
@ -59,7 +59,7 @@ updated: 2026-08-14
| navi-config | data (VM 1130) | 192.168.1.130:8422 | Internal | [[recon]] [[navi]] node config API | | navi-config | data (VM 1130) | 192.168.1.130:8422 | Internal | [[recon]] [[navi]] node config API |
| navi-contacts | data (VM 1130) | 192.168.1.130:8423 | Internal | [[recon]] [[navi]] contact enrichment API | | navi-contacts | data (VM 1130) | 192.168.1.130:8423 | Internal | [[recon]] [[navi]] contact enrichment API |
| navi-landclass | data (VM 1130) | 192.168.1.130:8424 | Internal | [[recon]] [[navi]] land classification API | | navi-landclass | data (VM 1130) | 192.168.1.130:8424 | Internal | [[recon]] [[navi]] land classification API |
| navi-places | data (VM 1130) | 192.168.1.130:8425 | Internal | RECON navi OSM place detail/enrichment | | navi-places | data (VM 1130) | 192.168.1.130:8425 | Internal | [[recon]] [[navi]] OSM place detail/enrichment |
| navi-geo | data (VM 1130) | 192.168.1.130:8426 | Internal | RECON navi geocode/reverse geocode API | | navi-geo | data (VM 1130) | 192.168.1.130:8426 | Internal | RECON navi geocode/reverse geocode API |
| navi-admin | data (VM 1130) | 192.168.1.130:8427 | Internal | RECON navi fleet admin-info aggregator | | navi-admin | data (VM 1130) | 192.168.1.130:8427 | Internal | RECON navi fleet admin-info aggregator |
| navi-offroute | data (VM 1130) | 192.168.1.130:8428 | Internal | RECON navi off-network router + MVUM API | | navi-offroute | data (VM 1130) | 192.168.1.130:8428 | Internal | RECON navi off-network router + MVUM API |
@ -149,7 +149,7 @@ updated: 2026-08-14
- `img/echo6-logo.png` — Echo6 logo (replaces [[searxng]] logo) - `img/echo6-logo.png` — Echo6 logo (replaces [[searxng]] logo)
- `img/favicon.png` — Echo6 favicon - `img/favicon.png` — Echo6 favicon
- Config: `/opt/searxng/searxng-config/settings.yml` (instance_name: "Echo6", dark theme, center_alignment: false) - Config: `/opt/searxng/searxng-config/settings.yml` (instance_name: "Echo6", dark theme, center_alignment: false)
- [[searxng]] version: 2026.2.6 (Docker image: searxng/searxng:latest) - [[searxng]] version: 2026.2.6 (Docker image: [[searxng]]/searxng:latest)
### utility - CT 104 (192.168.1.104 / Tailscale: 100.64.0.12) ### utility - CT 104 (192.168.1.104 / Tailscale: 100.64.0.12)
- [[central]] data-hub spine (3 systemd units: central-supervisor, central-archive, central-gui) - [[central]] data-hub spine (3 systemd units: central-supervisor, central-archive, central-gui)
@ -202,7 +202,7 @@ updated: 2026-08-14
- Nextcloud AIO (https://nextcloud.echo6.co) - Nextcloud AIO (https://nextcloud.echo6.co)
- Apache port 11000, AIO management on 8080 - Apache port 11000, AIO management on 8080
- NFS storage from pi-nas (/mnt/nextcloud) - NFS storage from pi-nas (/mnt/nextcloud)
- SSO via Authentik OIDC - SSO via [[authentik]] OIDC
### media - VM 105 (192.168.1.160 / Tailscale: 100.64.0.18) ### media - VM 105 (192.168.1.160 / Tailscale: 100.64.0.18)
- ARR media automation stack (Docker) - ARR media automation stack (Docker)
@ -293,7 +293,7 @@ updated: 2026-08-14
- Port: 4403 (default), firmware 2.7.19 (PORTDUINO/native) - Port: 4403 (default), firmware 2.7.19 (PORTDUINO/native)
- Role: CLIENT_BASE, position: 42.574, -114.607 (manual) - Role: CLIENT_BASE, position: 42.574, -114.607 (manual)
- MAC source: eth0 (derived MAC `00:bd:27:78:0c:47`) - MAC source: eth0 (derived MAC `00:bd:27:78:0c:47`)
- MeshAI bot (CT 108) connects to this node via TCP `localhost:4403` (Docker network) - [[meshai]] bot (CT 108) connects to this node via TCP `localhost:4403` (Docker network)
- Service: `meshtasticd.service` (single instance, runs as user meshtastic) - Service: `meshtasticd.service` (single instance, runs as user meshtastic)
- Config: `/etc/meshtasticd/config.yaml` + `/etc/meshtasticd/config.d/ZebraHat_2W.yaml` - Config: `/etc/meshtasticd/config.yaml` + `/etc/meshtasticd/config.d/ZebraHat_2W.yaml`
- User: zvx, password auth (`sshpass -p '7redditGold' ssh zvx@aida-nebra`) - User: zvx, password auth (`sshpass -p '7redditGold' ssh zvx@aida-nebra`)

