echo6-docs/engine/sweep-full.log
echo6-autocommit eb7eade7fa auto: docs sync 2026-06-18T18:00:10+00:00
Files changed: .gitignore CLAUDE.md credentials engine/.embcache.json engine/changelog.md engine/config.yaml engine/lib/__pycache__/agent.cpython-312.pyc engine/lib/agent.py engine/lib/lint.py engine/lint-report.md engine/sweep-full.log engine/sweep.sh vault/.obsidian/graph.json vault/.obsidian/workspace.json vault/INDEX.md vault/archive/projects/mmud/last-ember-chronicle.html vault/archive/projects/mmud/last-ember-howto.html vault/archive/projects/mmud/last-ember.html vault/archive/projects/mmud/mmud-phase5-prompt.md vault/archive/projects/mmud/mmud-phase6-prompt.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/01-update-planned.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/02-npc-nodes.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/03-darkcragg.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/04-dcrg-node.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/05-phase5.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/06-phase6.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/README.md vault/archive/projects/mmud/mmud-prompts/mmud-prompts/mmud-project.md vault/docs/hardware/environment.md vault/docs/hardware/ip-allocation.md vault/docs/matrix/archivist.md vault/docs/matrix/matrix_host.md vault/docs/matrix/mautrix_signal.md vault/docs/matrix/synapse.md vault/docs/matrix/synapse_retention_discovery.md vault/docs/navi/cc-rules.md vault/docs/navi/deployment.md vault/docs/navi/themes.md vault/docs/services/ots-setup.md vault/docs/services/services.md vault/docs/services/usenet.md vault/docs/software/authentik.md vault/docs/software/caddy.md vault/docs/software/dns.md vault/docs/software/geo-tools.md vault/docs/software/recon.md vault/docs/software/searxng.md vault/glossary.md vault/notes/echo6-landing-page-data-export.md vault/notes/ia-download-queue.md vault/plans/vaultwarden-plan.md vault/projects/advbbs-project.md vault/projects/argus.md vault/projects/deploy-livesync.md vault/projects/matrix-synapse-deployment.md vault/projects/meshtastic-headscale-runbook.md vault/projects/mmud-project.md vault/runbooks/add-peertube-channel.md vault/runbooks/authentik-access-groups.md vault/runbooks/authentik-create-invitation.md vault/runbooks/authentik-oidc-application.md vault/runbooks/authentik-upgrade.md vault/runbooks/ct-runbook.md vault/runbooks/edge2-access-reference.md vault/runbooks/expose-service-contabo.md vault/runbooks/expose-service-edge2.md vault/runbooks/expose-service-home.md vault/runbooks/headscale-onboard-node.md vault/runbooks/ia-cli-reference.md vault/runbooks/ia-download-mirror.md vault/runbooks/idahomesh-bridge-setup.md vault/runbooks/idahomesh-vpn-device-setup.md vault/runbooks/lxc-service-migration.md vault/runbooks/mailcow-create-mailbox.md vault/runbooks/meshmonitor-password-reset.md vault/runbooks/meshtastic-sidecar-node.md vault/runbooks/meshtasticd-sim-nodes-runbook.md vault/runbooks/nordvpn-lxc.md vault/runbooks/peertube-remote-runner.md vault/runbooks/pg-backup.md vault/runbooks/pi-nas-omv-runbook.md vault/runbooks/pipeline-patterns.md vault/runbooks/proxmox-create-ubuntu-vm.md vault/runbooks/proxmox-onboard-node.md vault/runbooks/recon-operations.md vault/runbooks/recon-service-integration.md vault/runbooks/syncthing-add-node.md vault/session-resume/SESSION-HANDOFF-meshai-test.md
2026-06-18 18:00:10 +00:00

3492 lines
123 KiB
Text
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

[sweep] Starting full-vault sweep: 61 docs at Thu Jun 18 16:52:32 UTC 2026
[sweep] [1/61] Processing vault/CLAUDE-baseline.md ...
[tag] Calling tagger on CLAUDE.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to CLAUDE.md ...
[embed] Embedding CLAUDE.md ...
[warn] Embedding failed: '/home/zvx/.claude/CLAUDE.md' is not in the subpath of '/home/zvx/projects/.ref/vault'
[apply] Wrote /home/zvx/.claude/CLAUDE.md
========================================================================
VAULT TAGGER v4 — CLAUDE.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
--- a/CLAUDE.md
+++ b/CLAUDE.md (linked)
@@ -23,5 +23,5 @@
- **Host protection:** never `shutdown`/`reboot`/`poweroff` any host; never include cortex (primary Claude Code host) or TOC in availability-affecting bulk operations; never install packages on any host (pip/npm/apt) without explicit permission.
- **No changes without approval:** never deploy, change service ports, or change network/firewall config without explicit approval. If a target is unreachable or blocked → **STOP and report**; never redirect to an alternate host.
-- **Resilience:** every deployment must survive a reboot.
+- **Resilience:** every [[deployment]] must survive a reboot.
- **Credentials:** source from `.ref/credentials`; never commit secrets to a git-tracked file — *except* the private `echo6-docs` Forge repo (the one documented exception).
- **Git:** GitHub `origin` is the source of truth and push target — *except* `echo6-docs`, which lives on Forge directly. Branch off the default branch before committing. Commit/push only when asked.
@@ -40,5 +40,5 @@
| toc | 192.168.1.244 | 100.64.0.13 | GPU host (passthrough → cortex) |
| **cortex** (VM 150) | 192.168.1.150 | 100.64.0.14 | GPU compute, **Claude Code**, AI |
-| recon-vm (VM 1130) | 192.168.1.130 | 100.64.0.24 | RECON pipeline |
+| recon-vm (VM 1130) | 192.168.1.130 | 100.64.0.24 | [[recon]] pipeline |
| Contabo VPS | 5.189.158.149 | 100.64.0.1 | Auth, Forge, Mail, Matrix, VPN, Vault |
| **edge2** (Contabo) | 184.174.35.153 | 100.64.0.26 | Proxmox edge node (PVE 8, LXC-only) — hosts **PDM** (Datacenter Mgr, CT 100 → 100.64.0.28:8443) |
@@ -46,5 +46,5 @@
- **SSH:** `ssh zvx@<ip>` (key auth) for most; `root@<ip>` for Proxmox hosts + Contabo. Password-auth exceptions (aida-nebra, mt-isr, toc, matt-desktop) → see `environment.md`.
-- **DNS targets:** Contabo services (auth, forge, mail, vpn, vault, matrix) → `5.189.158.149`; home services (echo6.co, ai, jellyfin, immich, nextcloud, recon, stream) → `199.6.36.163` (via utility Caddy).
+- **[[dns]] targets:** Contabo [[services]] (auth, forge, mail, vpn, vault, matrix) → `5.189.158.149`; home services (echo6.co, ai, jellyfin, immich, nextcloud, recon, stream) → `199.6.36.163` (via utility [[caddy]]).
---
### Related (bge-m3 top-5)
### Proposed frontmatter
---
title: Echo6 Infrastructure — Claude Guidelines
tags:
- mesh
aliases: []
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [1/61] Done vault/CLAUDE-baseline.md
[sweep] [2/61] Processing vault/docs/hardware/environment.md ...
[tag] Calling tagger on environment.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to environment.md ...
[embed] Embedding environment.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/hardware/environment.md
========================================================================
VAULT TAGGER v4 — environment.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/environment.md
+++ b/environment.md (linked)
@@ -7,5 +7,5 @@
| Node | Local IP | Tailscale | Hardware | RAM | Purpose |
| ------- | ------------- | ----------- | ----------------------------------------------- | -------------- | -------------------------------- |
-| data | 192.168.1.240 | 100.64.0.6 | AMD Ryzen 7 PRO 5750GE, 1TB NVMe + 1TB SATA SSD | 32GB DDR4-3200 | Database services |
+| data | 192.168.1.240 | 100.64.0.6 | AMD Ryzen 7 PRO 5750GE, 1TB NVMe + 1TB SATA SSD | 32GB DDR4-3200 | Database [[services]] |
| utility | 192.168.1.241 | 100.64.0.5 | AMD Ryzen 7 PRO 5750GE, 512GB NVMe | 32GB DDR4-3200 | Utility services, monitoring |
| cloud | 192.168.1.242 | 100.64.0.4 | Intel i7-12700T, 512GB NVMe | 32GB DDR4-3200 | Cloud storage, personal services |
@@ -25,5 +25,5 @@
- **media NIC:** Original Intel e1000e NIC crashes under sustained NFS load — replaced with USB Realtek RTL8153 GbE adapter on vmbr0
-- **Tailscale DNS bootstrap:** All LXC containers with Tailscale have a systemd drop-in (`/etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf`) that ensures fallback DNS exists before tailscaled starts, preventing chicken-and-egg DNS resolution failures on reboot
+- **Tailscale [[dns]] bootstrap:** All LXC containers with Tailscale have a systemd drop-in (`/etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf`) that ensures fallback DNS exists before tailscaled starts, preventing chicken-and-egg DNS resolution failures on reboot
### TOC Node Details
@@ -39,5 +39,5 @@
|----|------|------|----------|-----------|---------|
| cortex | toc | 150 | 192.168.1.150 | 100.64.0.14 | GPU compute — Open WebUI, Ollama, Qdrant, TEI, Claude Code |
-| recon-vm | data | 1130 | 192.168.1.130 | 100.64.0.24 | RECON knowledge extraction pipeline, Files, Kiwix |
+| recon-vm | data | 1130 | 192.168.1.130 | 100.64.0.24 | [[recon]] knowledge extraction pipeline, Files, Kiwix |
| arr | media | 105 | 192.168.1.160 | 100.64.0.18 | ARR media automation stack (Jellyfin, Sonarr, Radarr, etc.) |
@@ -84,5 +84,5 @@
| pi-nas | 192.168.1.245 | 100.64.0.21 | Raspberry Pi NAS |
| matt-desktop | 192.168.1.111 | 100.64.0.10 | Personal workstation (Windows, your PC) |
-| Contabo Server | 5.189.158.149 | 100.64.0.1 | External VPS: Mail, Authentik, Headscale, Forge, Matrix |
+| Contabo Server | 5.189.158.149 | 100.64.0.1 | External VPS: Mail, [[authentik]], Headscale, Forge, Matrix |
| edge2 | 184.174.35.153 | 100.64.0.26 | Contabo Cloud VPS 30 NVMe — Proxmox VE 8.4.19 (LXC-only), 8c/24GB/400GB |
@@ -94,6 +94,6 @@
|-----------|------|----------|-----------|---------|
| meshmonitor | utility (CT 100) | 192.168.1.100 | 100.64.0.7 | Meshtastic mesh monitoring (zvx-echo6/meshmonitor fork, multi-channel) |
-| caddy | utility (CT 101) | 192.168.1.101 | 100.64.0.8 | Home reverse proxy |
-| searxng | utility (CT 102) | 192.168.1.102 | 100.64.0.15 | Echo6 Search homepage (SearXNG, echo6.co) |
+| [[caddy]] | utility (CT 101) | 192.168.1.101 | 100.64.0.8 | Home reverse proxy |
+| [[searxng]] | utility (CT 102) | 192.168.1.102 | 100.64.0.15 | Echo6 Search homepage (SearXNG, echo6.co) |
| immich | cloud (CT 120) | 192.168.1.182 | 100.64.0.2 | Immich photo management |
| nextcloud | cloud (CT 121) | 192.168.1.183 | 100.64.0.11 | Nextcloud AIO |
@@ -101,6 +101,6 @@
| mesh-bridge | utility (CT 107) | 192.168.1.107 | 100.64.0.22 | Dual-tailscaled bridge (echo6 ↔ idahomesh) |
| meshai | utility (CT 108) | 192.168.1.144 | 100.64.0.32 | MeshAI - LLM-powered Meshtastic assistant |
-| archivist | utility (CT 118) | 192.168.1.118 | — | Archivist knowledge pipeline |
-| argus | utility (CT 103) | 192.168.1.103 | 100.64.0.25 | ARGUS - OSINT intelligence gathering platform |
+| [[archivist]] | utility (CT 118) | 192.168.1.118 | — | Archivist knowledge pipeline |
+| [[argus]] | utility (CT 103) | 192.168.1.103 | 100.64.0.25 | ARGUS - OSINT intelligence gathering platform |
| peertube | media (CT 110) | 192.168.1.170 | 100.64.0.23 | PeerTube video streaming |
| pdm | edge2 (CT 100) | 10.10.10.10 | 100.64.0.28 | Proxmox Datacenter Manager |
### Related (bge-m3 top-5)
[[ip-allocation]]
[[headscale-onboard-node]]
[[caddy]]
[[ct-runbook]]
[[proxmox-create-ubuntu-vm]]
### Proposed frontmatter
---
title: Echo6 Environment Reference
type: reference
tags:
- proxmox
aliases: []
related:
- [[ip-allocation]]
- [[headscale-onboard-node]]
- [[caddy]]
- [[ct-runbook]]
- [[proxmox-create-ubuntu-vm]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [2/61] Done vault/docs/hardware/environment.md
[sweep] [3/61] Processing vault/docs/hardware/ip-allocation.md ...
[tag] Calling tagger on ip-allocation.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to ip-allocation.md ...
[embed] Embedding ip-allocation.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/hardware/ip-allocation.md
========================================================================
VAULT TAGGER v4 — ip-allocation.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/ip-allocation.md
+++ b/ip-allocation.md (linked)
@@ -28,7 +28,7 @@
|----|-----------|------|---------|
| .100 | meshmonitor (CT 100) | utility | MeshMonitor web UI |
-| .101 | caddy (CT 101) | utility | Home reverse proxy |
-| .102 | searxng (CT 102) | utility | Echo6 Search (SearXNG) |
-| .103 | argus (CT 103) | utility | ARGUS OSINT platform |
+| .101 | [[caddy]] (CT 101) | utility | Home reverse proxy |
+| .102 | [[searxng]] (CT 102) | utility | Echo6 Search (SearXNG) |
+| .103 | [[argus]] (CT 103) | utility | ARGUS OSINT platform |
| .104 | meshing-around (CT 104) | utility | Mesh bot + WebGUI |
| .106 | meshtastic-hs (CT 106) | utility | IdahoMesh Headscale |
@@ -41,6 +41,6 @@
| .115 | mmud-trvl (CT 115) | utility | MMUD SIM: TRVL (Torval merchant) |
| .116 | mmud-wspr (CT 116) | utility | MMUD SIM: WSPR (Whisper sage) |
-| .118 | archivist (CT 118) | utility | Signal/Matrix archive bot |
-| .130 | recon (VM 1130) | data | RECON pipeline (migrated from CT 130) |
+| .118 | [[archivist]] (CT 118) | utility | Signal/Matrix archive bot |
+| .130 | [[recon]] (VM 1130) | data | RECON pipeline (migrated from CT 130) |
| .144 | meshai (CT 108) | utility | MeshAI assistant |
| .170 | peertube (CT 110) | media | PeerTube streaming |
@@ -59,5 +59,5 @@
| 10.10.10.21 | forgejo | CT 103 | 100.64.0.34 | Forgejo git server (migrated from Contabo 2026-06-16) |
| 10.10.10.22 | livesync | CT 104 | 100.64.0.35 | LiveSync Obsidian sync (CouchDB + provisioner; migrated from Contabo 2026-06-16) |
-| 10.10.10.23 | authentik | CT 105 | 100.64.0.36 | Authentik SSO platform (migrated from Contabo 2026-06-18) |
+| 10.10.10.23 | [[authentik]] | CT 105 | 100.64.0.36 | Authentik SSO platform (migrated from Contabo 2026-06-18) |
### VMs (.150-.199)
@@ -81,5 +81,5 @@
|----|----------|------|-----------|
| .240 | data | Proxmox - DB node | 100.64.0.20 |
-| .241 | utility | Proxmox - Utility services | 100.64.0.19 |
+| .241 | utility | Proxmox - Utility [[services]] | 100.64.0.19 |
| .242 | cloud | Proxmox - Cloud storage | 100.64.0.22 |
| .243 | media | Proxmox - Media server | 100.64.0.21 |
### Related (bge-m3 top-5)
[[services]]
[[environment]]
[[caddy]]
[[headscale-onboard-node]]
[[meshtastic-headscale-runbook]]
### Proposed frontmatter
---
title: Echo6 Network IP Allocation
type: reference
tags:
- proxmox
aliases: []
related:
- [[services]]
- [[environment]]
- [[caddy]]
- [[headscale-onboard-node]]
- [[meshtastic-headscale-runbook]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [3/61] Done vault/docs/hardware/ip-allocation.md
[sweep] [4/61] Processing vault/docs/matrix/archivist.md ...
