echo6-docs/vault/docs/services/services.md
echo6-autocommit 4526e1843b auto: docs sync 2026-08-24T12:00:05+00:00
Files changed: engine/.embcache.json engine/changelog.md engine/lint-report.md vault/.obsidian/workspace.json vault/docs/services/services.md vault/docs/software/caddy.md vault/docs/software/dns.md vault/runbooks/expose-service-edge2.md vault/runbooks/expose-service-home.md
2026-08-24 12:00:05 +00:00

35 KiB
Raw Blame History

title type tags aliases related updated
Current Services Inventory reference
mesh
caddy
ip-allocation
meshtastic-headscale-runbook
lxc-service-migration
central
2026-08-24

Current Services Inventory

dns split (2026-06-19): mail/autodiscover/autoconfig.echo6.coedge1 (5.189.158.149, mail-only rebuilt Contabo VPS). vault/forge/notes/auth/matrix/element/vpn/proxmox.echo6.coedge2 (184.174.35.153, permanent front door for all other services). Tailnet split-DNS is NOT used for echo6.co; echo6.co resolves via public GoDaddy DNS.

Active Services

Service Location IP:Port Access Notes
MeshMonitor utility (CT 100) 192.168.1.100:8080 / :4404 https://mesh.echo6.co Meshtastic mesh monitoring (upstream ghcr.io/yeraze/meshmonitor:latest, multi-channel AutoAnnounce/AutoResponder)
Utility caddy utility (CT 101) 192.168.1.101 / 100.64.0.8 199.6.36.163 (ports 80/443) Reverse proxy for home services
Echo6 Search (searxng) utility (CT 102) 192.168.1.102:8080 https://echo6.co Branded search homepage (Docker, custom theme)
meshtasticd (AIDA-N2) aida-nebra 192.168.1.253:4403 Internal AIDA-N2(RPT,LLM) node !27780c47, Nebra 2W hat (ZebraHat), CLIENT_BASE role, fw 2.7.19. meshai (CT 108) connects via TCP localhost:4403
Meshtastic CLI mt-isr 192.168.1.141 Internal Station G2 WiFi bridge + TCP management
meshtasticd mt-burleybutte 192.168.1.185:4403 Internal Software Meshtastic node (Nebra 2W hat)
IdahoMesh Headscale utility (CT 106) 192.168.1.106:8080 https://vpn.idahomesh.com Meshtastic mesh VPN coordination
mesh-bridge utility (CT 107) 192.168.1.107 Internal Dual-tailscaled bridge (echo6 ↔ idahomesh)
meshai utility (CT 108) 192.168.1.144:4403 / :8080 Internal LLM-powered Meshtastic assistant (Docker, work-meshai local build, gemini-3.1-flash-lite, Google grounding)
argus utility (CT 103) 192.168.1.103:8080 Internal Python app on :8080 — OSINT intelligence gathering platform
central utility (CT 104) 192.168.1.104:8000 / 100.64.0.12 central.echo6.mesh (mesh) Data-hub spine — ~25 adapters → NATS/JetStream → TimescaleDB; serves traffic tiles to navi — see central
NATS/JetStream (central) utility (CT 104) 192.168.1.104:4222 / :8222 Internal central backend message bus (NATS :4222 client, :8222 monitoring)
TimescaleDB/PostGIS (central) utility (CT 104) 192.168.1.104:5432 Internal central backend time-series + geospatial database (PostgreSQL 16 + TimescaleDB + PostGIS)
authentik edge2 (CT 105) 100.64.0.36:9000 https://auth.echo6.co SSO provider (Echo6 branded, custom CSS, dark theme) — fronted by edge2 host caddy (reverse_proxy 100.64.0.36:9000); migrated from Contabo 2026-06-18
Forge (Forgejo) edge2 (CT 103) 100.64.0.34:3001 HTTP / :2222 SSH (via edge2 DNAT) https://forge.echo6.co Git server — fronted by edge2 host caddy (reverse_proxy 100.64.0.34:3001); git SSH via iptables DNAT on edge2 (forgejo-ssh-dnat.service) — migrated from Contabo 2026-06-16