View file

@ -9,8 +9,8 @@ related:
- [[ip-allocation]] - [[ip-allocation]]
- [[lxc-service-migration]] - [[lxc-service-migration]]
- [[expose-service-edge2]] - [[expose-service-edge2]]
- [[authentik]] - [[matrix-synapse-deployment]]
updated: 2026-07-13 updated: 2026-08-24
--- ---
# Caddy & DNS Reference # Caddy & DNS Reference
@ -69,7 +69,7 @@ journalctl -u caddy -f
| search.echo6.co | — | — | 301 redirect to echo6.co | | search.echo6.co | — | — | 301 redirect to echo6.co |
| nas.echo6.co | 100.64.0.21:80 | Tailscale | OpenMediaVault (pi-nas) | | nas.echo6.co | 100.64.0.21:80 | Tailscale | OpenMediaVault (pi-nas) |
| immich.echo6.co | 192.168.1.182:2283 | Local IP | immich (has 2FA) | | immich.echo6.co | 192.168.1.182:2283 | Local IP | immich (has 2FA) |
| nextcloud.echo6.co | 192.168.1.183:11000 | Local IP | nextcloud AIO (SSO via Authentik) | | nextcloud.echo6.co | 192.168.1.183:11000 | Local IP | nextcloud AIO (SSO via [[authentik]]) |
| jellyfin.echo6.co | 100.64.0.18:8096 | Tailscale | Jellyfin media server (SSO via Authentik) | | jellyfin.echo6.co | 100.64.0.18:8096 | Tailscale | Jellyfin media server (SSO via Authentik) |
| requests.echo6.co | 100.64.0.18:5055 | Tailscale | Jellyseer request management (SSO via Authentik) | | requests.echo6.co | 100.64.0.18:5055 | Tailscale | Jellyseer request management (SSO via Authentik) |
| stream.echo6.co | 192.168.1.170:80 | Local IP | peertube video streaming (SSO via Authentik) | | stream.echo6.co | 192.168.1.170:80 | Local IP | peertube video streaming (SSO via Authentik) |
@ -79,7 +79,7 @@ journalctl -u caddy -f
| lidarr.echo6.co | 100.64.0.18:8686 | Tailscale | lidarr music automation (Authentik forward auth) | | lidarr.echo6.co | 100.64.0.18:8686 | Tailscale | lidarr music automation (Authentik forward auth) |
| navidrome.echo6.co | 100.64.0.18:4533 | Tailscale | navidrome music server (Authentik forward auth, /rest/* exempt for Subsonic API) | | navidrome.echo6.co | 100.64.0.18:4533 | Tailscale | navidrome music server (Authentik forward auth, /rest/* exempt for Subsonic API) |
| vpn.idahomesh.com | 192.168.1.106:8080 | Local IP | IdahoMesh Headscale VPN coordination | | vpn.idahomesh.com | 192.168.1.106:8080 | Local IP | IdahoMesh Headscale VPN coordination |
| mwpreview.k7zvx.com | 100.64.0.39:8090 | Tailscale | MeshWars public preview (CT 113, feat/places branch; /admin + /api/admin/* blocked -- 404 -- on this public host, reachable only over tailnet) | | mwpreview.k7zvx.com | 100.64.0.39:8090 | Tailscale | [[meshwars]] public preview (CT 113, feat/places branch; /admin + /api/admin/* blocked -- 404 -- on this public host, reachable only over tailnet) |
### Commands ### Commands
@ -145,7 +145,7 @@ dig +short forge.echo6.co @100.64.0.1 # Test
| forge | Forgejo Git | | forge | Forgejo Git |
| vpn | Headscale VPN | | vpn | Headscale VPN |
| vault | Vaultwarden | | vault | Vaultwarden |
| matrix | Matrix Synapse | | matrix | Matrix [[synapse]] |
| element | Element Web | | element | Element Web |
| notes | LiveSync (CouchDB + provisioner) | | notes | LiveSync (CouchDB + provisioner) |
| proxmox | Proxmox VE (via Tailscale to data node) | | proxmox | Proxmox VE (via Tailscale to data node) |
@ -177,7 +177,7 @@ dig +short forge.echo6.co @100.64.0.1 # Test
| immich | Immich | | immich | Immich |
| nextcloud | Nextcloud | | nextcloud | Nextcloud |
| requests | Jellyseer | | requests | Jellyseer |
| files | RECON PDF library | | files | [[recon]] PDF library |
| recon | RECON dashboard | | recon | RECON dashboard |
| lidarr | Lidarr music automation | | lidarr | Lidarr music automation |
| navidrome | Navidrome music server | | navidrome | Navidrome music server |
@ -246,4 +246,4 @@ oidc:
--- ---
*Last updated: 2026-07-11 — Flip off Contabo completed: "Contabo Caddy" section → "edge2 Caddy" (front door for auth/forge/vpn/vault/matrix/element/notes/proxmox, CTs verified against [[ip-allocation]]/[[services]]); Mailcow + autodiscover/autoconfig moved to edge1 (separate mail-only host, not on edge2); WATCHTOWER + TAK/SIGIL marked decommissioned (dead 100.64.0.1 backends removed); Headscale config location + Port Map updated to edge2; `ssh root@100.64.0.1``ssh edge2`. dnsmasq split-DNS section marked HISTORICAL/OBSOLETE (echo6.co split-DNS retired, ran on the dead pre-2026-06-19 Contabo host, not repointed to edge1/edge2 per [[services]]); GoDaddy DNS Records section corrected — edge2 [[services]] (auth/forge/vpn/vault/matrix/element/notes/proxmox) → 184.174.35.153, mail → edge1 5.189.158.149 (unchanged public IP), wt/tak marked as removed records. Prior: 2026-04-13 — Audit sync: added MAS routing on matrix.echo6.co, lidarr/navidrome/vpn.idahomesh.com to utility Caddy, proxmox/tak to GoDaddy, removed ghost docs.echo6.co entries, added dnsmasq lidarr/navidrome* *Last updated: 2026-07-11 — Flip off Contabo completed: "Contabo Caddy" section → "edge2 Caddy" (front door for auth/forge/vpn/vault/matrix/element/notes/proxmox, CTs verified against [[ip-allocation]]/[[services]]); Mailcow + autodiscover/autoconfig moved to edge1 (separate mail-only host, not on edge2); WATCHTOWER + TAK/SIGIL marked decommissioned (dead 100.64.0.1 backends removed); Headscale config location + Port Map updated to edge2; `ssh root@100.64.0.1``ssh edge2`. dnsmasq split-DNS section marked HISTORICAL/OBSOLETE (echo6.co split-DNS retired, ran on the dead pre-2026-06-19 Contabo host, not repointed to edge1/edge2 per [[services]]); GoDaddy [[dns]] Records section corrected — edge2 [[services]] (auth/forge/vpn/vault/matrix/element/notes/proxmox) → 184.174.35.153, mail → edge1 5.189.158.149 (unchanged public IP), wt/tak marked as removed records. Prior: 2026-04-13 — Audit sync: added MAS routing on matrix.echo6.co, lidarr/navidrome/vpn.idahomesh.com to utility Caddy, proxmox/tak to GoDaddy, removed ghost docs.echo6.co entries, added dnsmasq lidarr/navidrome*