[tag] Calling tagger on archivist.md ...
[tag] tags=['matrix'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to archivist.md ...
[embed] Embedding archivist.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/matrix/archivist.md
========================================================================
VAULT TAGGER v4 — archivist.md
========================================================================
### Tags
['matrix'] (confidence=0.85)
### Body wikilink diff
--- a/archivist.md
+++ b/archivist.md (linked)
@@ -32,6 +32,6 @@
- **Utility host fstab:** `192.168.1.245:/export/library /mnt/library nfs defaults,soft,timeo=150 0 0`
- **CT 118 mp0:** `/mnt/library,mp=/mnt/library,ro=0`
-- **Pattern source:** recon-vm (VM 1130, RECON) on data node uses identical approach
-- Utility host did NOT have /mnt/library mounted before this deployment
+- **Pattern source:** recon-vm (VM 1130, [[recon]]) on data node uses identical approach
+- Utility host did NOT have /mnt/library mounted before this [[deployment]]
### Write access
@@ -153,5 +153,5 @@
- Shared-secret registration (`/_synapse/admin/v1/register`) returns 404 under MAS — endpoint disabled
- Must use `mas-cli manage register-user` or `manage set-password` for existing users
-- MAS creates user in both MAS DB and Synapse DB
+- MAS creates user in both MAS DB and [[synapse]] DB
- Orphaned Synapse `profiles` row caused provisioning failure — fixed by DELETE
- Each `client.login()` creates a NEW MAS compat session with random device ID — use `restore_login()` with stable compat token instead
### Related (bge-m3 top-5)
[[caddy]]
[[mautrix_signal]]
[[matrix-synapse-deployment]]
[[services]]
[[recon-operations]]
### Proposed frontmatter
---
title: Signal Archive Bot — Deployment Reference
type: reference
tags:
- matrix
aliases: []
related:
- [[caddy]]
- [[mautrix_signal]]
- [[matrix-synapse-deployment]]
- [[services]]
- [[recon-operations]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [4/61] Done vault/docs/matrix/archivist.md
[sweep] [5/61] Processing vault/docs/matrix/matrix_host.md ...
[tag] Calling tagger on matrix_host.md ...
[tag] tags=['matrix'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to matrix_host.md ...
[embed] Embedding matrix_host.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/matrix/matrix_host.md
========================================================================
VAULT TAGGER v4 — matrix_host.md
========================================================================
### Tags
['matrix'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[matrix-synapse-deployment]]
[[synapse]]
[[expose-service-contabo]]
[[ct-runbook]]
[[lxc-service-migration]]
### Proposed frontmatter
---
title: Matrix Host Reference — Contabo VPS
type: reference
tags:
- matrix
aliases: []
related:
- [[matrix-synapse-deployment]]
- [[synapse]]
- [[expose-service-contabo]]
- [[ct-runbook]]
- [[lxc-service-migration]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [5/61] Done vault/docs/matrix/matrix_host.md
[sweep] [6/61] Processing vault/docs/matrix/mautrix_signal.md ...
[tag] Calling tagger on mautrix_signal.md ...
[tag] tags=['matrix'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to mautrix_signal.md ...
[embed] Embedding mautrix_signal.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/matrix/mautrix_signal.md
========================================================================
VAULT TAGGER v4 — mautrix_signal.md
========================================================================
### Tags
['matrix'] (confidence=0.85)
### Body wikilink diff
--- a/mautrix_signal.md
+++ b/mautrix_signal.md (linked)
@@ -7,5 +7,5 @@
- **Image:** dock.mau.dev/mautrix/signal:v0.2603.0
- **Container:** mautrix-signal
-- **Compose:** /opt/matrix/docker-compose.yml (same stack as Synapse)
+- **Compose:** /opt/matrix/docker-compose.yml (same stack as [[synapse]])
- **Config dir:** /opt/matrix/mautrix-signal/
- **Network:** matrix-net (internal only, no host port mapping)
### Related (bge-m3 top-5)
[[synapse]]
[[matrix-synapse-deployment]]
[[synapse_retention_discovery]]
[[archivist]]
[[advbbs-project]]
### Proposed frontmatter
---
title: mautrix-signal Bridge Reference
type: reference
tags:
- matrix
aliases: []
related:
- [[synapse]]
- [[matrix-synapse-deployment]]
- [[synapse_retention_discovery]]
- [[archivist]]
- [[advbbs-project]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [6/61] Done vault/docs/matrix/mautrix_signal.md
[sweep] [7/61] Processing vault/docs/matrix/synapse.md ...
[tag] Calling tagger on synapse.md ...
[tag] tags=['matrix'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to synapse.md ...
[embed] Embedding synapse.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/matrix/synapse.md
========================================================================
VAULT TAGGER v4 — synapse.md
========================================================================
### Tags
['matrix'] (confidence=0.85)
### Body wikilink diff
--- a/synapse.md
+++ b/synapse.md (linked)
@@ -32,5 +32,5 @@
- Listen: 8080 (web), 8081 (internal/health)
- Database: postgresql://mas:***@matrix-postgres:5432/mas
-- Upstream OAuth2: Authentik (auth.echo6.co) via OIDC
+- Upstream OAuth2: [[authentik]] (auth.echo6.co) via OIDC
- Client ID: 93kCoZkBlnJyD9EcAm7E4btKflecOcBm9DGONB5T
- Issuer: https://auth.echo6.co/application/o/matrix/
@@ -56,5 +56,5 @@
## Federation
-- Well-known served from echo6.co (utility Caddy, NOT matrix.echo6.co)
+- Well-known served from echo6.co (utility [[caddy]], NOT matrix.echo6.co)
- /.well-known/matrix/server: {"m.server": "matrix.echo6.co:443"}
- /.well-known/matrix/client: base_url=https://matrix.echo6.co, issuer=https://matrix.echo6.co/
### Related (bge-m3 top-5)
[[matrix-synapse-deployment]]
[[mautrix_signal]]
[[matrix_host]]
[[synapse_retention_discovery]]
[[caddy]]
### Proposed frontmatter
---
title: Synapse Deployment Reference
type: reference
tags:
- matrix
aliases: []
related:
- [[matrix-synapse-deployment]]
- [[mautrix_signal]]
- [[matrix_host]]
- [[synapse_retention_discovery]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [7/61] Done vault/docs/matrix/synapse.md
[sweep] [8/61] Processing vault/docs/matrix/synapse_retention_discovery.md ...
[tag] Calling tagger on synapse_retention_discovery.md ...
[tag] tags=['matrix'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to synapse_retention_discovery.md ...
[embed] Embedding synapse_retention_discovery.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/matrix/synapse_retention_discovery.md
========================================================================
VAULT TAGGER v4 — synapse_retention_discovery.md
========================================================================
### Tags
['matrix'] (confidence=0.85)
### Body wikilink diff
--- a/synapse_retention_discovery.md
+++ b/synapse_retention_discovery.md (linked)
@@ -26,5 +26,5 @@
- Backup: `/opt/matrix/synapse/homeserver.yaml.bak-20260412`
- Applied: 2026-04-12 03:06 UTC
-- Synapse restarted, health verified, bridge reconnected, Element login confirmed
+- [[synapse]] restarted, health verified, bridge reconnected, Element login confirmed
- Rollback: restore backup and `docker compose restart synapse`
### Related (bge-m3 top-5)
[[mautrix_signal]]
[[synapse]]
[[matrix-synapse-deployment]]
[[SESSION-HANDOFF-meshai-test]]
[[caddy]]
### Proposed frontmatter
---
title: Synapse Retention Discovery
type: reference
tags:
- matrix
aliases: []
related:
- [[mautrix_signal]]
- [[synapse]]
- [[matrix-synapse-deployment]]
- [[SESSION-HANDOFF-meshai-test]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [8/61] Done vault/docs/matrix/synapse_retention_discovery.md
[sweep] [9/61] Processing vault/docs/navi/cc-rules.md ...
[tag] Calling tagger on cc-rules.md ...
[tag] tags=['recon'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to cc-rules.md ...
[embed] Embedding cc-rules.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/navi/cc-rules.md
========================================================================
VAULT TAGGER v4 — cc-rules.md
========================================================================
### Tags
['recon'] (confidence=0.85)
### Body wikilink diff
--- a/cc-rules.md
+++ b/cc-rules.md (linked)
@@ -96,5 +96,5 @@
- [ ] Route between two addresses — polyline renders
- [ ] Click city label — boundary outline appears
-- [ ] Theme switching (all 4 themes)
+- [ ] Theme switching (all 4 [[themes]])
- [ ] Overlay toggles (hillshade, contours, public lands)
- [ ] Console: no "bt is not defined" or "f is not defined"
### Related (bge-m3 top-5)
[[deployment]]
[[CLAUDE-baseline]]
[[environment]]
[[themes]]
[[caddy]]
### Proposed frontmatter
---
title: "Navi: Claude Code Rules"
type: reference
tags:
- recon
aliases: []
related:
- [[deployment]]
- [[CLAUDE-baseline]]
- [[environment]]
- [[themes]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [9/61] Done vault/docs/navi/cc-rules.md
[sweep] [10/61] Processing vault/docs/navi/deployment.md ...
[tag] Calling tagger on deployment.md ...
[tag] tags=['recon'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to deployment.md ...
[embed] Embedding deployment.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/navi/deployment.md
========================================================================
VAULT TAGGER v4 — deployment.md
========================================================================
### Tags
['recon'] (confidence=0.85)
### Body wikilink diff
--- a/deployment.md
+++ b/deployment.md (linked)
@@ -26,5 +26,5 @@
- `index.html`: no-cache (always fresh)
- Hashed assets (`*.js`, `*.css`): cache forever
-- **Caddy** on CT 101 routes `navi.echo6.co` → VM 1130:8440
+- **[[caddy]]** on CT 101 routes `navi.echo6.co` → VM 1130:8440
## Pre-Deploy Checklist
### Related (bge-m3 top-5)
[[cc-rules]]
[[environment]]
[[recon-operations]]
[[ct-runbook]]
[[themes]]
### Proposed frontmatter
---
title: Navi Deployment
type: reference
tags:
- recon
aliases: []
related:
- [[cc-rules]]
- [[environment]]
- [[recon-operations]]
- [[ct-runbook]]
- [[themes]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [10/61] Done vault/docs/navi/deployment.md
[sweep] [11/61] Processing vault/docs/navi/themes.md ...
[tag] Calling tagger on themes.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to themes.md ...
[embed] Embedding themes.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/navi/themes.md
========================================================================
VAULT TAGGER v4 — themes.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[cc-rules]]
[[deployment]]
[[searxng]]
[[echo6-landing-page-data-export]]
[[pipeline-patterns]]
### Proposed frontmatter
---
title: Navi Theme System
type: reference
tags:
- auth
aliases: []
related:
- [[cc-rules]]
- [[deployment]]
- [[searxng]]
- [[echo6-landing-page-data-export]]
- [[pipeline-patterns]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [11/61] Done vault/docs/navi/themes.md
[sweep] [12/61] Processing vault/docs/services/ots-setup.md ...
[tag] Calling tagger on ots-setup.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to ots-setup.md ...
[embed] Embedding ots-setup.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/services/ots-setup.md
========================================================================
VAULT TAGGER v4 — ots-setup.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/ots-setup.md
+++ b/ots-setup.md (linked)
@@ -54,5 +54,5 @@
### DNS
- **Domain:** ots.k7zvx.com
-- **DNS Provider:** GoDaddy
+- **[[dns]] Provider:** GoDaddy
- **Record Type:** A
- **Points to:** 199.6.36.163 (home external IP)
@@ -62,5 +62,5 @@
- **Provider:** Let's Encrypt
- **Method:** acme.sh with GoDaddy DNS validation
-- **Location:** /etc/caddy/certs/ots.k7zvx.com.* (on CT 101)
+- **Location:** /etc/[[caddy]]/certs/ots.k7zvx.com.* (on CT 101)
- **Auto-renewal:** Configured via acme.sh
@@ -90,5 +90,5 @@
- **Install User:** zvx
- **Install Path:** /home/zvx/ots/
-- **Virtual Environment:** /home/zvx/.opentakserver_venv/
+- **Virtual [[environment]]:** /home/zvx/.opentakserver_venv/
- **Version:** 1.7.10
@@ -141,5 +141,5 @@
- Meshtastic mesh positions to appear as TAK contacts on the map
- Text messages from mesh to flow into TAK chat
-- Remote gateway deployment over Starlink, cell hotspots, or any internet connection
+- Remote gateway [[deployment]] over Starlink, cell hotspots, or any internet connection
**Setup Date:** April 17, 2026
@@ -559,5 +559,5 @@
### ISP-Specific Issue
-The Ubuntu mirror issue is specific to Filer Telephone Company's network peering. This may affect other services in the future. Consider:
+The Ubuntu mirror issue is specific to Filer Telephone Company's network peering. This may affect other [[services]] in the future. Consider:
- Using mirrors.kernel.org for all Ubuntu-based containers
- Setting up a local apt-cacher-ng if this becomes widespread
### Related (bge-m3 top-5)
[[ct-runbook]]
[[caddy]]
[[ip-allocation]]
[[environment]]
[[synapse]]
### Proposed frontmatter
---
title: OpenTAKServer Setup Documentation
type: reference
tags:
- proxmox
aliases: []
related:
- [[ct-runbook]]
- [[caddy]]
- [[ip-allocation]]
- [[environment]]
- [[synapse]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [12/61] Done vault/docs/services/ots-setup.md
[sweep] [13/61] Processing vault/docs/services/services.md ...
[tag] Calling tagger on services.md ...
[tag] tags=['media'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to services.md ...
