Files changed: engine/changelog.md engine/lint-report.md vault/.obsidian/workspace.json vault/projects/fleet-patch-audit.md vault/projects/fleet-platform-baseline.md
3.7 KiB
| title | type | tags | related | updated | status | |||
|---|---|---|---|---|---|---|---|---|
| Fleet Platform Baseline — post-patch 2026-06-22 | reference |
|
|
2026-06-22 | current |
Fleet Platform Baseline — post-patch 2026-06-22
Point-in-time platform state after the 2026-06-19/22 patch campaign. Full campaign record and accepted caveats in fleet-patch-audit.
Proxmox cluster (echo6-cluster)
5 nodes, quorum 3/5, no HA configured.
| Node | Platform |
|---|---|
| data, utility, cloud, media, toc | PVE 9.2.3 / kernel 7.0.12-1-pve (QEMU 11, LXC 7) |
All 5 nodes on pve-no-subscription (trixie). data, cloud, and media had the repo added during the campaign (utility and toc already had it). LXC containers share the host kernel (7.0); VM guests carry their own Ubuntu kernels.
Other hosts
pi-nas
OMV 8.4.0-3 / kernel 6.18.34+rpt-rpi-2712 (arm64, Raspberry Pi 4). rpi-eeprom held (SPI bootloader, intentionally untouched). RAID1 2.8 TB NFS backend serving /export/{arr,immich,nextcloud,peertube,data}. Retained artifact: /root/boot-backup-pre6.18-20260622.tar.gz (kernel rollback). Durable mailcow backup also on pi-nas (…/contabo-prewipe-2026-06/mailcow/, sha256-verified).
cortex (VM150 on toc, GPU)
Ubuntu 24.04. NVIDIA driver 580.167.08, nvidia-container-toolkit 1.19.1. AI stack: Ollama 0.30.10 (vault-tagger, GPU), TEI 1.9 / bge-m3 (embeddings, GPU), Qdrant 1.18.2, Open-WebUI 0.9.6. These power the .ref vault engine. See toc-cortex-pve9.2-update for the toc+cortex upgrade procedure.
recon-vm (VM1130 on data) Ubuntu 24.04 (security-patched). PostgreSQL 16, Valhalla, Nominatim 4.5 (v5 deferred — see nominatim-v5-reimport), Photon, Kiwix.
Key application versions (as of 2026-06-22)
| App | Host | Version | Notes |
|---|---|---|---|
| Authentik | edge2 CT105 | 2026.5.3 | Fleet SSO |
| Forgejo | edge2 CT103 | 15.0.3 | — |
| Headscale | edge2 CT107 | 0.29.1 | Fleet tailnet coordinator at vpn.echo6.co; boot-survival fixed (ports bound to 10.10.10.25, not tailscale IP) |
| Headscale (IdahoMesh) | utility CT106 | 0.29.1 | Separate IdahoMesh mesh at vpn.idahomesh.com |
| Nextcloud | cloud CT121 | 33.0.5 | AIO; data on pi-nas NFS |
| Immich | cloud CT120 | 2.7.5 | Photos on pi-nas NFS |
| PeerTube | media CT110 | 8.2.1 | — |
| OpenTAKServer | utility CT109 | 1.7.12 | RabbitMQ stays 3.12 by decision; MediaMTX 1.19.1; Mumble 1.5.517 |
| Matrix/Synapse | edge2 CT106 | 1.155.0 | — |
| Vaultwarden | edge2 CT102 | 1.36.0 | — |
| PDM | edge2 CT100 | 1.1.4 | — |
| CouchDB/LiveSync | edge2 CT104 | 3.5.2 | — |
| Jellyfin | media VM105 | 10.11.11 | — |
| Sonarr | media VM105 | 4.0.17 | — |
| Radarr | media VM105 | 6.2.1 | — |
| Prowlarr | media VM105 | 2.4.0 | — |
| SABnzbd | media VM105 | 5.0.4 | — |
| Navidrome | media VM105 | 0.62.0 | — |
| Lidarr | media VM105 | v2 | Image-capped — lidarr-on-steroids maintainer has not shipped v3 |
| Jellyseerr | media VM105 | preview-OIDC | Kept — stable 3.3.0 lacks OIDC/SSO support |
Accepted caveats (decisions, not TODOs)
- Guest OS security-only: LXC containers and VMs received security-pocket apt only (Phase 1 scope). Non-security package drift was not swept. A full
apt full-upgrade("Phase 1.5") is an option if ever wanted. - RabbitMQ 3.12 (EOL): left by decision — OTS does not support 4.x. AMQP/MQTT ports are localhost-bound; low exposure. Revisit if/when OTS officially supports RabbitMQ 4.x.
- Nominatim 4.5: v5 re-import is a separate project; see nominatim-v5-reimport.
- Optional cosmetic follow-ups: navidrome.echo6.co expired cert; MediaMTX deprecated config param names;
rpi-eepromheld; vestigial utility exit-node route (0.0.0.0/0).