Headscale edge2 (CT 107) 100.64.0.38:8084 https://vpn.echo6.co Tailscale coordination (OIDC enabled) — fronted by edge2 host caddymigrated from Contabo 2026-06-19
Headplane edge2 (CT 107) 100.64.0.38:3100 https://vpn.echo6.co/admin Headscale web UI (OIDC via authentik) — fronted by edge2 host caddymigrated from Contabo 2026-06-19
Mailcow edge1 CT 101 (10.10.10.2) 5.189.158.149 https://mail.echo6.co Email server (privileged LXC on rebuilt Contabo VPS, updated commit 52a41b4d / SOGo 5.12.8) — rebuilt in-place 2026-06-19
meshwars Preview utility (CT 113) 192.168.1.113 / 100.64.0.39:8090 https://mwpreview.k7zvx.com Public preview of the unreleased feat/places MeshWars branch, running a periodically-refreshed read-only copy of production (CT 119) data; /admin and /api/admin/* return 404 on the public host, admin reachable only over the tailnet
Vaultwarden edge2 (CT 102) 100.64.0.33:8086 https://vault.echo6.co Password manager 1.37.1 (SSO enabled) — fronted by edge2 host caddy (reverse_proxy 100.64.0.33:8086)
Grav edge2 (CT 101) 10.10.10.11:80 https://idahomesh.com (+www) Flat-file CMS 2.0.11, no database — Admin2 plugin at /admin; Apache 2.4.67 + mod_php + PHP 8.4.21; migrated from WordPress 2026-07-17 (MariaDB purged from the container); hostname still wordpress (unchanged) — fronted by edge2 host Caddy via internal bridge IP (reverse_proxy 10.10.10.11:80), unlike other edge2 services which proxy over tailnet
Syncthing cortex 100.64.0.14:22000 Internal (Tailscale) File sync — ~/.claude/, ~/projects/ (Syncthing on Contabo decommissioned 2026-06-19 with edge1 rebuild)
Proxmox VE data node 192.168.1.240:8006 https://proxmox.echo6.co Cluster web UI (via Caddy+Tailscale)
Immich cloud (CT 120) 192.168.1.182:2283 https://immich.echo6.co Photo management (Docker, NFS storage on pi-nas)
Nextcloud cloud (CT 121) 192.168.1.183:11000 https://nextcloud.echo6.co Cloud storage (AIO Docker, NFS on pi-nas, SSO)
Jellyfin media (VM 105) 192.168.1.160:8096 https://jellyfin.echo6.co Media server (Docker, NFS on pi-nas, SSO)
Jellyseer media (VM 105) 192.168.1.160:5055 https://requests.echo6.co Media request management (Docker, SSO)
Sonarr media (VM 105) 192.168.1.160:8989 Internal TV automation (Docker)
Radarr media (VM 105) 192.168.1.160:7878 Internal Movie automation (Docker)
Prowlarr media (VM 105) 192.168.1.160:9696 Internal Indexer manager (Docker)
SABnzbd media (VM 105) 192.168.1.160:8080 Internal usenet download client (Docker)
PeerTube media (CT 110) 192.168.1.170:9000 https://stream.echo6.co Video streaming (native, NFS on pi-nas, SSO). CT raised to 8GB + redis capped 2026-08-13 — see peertube-sitemap-redis-oom
Open WebUI cortex (VM 150) 192.168.1.150:8080 https://ai.echo6.co AI chat interface (Docker, Ollama backend, SSO)
Qdrant cortex (VM 150) 192.168.1.150:6333 Internal Vector database (Docker, recon knowledge store)
TEI cortex (VM 150) 192.168.1.150:8090 Internal Text embeddings (Docker, bge-m3 1024-dim)
recon data (VM 1130) 192.168.1.130:8420 https://recon.echo6.co Knowledge extraction pipeline (systemd, dashboard+API)
navi-config data (VM 1130) 192.168.1.130:8422 Internal recon navi node config API
navi-contacts data (VM 1130) 192.168.1.130:8423 Internal recon navi contact enrichment API
navi-landclass data (VM 1130) 192.168.1.130:8424 Internal recon navi land classification API