[embed] Embedding services.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/services/services.md
========================================================================
VAULT TAGGER v4 — services.md
========================================================================
### Tags
['media'] (confidence=0.85)
### Body wikilink diff
--- a/services.md
+++ b/services.md (linked)
@@ -6,6 +6,6 @@
|---------|----------|---------|--------|-------|
| MeshMonitor | utility (CT 100) | 192.168.1.100:8080 | https://mesh.echo6.co | Meshtastic mesh monitoring (zvx-echo6/meshmonitor fork, multi-channel AutoAnnounce/AutoResponder) |
-| Utility Caddy | utility (CT 101) | 192.168.1.101 / 100.64.0.8 | 199.6.36.163 (ports 80/443) | Reverse proxy for home services |
-| Echo6 Search (SearXNG) | utility (CT 102) | 192.168.1.102:8080 | https://echo6.co | Branded search homepage (Docker, custom theme) |
+| Utility [[caddy]] | utility (CT 101) | 192.168.1.101 / 100.64.0.8 | 199.6.36.163 (ports 80/443) | Reverse proxy for home services |
+| Echo6 Search ([[searxng]]) | utility (CT 102) | 192.168.1.102:8080 | https://echo6.co | Branded search homepage (Docker, custom theme) |
| meshtasticd (AIDA-N2) | aida-nebra | 192.168.1.253:4403 | Internal | AIDA-N2(RPT,LLM) node !27780c47, Nebra 2W hat (ZebraHat), CLIENT_BASE role, fw 2.7.19. MeshAI (CT 108) connects via TCP localhost:4403 |
| Meshtastic CLI | mt-isr | 192.168.1.141 | Internal | Station G2 WiFi bridge + TCP management |
@@ -14,6 +14,6 @@
| mesh-bridge | utility (CT 107) | 192.168.1.107 | Internal | Dual-tailscaled bridge (echo6 ↔ idahomesh) |
| MeshAI | utility (CT 108) | 192.168.1.144:4403 | Internal | LLM-powered Meshtastic assistant (Docker, Gemini Flash, Google grounding) |
-| ARGUS | utility (CT 103) | 192.168.1.103 | Internal | OSINT intelligence gathering platform (Docker, SearXNG + local LLM analysis) |
-| Authentik | edge2 (CT 105) | 100.64.0.36:9000 | https://auth.echo6.co | SSO provider (Echo6 branded, custom CSS, dark theme) — fronted by Contabo Caddy (reverse_proxy 100.64.0.36:9000); **migrated from Contabo 2026-06-18** |
+| [[argus]] | utility (CT 103) | 192.168.1.103 | Internal | OSINT intelligence gathering platform (Docker, SearXNG + local LLM analysis) |
+| [[authentik]] | edge2 (CT 105) | 100.64.0.36:9000 | https://auth.echo6.co | SSO provider (Echo6 branded, custom CSS, dark theme) — fronted by Contabo Caddy (reverse_proxy 100.64.0.36:9000); **migrated from Contabo 2026-06-18** |
| Forge (Forgejo) | edge2 (CT 103) | 100.64.0.34:3001 HTTP / :2222 SSH (via Contabo DNAT) | https://forge.echo6.co | Git server — fronted by Contabo Caddy (reverse_proxy 100.64.0.34:3001); git SSH via iptables DNAT on Contabo (forgejo-ssh-dnat.service) — **migrated from Contabo 2026-06-16** |
| Headscale | Contabo | 5.189.158.149 | https://vpn.echo6.co | Tailscale coordination (OIDC enabled) |
@@ -31,16 +31,16 @@
| Radarr | media (VM 105) | 192.168.1.160:7878 | Internal | Movie automation (Docker) |
| Prowlarr | media (VM 105) | 192.168.1.160:9696 | Internal | Indexer manager (Docker) |
-| SABnzbd | media (VM 105) | 192.168.1.160:8080 | Internal | Usenet download client (Docker) |
+| SABnzbd | media (VM 105) | 192.168.1.160:8080 | Internal | [[usenet]] download client (Docker) |
| PeerTube | media (CT 110) | 192.168.1.170:9000 | https://stream.echo6.co | Video streaming (native, NFS on pi-nas, SSO) |
| WATCHTOWER | **Decommissioned (2026-06-16)** | — | ~~wt.echo6.co~~ | Was Docker on Contabo `/opt/watchtower`; stopped & archived to forge.echo6.co/matt/archive-watchtower |
| Open WebUI | cortex (VM 150) | 192.168.1.150:8080 | https://ai.echo6.co | AI chat interface (Docker, Ollama backend, SSO) |
-| Qdrant | cortex (VM 150) | 192.168.1.150:6333 | Internal | Vector database (Docker, RECON knowledge store) |
+| Qdrant | cortex (VM 150) | 192.168.1.150:6333 | Internal | Vector database (Docker, [[recon]] knowledge store) |
| TEI | cortex (VM 150) | 192.168.1.150:8090 | Internal | Text embeddings (Docker, bge-m3 1024-dim) |
| RECON | data (VM 1130) | 192.168.1.130:8420 | https://recon.echo6.co | Knowledge extraction pipeline (systemd, dashboard+API) |
| Files | data (VM 1130) | 192.168.1.130:8888 | https://files.echo6.co | PDF library (nginx, Authentik forward auth) |
| Samba | data | 192.168.1.240:445 | Internal | SMB file sharing — `//data/library` → /mnt/data/library (guest access) |
-| Matrix Synapse | Contabo | 127.0.0.1:8008 | https://matrix.echo6.co | Matrix homeserver (Docker, SSO) |
+| Matrix [[synapse]] | Contabo | 127.0.0.1:8008 | https://matrix.echo6.co | Matrix homeserver (Docker, SSO) |
| Element Web | Contabo | 127.0.0.1:8088 | https://element.echo6.co | Matrix web client (Docker) |
-| mautrix-signal | Contabo | internal (29328) | DM @signalbot:echo6.co | Signal bridge (Docker, E2BE, MSC4190, double puppeting) |
+| [[mautrix_signal]] | Contabo | internal (29328) | DM @signalbot:echo6.co | Signal bridge (Docker, E2BE, MSC4190, double puppeting) |
| LiveSync | edge2 (CT 104) | 100.64.0.35:5984 (CouchDB) / :5985 (provisioner) | https://notes.echo6.co | Obsidian sync (CouchDB + provisioner, Docker, JWT auth) — fronted by Contabo Caddy (reverse_proxy 100.64.0.35:5984 / :5985); **migrated from Contabo 2026-06-16** |
| TAK Server | **Decommissioned (2026-06-16)** | — | ~~tak.echo6.co~~ | Was Docker on Contabo `/opt/tak-server-deploy`; stopped & archived to forge.echo6.co/matt/archive-tak-server |
@@ -52,5 +52,5 @@
| Matrix MAS | Contabo | 127.0.0.1:8085 | Internal (via Caddy) | Matrix Authentication Service (Docker, handles login/logout/OIDC for Synapse) |
| Termix | Contabo | 0.0.0.0:8083 | Internal (no Caddy block) | Terminal sharing tool (Docker, ghcr.io/lukegus/termix:latest) |
-| Archivist | utility (CT 118) | 192.168.1.118 | Internal | Signal/Matrix room archive bot (systemd) — see archivist.md for details |
+| [[archivist]] | utility (CT 118) | 192.168.1.118 | Internal | Signal/Matrix room archive bot (systemd) — see archivist.md for details |
| pt-transcoder | cortex (VM 150) | N/A | Internal | PeerTube H.265 NVENC transcoder (systemd, /opt/bulk-import/transcoder.py) |
| recon-sparse | cortex (VM 150) | 192.168.1.150:8091 | Internal | RECON sparse embedding service (systemd, bge-m3 model, port 8091) |
@@ -76,5 +76,5 @@
- Qdrant (port 6333, internal, Docker — vector DB for RECON)
- TEI (port 8090, internal, Docker — bge-m3 embeddings for RECON)
-- PeerTube remote runner (peertube-runner service, Whisper auto-captioning via smart GPU/CPU wrapper, concurrency=2, MemoryMax=20G)
+- [[peertube-remote-runner]] (peertube-runner service, Whisper auto-captioning via smart GPU/CPU wrapper, concurrency=2, MemoryMax=20G)
- pt-transcoder (systemd: pt-transcoder.service, PeerTube H.265 NVENC transcoder)
- Script: `/opt/bulk-import/transcoder.py`
@@ -246,5 +246,5 @@
- G2 config: Freq51 (ch0, psk=1A==) + MediumFast (ch1), MEDIUM_FAST preset, ch=51, txPower=11
- G2 gold config backup: `isr@192.168.1.141:~/backups/g2-gold-config.yaml`
-- DNS bootstrap drop-in for tailscaled (reboot-safe)
+- [[dns]] bootstrap drop-in for tailscaled (reboot-safe)
- User: isr, password auth (see credentials)
### Related (bge-m3 top-5)
[[ip-allocation]]
[[caddy]]
[[glossary]]
[[meshtastic-headscale-runbook]]
[[lxc-service-migration]]
### Proposed frontmatter
---
title: Current Services Inventory
type: reference
tags:
- media
aliases: []
related:
- [[ip-allocation]]
- [[caddy]]
- [[glossary]]
- [[meshtastic-headscale-runbook]]
- [[lxc-service-migration]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [13/61] Done vault/docs/services/services.md
[sweep] [14/61] Processing vault/docs/services/usenet.md ...
[tag] Calling tagger on usenet.md ...
[tag] tags=['media'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to usenet.md ...
[embed] Embedding usenet.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/services/usenet.md
========================================================================
VAULT TAGGER v4 — usenet.md
========================================================================
### Tags
['media'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[dns]]
[[recon-operations]]
[[proxmox-onboard-node]]
[[caddy]]
[[glossary]]
### Proposed frontmatter
---
title: Usenet Configuration
type: reference
tags:
- media
aliases: []
related:
- [[dns]]
- [[recon-operations]]
- [[proxmox-onboard-node]]
- [[caddy]]
- [[glossary]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [14/61] Done vault/docs/services/usenet.md
[sweep] [15/61] Processing vault/docs/software/authentik.md ...
[tag] Calling tagger on authentik.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to authentik.md ...
[embed] Embedding authentik.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/software/authentik.md
========================================================================
VAULT TAGGER v4 — authentik.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
--- a/authentik.md
+++ b/authentik.md (linked)
@@ -207,5 +207,5 @@
| Forgejo | `https://app.echo6.co/user/oauth2/Authentik/callback` |
| Jellyfin (SSO plugin) | `https://app.echo6.co/sso/OID/redirect/Authentik` |
-| Caddy forward auth | `https://app.echo6.co/outpost.goauthentik.io/callback` |
+| [[caddy]] forward auth | `https://app.echo6.co/outpost.goauthentik.io/callback` |
## Users
@@ -311,5 +311,5 @@
- **Admin sidebar:** Dark with cyan hover/active states
- **User dashboard:** 3-column grid layout, dark cards with cyan border on hover
-- **Application icons:** Custom SVG icons uploaded for all 15 services
+- **Application icons:** Custom SVG icons uploaded for all 15 [[services]]
### CSS Storage
@@ -341,5 +341,5 @@
```
-This provides seamless SSO: authenticated users pass through to the app, unauthenticated users get the login page then redirect to the app. Used by the SearXNG waffle menu and nav bar.
+This provides seamless SSO: authenticated users pass through to the app, unauthenticated users get the login page then redirect to the app. Used by the [[searxng]] waffle menu and nav bar.
| App Slug | Service | Launch URL |
### Related (bge-m3 top-5)
[[authentik-oidc-application]]
[[mailcow-create-mailbox]]
[[caddy]]
[[echo6-landing-page-data-export]]
[[authentik-access-groups]]
### Proposed frontmatter
---
title: Authentik SSO Configuration
type: reference
tags:
- auth
aliases: []
related:
- [[authentik-oidc-application]]
- [[mailcow-create-mailbox]]
- [[caddy]]
- [[echo6-landing-page-data-export]]
- [[authentik-access-groups]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [15/61] Done vault/docs/software/authentik.md
[sweep] [16/61] Processing vault/docs/software/caddy.md ...
[tag] Calling tagger on caddy.md ...
[tag] tags=['dns'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to caddy.md ...
[embed] Embedding caddy.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/software/caddy.md
========================================================================
VAULT TAGGER v4 — caddy.md
========================================================================
### Tags
['dns'] (confidence=0.85)
### Body wikilink diff
--- a/caddy.md
+++ b/caddy.md (linked)
@@ -21,8 +21,8 @@
| proxmox.echo6.co | https://100.64.0.6:8006 (via Tailscale) | Proxmox VE (data node) |
| wt.echo6.co | 127.0.0.1:8099 ([[authentik]] forward auth) | WATCHTOWER ops dashboard |
-| matrix.echo6.co | 127.0.0.1:8008 + 127.0.0.1:8085 | Matrix [[synapse]] + MAS (login/logout/refresh/auth_metadata → MAS:8085, _matrix/* → Synapse:8008, default → MAS:8085) |
+| matrix.echo6.co | 127.0.0.1:8008 + 127.0.0.1:8085 | Matrix [[synapse]] + MAS (login/logout/refresh/auth_metadata → MAS:8085, _matrix/* → [[synapse]]:8008, default → MAS:8085) |
| element.echo6.co | 127.0.0.1:8088 | Element Web client |
| notes.echo6.co | 127.0.0.1:5984 + 127.0.0.1:5985 | LiveSync (CouchDB + provisioner, forward auth on /_provision*, CORS for Obsidian) |
-| tak.echo6.co | https://100.64.0.1:8446 + 100.64.0.1:8990 | TAK Server admin (8446, Authentik forward auth) + SIGIL console (/sigil, 8990) |
+| tak.echo6.co | https://100.64.0.1:8446 + 100.64.0.1:8990 | TAK Server admin (8446, [[authentik]] forward auth) + SIGIL console (/sigil, 8990) |
### Commands
@@ -100,5 +100,5 @@
| element.echo6.co | 100.64.0.1 | Element Web (via Contabo Caddy) |
| echo6.co | 100.64.0.8 | Echo6 Search homepage (via utility Caddy) |
-| files.echo6.co | 100.64.0.8 | RECON PDF library (via utility Caddy) |
+| files.echo6.co | 100.64.0.8 | [[recon]] PDF library (via utility Caddy) |
| recon.echo6.co | 100.64.0.8 | RECON dashboard (via utility Caddy) |
| lidarr.echo6.co | 100.64.0.8 | Lidarr music automation (via utility Caddy) |
@@ -138,5 +138,5 @@
| Subdomain | Service |
|-----------|---------|
-| @ | Echo6 Search homepage (SearXNG) |
+| @ | Echo6 Search homepage ([[searxng]]) |
| ai | Open WebUI |
| stream | PeerTube |
### Related (bge-m3 top-5)
[[services]]
[[ip-allocation]]
[[headscale-onboard-node]]
[[expose-service-home]]
[[lxc-service-migration]]
### Proposed frontmatter
---
title: "Caddy & DNS Reference"
type: reference
tags:
- dns
aliases: []
related:
- [[services]]
- [[ip-allocation]]
- [[headscale-onboard-node]]
- [[expose-service-home]]
- [[lxc-service-migration]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [16/61] Done vault/docs/software/caddy.md
[sweep] [17/61] Processing vault/docs/software/dns.md ...
[tag] Calling tagger on dns.md ...
[tag] tags=['dns'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to dns.md ...
[embed] Embedding dns.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/software/dns.md
========================================================================
VAULT TAGGER v4 — dns.md
========================================================================
### Tags
['dns'] (confidence=0.85)
### Body wikilink diff
--- a/dns.md
+++ b/dns.md (linked)
@@ -15,5 +15,5 @@
| Purpose | IP |
|---------|-----|
-| External (home services) | `199.6.36.163` |
+| External (home [[services]]) | `199.6.36.163` |
| Contabo Server | `5.189.158.149` |
### Related (bge-m3 top-5)
[[usenet]]
[[caddy]]
[[expose-service-contabo]]
[[headscale-onboard-node]]
[[authentik-oidc-application]]
### Proposed frontmatter
---
title: GoDaddy DNS Management
type: reference
tags:
- dns
aliases: []
related:
- [[usenet]]
- [[caddy]]
- [[expose-service-contabo]]
- [[headscale-onboard-node]]
- [[authentik-oidc-application]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [17/61] Done vault/docs/software/dns.md
[sweep] [18/61] Processing vault/docs/software/geo-tools.md ...