View file

@ -6,10 +6,10 @@ tags:
aliases: [] aliases: []
related: related:
- [[caddy]] - [[caddy]]
- [[services]] - [[expose-service-home]]
- [[expose-service-contabo]] - [[expose-service-contabo]]
- [[usenet]] - [[services]]
- [[expose-service-edge2]] - [[headscale-onboard-node]]
updated: 2026-08-24 updated: 2026-08-24
--- ---
# GoDaddy DNS Management # GoDaddy DNS Management
@ -29,7 +29,7 @@ GoDaddy's API has two kinds of write endpoints for A records:
- `PUT /v1/domains/<domain>/records/A` and `PUT /v1/domains/<domain>/records` - `PUT /v1/domains/<domain>/records/A` and `PUT /v1/domains/<domain>/records`
— **replace every record of that type on the whole domain.** — **replace every record of that type on the whole domain.**
Both `k7zvx.com` and `echo6.co` front live production services (mail, auth, Both `k7zvx.com` and `echo6.co` front live production [[services]] (mail, auth,
forge, vpn, vault, matrix, element, and more). Calling one of the record-SET forge, vpn, vault, matrix, element, and more). Calling one of the record-SET
endpoints to "add" a record would wipe every other A record on the zone. endpoints to "add" a record would wipe every other A record on the zone.
`godaddy-dns.py` only ever uses the single-record endpoint to write, and does `godaddy-dns.py` only ever uses the single-record endpoint to write, and does
@ -101,8 +101,3 @@ godaddy-dns.py add-a echo6.co auth 184.174.35.153
```bash ```bash
godaddy-dns.py add-a echo6.co mail 5.189.158.149 godaddy-dns.py add-a echo6.co mail 5.189.158.149
``` ```
### Create CNAME alias
```bash
godaddy-dns.py add-cname echo6.co alias target.echo6.co
```

View file

@ -6,8 +6,8 @@ tags:
aliases: [] aliases: []
related: related:
- [[lxc-service-migration]] - [[lxc-service-migration]]
- [[expose-service-contabo]]
- [[expose-service-home]] - [[expose-service-home]]
- [[expose-service-contabo]]
- [[edge2-access-reference]] - [[edge2-access-reference]]
- [[caddy]] - [[caddy]]
updated: 2026-08-24 updated: 2026-08-24

View file

@ -9,7 +9,7 @@ related:
- [[expose-service-contabo]] - [[expose-service-contabo]]
- [[proxmox-onboard-node]] - [[proxmox-onboard-node]]
- [[headscale-onboard-node]] - [[headscale-onboard-node]]
- [[ct-runbook]] - [[lxc-service-migration]]
updated: 2026-08-24 updated: 2026-08-24
--- ---
# Expose Service on Home Network # Expose Service on Home Network