navi-places data (VM 1130) 192.168.1.130:8425 Internal recon navi OSM place detail/enrichment
navi-geo data (VM 1130) 192.168.1.130:8426 Internal RECON navi geocode/reverse geocode API
navi-admin data (VM 1130) 192.168.1.130:8427 Internal RECON navi fleet admin-info aggregator
navi-offroute data (VM 1130) 192.168.1.130:8428 Internal RECON navi off-network router + MVUM API
navi (navi.echo6.co) data (VM 1130) 192.168.1.130:8440 https://navi.echo6.co Offline navigation platform — see navi
dem-origin data (VM 1130) 127.0.0.1:8441 Internal Local DEM tile origin for navi (658GB planet-dem.pmtiles)
Valhalla data (VM 1130) 192.168.1.130:8002 Internal navi geo backend (routing) — see navi
Nominatim data (VM 1130) 192.168.1.130:8010 Internal navi geo backend (geocoder) — see navi
Photon data (VM 1130) 192.168.1.130:2322 Internal navi geo backend (geocoder + Elasticsearch :9201) — see navi
PostgreSQL/PostGIS data (VM 1130) 192.168.1.130:5432 Internal navi geo backend (padus, overture DBs) — see navi
Files data (VM 1130) 192.168.1.130:8888 https://files.echo6.co PDF library (nginx, authentik forward auth)
Samba data 192.168.1.240:445 Internal SMB file sharing — //data/library → /mnt/data/library (guest access)
Matrix synapse edge2 (CT 106) 100.64.0.37:8008 https://matrix.echo6.co Matrix homeserver (Docker, SSO) — migrated from Contabo 2026-06-18
Element Web edge2 (CT 106) 100.64.0.37:8088 https://element.echo6.co Matrix web client (Docker) — migrated from Contabo 2026-06-18
mautrix_signal edge2 (CT 106) internal (29328) DM @signalbot:echo6.co Signal bridge (Docker, E2BE, MSC4190, double puppeting) — migrated from Contabo 2026-06-18
LiveSync edge2 (CT 104) 100.64.0.35:5984 (CouchDB) / :5985 (provisioner) https://notes.echo6.co Obsidian sync (CouchDB + provisioner, Docker, JWT auth) — fronted by edge2 host Caddy; migrated from Contabo 2026-06-16
OpenTAKServer (OTS) utility (CT 109) 192.168.1.109:443 https://ots.k7zvx.com Live TAK server (native install, nginx+RabbitMQ+PostgreSQL, Meshtastic MQTT gateway on port 8883) — see ots-setup
Echo6 Cortex Agent cortex (VM 150) N/A (Matrix bot) #cortex:echo6.co in echo6-ops space Claude Code bridge — @cortex:echo6.co, session continuity, E2EE (systemd)
Matrix MAS edge2 (CT 106) 100.64.0.37:8085 Internal (via edge2 Caddy) Matrix Authentication Service (Docker, handles login/logout/OIDC for synapse) — migrated from Contabo 2026-06-18
archivist utility (CT 118) 192.168.1.118 Internal Signal/Matrix room archive bot (systemd) — see archivist.md for details
pt-transcoder cortex (VM 150) N/A Internal PeerTube H.265 NVENC transcoder (systemd, /opt/bulk-import/transcoder.py)
recon-sparse cortex (VM 150) 192.168.1.150:8091 Internal RECON sparse embedding service (systemd, bge-m3 model, port 8091)
obsidian-remote cortex (VM 150) 100.64.0.14:8082 → :3001 Internal (Tailscale) Headless web Obsidian (lscr.io/linuxserver/obsidian:latest, Docker)
mcc media (CT 111) 192.168.1.111:80 Internal Caddy + Postfix, OpenHop (pymc) console web app; serves static frontend, reverse-proxies /api,/auth,/ws → 192.168.1.253:8000 (aida-nebra). Port 80 only — no 443 listener
Samba cortex (VM 150) 192.168.1.150:445 Internal SMB file sharing — //cortex/projects → /home/zvx/projects (guest access)
Home Assistant ha (cloud VM 151) 192.168.1.151:8123 / 100.64.0.16 Internal Home automation platform (Docker, Ubuntu 24.04)