[tag] Calling tagger on geo-tools.md ...
[tag] tags=['storage'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to geo-tools.md ...
[embed] Embedding geo-tools.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/software/geo-tools.md
========================================================================
VAULT TAGGER v4 — geo-tools.md
========================================================================
### Tags
['storage'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[cc-rules]]
[[ct-runbook]]
[[environment]]
[[meshtasticd-sim-nodes-runbook]]
[[recon-operations]]
### Proposed frontmatter
---
title: Geo Processing Tools — Cortex
type: reference
tags:
- storage
aliases: []
related:
- [[cc-rules]]
- [[ct-runbook]]
- [[environment]]
- [[meshtasticd-sim-nodes-runbook]]
- [[recon-operations]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [18/61] Done vault/docs/software/geo-tools.md
[sweep] [19/61] Processing vault/docs/software/recon.md ...
[tag] Calling tagger on recon.md ...
[tag] tags=['recon'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to recon.md ...
[embed] Embedding recon.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/software/recon.md
========================================================================
VAULT TAGGER v4 — recon.md
========================================================================
### Tags
['recon'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[recon-operations]]
[[ia-download-queue]]
[[services]]
[[usenet]]
[[caddy]]
### Proposed frontmatter
---
title: RECON — Knowledge Extraction Pipeline
type: reference
tags:
- recon
aliases: []
related:
- [[recon-operations]]
- [[ia-download-queue]]
- [[services]]
- [[usenet]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [19/61] Done vault/docs/software/recon.md
[sweep] [20/61] Processing vault/docs/software/searxng.md ...
[tag] Calling tagger on searxng.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to searxng.md ...
[embed] Embedding searxng.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/docs/software/searxng.md
========================================================================
VAULT TAGGER v4 — searxng.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/searxng.md
+++ b/searxng.md (linked)
@@ -20,5 +20,5 @@
| Search engine | SearXNG (Docker, v2026.2.6) | searxng container |
| Cache | Valkey (Redis-compatible) | valkey container |
-| Reverse proxy | Utility Caddy (CT 101) | 192.168.1.101 |
+| Reverse proxy | Utility [[caddy]] (CT 101) | 192.168.1.101 |
| SSL certs | acme.sh (Let's Encrypt) | /etc/caddy/certs/ on CT 101 |
@@ -57,5 +57,5 @@
- **Nav bar:** Left: `.//files`, `.//stream` — Right: `.//photos`, `.//mail`, waffle menu, login avatar
- **Waffle menu:** 3x3 grid of service tiles (Aurora, Stream, Files, Watchtower, Photos, Mail, Cloud, Admin, Search) with inline SVG icons
-- **All nav links:** Use Authentik SSO launch URLs (`https://auth.echo6.co/application/launch/<slug>/`)
+- **All nav links:** Use [[authentik]] SSO launch URLs (`https://auth.echo6.co/application/launch/<slug>/`)
## Configuration
@@ -70,5 +70,5 @@
- `server.base_url`: "https://echo6.co/"
-**Environment:** Set in docker-compose.yml:
+**[[environment]]:** Set in docker-compose.yml:
- `SEARXNG_BASE_URL=https://echo6.co/`
- `INSTANCE_NAME=Echo6`
@@ -122,5 +122,5 @@
- `echo6.co` → `100.64.0.8` (utility Caddy)
-**GoDaddy DNS:**
+**GoDaddy [[dns]]:**
- `@` (echo6.co) → `199.6.36.163` (home)
- `search` → `199.6.36.163` (home)
@@ -128,3 +128,3 @@
---
-*Last updated: 2026-02-17 — Initial creation after Echo6 homepage deployment*
+*Last updated: 2026-02-17 — Initial creation after Echo6 homepage [[deployment]]*
### Related (bge-m3 top-5)
[[echo6-landing-page-data-export]]
[[caddy]]
[[ip-allocation]]
[[headscale-onboard-node]]
[[services]]
### Proposed frontmatter
---
title: SearXNG — Echo6 Search Homepage
type: reference
tags:
- proxmox
aliases: []
related:
- [[echo6-landing-page-data-export]]
- [[caddy]]
- [[ip-allocation]]
- [[headscale-onboard-node]]
- [[services]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [20/61] Done vault/docs/software/searxng.md
[sweep] [21/61] Processing vault/glossary.md ...
[tag] Calling tagger on glossary.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to glossary.md ...
[embed] Embedding glossary.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/glossary.md
========================================================================
VAULT TAGGER v4 — glossary.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/glossary.md
+++ b/glossary.md (linked)
@@ -6,5 +6,5 @@
## Topic categories
-mesh · matrix · recon · media · auth · dns · vpn · storage · proxmox · ai · mail
+mesh · matrix · [[recon]] · media · auth · [[dns]] · vpn · storage · proxmox · ai · mail
## Acronyms
@@ -21,6 +21,6 @@
### Hosts / Proxmox nodes
-- **argus** — aliases: 100.64.0.25
-- **authentik** — aliases: 100.64.0.36
+- **[[argus]]** — aliases: 100.64.0.25
+- **[[authentik]]** — aliases: 100.64.0.36
- **bluefin** — aliases: 100.64.0.30
- **cloud** (Cloud) — aliases: 192.168.1.242, 100.64.0.4
@@ -49,6 +49,6 @@
### LXC Containers
-- **archivist** — aliases: 192.168.1.118, CT 118 — on: utility
-- **caddy** — aliases: 192.168.1.101, CT 101, 100.64.0.8 — on: utility
+- **[[archivist]]** — aliases: 192.168.1.118, CT 118 — on: utility
+- **[[caddy]]** — aliases: 192.168.1.101, CT 101, 100.64.0.8 — on: utility
- **immich** — aliases: 192.168.1.182, CT 120, 100.64.0.2 — on: cloud
- **livesync** — aliases: 10.10.10.22, CT 104, 100.64.0.35 — on: edge2
@@ -56,5 +56,5 @@
- **pdm** — aliases: 10.10.10.10, CT 100, 100.64.0.28 — on: edge2
- **running** — aliases: CT 100 — on: utility _(live)_
-- **searxng** — aliases: 192.168.1.102, CT 102, 100.64.0.15 — on: utility
+- **[[searxng]]** — aliases: 192.168.1.102, CT 102, 100.64.0.15 — on: utility
- **vaultwarden** — aliases: 10.10.10.20, CT 102, 100.64.0.33 — on: edge2
- **wordpress** — aliases: 10.10.10.11, CT 101, 100.64.0.31 — on: edge2
@@ -113,6 +113,6 @@
- **matrix-mas** (Matrix MAS) — aliases: Matrix MAS — on: contabo
- **matrix-postgres** — aliases: matrix-postgres — on: contabo _(live)_
-- **matrix-synapse** (Matrix Synapse) — aliases: Matrix Synapse, matrix — on: contabo
-- **mautrix-signal** — aliases: mautrix-signal — on: contabo
+- **matrix-synapse** (Matrix [[synapse]]) — aliases: Matrix Synapse, matrix — on: contabo
+- **[[mautrix_signal]]** — aliases: mautrix-signal — on: contabo
- **meshtastic-cli** (Meshtastic CLI) — aliases: Meshtastic CLI — on: mt-isr
- **meshtasticd** — aliases: meshtasticd — on: mt-burleybutte
@@ -144,9 +144,9 @@
### Projects
-- **advbbs-project** — aliases: advbbs-project
+- **[[advbbs-project]]** — aliases: advbbs-project
- **argus** — aliases: argus
-- **deploy-livesync** — aliases: deploy-livesync
-- **matrix-synapse-deployment** — aliases: matrix-synapse-deployment
-- **meshtastic-headscale-runbook** — aliases: meshtastic-headscale-runbook
-- **mmud-project** — aliases: mmud-project
+- **[[deploy-livesync]]** — aliases: deploy-livesync
+- **[[matrix-synapse-deployment]]** — aliases: matrix-synapse-deployment
+- **[[meshtastic-headscale-runbook]]** — aliases: meshtastic-headscale-runbook
+- **[[mmud-project]]** — aliases: mmud-project
### Related (bge-m3 top-5)
[[services]]
[[ip-allocation]]
[[caddy]]
[[authentik]]
[[usenet]]
### Proposed frontmatter
---
title: "Glossary & Vocabulary"
type: reference
tags:
- proxmox
aliases: []
related:
- [[services]]
- [[ip-allocation]]
- [[caddy]]
- [[authentik]]
- [[usenet]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [21/61] Done vault/glossary.md
[sweep] [22/61] Processing vault/notes/echo6-landing-page-data-export.md ...
[tag] Calling tagger on echo6-landing-page-data-export.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to echo6-landing-page-data-export.md ...
[embed] Embedding echo6-landing-page-data-export.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/notes/echo6-landing-page-data-export.md
========================================================================
VAULT TAGGER v4 — echo6-landing-page-data-export.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
--- a/echo6-landing-page-data-export.md
+++ b/echo6-landing-page-data-export.md (linked)
@@ -37,6 +37,6 @@
| Service | URL | Description | Auth |
|---------|-----|-------------|------|
-| Echo6 Search (Homepage) | https://echo6.co | [[searxng]] search — branded cyberpunk homepage, Google-style layout | Public (SearXNG) |
-| Aurora (AI Assistant) | https://ai.echo6.co | RAG-augmented LLM chat — locally-hosted, queries a 95K+ vector knowledge base | Authentik OIDC |
+| Echo6 Search (Homepage) | https://echo6.co | [[searxng]] search — branded cyberpunk homepage, Google-style layout | Public ([[searxng]]) |
+| Aurora (AI Assistant) | https://ai.echo6.co | RAG-augmented LLM chat — locally-hosted, queries a 95K+ vector knowledge base | [[authentik]] OIDC |
| PeerTube (Video) | https://stream.echo6.co | Self-hosted video platform — 99 curated YouTube channels mirrored, GPU-transcoded | Authentik OIDC |
| File Server | https://files.echo6.co | PDF/document library — ~13,239 documents (military doctrine, survival, comms, trades) | Public |
@@ -219,5 +219,5 @@
### Nodes (all connected via Tailscale / self-hosted Headscale)
-| Node | Role | Key Services |
+| Node | Role | Key [[services]] |
|------|------|-------------|
| data | Proxmox host | Hosts [[recon]] VM (VM 1130) |
@@ -325,5 +325,5 @@
| Interface | OpenWebUI at ai.echo6.co |
| Model | JOSIEFIED Qwen3 8B (~55 tok/s, ~5GB VRAM) |
-| RAG source | RECON Qdrant (95K+ vectors, top-5 retrieval) |
+| RAG source | [[recon]] Qdrant (95K+ vectors, top-5 retrieval) |
| Embedding model | bge-m3 (1024-dim via TEI) |
| Score threshold | 0.3 cosine similarity |
@@ -404,6 +404,6 @@
|-------|-----------|
| Mesh VPN | Tailscale (self-hosted Headscale) |
-| Reverse proxy | Caddy (CT 101 on utility) — auto TLS |
-| DNS | GoDaddy (external), dnsmasq split DNS (internal) |
+| Reverse proxy | [[caddy]] (CT 101 on utility) — auto TLS |
+| [[dns]] | GoDaddy (external), dnsmasq split DNS (internal) |
| Authentication | Authentik OIDC SSO across all services |
| SSO Launch URLs | `https://auth.echo6.co/application/launch/<slug>/` for seamless pass-through |
### Related (bge-m3 top-5)
[[searxng]]
[[authentik]]
[[ip-allocation]]
[[caddy]]
[[CLAUDE-baseline]]
### Proposed frontmatter
---
title: Echo6 Landing Page — Data Export
type: note
tags:
- auth
aliases: []
related:
- [[searxng]]
- [[authentik]]
- [[ip-allocation]]
- [[caddy]]
- [[CLAUDE-baseline]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [22/61] Done vault/notes/echo6-landing-page-data-export.md
[sweep] [23/61] Processing vault/notes/ia-download-queue.md ...
[tag] Calling tagger on ia-download-queue.md ...
[tag] tags=['storage'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to ia-download-queue.md ...
[embed] Embedding ia-download-queue.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/notes/ia-download-queue.md
========================================================================
VAULT TAGGER v4 — ia-download-queue.md
========================================================================
### Tags
['storage'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[ia-download-mirror]]
[[ia-cli-reference]]
[[recon]]
[[usenet]]
[[glossary]]
### Proposed frontmatter
---
title: Internet Archive Download Queue
type: note
tags:
- storage
aliases: []
related:
- [[ia-download-mirror]]
- [[ia-cli-reference]]
- [[recon]]
- [[usenet]]
- [[glossary]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [23/61] Done vault/notes/ia-download-queue.md
[sweep] [24/61] Processing vault/plans/vaultwarden-plan.md ...
[tag] Calling tagger on vaultwarden-plan.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to vaultwarden-plan.md ...
[embed] Embedding vaultwarden-plan.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/plans/vaultwarden-plan.md
========================================================================
VAULT TAGGER v4 — vaultwarden-plan.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/vaultwarden-plan.md
+++ b/vaultwarden-plan.md (linked)
@@ -20,9 +20,9 @@
## Context
-We're consolidating both Contabo VPSes onto Proxmox. edge2 is up and proven (PVE 8 + PDM). The next phase is evacuating services off the **main Contabo** so it can be rebuilt as `edge1` — moving each service into an LXC on edge2, with the live Contabo as rollback, mail handled last on its original IP.
-
-**Vaultwarden is the pilot** because it's the lowest-risk service: a single container, ~5.3 MB of SQLite data, no external DB, and `SSO_ONLY=false` so local master-password login works even if Authentik is down. This run **doubles as the reusable per-service LXC-migration template** — phases are tagged `[G]` generic vs `[S]` service-specific.
-
-The cutover uses a **proven, low-risk pattern**: public DNS never changes; we stand up the service on edge2, then re-point *one token* of Contabo's Caddy backend to the new instance over the tailnet (exactly how `proxmox.echo6.co` already routes to `100.64.0.6:8006`). Rollback = revert that one token + restart source (~12 s).
+We're consolidating both Contabo VPSes onto Proxmox. edge2 is up and proven (PVE 8 + PDM). The next phase is evacuating [[services]] off the **main Contabo** so it can be rebuilt as `edge1` — moving each service into an LXC on edge2, with the live Contabo as rollback, mail handled last on its original IP.
+
+**Vaultwarden is the pilot** because it's the lowest-risk service: a single container, ~5.3 MB of SQLite data, no external DB, and `SSO_ONLY=false` so local master-password login works even if [[authentik]] is down. This run **doubles as the reusable per-service LXC-migration template** — phases are tagged `[G]` generic vs `[S]` service-specific.
+
+The cutover uses a **proven, low-risk pattern**: public [[dns]] never changes; we stand up the service on edge2, then re-point *one token* of Contabo's [[caddy]] backend to the new instance over the tailnet (exactly how `proxmox.echo6.co` already routes to `100.64.0.6:8006`). Rollback = revert that one token + restart source (~12 s).
**edge2 access (pinned):** `ssh admin@184.174.35.153` (alias `edge2`, key `~/.ssh/contabo2_ed25519`), then `sudo` for every `pct`/`pvesm`/`pveam` command. `root@100.64.0.26` is refused — do not use it.
@@ -48,5 +48,5 @@
### Phase 0a — Validate a LOCAL user exists + record to credentials `[S]` ← user-requested GATE
-- Take a read-only hot snapshot of the live DB and query `users`: confirm **≥1 account has a non-empty `password_hash`** (= master password set → local email+password login works, independent of SSO). Recon already confirms: **one account `matt@echo6.co`, password_hash non-empty, email verified, enabled → GATE PASS.** Record email(s), `login_count`, verified status.
+- Take a read-only hot snapshot of the live DB and query `users`: confirm **≥1 account has a non-empty `password_hash`** (= master password set → local email+password login works, independent of SSO). [[recon]] already confirms: **one account `matt@echo6.co`, password_hash non-empty, email verified, enabled → GATE PASS.** Record email(s), `login_count`, verified status.
- **Record to `/home/zvx/projects/.ref/credentials`** under a `# Vaultwarden (vault.echo6.co)` section: the account email(s), `SSO_ONLY=false` (local login enabled), and a note that the **master password is Matt's own secret — not stored anywhere in plaintext** (Vaultwarden keeps only the PBKDF2/Argon2 hash). The `ADMIN_TOKEN` (from `.env`) goes here as admin-panel break-glass.
- **GATE:** if NO account has a master password set, **STOP and surface it** — the local-login safety net wouldn't exist. Also confirm with Matt he knows the master password for at least one listed account (we can't recover it, only verify the account exists).
@@ -182,5 +182,5 @@
## Gotchas
- **G1** Stale `caddy.md`/archive mentions a `:3012`/`notifications/hub` WS route — live Caddy has **none** (in-process WS on `:8086`). Confirmed in Phase 0.
-- **G2** edge2 `vmbr0` has **no DHCP** and no `local-lvm` → static IP `10.10.10.20/24` + `local` (dir) storage. (Overrides ct-runbook defaults.)
+- **G2** edge2 `vmbr0` has **no DHCP** and no `local-lvm` → static IP `10.10.10.20/24` + `local` (dir) storage. (Overrides [[ct-runbook]] defaults.)
- **G3** Source binds loopback-only (`127.0.0.1:8086:80`); LXC must bind the tailnet IP (`VW_TS_IP:8086:80`) so Caddy reaches it. Keep the container-side `:80`.
- **G4** SQLite is in WAL mode with a **live 2.4 MB WAL** → use hot `.backup` (single self-contained file, no `-wal`/`-shm`); never copy a live `db.sqlite3`+WAL naively. Here we also **stop the source first** for zero-loss.
### Related (bge-m3 top-5)
[[lxc-service-migration]]
[[expose-service-edge2]]
[[edge2-access-reference]]
[[caddy]]
[[ip-allocation]]
### Proposed frontmatter
---
title: Vaultwarden → edge2 LXC — Migration Pilot (+ reusable LXC-migration runbook) — v2
type: note
tags:
- proxmox
aliases: []
related:
- [[lxc-service-migration]]
- [[expose-service-edge2]]
- [[edge2-access-reference]]
- [[caddy]]
- [[ip-allocation]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [24/61] Done vault/plans/vaultwarden-plan.md
[sweep] [25/61] Processing vault/projects/advbbs-project.md ...
[tag] Calling tagger on advbbs-project.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to advbbs-project.md ...
[embed] Embedding advbbs-project.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/projects/advbbs-project.md
========================================================================
VAULT TAGGER v4 — advbbs-project.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[meshtastic-sidecar-node]]
[[meshtasticd-sim-nodes-runbook]]
[[mautrix_signal]]
[[meshtastic-headscale-runbook]]
[[services]]
### Proposed frontmatter
---
title: advBBS — Claude Code Project Context
type: project
tags:
- mesh
aliases: []
related:
- [[meshtastic-sidecar-node]]
- [[meshtasticd-sim-nodes-runbook]]
- [[mautrix_signal]]
- [[meshtastic-headscale-runbook]]
- [[services]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [25/61] Done vault/projects/advbbs-project.md
[sweep] [26/61] Processing vault/projects/argus.md ...
[tag] Calling tagger on argus.md ...
[tag] tags=['recon'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to argus.md ...
[embed] Embedding argus.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/projects/argus.md
========================================================================
VAULT TAGGER v4 — argus.md
========================================================================
### Tags
['recon'] (confidence=0.85)
### Body wikilink diff
--- a/argus.md
+++ b/argus.md (linked)
@@ -58,5 +58,5 @@
**[[dns]] Bootstrap Fix:**
-Systemd drop-in at `/etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf` ensures fallback DNS (1.1.1.1, 8.8.8.8) exists before tailscaled starts, preventing chicken-and-egg DNS resolution failures on reboot.
+Systemd drop-in at `/etc/systemd/system/tailscaled.service.d/dns-bootstrap.conf` ensures fallback [[dns]] (1.1.1.1, 8.8.8.8) exists before tailscaled starts, preventing chicken-and-egg DNS resolution failures on reboot.
```bash
@@ -248,5 +248,5 @@
## Next Steps (Application Deployment)
-1. **SearXNG deployment:** Docker container for self-hosted search aggregation
+1. **[[searxng]] [[deployment]]:** Docker container for self-hosted search aggregation
2. **LLM integration:** Local model for analysis (Ollama on cortex or self-hosted)
3. **Database:** SQLite for processed intel, possibly Qdrant for vector search (cortex:6333 available)
### Related (bge-m3 top-5)
[[headscale-onboard-node]]
[[ip-allocation]]
[[caddy]]
[[ct-runbook]]
[[ots-setup]]
### Proposed frontmatter
---
title: ARGUS - OSINT Intelligence Platform
type: project
tags:
- recon
aliases: []
related:
- [[headscale-onboard-node]]
- [[ip-allocation]]
- [[caddy]]
- [[ct-runbook]]
- [[ots-setup]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [26/61] Done vault/projects/argus.md
[sweep] [27/61] Processing vault/projects/deploy-livesync.md ...
[tag] Calling tagger on deploy-livesync.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to deploy-livesync.md ...
[embed] Embedding deploy-livesync.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/projects/deploy-livesync.md
========================================================================
VAULT TAGGER v4 — deploy-livesync.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
--- a/deploy-livesync.md
+++ b/deploy-livesync.md (linked)
@@ -1,5 +1,5 @@
# Deploying CouchDB with JWT auth for Obsidian LiveSync via Authentik
-**LiveSync has native client-side JWT support that eliminates the need for a browser-based OIDC flow.** The plugin generates and signs JWTs internally using a stored private key, sending `Authorization: Bearer` headers directly to CouchDB. This fundamentally changes the architecture: instead of proxying OIDC tokens, you provision per-user key pairs, configure CouchDB with the public keys, and distribute setup URIs containing the private keys. Authentik serves as the identity backbone for a provisioning service — not as a runtime token issuer. No one has publicly documented a complete LiveSync + SSO deployment, making this guide a synthesis of the Kishieel Keycloak series, CouchDB JWT internals, Authentik's claim customization, and the LiveSync plugin's JWT implementation.
+**LiveSync has native client-side JWT support that eliminates the need for a browser-based OIDC flow.** The plugin generates and signs JWTs internally using a stored private key, sending `Authorization: Bearer` headers directly to CouchDB. This fundamentally changes the architecture: instead of proxying OIDC tokens, you provision per-user key pairs, configure CouchDB with the public keys, and distribute setup URIs containing the private keys. [[authentik]] serves as the identity backbone for a provisioning service — not as a runtime token issuer. No one has publicly documented a complete LiveSync + SSO [[deployment]], making this guide a synthesis of the Kishieel Keycloak series, CouchDB JWT internals, Authentik's claim customization, and the LiveSync plugin's JWT implementation.
---
@@ -198,5 +198,5 @@
**CORS is the most common failure mode.** Issue #628 documents that LiveSync does not send the `Origin` header on non-preflight requests, causing CouchDB's CORS handler to omit `Access-Control-Allow-Origin` from responses. The fix is configuring CORS in `local.ini` (shown above) rather than relying on the reverse proxy alone. Required origins: `app://obsidian.md`, `capacitor://localhost`, `http://localhost`.
-**The Caddy reverse proxy config** for `notes.echo6.co`:
+**The [[caddy]] reverse proxy config** for `notes.echo6.co`:
```
### Related (bge-m3 top-5)
[[authentik-oidc-application]]
[[authentik]]
[[authentik-access-groups]]
[[expose-service-home]]
[[authentik-upgrade]]
### Proposed frontmatter
---
title: Deploying CouchDB with JWT auth for Obsidian LiveSync via Authentik
type: project
tags:
- auth
aliases: []
related:
- [[authentik-oidc-application]]
- [[authentik]]
- [[authentik-access-groups]]
- [[expose-service-home]]
- [[authentik-upgrade]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [27/61] Done vault/projects/deploy-livesync.md
[sweep] [28/61] Processing vault/projects/matrix-synapse-deployment.md ...
[tag] Calling tagger on matrix-synapse-deployment.md ...
[tag] tags=['matrix'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to matrix-synapse-deployment.md ...
[embed] Embedding matrix-synapse-deployment.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/projects/matrix-synapse-deployment.md
========================================================================
VAULT TAGGER v4 — matrix-synapse-deployment.md
========================================================================
### Tags
['matrix'] (confidence=0.85)
### Body wikilink diff
--- a/matrix-synapse-deployment.md
+++ b/matrix-synapse-deployment.md (linked)
@@ -3,5 +3,5 @@
**Status:** Deployed 2026-02-15, migrated to Contabo 2026-02-15
**Target:** Contabo VPS (5.189.158.149 / 100.64.0.1)
-**URLs:** https://matrix.echo6.co (Synapse), https://element.echo6.co (Element Web)
+**URLs:** https://matrix.echo6.co ([[synapse]]), https://element.echo6.co (Element Web)
**Server Name:** echo6.co (federated identity: @user:echo6.co)
@@ -13,7 +13,7 @@
|-----------|--------|
| Host | Contabo VPS (5.189.158.149 / 100.64.0.1) |
-| Docker services | Synapse (127.0.0.1:8008), Element Web (127.0.0.1:8088), PostgreSQL 16 |
-| Reverse proxy | Contabo Caddy (auto ACME certs) |
-| SSO | Authentik OIDC → communication-users group |
+| Docker [[services]] | Synapse (127.0.0.1:8008), Element Web (127.0.0.1:8088), PostgreSQL 16 |
+| Reverse proxy | Contabo [[caddy]] (auto ACME certs) |
+| SSO | [[authentik]] OIDC → communication-users group |
| Federation | Well-known delegation on echo6.co base domain (served by utility Caddy) |
| Compose path | `/opt/matrix/docker-compose.yml` |
@@ -234,5 +234,5 @@
- Backend: `192.168.1.108:8008` (local IP, has OIDC)
-- Issue cert, install cert, add Caddy site block, add GoDaddy DNS
+- Issue cert, install cert, add Caddy site block, add GoDaddy [[dns]]
Caddy site block (note the path-based routing for Matrix):
@@ -457,5 +457,5 @@
## Post-Deploy Updates
-After deployment, update these docs:
+After [[deployment]], update these docs:
- `docs/services/services.md` — add Matrix entry
### Related (bge-m3 top-5)
[[synapse]]
[[matrix_host]]
[[mautrix_signal]]
[[caddy]]
[[lxc-service-migration]]
### Proposed frontmatter
---
title: Matrix Synapse Deployment
type: project
tags:
- matrix
aliases: []
related:
- [[synapse]]
- [[matrix_host]]
- [[mautrix_signal]]
- [[caddy]]
- [[lxc-service-migration]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [28/61] Done vault/projects/matrix-synapse-deployment.md
[sweep] [29/61] Processing vault/projects/meshtastic-headscale-runbook.md ...
[tag] Calling tagger on meshtastic-headscale-runbook.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to meshtastic-headscale-runbook.md ...
[embed] Embedding meshtastic-headscale-runbook.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/projects/meshtastic-headscale-runbook.md
========================================================================
VAULT TAGGER v4 — meshtastic-headscale-runbook.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[idahomesh-bridge-setup]]
[[idahomesh-vpn-device-setup]]
[[meshtastic-sidecar-node]]
[[headscale-onboard-node]]
[[caddy]]
### Proposed frontmatter
---
title: IdahoMesh Tailnet Runbook
type: project
tags:
- mesh
aliases: []
related:
- [[idahomesh-bridge-setup]]
- [[idahomesh-vpn-device-setup]]
- [[meshtastic-sidecar-node]]
- [[headscale-onboard-node]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [29/61] Done vault/projects/meshtastic-headscale-runbook.md
[sweep] [30/61] Processing vault/projects/mmud-project.md ...
[tag] Calling tagger on mmud-project.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to mmud-project.md ...
[embed] Embedding mmud-project.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/projects/mmud-project.md
========================================================================
VAULT TAGGER v4 — mmud-project.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[advbbs-project]]
[[meshtasticd-sim-nodes-runbook]]
[[ip-allocation]]
[[services]]
[[meshtastic-headscale-runbook]]
### Proposed frontmatter
---
title: MMUD — Mesh Multi-User Dungeon
type: project
tags:
- mesh
aliases: []
related:
- [[advbbs-project]]
- [[meshtasticd-sim-nodes-runbook]]
- [[ip-allocation]]
- [[services]]
- [[meshtastic-headscale-runbook]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [30/61] Done vault/projects/mmud-project.md
[sweep] [31/61] Processing vault/runbooks/add-peertube-channel.md ...
[tag] Calling tagger on add-peertube-channel.md ...
[tag] tags=['media'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to add-peertube-channel.md ...
[embed] Embedding add-peertube-channel.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/add-peertube-channel.md
========================================================================
VAULT TAGGER v4 — add-peertube-channel.md
========================================================================
### Tags
['media'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[peertube-remote-runner]]
[[recon-operations]]
[[recon-service-integration]]
[[proxmox-onboard-node]]
[[ct-runbook]]
### Proposed frontmatter
---
title: Add PeerTube Channel
type: runbook
tags:
- media
aliases: []
related:
- [[peertube-remote-runner]]
- [[recon-operations]]
- [[recon-service-integration]]
- [[proxmox-onboard-node]]
- [[ct-runbook]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [31/61] Done vault/runbooks/add-peertube-channel.md
[sweep] [32/61] Processing vault/runbooks/authentik-access-groups.md ...
[tag] Calling tagger on authentik-access-groups.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to authentik-access-groups.md ...
[embed] Embedding authentik-access-groups.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/authentik-access-groups.md
========================================================================
VAULT TAGGER v4 — authentik-access-groups.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
--- a/authentik-access-groups.md
+++ b/authentik-access-groups.md (linked)
@@ -3,5 +3,5 @@
Manage group-based application access via the [[authentik]] API. No web UI interaction required.
-**Authentik instance:** https://auth.echo6.co (Contabo, 100.64.0.1)
+**[[authentik]] instance:** https://auth.echo6.co (Contabo, 100.64.0.1)
**Key behavior:** Users in `authentik Admins` (is_superuser=true) bypass ALL policy checks automatically. Group bindings only restrict non-superuser access.