Services by Server

toc - Proxmox Host (192.168.1.244 / Tailscale: 100.64.0.13)

  • Proxmox VE node (echo6-cluster)
  • GPU passthrough host for cortex VM
  • No direct services — workloads run on cortex VM

cortex - VM 150 on toc (192.168.1.150 / Tailscale: 100.64.0.14)

  • GPU compute VM (RTX A4000)
  • Claude Code host
  • Syncthing (syncs with Contabo)
  • Open WebUI (port 8080, https://ai.echo6.co, Docker, SSO via authentik, Echo6 theme)
    • Compose path: /opt/open-webui/docker-compose.yml
    • Echo6 theme: togglable via "E6" button (bottom-right), persisted in localStorage
    • Theme files bind-mounted from /home/zvx/echo6-theme/ into container
    • DEFAULT_USER_ROLE=user (new signups auto-activated, not pending)
  • Ollama (port 11434, internal, Docker with GPU)
  • Qdrant (port 6333, internal, Docker — vector DB for RECON)
  • TEI (port 8090, internal, Docker — bge-m3 embeddings for RECON)
  • peertube-remote-runner (peertube-runner service, Whisper auto-captioning via smart GPU/CPU wrapper, concurrency=2, MemoryMax=20G)
  • pt-transcoder (systemd: pt-transcoder.service, PeerTube H.265 NVENC transcoder)
    • Script: /opt/bulk-import/transcoder.py
    • MemoryMax=12G, Restart=always, RestartSec=60
    • Depends on: nvidia-persistenced.service
  • recon-sparse (systemd: recon-sparse.service, RECON sparse embedding service)
    • Script: /opt/recon-sparse/sparse_embed_service.py --port 8091
    • Model: BAAI/bge-m3 (HuggingFace cache)
    • Restart=on-failure, RestartSec=10
  • Samba (smbd/nmbd, system packages)
    • Share: //cortex/projects/home/zvx/projects (browseable, read-write, guest OK, force user/group zvx)
    • Workgroup: WORKGROUP, standalone server
  • Echo6 Cortex Agent (systemd: echo6-agent.service, matrix-nio bot, @cortex:echo6.co)
    • Install path: /opt/echo6-agent/
    • Matrix space: echo6-ops, room: #cortex:echo6.co (E2EE, private)
    • Session continuity via claude -p --resume, persistent per-room sessions
    • !new resets conversation session
    • Allowed users: @matt:echo6.co
    • MAS user ID: 01KKX88ARGK0BTA1JMB2QVAW4C

utility - CT 100 (192.168.1.100 / Tailscale: 100.64.0.7)

  • MeshMonitor (port 8080 + 4404, https://mesh.echo6.co)
  • Image: ghcr.io/yeraze/meshmonitor:latest (upstream image, not local fork build)
  • Multi-channel AutoAnnounce and AutoResponder support

utility - CT 101 (192.168.1.101 / Tailscale: 100.64.0.8)

  • Utility Caddy (reverse proxy for VPN-only services)

utility - CT 102 (192.168.1.102 / Tailscale: 100.64.0.15)

  • Echo6 Search — branded searxng homepage (port 8080, https://echo6.co)
  • Custom cyberpunk theme: JetBrains Mono font, cyan/yellow palette, dark backgrounds
  • Homepage: centered Echo6 logo + pill search bar (Google-style, viewport-locked no-scroll)
  • Results page: full-width two-column grid (results + sidebar), stretched search header
  • Top nav bar: .//photos, .//mail, waffle app launcher (11 services), login avatar
  • All nav links use authentik launch URLs for seamless SSO pass-through
  • search.echo6.co permanently redirects to echo6.co (301)
  • Redis/Valkey cache (valkey container)
  • Compose path: /opt/searxng/docker-compose.yml
  • Theme files: /opt/searxng/custom/ (bind-mounted into container)
    • templates/simple/base.html — custom template (nav, CSS, waffle menu, footer)
    • templates/simple/index.html — custom homepage (Echo6 logo replaces searxng title)
    • img/echo6-logo.png — Echo6 logo (replaces searxng logo)
    • img/favicon.png — Echo6 favicon
  • Config: /opt/searxng/searxng-config/settings.yml (instance_name: "Echo6", dark theme, center_alignment: false)
  • searxng version: 2026.2.6 (Docker image: searxng/searxng:latest)

utility - CT 104 (192.168.1.104 / Tailscale: 100.64.0.12)