### Related (bge-m3 top-5)
[[authentik-oidc-application]]
[[authentik]]
[[authentik-create-invitation]]
[[deploy-livesync]]
[[proxmox-onboard-node]]
### Proposed frontmatter
---
title: Authentik Access Groups
type: runbook
tags:
- auth
aliases: []
related:
- [[authentik-oidc-application]]
- [[authentik]]
- [[authentik-create-invitation]]
- [[deploy-livesync]]
- [[proxmox-onboard-node]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [32/61] Done vault/runbooks/authentik-access-groups.md
[sweep] [33/61] Processing vault/runbooks/authentik-create-invitation.md ...
[tag] Calling tagger on authentik-create-invitation.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to authentik-create-invitation.md ...
[embed] Embedding authentik-create-invitation.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/authentik-create-invitation.md
========================================================================
VAULT TAGGER v4 — authentik-create-invitation.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
--- a/authentik-create-invitation.md
+++ b/authentik-create-invitation.md (linked)
@@ -1,5 +1,5 @@
# Authentik: Create Invitation
-Create user invitations via the Authentik Admin UI. Supports two modes: email (automatic delivery) and link-sharing (manual delivery).
+Create user invitations via the [[authentik]] Admin UI. Supports two modes: email (automatic delivery) and link-sharing (manual delivery).
---
@@ -120,5 +120,5 @@
## After Enrollment
-New users are created under the `users/enrolled` path. To grant them access to services:
+New users are created under the `users/enrolled` path. To grant them access to [[services]]:
1. Navigate to **Directory → Groups**
### Related (bge-m3 top-5)
[[authentik-access-groups]]
[[authentik]]
[[authentik-oidc-application]]
[[authentik-upgrade]]
[[mailcow-create-mailbox]]
### Proposed frontmatter
---
title: "Authentik: Create Invitation"
type: runbook
tags:
- auth
aliases: []
related:
- [[authentik-access-groups]]
- [[authentik]]
- [[authentik-oidc-application]]
- [[authentik-upgrade]]
- [[mailcow-create-mailbox]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [33/61] Done vault/runbooks/authentik-create-invitation.md
[sweep] [34/61] Processing vault/runbooks/authentik-oidc-application.md ...
[tag] Calling tagger on authentik-oidc-application.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to authentik-oidc-application.md ...
[embed] Embedding authentik-oidc-application.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/authentik-oidc-application.md
========================================================================
VAULT TAGGER v4 — authentik-oidc-application.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
--- a/authentik-oidc-application.md
+++ b/authentik-oidc-application.md (linked)
@@ -1,7 +1,7 @@
# Add Authentik OIDC to an Application
-Fully automated via Authentik API. No web UI interaction required.
-
-**Prerequisite:** DNS must already exist for the service (run expose-service-contabo.md or expose-service-home.md first).
+Fully automated via [[authentik]] API. No web UI interaction required.
+
+**Prerequisite:** [[dns]] must already exist for the service (run expose-service-contabo.md or expose-service-home.md first).
**Authentik instance:** https://auth.echo6.co (Contabo, 100.64.0.1)
@@ -215,5 +215,5 @@
### Common config patterns
-**Environment variables (Docker):**
+**[[environment]] variables (Docker):**
```bash
### Related (bge-m3 top-5)
[[authentik]]
[[authentik-access-groups]]
[[authentik-upgrade]]
[[mailcow-create-mailbox]]
[[expose-service-home]]
### Proposed frontmatter
---
title: Add Authentik OIDC to an Application
type: runbook
tags:
- auth
aliases: []
related:
- [[authentik]]
- [[authentik-access-groups]]
- [[authentik-upgrade]]
- [[mailcow-create-mailbox]]
- [[expose-service-home]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [34/61] Done vault/runbooks/authentik-oidc-application.md
[sweep] [35/61] Processing vault/runbooks/authentik-upgrade.md ...
[tag] Calling tagger on authentik-upgrade.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to authentik-upgrade.md ...
[embed] Embedding authentik-upgrade.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/authentik-upgrade.md
========================================================================
VAULT TAGGER v4 — authentik-upgrade.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
--- a/authentik-upgrade.md
+++ b/authentik-upgrade.md (linked)
@@ -1,5 +1,5 @@
# Authentik: Major Version Upgrade
-Upgrade Authentik between major versions on Contabo. Covers backup, upgrade, verification, and rollback.
+Upgrade [[authentik]] between major versions on Contabo. Covers backup, upgrade, verification, and rollback.
---
@@ -38,5 +38,5 @@
Look for:
- **Breaking changes** — removed features, changed defaults, API changes
-- **Dependency changes** — added/removed services (e.g., Redis removed in 2025.10)
+- **Dependency changes** — added/removed [[services]] (e.g., Redis removed in 2025.10)
- **Configuration changes** — new required env vars, changed mount paths
- **Database migrations** — large migrations that may take time
### Related (bge-m3 top-5)
[[authentik-oidc-application]]
[[lxc-service-migration]]
[[authentik]]
[[authentik-create-invitation]]
[[ct-runbook]]
### Proposed frontmatter
---
title: "Authentik: Major Version Upgrade"
type: runbook
tags:
- auth
aliases: []
related:
- [[authentik-oidc-application]]
- [[lxc-service-migration]]
- [[authentik]]
- [[authentik-create-invitation]]
- [[ct-runbook]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [35/61] Done vault/runbooks/authentik-upgrade.md
[sweep] [36/61] Processing vault/runbooks/ct-runbook.md ...
[tag] Calling tagger on ct-runbook.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to ct-runbook.md ...
[embed] Embedding ct-runbook.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/ct-runbook.md
========================================================================
VAULT TAGGER v4 — ct-runbook.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[proxmox-onboard-node]]
[[headscale-onboard-node]]
[[meshtasticd-sim-nodes-runbook]]
[[proxmox-create-ubuntu-vm]]
[[ots-setup]]
### Proposed frontmatter
---
title: Proxmox CT/LXC Provisioning Runbook
type: runbook
tags:
- proxmox
aliases: []
related:
- [[proxmox-onboard-node]]
- [[headscale-onboard-node]]
- [[meshtasticd-sim-nodes-runbook]]
- [[proxmox-create-ubuntu-vm]]
- [[ots-setup]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [36/61] Done vault/runbooks/ct-runbook.md
[sweep] [37/61] Processing vault/runbooks/edge2-access-reference.md ...
[tag] Calling tagger on edge2-access-reference.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to edge2-access-reference.md ...
[embed] Embedding edge2-access-reference.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/edge2-access-reference.md
========================================================================
VAULT TAGGER v4 — edge2-access-reference.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/edge2-access-reference.md
+++ b/edge2-access-reference.md (linked)
@@ -85,5 +85,5 @@
1. The SSH error shows `publickey,password` as available methods — this is misleading because `PasswordAuthentication no` is enforced, but the SSH banner still lists both
2. We tried `root@` (wrong user) and the default `id_ed25519` (wrong key)
-3. The environment docs didn't document the `admin` user or the specific key requirement
+3. The [[environment]] docs didn't document the `admin` user or the specific key requirement
**Resolution:** Added cortex's default `id_ed25519`, WSL2 key, and Windows key to admin's `authorized_keys`. Added SSH config alias `edge2` → `admin@100.64.0.26`.
### Related (bge-m3 top-5)
[[expose-service-edge2]]
[[proxmox-onboard-node]]
[[vaultwarden-plan]]
[[lxc-service-migration]]
[[headscale-onboard-node]]
### Proposed frontmatter
---
title: edge2 Access Reference
type: runbook
tags:
- proxmox
aliases: []
related:
- [[expose-service-edge2]]
- [[proxmox-onboard-node]]
- [[vaultwarden-plan]]
- [[lxc-service-migration]]
- [[headscale-onboard-node]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [37/61] Done vault/runbooks/edge2-access-reference.md
[sweep] [38/61] Processing vault/runbooks/expose-service-contabo.md ...
[tag] Calling tagger on expose-service-contabo.md ...
[tag] tags=['dns'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to expose-service-contabo.md ...
[embed] Embedding expose-service-contabo.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/expose-service-contabo.md
========================================================================
VAULT TAGGER v4 — expose-service-contabo.md
========================================================================
### Tags
['dns'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[expose-service-edge2]]
[[expose-service-home]]
[[lxc-service-migration]]
[[headscale-onboard-node]]
[[caddy]]
### Proposed frontmatter
---
title: Expose Service on Contabo
type: runbook
tags:
- dns
aliases: []
related:
- [[expose-service-edge2]]
- [[expose-service-home]]
- [[lxc-service-migration]]
- [[headscale-onboard-node]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [38/61] Done vault/runbooks/expose-service-contabo.md
[sweep] [39/61] Processing vault/runbooks/expose-service-edge2.md ...
[tag] Calling tagger on expose-service-edge2.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to expose-service-edge2.md ...
[embed] Embedding expose-service-edge2.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/expose-service-edge2.md
========================================================================
VAULT TAGGER v4 — expose-service-edge2.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/expose-service-edge2.md
+++ b/expose-service-edge2.md (linked)
@@ -3,5 +3,5 @@
## Context
-edge2 is a Proxmox VE 8 node (184.174.35.153 / 100.64.0.26) running LXC containers on an internal bridge (`vmbr0`, subnet `10.10.10.0/24`, gateway `10.10.10.1`). Services run inside unprivileged LXC containers. Caddy on the edge2 host terminates TLS and reverse-proxies to the container's internal IP.
+edge2 is a Proxmox VE 8 node (184.174.35.153 / 100.64.0.26) running LXC containers on an internal bridge (`vmbr0`, subnet `10.10.10.0/24`, gateway `10.10.10.1`). [[services]] run inside unprivileged LXC containers. [[caddy]] on the edge2 host terminates TLS and reverse-proxies to the container's internal IP.
## Prerequisites
@@ -9,5 +9,5 @@
- SSH access to edge2: `ssh edge2` (admin@100.64.0.26, key auth, passwordless sudo)
- Debian 13 CT template cached: `local:vztmpl/debian-13-standard_13.1-2_amd64.tar.zst`
-- DNS provider access (Cloudflare, GoDaddy, etc.)
+- [[dns]] provider access (Cloudflare, GoDaddy, etc.)
## Steps
### Related (bge-m3 top-5)
[[lxc-service-migration]]
[[edge2-access-reference]]
[[expose-service-contabo]]
[[expose-service-home]]
[[vaultwarden-plan]]
### Proposed frontmatter
---
title: Expose Service on edge2 (Contabo Cloud VPS)
type: runbook
tags:
- proxmox
aliases: []
related:
- [[lxc-service-migration]]
- [[edge2-access-reference]]
- [[expose-service-contabo]]
- [[expose-service-home]]
- [[vaultwarden-plan]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [39/61] Done vault/runbooks/expose-service-edge2.md
[sweep] [40/61] Processing vault/runbooks/expose-service-home.md ...
[tag] Calling tagger on expose-service-home.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to expose-service-home.md ...
[embed] Embedding expose-service-home.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/expose-service-home.md
========================================================================
VAULT TAGGER v4 — expose-service-home.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/expose-service-home.md
+++ b/expose-service-home.md (linked)
@@ -3,6 +3,6 @@
## Prerequisites
- Service running on a Proxmox CT/VM or bare metal
-- Router forwards 80/443 to Utility Caddy (192.168.1.101) — one-time setup
-- Determine pattern: does the service have Authentik OIDC?
+- Router forwards 80/443 to Utility [[caddy]] (192.168.1.101) — one-time setup
+- Determine pattern: does the service have [[authentik]] OIDC?
## Steps
### Related (bge-m3 top-5)
[[expose-service-edge2]]
[[expose-service-contabo]]
[[caddy]]
[[proxmox-onboard-node]]
[[ct-runbook]]
### Proposed frontmatter
---
title: Expose Service on Home Network
type: runbook
tags:
- proxmox
aliases: []
related:
- [[expose-service-edge2]]
- [[expose-service-contabo]]
- [[caddy]]
- [[proxmox-onboard-node]]
- [[ct-runbook]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [40/61] Done vault/runbooks/expose-service-home.md
[sweep] [41/61] Processing vault/runbooks/headscale-onboard-node.md ...
[tag] Calling tagger on headscale-onboard-node.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to headscale-onboard-node.md ...
[embed] Embedding headscale-onboard-node.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/headscale-onboard-node.md
========================================================================
VAULT TAGGER v4 — headscale-onboard-node.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/headscale-onboard-node.md
+++ b/headscale-onboard-node.md (linked)
@@ -78,5 +78,5 @@
- `docs/hardware/ip-allocation.md` — Tailscale IPs section.
- `CLAUDE.md` cluster cheat-sheet — Proxmox hosts only.
-- `docs/services/services.md` — once services are deployed on the node.
+- `docs/services/services.md` — once [[services]] are deployed on the node.
## Worked example — edge2 (2026-06-16)
### Related (bge-m3 top-5)
[[proxmox-onboard-node]]
[[ct-runbook]]
[[caddy]]
[[meshtastic-headscale-runbook]]
[[lxc-service-migration]]
### Proposed frontmatter
---
title: Headscale / Tailscale — Onboard a New Node
type: runbook
tags:
- proxmox
aliases: []
related:
- [[proxmox-onboard-node]]
- [[ct-runbook]]
- [[caddy]]
- [[meshtastic-headscale-runbook]]
- [[lxc-service-migration]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [41/61] Done vault/runbooks/headscale-onboard-node.md
[sweep] [42/61] Processing vault/runbooks/ia-cli-reference.md ...
[tag] Calling tagger on ia-cli-reference.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to ia-cli-reference.md ...
[embed] Embedding ia-cli-reference.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/ia-cli-reference.md
========================================================================
VAULT TAGGER v4 — ia-cli-reference.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[ia-download-mirror]]
[[ia-download-queue]]
[[idahomesh-vpn-device-setup]]
[[archivist]]
[[usenet]]
### Proposed frontmatter
---
title: Internet Archive CLI Reference
type: runbook
tags:
- auth
aliases: []
related:
- [[ia-download-mirror]]
- [[ia-download-queue]]
- [[idahomesh-vpn-device-setup]]
- [[archivist]]
- [[usenet]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [42/61] Done vault/runbooks/ia-cli-reference.md
[sweep] [43/61] Processing vault/runbooks/ia-download-mirror.md ...
[tag] Calling tagger on ia-download-mirror.md ...
[tag] tags=['storage'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to ia-download-mirror.md ...
[embed] Embedding ia-download-mirror.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/ia-download-mirror.md
========================================================================
VAULT TAGGER v4 — ia-download-mirror.md
========================================================================
### Tags
['storage'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[ia-cli-reference]]
[[ia-download-queue]]
[[pipeline-patterns]]
[[syncthing-add-node]]
[[idahomesh-vpn-device-setup]]
### Proposed frontmatter
---
title: "Download & Mirror from Internet Archive"
type: runbook
tags:
- storage
aliases: []
related:
- [[ia-cli-reference]]
- [[ia-download-queue]]
- [[pipeline-patterns]]
- [[syncthing-add-node]]
- [[idahomesh-vpn-device-setup]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [43/61] Done vault/runbooks/ia-download-mirror.md
[sweep] [44/61] Processing vault/runbooks/idahomesh-bridge-setup.md ...
[tag] Calling tagger on idahomesh-bridge-setup.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to idahomesh-bridge-setup.md ...
[embed] Embedding idahomesh-bridge-setup.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/idahomesh-bridge-setup.md
========================================================================
VAULT TAGGER v4 — idahomesh-bridge-setup.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[meshtastic-headscale-runbook]]
[[idahomesh-vpn-device-setup]]
[[meshtastic-sidecar-node]]
[[headscale-onboard-node]]
[[caddy]]
### Proposed frontmatter
---
title: IdahoMesh Bridge Setup
type: runbook
tags:
- mesh
aliases: []
related:
- [[meshtastic-headscale-runbook]]
- [[idahomesh-vpn-device-setup]]
- [[meshtastic-sidecar-node]]
- [[headscale-onboard-node]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [44/61] Done vault/runbooks/idahomesh-bridge-setup.md
[sweep] [45/61] Processing vault/runbooks/idahomesh-vpn-device-setup.md ...
[tag] Calling tagger on idahomesh-vpn-device-setup.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to idahomesh-vpn-device-setup.md ...
[embed] Embedding idahomesh-vpn-device-setup.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/idahomesh-vpn-device-setup.md
========================================================================
VAULT TAGGER v4 — idahomesh-vpn-device-setup.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
--- a/idahomesh-vpn-device-setup.md
+++ b/idahomesh-vpn-device-setup.md (linked)
@@ -256,5 +256,5 @@
- Confirm the device has internet access: `curl -I https://vpn.idahomesh.com`
-- Check DNS resolution: `dig vpn.idahomesh.com`
+- Check [[dns]] resolution: `dig vpn.idahomesh.com`
- Verify the preauthkey hasn't expired
### Related (bge-m3 top-5)
[[idahomesh-bridge-setup]]
[[meshtastic-headscale-runbook]]
[[meshtastic-sidecar-node]]
[[headscale-onboard-node]]
[[caddy]]
### Proposed frontmatter
---
title: IdahoMesh VPN — Device Setup
type: runbook
tags:
- mesh
aliases: []
related:
- [[idahomesh-bridge-setup]]
- [[meshtastic-headscale-runbook]]
- [[meshtastic-sidecar-node]]
- [[headscale-onboard-node]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [45/61] Done vault/runbooks/idahomesh-vpn-device-setup.md
[sweep] [46/61] Processing vault/runbooks/lxc-service-migration.md ...
[tag] Calling tagger on lxc-service-migration.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to lxc-service-migration.md ...
[embed] Embedding lxc-service-migration.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/lxc-service-migration.md
========================================================================
VAULT TAGGER v4 — lxc-service-migration.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/lxc-service-migration.md
+++ b/lxc-service-migration.md (linked)
@@ -1,5 +1,5 @@
# LXC Service Migration — Contabo → edge2
-> Proven pilots: **Vaultwarden → edge2 CT 102** (SQLite, 2026-06-16), **Forgejo → edge2 CT 103** (PostgreSQL + non-Caddy SSH port, 2026-06-16), **LiveSync (CouchDB) → edge2 CT 104** (cold named-volume tar + bind-mounted config, 2026-06-16), and **Authentik (PostgreSQL keystone) → edge2 CT 105** (SECRET_KEY-must-travel, multi-block Caddy cutover across 2 site blocks, reboot tailscale-before-docker race, 2026-06-18). This runbook generalizes these patterns into a reusable template for evacuating any Contabo-Caddy-fronted service to an edge2 LXC.
+> Proven pilots: **Vaultwarden → edge2 CT 102** (SQLite, 2026-06-16), **Forgejo → edge2 CT 103** (PostgreSQL + non-Caddy SSH port, 2026-06-16), **LiveSync (CouchDB) → edge2 CT 104** (cold named-volume tar + bind-mounted config, 2026-06-16), and **[[authentik]] (PostgreSQL keystone) → edge2 CT 105** (SECRET_KEY-must-travel, multi-block [[caddy]] cutover across 2 site blocks, reboot tailscale-before-docker race, 2026-06-18). This runbook generalizes these patterns into a reusable template for evacuating any Contabo-Caddy-fronted service to an edge2 LXC.
---
@@ -7,5 +7,5 @@
## Overview
-Move a Docker service from the main Contabo VPS into an LXC on edge2, with the Contabo Caddy frontend unchanged (public DNS never moves; only the upstream token in the Caddyfile changes). Rollback is a single line.
+Move a Docker service from the main Contabo VPS into an LXC on edge2, with the Contabo Caddy frontend unchanged (public [[dns]] never moves; only the upstream token in the Caddyfile changes). Rollback is a single line.
**Architecture after migration:**
@@ -429,5 +429,5 @@
| G14 | **Reboot race — Docker binding to the tailnet IP can start before Tailscale is online, failing the bind and leaving the service unreachable after a reboot.** Fix: create a systemd unit on the CT that runs `docker compose up` and has `After=tailscale-online.target` + `Requires=tailscale-online.target` (or equivalent `tailscale status --wait` pre-check). Alternatively, `restart: unless-stopped` in the compose file will cause Docker to self-heal via restarts, but the service will be unreachable for the first ~1030 s after reboot. Verify reboot survival explicitly (Phase 8). Proven required for Authentik (CT 105, 2026-06-18). |
| G15 | **Do NOT change the dnsmasq split-DNS entry during cutover.** The dnsmasq entry for `<service>.echo6.co` points at the Caddy/TLS host (100.64.0.1 = Contabo), NOT the backend. Only the Caddy upstream changes. Repointing dnsmasq to the backend tailnet IP would break internal HTTPS (no cert, no TLS termination). The Caddy host is always the internal DNS target; the backend IP only appears in the Caddy `reverse_proxy` directive. |
-| G16 | **SECRET_KEY and session-signing material must travel byte-for-byte for keystone/session-bearing services** (e.g. Authentik `AUTHENTIK_SECRET_KEY`, Vaultwarden `rsa_key.pem`). Carrying them verbatim means existing browser sessions survive the cutover — users drop straight in with no forced re-login. If the key is regenerated on the target, all active sessions are invalidated immediately. Confirm from startup logs that no new key was generated. |
+| G16 | **SECRET_KEY and session-signing material must travel byte-for-byte for keystone/session-bearing [[services]]** (e.g. Authentik `AUTHENTIK_SECRET_KEY`, Vaultwarden `rsa_key.pem`). Carrying them verbatim means existing browser sessions survive the cutover — users drop straight in with no forced re-login. If the key is regenerated on the target, all active sessions are invalidated immediately. Confirm from startup logs that no new key was generated. |
| N | The composed **Contabo-Caddy → edge2-LXC tailnet** path is unexercised for each new service. Keep the Phase 6 HTTP `/alive` 200 gate as a HARD pre-cutover requirement (use `curl`, not ICMP). |
@@ -436,5 +436,5 @@
## Template Summary
-**Generic phases (identical for every service):** 0 (recon) → 1 (LXC provision) → 2 (Docker) → 3 (Tailscale + DNS-bootstrap + reachability pre-gate) → 7 (one-token Caddy cutover + backup + validate + restart) → 7a (if service exposes non-Caddy TCP port: iptables DNAT systemd unit on Contabo) → 8 (end-to-end + reboot survival) → 9 (deferred decommission).
+**Generic phases (identical for every service):** 0 ([[recon]]) → 1 (LXC provision) → 2 (Docker) → 3 (Tailscale + DNS-bootstrap + reachability pre-gate) → 7 (one-token Caddy cutover + backup + validate + restart) → 7a (if service exposes non-Caddy TCP port: iptables DNAT systemd unit on Contabo) → 8 (end-to-end + reboot survival) → 9 (deferred decommission).
**Service-specific phases:** 0a (pre-migration gate), 4 (compose/config — copy from live host), 5 (data migration method depends on storage type), 6 (health gates — service-specific checks before cutover).
### Related (bge-m3 top-5)
[[expose-service-edge2]]
[[vaultwarden-plan]]
[[headscale-onboard-node]]
[[caddy]]
[[expose-service-contabo]]
### Proposed frontmatter
---
title: LXC Service Migration — Contabo → edge2
type: runbook
tags:
- proxmox
aliases: []
related:
- [[expose-service-edge2]]
- [[vaultwarden-plan]]
- [[headscale-onboard-node]]
- [[caddy]]
- [[expose-service-contabo]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [46/61] Done vault/runbooks/lxc-service-migration.md
[sweep] [47/61] Processing vault/runbooks/mailcow-create-mailbox.md ...
[tag] Calling tagger on mailcow-create-mailbox.md ...
[tag] tags=['auth'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to mailcow-create-mailbox.md ...
[embed] Embedding mailcow-create-mailbox.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/mailcow-create-mailbox.md
========================================================================
VAULT TAGGER v4 — mailcow-create-mailbox.md
========================================================================
### Tags
['auth'] (confidence=0.85)
### Body wikilink diff
--- a/mailcow-create-mailbox.md
+++ b/mailcow-create-mailbox.md (linked)
@@ -7,5 +7,5 @@
## When to Use This
-Any time a new mailbox is created in Mailcow, but **especially** for service/system accounts that authenticate via SMTP to send mail programmatically (e.g., `no-reply@echo6.co` used by Authentik, `recon@echo6.co` used by the RECON pipeline). These accounts don't log in through the Mailcow web UI or SSO — they pass credentials directly to Postfix over SMTP, so they **must** use local password authentication.
+Any time a new mailbox is created in Mailcow, but **especially** for service/system accounts that authenticate via SMTP to send mail programmatically (e.g., `no-reply@echo6.co` used by [[authentik]], `recon@echo6.co` used by the [[recon]] pipeline). These accounts don't log in through the Mailcow web UI or SSO — they pass credentials directly to Postfix over SMTP, so they **must** use local password authentication.
---
### Related (bge-m3 top-5)
[[authentik]]
[[authentik-oidc-application]]
[[caddy]]
[[authentik-create-invitation]]
[[proxmox-onboard-node]]
### Proposed frontmatter
---
title: "Mailcow: Create Mailbox"
type: runbook
tags:
- auth
aliases: []
related:
- [[authentik]]
- [[authentik-oidc-application]]
- [[caddy]]
- [[authentik-create-invitation]]
- [[proxmox-onboard-node]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [47/61] Done vault/runbooks/mailcow-create-mailbox.md
[sweep] [48/61] Processing vault/runbooks/meshmonitor-password-reset.md ...
[tag] Calling tagger on meshmonitor-password-reset.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to meshmonitor-password-reset.md ...
[embed] Embedding meshmonitor-password-reset.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/meshmonitor-password-reset.md
========================================================================
VAULT TAGGER v4 — meshmonitor-password-reset.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[proxmox-onboard-node]]
[[recon-service-integration]]
[[ct-runbook]]
[[headscale-onboard-node]]
[[recon-operations]]
### Proposed frontmatter
---
title: MeshMonitor Admin Password Reset
type: runbook
tags:
- proxmox
aliases: []
related:
- [[proxmox-onboard-node]]
- [[recon-service-integration]]
- [[ct-runbook]]
- [[headscale-onboard-node]]
- [[recon-operations]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [48/61] Done vault/runbooks/meshmonitor-password-reset.md
[sweep] [49/61] Processing vault/runbooks/meshtastic-sidecar-node.md ...
[tag] Calling tagger on meshtastic-sidecar-node.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to meshtastic-sidecar-node.md ...
[embed] Embedding meshtastic-sidecar-node.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/meshtastic-sidecar-node.md
========================================================================
VAULT TAGGER v4 — meshtastic-sidecar-node.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[idahomesh-vpn-device-setup]]
[[meshtastic-headscale-runbook]]
[[idahomesh-bridge-setup]]
[[headscale-onboard-node]]
[[advbbs-project]]
### Proposed frontmatter
---
title: Meshtastic Sidecar Node — Modular Deployment Runbook
type: runbook
tags:
- mesh
aliases: []
related:
- [[idahomesh-vpn-device-setup]]
- [[meshtastic-headscale-runbook]]
- [[idahomesh-bridge-setup]]
- [[headscale-onboard-node]]
- [[advbbs-project]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [49/61] Done vault/runbooks/meshtastic-sidecar-node.md
[sweep] [50/61] Processing vault/runbooks/meshtasticd-sim-nodes-runbook.md ...
[tag] Calling tagger on meshtasticd-sim-nodes-runbook.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to meshtasticd-sim-nodes-runbook.md ...
[embed] Embedding meshtasticd-sim-nodes-runbook.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/meshtasticd-sim-nodes-runbook.md
========================================================================
VAULT TAGGER v4 — meshtasticd-sim-nodes-runbook.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
--- a/meshtasticd-sim-nodes-runbook.md
+++ b/meshtasticd-sim-nodes-runbook.md (linked)
@@ -3,5 +3,5 @@
## Overview
-This runbook covers deploying meshtasticd SIM (virtual) nodes inside LXC containers on Proxmox, each paired with a dedicated service (BBS, MeshSense, etc.). SIM nodes communicate with your real radio node over UDP and appear as normal nodes on the mesh — clients, maps, and other services can't tell the difference.
+This runbook covers deploying meshtasticd SIM (virtual) nodes inside LXC containers on Proxmox, each paired with a dedicated service (BBS, MeshSense, etc.). SIM nodes communicate with your real radio node over UDP and appear as normal nodes on the mesh — clients, maps, and other [[services]] can't tell the difference.
**Design principle:** One container = one SIM daemon + one service. Clean isolation, easy to snapshot, migrate, or tear down without affecting anything else.
@@ -136,5 +136,5 @@
- **Every SIM node must have a unique MAC.** If two nodes share a MAC, you'll get node ID collisions and unpredictable behavior.
- The last 3 byte pairs map to a hex color code displayed in client apps.
-- Pick a scheme that makes sense for your deployment, e.g.:
+- Pick a scheme that makes sense for your [[deployment]], e.g.:
- `DE:AD:00:FF:00:01` — SIM node 1 (BBS)
- `DE:AD:00:00:FF:02` — SIM node 2 (MeshSense)
### Related (bge-m3 top-5)
[[ct-runbook]]
[[meshtastic-sidecar-node]]
[[headscale-onboard-node]]
[[proxmox-onboard-node]]
[[ip-allocation]]
### Proposed frontmatter
---
title: Meshtasticd SIM Node Runbook — LXC Deployment
type: runbook
tags:
- mesh
aliases: []
related:
- [[ct-runbook]]
- [[meshtastic-sidecar-node]]
- [[headscale-onboard-node]]
- [[proxmox-onboard-node]]
- [[ip-allocation]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [50/61] Done vault/runbooks/meshtasticd-sim-nodes-runbook.md
[sweep] [51/61] Processing vault/runbooks/nordvpn-lxc.md ...
[tag] Calling tagger on nordvpn-lxc.md ...
[tag] tags=['vpn'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to nordvpn-lxc.md ...
[embed] Embedding nordvpn-lxc.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/nordvpn-lxc.md
========================================================================
VAULT TAGGER v4 — nordvpn-lxc.md
========================================================================
### Tags
['vpn'] (confidence=0.85)
### Body wikilink diff
--- a/nordvpn-lxc.md
+++ b/nordvpn-lxc.md (linked)
@@ -1,5 +1,5 @@
# NordVPN / WireGuard in LXC
-Set up VPN with IP rotation inside an LXC container. Handles the LXC-specific gotchas: TUN device, systemd compatibility, split tunneling so local services stay reachable.
+Set up VPN with IP rotation inside an LXC container. Handles the LXC-specific gotchas: TUN device, systemd compatibility, split tunneling so local [[services]] stay reachable.
---
@@ -328,5 +328,5 @@
### DNS stops working when VPN is up
-NordVPN CLI: `nordvpn set dns off` (use container's DNS, not NordVPN's).
+NordVPN CLI: `nordvpn set dns off` (use container's [[dns]], not NordVPN's).