  • central data-hub spine (3 systemd units: central-supervisor, central-archive, central-gui)
  • API/GUI on port 8000 (0.0.0.0), NATS :4222/:8222, PostgreSQL/TimescaleDB :5432
  • ~25 domain adapters (traffic, wildfire, weather, hydro, earthquakes, avalanche, disasters, satellite)
  • Serves navi traffic tiles at auth-exempt /api/traffic/flow/{z}/{x}/{y}.png|pbf
  • Tailscale hostname: central.echo6.mesh

utility - CT 108 (192.168.1.144 / Tailscale: 100.64.0.32)

  • meshai — LLM-powered Meshtastic mesh assistant (Docker)
  • Bot name: AIDA, node ID !27780c47, channel 8 whitelist
  • Image: work-meshai (local build, not ghcr.io/zvx-echo6/meshai:latest)
  • Backend: gemini-3.1-flash-lite with Google Search grounding
  • Connects to meshtasticd on aida-nebra (192.168.1.253:4403) — the AIDA-N2 node !27780c47
  • Exposes port 8080 (web UI)
  • Config TUI on port 7682 (meshai --config)
  • Commands: !help, !ping, !status, !weather, !reset, !clear
  • 7-day rolling conversation memory (SQLite), full history sent to LLM
  • Response: 175 char chunks × 3 messages max
  • Compose path: /home/zvx/meshai/docker-compose.yml

utility - CT 113 (192.168.1.113 / Tailscale: 100.64.0.39)

  • MeshWars Preview — public preview instance of the feat/places branch (Docker, compose path /home/zvx/meshwars/docker-compose.yml)
  • Fronted by utility caddy at https://mwpreview.k7zvx.com (Tailscale IP, /admin + /api/admin/* blocked with 404 on the public host)
  • /admin still reachable directly over the tailnet at 100.64.0.39:8090/admin
  • Database is a SQLite online-backup clone of CT 119's game.db, taken read-only; the place seed table is not present in production's schema yet and is auto-reloaded by the app on each restart after a clone
  • ADMIN_TOKEN is unique to this container, generated fresh — never copied from production
  • Join and check-in registration disabled by default

utility - CT 118 (192.168.1.118)

  • Signal/Matrix room archive bot (archivist.service via systemd)
  • 1 core, 1GB RAM, 8GB disk
  • Not registered in Headscale (no Tailscale)
  • Source: forge.echo6.co/matt/matrix-archivist (private)
  • See /home/zvx/projects/.ref/docs/matrix/archivist.md for implementation details

cloud - VM 151 "ha" (192.168.1.151 / Tailscale: 100.64.0.16)

  • Home Assistant (Docker, port 8123)
  • OS: Ubuntu 24.04
  • Headscale node id 54, user echo6
  • Home automation platform

cloud - CT 120 (192.168.1.182 / Tailscale: 100.64.0.2)

  • Immich photo management (https://immich.echo6.co)
  • Port 2283
  • NFS storage from pi-nas (/mnt/immich)
  • Compose path: /opt/immich/docker-compose.yml

cloud - CT 121 (192.168.1.183 / Tailscale: 100.64.0.11)

media - VM 105 (192.168.1.160 / Tailscale: 100.64.0.18)

  • ARR media automation stack (Docker)
  • Jellyfin media server (port 8096, https://jellyfin.echo6.co)
  • Jellyseer request management (port 5055, https://requests.echo6.co)
  • Sonarr TV automation (port 8989, internal)
  • Radarr movie automation (port 7878, internal)
  • Prowlarr indexer manager (port 9696, internal)
  • SABnzbd usenet downloader (port 8080, internal)
  • NFS storage from pi-nas (/mnt/arr)
  • Config dirs: /opt/arr/{jellyfin,jellyseer,sonarr,radarr,prowlarr,sabnzbd}

media - CT 110 (192.168.1.170 / Tailscale: 100.64.0.23)

  • PeerTube video streaming (https://stream.echo6.co)
  • Native install (Node.js 22, PostgreSQL 16, Redis, nginx)
  • Port 9000 (PeerTube), proxied via nginx on port 80
  • NFS storage from pi-nas (/var/www/peertube/storage, /export/peertube)
  • SSO via Authentik OIDC (peertube-plugin-auth-openid-connect)
  • Privileged container (NFS bind-mount)
  • Auto-transcription enabled (remote runners on cortex, Whisper medium model)
  • PeerTube Bulk Import Pipeline:
    • pt-downloader.service — YouTube channel downloader (yt-dlp, sliding window, cookie auth)
    • pt-importer.service — Uploads downloaded videos to PeerTube via resumable upload API
    • NordVPN (nordvpnd.service) — IP rotation for downloads
    • Config: /opt/bulk-import/config/ (channel-map.json, cookies.txt, downloader-state.json)
    • Logs: /opt/bulk-import/logs/
    • Pipeline dirs: /var/www/peertube/storage/pipeline/{staging,completed,transcoded,failed}

data - Proxmox Host (192.168.1.240 / Tailscale: 100.64.0.6)

  • Proxmox VE node (echo6-cluster)
  • Samba (smbd/nmbd, system packages)
    • Share: //data/library/mnt/data/library (browseable, read-write, guest OK, force user/group root)
    • Workgroup: WORKGROUP, standalone server

data - VM 1130 "recon-vm" (192.168.1.130 / Tailscale: 100.64.0.24)

  • Migrated from CT 130 (LXC) on 2026-04-19
  • OS: Ubuntu 24.04.4 LTS, kernel 6.8.0-110-generic
  • Resources: 4 cores, 24GB RAM, 180GB disk
  • Software: Docker 29.4.0, Python 3.12.3 (venv), Tailscale, nginx, sqlite3
  • RECON knowledge extraction pipeline
  • systemd services: recon.service, recon-watchdog.service, kiwix.service
  • Dashboard + API on port 8420 (https://recon.echo6.co)
  • navi-config on port 8422 (node config API)
  • navi-contacts on port 8423 (contact enrichment API)
  • navi-landclass on port 8424 (land classification API)
  • navi-places on port 8425 (OSM place detail/enrichment)
  • navi-geo on port 8426 (geocode/reverse geocode API)
  • navi-admin on port 8427 (fleet admin-info aggregator)
  • navi-offroute on port 8428 (off-network router + MVUM API)
  • nginx file server on port 8888 (https://files.echo6.co, Authentik forward auth)
  • Kiwix-serve on port 8430 (ZIM library, 10 sources)
  • navi (navi.echo6.co) on port :8440 — offline navigation platform front door (nginx SPA + API gateway); see navi
  • dem-origin on port :8441 (localhost only) — DEM tile origin serving 658GB planet-dem.pmtiles
  • Geo backends (Docker + system): Valhalla :8002 (routing), Nominatim :8010 (geocoder), Photon :2322 (geocoder + Elasticsearch :9201), PostgreSQL/PostGIS :5432 (padus, overture DBs)
  • Install: /opt/recon/ (Python 3, Flask, venv)
  • NFS mounts: pi-nas:/export/library → /mnt/library (PDF source), /mnt/nav, /mnt/kiwix
  • Pipeline: Extract (PyPDF2→pdftotext→Tesseract→Gemini Vision) → Enrich (Gemini) → Embed (TEI/Qdrant)
  • DB: SQLite (status), Qdrant on cortex:6333 (vectors)
  • Backups: rsync to Contabo every 6hrs (concepts, text, DB, config), DB snapshot every 2hrs
  • Config: /opt/recon/config.yaml, keys in /opt/recon/.env
  • Docs: /opt/recon/PROJECT-BIBLE.md
  • User: zvx (sudo, SSH key auth)

utility - CT 106 (192.168.1.106)

  • IdahoMesh Headscale (https://vpn.idahomesh.com)
  • Container name: meshtastic-hs
  • Manages meshtastic mesh VPN (separate from echo6 Headscale on Contabo)
  • Users: malice, sidpatchy, nebra

utility - CT 107 (192.168.1.107)

  • mesh-bridge — dual tailscaled instance
  • Bridges echo6 (100.64.0.0/10) ↔ idahomesh (100.100.0.0/16) networks
  • NAT masquerade + subnet route advertisement
  • Echo6 clients need --accept-routes to reach idahomesh devices
  • iptables FORWARD rules must be BEFORE ts-forward jump (Tailscale drops cross-tailnet packets otherwise)
  • Echo6 socket: /run/tailscale/tailscaled.sock (port 41641)
  • IdahoMesh socket: /var/run/tailscale-meshtastic/tailscaled.sock (port 41642, tun=tailscale1)
  • Rules persisted: /etc/iptables/rules.v4 via iptables-restore.service

pi-nas (192.168.1.245 / Tailscale: 100.64.0.21)