WireGuard: Remove the `DNS =` line from the `.conf` file.
### Related (bge-m3 top-5)
[[ct-runbook]]
[[meshtasticd-sim-nodes-runbook]]
[[proxmox-onboard-node]]
[[headscale-onboard-node]]
[[peertube-remote-runner]]
### Proposed frontmatter
---
title: NordVPN / WireGuard in LXC
type: runbook
tags:
- vpn
aliases: []
related:
- [[ct-runbook]]
- [[meshtasticd-sim-nodes-runbook]]
- [[proxmox-onboard-node]]
- [[headscale-onboard-node]]
- [[peertube-remote-runner]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [51/61] Done vault/runbooks/nordvpn-lxc.md
[sweep] [52/61] Processing vault/runbooks/peertube-remote-runner.md ...
[tag] Calling tagger on peertube-remote-runner.md ...
[tag] tags=['media'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to peertube-remote-runner.md ...
[embed] Embedding peertube-remote-runner.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/peertube-remote-runner.md
========================================================================
VAULT TAGGER v4 — peertube-remote-runner.md
========================================================================
### Tags
['media'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[add-peertube-channel]]
[[nordvpn-lxc]]
[[ct-runbook]]
[[proxmox-onboard-node]]
[[headscale-onboard-node]]
### Proposed frontmatter
---
title: PeerTube Remote Runner — GPU Transcoding
type: runbook
tags:
- media
aliases: []
related:
- [[add-peertube-channel]]
- [[nordvpn-lxc]]
- [[ct-runbook]]
- [[proxmox-onboard-node]]
- [[headscale-onboard-node]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [52/61] Done vault/runbooks/peertube-remote-runner.md
[sweep] [53/61] Processing vault/runbooks/pg-backup.md ...
[tag] Calling tagger on pg-backup.md ...
[tag] tags=['storage'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to pg-backup.md ...
[embed] Embedding pg-backup.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/pg-backup.md
========================================================================
VAULT TAGGER v4 — pg-backup.md
========================================================================
### Tags
['storage'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[ct-runbook]]
[[recon-operations]]
[[meshmonitor-password-reset]]
[[matrix-synapse-deployment]]
[[synapse]]
### Proposed frontmatter
---
title: PostgreSQL Backup (Docker)
type: runbook
tags:
- storage
aliases: []
related:
- [[ct-runbook]]
- [[recon-operations]]
- [[meshmonitor-password-reset]]
- [[matrix-synapse-deployment]]
- [[synapse]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [53/61] Done vault/runbooks/pg-backup.md
[sweep] [54/61] Processing vault/runbooks/pi-nas-omv-runbook.md ...
[tag] Calling tagger on pi-nas-omv-runbook.md ...
[tag] tags=['storage'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to pi-nas-omv-runbook.md ...
[embed] Embedding pi-nas-omv-runbook.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/pi-nas-omv-runbook.md
========================================================================
VAULT TAGGER v4 — pi-nas-omv-runbook.md
========================================================================
### Tags
['storage'] (confidence=0.85)
### Body wikilink diff
--- a/pi-nas-omv-runbook.md
+++ b/pi-nas-omv-runbook.md (linked)
@@ -112,5 +112,5 @@
### Enable SMB (Windows Shares)
-1. **Services → SMB/CIFS → Settings** — toggle **Enabled**, click **Save**
+1. **[[services]] → SMB/CIFS → Settings** — toggle **Enabled**, click **Save**
2. **Services → SMB/CIFS → Shares** — click **Create** for each shared folder you want accessible from Windows:
- Select the shared folder
### Related (bge-m3 top-5)
[[ct-runbook]]
[[proxmox-onboard-node]]
[[proxmox-create-ubuntu-vm]]
[[headscale-onboard-node]]
[[environment]]
### Proposed frontmatter
---
title: Pi 5 NAS — OMV Provisioning Runbook
type: runbook
tags:
- storage
aliases: []
related:
- [[ct-runbook]]
- [[proxmox-onboard-node]]
- [[proxmox-create-ubuntu-vm]]
- [[headscale-onboard-node]]
- [[environment]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [54/61] Done vault/runbooks/pi-nas-omv-runbook.md
[sweep] [55/61] Processing vault/runbooks/pipeline-patterns.md ...
[tag] Calling tagger on pipeline-patterns.md ...
[tag] tags=[] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to pipeline-patterns.md ...
[embed] Embedding pipeline-patterns.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/pipeline-patterns.md
========================================================================
VAULT TAGGER v4 — pipeline-patterns.md
========================================================================
### Tags
[] (confidence=0.85)
### Body wikilink diff
--- a/pipeline-patterns.md
+++ b/pipeline-patterns.md (linked)
@@ -7,5 +7,5 @@
3. **Pre-Flight Probe Gate** — *logic you inject*. Cheaply inspect each input and skip the expensive step when the work would be wasted (wrong format, already optimized, corrupt, too large).
-They compose: **Pattern 1 is how you deploy; Patterns 2 and 3 are two kinds of pre-flight logic you put inside the wrapper.** The running example throughout is the Whisper auto-captioning / PeerTube transcoder / RECON extraction stack on cortex.
+They compose: **Pattern 1 is how you deploy; Patterns 2 and 3 are two kinds of pre-flight logic you put inside the wrapper.** The running example throughout is the Whisper auto-captioning / PeerTube transcoder / [[recon]] extraction stack on cortex.
## Contents
@@ -216,5 +216,5 @@
### Example — Whisper transcription routing (PeerTube runner on cortex)
-The PeerTube remote runner calls `whisper-ctranslate2` for auto-captioning. The smart wrapper intercepts this to route short videos to GPU and long videos to CPU (the routing logic itself is **Pattern 2** below).
+The [[peertube-remote-runner]] calls `whisper-ctranslate2` for auto-captioning. The smart wrapper intercepts this to route short videos to GPU and long videos to CPU (the routing logic itself is **Pattern 2** below).
```
### Related (bge-m3 top-5)
[[meshtastic-sidecar-node]]
[[meshtastic-headscale-runbook]]
[[headscale-onboard-node]]
[[idahomesh-vpn-device-setup]]
[[syncthing-add-node]]
### Proposed frontmatter
---
title: "Pipeline & Wrapper Patterns"
type: runbook
tags: []
aliases: []
related:
- [[meshtastic-sidecar-node]]
- [[meshtastic-headscale-runbook]]
- [[headscale-onboard-node]]
- [[idahomesh-vpn-device-setup]]
- [[syncthing-add-node]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [55/61] Done vault/runbooks/pipeline-patterns.md
[sweep] [56/61] Processing vault/runbooks/proxmox-create-ubuntu-vm.md ...
[tag] Calling tagger on proxmox-create-ubuntu-vm.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to proxmox-create-ubuntu-vm.md ...
[embed] Embedding proxmox-create-ubuntu-vm.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/proxmox-create-ubuntu-vm.md
========================================================================
VAULT TAGGER v4 — proxmox-create-ubuntu-vm.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/proxmox-create-ubuntu-vm.md
+++ b/proxmox-create-ubuntu-vm.md (linked)
@@ -280,4 +280,4 @@
1. Update `/home/zvx/projects/.ref/docs/hardware/environment.md` with the new VM's IP and Tailscale IP
-2. Update `/home/zvx/projects/.ref/docs/services/services.md` once services are deployed
+2. Update `/home/zvx/projects/.ref/docs/services/services.md` once [[services]] are deployed
3. Remove the cloud image ISO if disk space is tight: `ssh root@$PVE_HOST 'rm /var/lib/vz/template/iso/noble-server-cloudimg-amd64.img'`
### Related (bge-m3 top-5)
[[ct-runbook]]
[[environment]]
[[proxmox-onboard-node]]
[[headscale-onboard-node]]
[[pi-nas-omv-runbook]]
### Proposed frontmatter
---
title: Proxmox — Create Ubuntu VM (Cloud-Init)
type: runbook
tags:
- proxmox
aliases: []
related:
- [[ct-runbook]]
- [[environment]]
- [[proxmox-onboard-node]]
- [[headscale-onboard-node]]
- [[pi-nas-omv-runbook]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [56/61] Done vault/runbooks/proxmox-create-ubuntu-vm.md
[sweep] [57/61] Processing vault/runbooks/proxmox-onboard-node.md ...
[tag] Calling tagger on proxmox-onboard-node.md ...
[tag] tags=['proxmox'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to proxmox-onboard-node.md ...
[embed] Embedding proxmox-onboard-node.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/proxmox-onboard-node.md
========================================================================
VAULT TAGGER v4 — proxmox-onboard-node.md
========================================================================
### Tags
['proxmox'] (confidence=0.85)
### Body wikilink diff
--- a/proxmox-onboard-node.md
+++ b/proxmox-onboard-node.md (linked)
@@ -210,5 +210,5 @@
Check `/etc/hosts` on all nodes includes the new hostname and IP.
-**Authentik realm missing**
+**[[authentik]] realm missing**
Check `systemctl status pve-cluster`. Realm syncs via pmxcfs in `/etc/pve/domains.cfg`.
### Related (bge-m3 top-5)
[[ct-runbook]]
[[headscale-onboard-node]]
[[proxmox-create-ubuntu-vm]]
[[edge2-access-reference]]
[[expose-service-home]]
### Proposed frontmatter
---
title: "Runbook: Onboard a Proxmox Node"
type: runbook
tags:
- proxmox
aliases: []
related:
- [[ct-runbook]]
- [[headscale-onboard-node]]
- [[proxmox-create-ubuntu-vm]]
- [[edge2-access-reference]]
- [[expose-service-home]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [57/61] Done vault/runbooks/proxmox-onboard-node.md
[sweep] [58/61] Processing vault/runbooks/recon-operations.md ...
[tag] Calling tagger on recon-operations.md ...
[tag] tags=['recon'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to recon-operations.md ...
[embed] Embedding recon-operations.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/recon-operations.md
========================================================================
VAULT TAGGER v4 — recon-operations.md
========================================================================
### Tags
['recon'] (confidence=0.85)
### Body wikilink diff
--- a/recon-operations.md
+++ b/recon-operations.md (linked)
@@ -5,7 +5,7 @@
- **Host:** recon-vm (VM 1130 on data node) — migrated from CT 130 on 2026-04-19
- **IP:** 192.168.1.130 / 100.64.0.24
-- **Install:** /opt/recon/
+- **Install:** /opt/[[recon]]/
- **User:** zvx
-- **Services:** `recon.service`, `recon-watchdog.service`, `kiwix.service` (systemd)
+- **[[services]]:** `recon.service`, `recon-watchdog.service`, `kiwix.service` (systemd)
## Service Management
### Related (bge-m3 top-5)
[[recon]]
[[deployment]]
[[caddy]]
[[recon-service-integration]]
[[services]]
### Proposed frontmatter
---
title: RECON Operations Runbook
type: runbook
tags:
- recon
aliases: []
related:
- [[recon]]
- [[deployment]]
- [[caddy]]
- [[recon-service-integration]]
- [[services]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [58/61] Done vault/runbooks/recon-operations.md
[sweep] [59/61] Processing vault/runbooks/recon-service-integration.md ...
[tag] Calling tagger on recon-service-integration.md ...
[tag] tags=['recon'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to recon-service-integration.md ...
[embed] Embedding recon-service-integration.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/recon-service-integration.md
========================================================================
VAULT TAGGER v4 — recon-service-integration.md
========================================================================
### Tags
['recon'] (confidence=0.85)
### Body wikilink diff
--- a/recon-service-integration.md
+++ b/recon-service-integration.md (linked)
@@ -9,5 +9,5 @@
## Prerequisites
-- A running Flask or FastAPI dashboard (e.g., RECON on VM 1130, WATCHTOWER on Contabo)
+- A running Flask or FastAPI dashboard (e.g., [[recon]] on VM 1130, WATCHTOWER on Contabo)
- The target service running on a reachable host (LXC, VM, or bare metal)
- SSH access from the dashboard host to the target host
@@ -211,5 +211,5 @@
## Step 4: Add Frontend Panel
-Add a service management panel to the dashboard UI. This goes in the appropriate tab (e.g., Upload, Dashboard, or a new Services tab).
+Add a service management panel to the dashboard UI. This goes in the appropriate tab (e.g., Upload, Dashboard, or a new [[services]] tab).
```html
### Related (bge-m3 top-5)
[[proxmox-onboard-node]]
[[recon-operations]]
[[headscale-onboard-node]]
[[lxc-service-migration]]
[[caddy]]
### Proposed frontmatter
---
title: RECON Dashboard Service Integration
type: runbook
tags:
- recon
aliases: []
related:
- [[proxmox-onboard-node]]
- [[recon-operations]]
- [[headscale-onboard-node]]
- [[lxc-service-migration]]
- [[caddy]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [59/61] Done vault/runbooks/recon-service-integration.md
[sweep] [60/61] Processing vault/runbooks/syncthing-add-node.md ...
[tag] Calling tagger on syncthing-add-node.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to syncthing-add-node.md ...
[embed] Embedding syncthing-add-node.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/runbooks/syncthing-add-node.md
========================================================================
VAULT TAGGER v4 — syncthing-add-node.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[ct-runbook]]
[[proxmox-onboard-node]]
[[meshtasticd-sim-nodes-runbook]]
[[idahomesh-vpn-device-setup]]
[[headscale-onboard-node]]
### Proposed frontmatter
---
title: "Syncthing: Add a New Node to the Project Sync Cluster"
type: runbook
tags:
- mesh
aliases: []
related:
- [[ct-runbook]]
- [[proxmox-onboard-node]]
- [[meshtasticd-sim-nodes-runbook]]
- [[idahomesh-vpn-device-setup]]
- [[headscale-onboard-node]]
updated: 2026-06-18
---
[APPLY] applied=True
[sweep] [60/61] Done vault/runbooks/syncthing-add-node.md
[sweep] [61/61] Processing vault/session-resume/SESSION-HANDOFF-meshai-test.md ...
[tag] Calling tagger on SESSION-HANDOFF-meshai-test.md ...
[tag] tags=['mesh'] confidence=0.85
[link] Building doc index ...
[link] Applying wikilinks to SESSION-HANDOFF-meshai-test.md ...
[embed] Embedding SESSION-HANDOFF-meshai-test.md ...
[embed] 5 related
[apply] Wrote /home/zvx/projects/.ref/vault/session-resume/SESSION-HANDOFF-meshai-test.md
========================================================================
VAULT TAGGER v4 — SESSION-HANDOFF-meshai-test.md
========================================================================
### Tags
['mesh'] (confidence=0.85)
### Body wikilink diff
(no new wikilinks)
### Related (bge-m3 top-5)
[[meshtastic-sidecar-node]]
[[meshtastic-headscale-runbook]]
[[services]]
[[synapse_retention_discovery]]
[[caddy]]
### Proposed frontmatter
---
title: Session Handoff — MeshAI radio-drop resilience test
type: session
tags:
- mesh
aliases: []
related:
- [[meshtastic-sidecar-node]]
- [[meshtastic-headscale-runbook]]
- [[services]]
- [[synapse_retention_discovery]]
- [[caddy]]
updated: 2026-06-18
status: open
created: 2026-06-17
origin: matt-desktop (WSL)
resume-on: cortex
---
[APPLY] applied=True
[sweep] [61/61] Done vault/session-resume/SESSION-HANDOFF-meshai-test.md
[sweep] Sweep complete at Thu Jun 18 16:54:24 UTC 2026