  • OpenMediaVault NAS (https://nas.echo6.co)
  • Port 80 (HTTP)
  • Internet Archive CLI (ia v5.7.2) installed for archive.org uploads

aida-nebra (192.168.1.253 / Tailscale: 100.64.0.9)

  • AIDA-N2(RPT,LLM) — meshtasticd node !27780c47 (short name: AIDA)
  • Hardware: Nebra 2W SX1262 hat (ZebraHat config in /etc/meshtasticd/config.d/)
  • Port: 4403 (default), firmware 2.7.19 (PORTDUINO/native)
  • Role: CLIENT_BASE, position: 42.574, -114.607 (manual)
  • MAC source: eth0 (derived MAC 00:bd:27:78:0c:47)
  • meshai bot (CT 108) connects to this node via TCP localhost:4403 (Docker network)
  • Service: meshtasticd.service (single instance, runs as user meshtastic)
  • Config: /etc/meshtasticd/config.yaml + /etc/meshtasticd/config.d/ZebraHat_2W.yaml
  • User: zvx, password auth (sshpass -p '7redditGold' ssh zvx@aida-nebra)

mt-isr (192.168.1.141 / IdahoMesh: 100.100.0.5)

  • Raspberry Pi Zero 2 W, Debian 13 (trixie), Waveshare ETH/USB HUB HAT
  • No meshtasticd (G2 managed via WiFi TCP, not local daemon)
  • Meshtastic Python CLI v2.7.7 in venv (/home/isr/meshtastic-cli/)
  • Tailscale on IdahoMesh tailnet (vpn.idahomesh.com, nebra user)
  • WiFi hotspot: ISR-MESH (192.168.4.0/24, PMF disabled for ESP32 compatibility)
  • Station G2 radio connected via WiFi at 192.168.4.241, managed via TCP
  • G2 config: Freq51 (ch0, psk=1A==) + MediumFast (ch1), MEDIUM_FAST preset, ch=51, txPower=11
  • G2 gold config backup: isr@192.168.1.141:~/backups/g2-gold-config.yaml
  • dns bootstrap drop-in for tailscaled (reboot-safe)
  • User: isr, password auth (see credentials)

mt-burleybutte (192.168.1.185)

  • meshtasticd (software Meshtastic node, Nebra 2W hat)
  • Raspberry Pi OS, user bb
  • Static MAC: A7:A1:30:79:BB:BB
  • Tailscale registered on IdahoMesh Headscale (vpn.idahomesh.com) under malice user

edge2 - CT 103 (10.10.10.21 / Tailscale: 100.64.0.34, node 46 forgejo)

  • Forgejo git server (https://forge.echo6.comigrated from Contabo 2026-06-16)
    • Headscale node id 46, name forgejo, user echo6
    • Compose path: /opt/forgejo/docker-compose.yml
    • Containers: forgejo (codeberg.org/forgejo/forgejo:14) + forgejo-db (postgres:16-alpine)
    • Volumes: forgejo-data (git repos, app.ini, SSH host keys) + forgejo-db
    • HTTP: binds to 100.64.0.34:3001; edge2 host Caddy proxies here over tailnet (reverse_proxy 100.64.0.34:3001)
    • SSH: git@forge.echo6.co:2222 → edge2 iptables DNAT (systemd unit forgejo-ssh-dnat.service, enabled, reboot-persistent) → 100.64.0.34:2222 → container port 22; SSH host keys preserved (no client warning)
    • Login via Authentik OIDC (auth.echo6.co) — unchanged
    • DB: PostgreSQL 16 (forgejo_db container); 9 repos, 1 user verified at migration
    • Source (Contabo /opt/forgejo) was wiped with edge1 OS rebuild 2026-06-19

edge2 - CT 104 (10.10.10.22 / Tailscale: 100.64.0.35, node livesync)

  • LiveSync Obsidian sync service (https://notes.echo6.comigrated from Contabo 2026-06-16)
    • Headscale hostname livesync, tailnet IP 100.64.0.35
    • Compose path: /opt/livesync/docker-compose.yml
    • Containers: livesync-couchdb (couchdb:3.4) + livesync-provisioner (custom image)
    • Named volumes: couchdb-data, provisioner-data
    • Bind mounts: couchdb/local.ini, couchdb/local.d/ (incl. jwt-keys.ini)
    • CouchDB binds to 100.64.0.35:5984; provisioner binds to 100.64.0.35:5985
    • edge2 host Caddy proxies notes.echo6.coreverse_proxy 100.64.0.35:5984 (CouchDB) + reverse_proxy 100.64.0.35:5985 (provisioner); Authentik forward_auth on /_provision; Obsidian CORS preserved
    • Auth: per-user JWT (ES512) via provisioner; databases: cc-db, userdb-matt
    • Data: ~16 MB in couchdb-data
    • Source on Contabo wiped with edge1 rebuild 2026-06-19
    • Resources: 2 cores / 1024 MB RAM / 512 MB swap / 8 GB rootfs on local; unprivileged; onboot; Docker

edge2 - CT 105 (10.10.10.23 / Tailscale: 100.64.0.36, node 48 authentik)

  • Authentik SSO platform (https://auth.echo6.comigrated from Contabo 2026-06-18)
    • Headscale node id 48, hostname authentik, tailnet IP 100.64.0.36
    • Compose path: /opt/authentik/docker-compose.yml
    • Containers: authentik-server + authentik-worker (ghcr.io/goauthentik/server:2025.12.4) + authentik-postgres (postgres:16); NO Redis
    • Worker runs as user:root and has docker.sock bind-mount (manages embedded outposts)
    • Binds to 100.64.0.36:9000; edge2 host Caddy proxies here over tailnet for both auth.echo6.co (catch-all + outpost path matcher) and notes.echo6.co outpost/forward_auth references
    • AUTHENTIK_SECRET_KEY carried byte-for-byte (sessions stayed valid across cutover — users dropped straight in)
    • Bind-mounts (data/media, branding, certs, custom-templates) migrated intact
    • Email dep: mail.echo6.co (unchanged)
    • DB: PostgreSQL 16 (authentik-postgres container); ~705 MB (~18 MB pg_dump)
    • Source on Contabo wiped with edge1 rebuild 2026-06-19
    • Reboot-survival fix: systemd unit on CT 105 gates docker compose up on tailscale-online (Docker was racing Tailscale on boot, failing the bind to the tailnet IP)
    • Resources: 2 cores / 4096 MB RAM / 512 MB swap / 20 GB rootfs on local; unprivileged; onboot; Docker

edge2 - CT 106 (10.10.10.24 / Tailscale: 100.64.0.37, node matrix)

  • Matrix stack (https://matrix.echo6.co, https://element.echo6.comigrated from Contabo 2026-06-18)
    • Headscale hostname matrix, tailnet IP 100.64.0.37
    • Compose path: /opt/matrix/matrix-stack.service (systemd service with tailscale-before-docker reboot guard)
    • Containers: synapse (:8008), matrix-mas (:8085), element (:8088), matrix-postgres, mautrix-signal (29328 internal) — 5 containers total
    • Databases: PostgreSQL DBs synapse, mas, mautrix_signal on matrix-postgres container — 3 DBs total
    • Binds to 100.64.0.37; edge2 host Caddy proxies:
      • matrix.echo6.cosynapse (100.64.0.37:8008) + MAS sub-routes
      • element.echo6.co → Element (100.64.0.37:8088)
      • MAS (100.64.0.37:8085) handles login/logout/refresh/auth_metadata
    • Federation delegation from apex echo6.co (.well-known) unchanged
    • MAS→Authentik OIDC (auth.echo6.co) unchanged
    • Signal bridge: @signalbot:echo6.co, E2BE + MSC4190, double puppeting; bridge state preserved in mautrix_signal DB
    • Source on Contabo wiped with edge1 rebuild 2026-06-19
    • Resources: 2 cores / 4096 MB RAM / 1024 MB swap / 20 GB rootfs on local; unprivileged; onboot; Docker

edge2 - CT 107 (10.10.10.25 / Tailscale: 100.64.0.38, node headscale)

  • Headscale + Headplane (https://vpn.echo6.comigrated from Contabo 2026-06-19)
    • Headscale hostname headscale, tailnet IP 100.64.0.38
    • Compose path: /opt/headscale/ (managed via headscale-stack.service systemd reboot guard)
    • Headscale 0.28.0 on :8084; Headplane on :3100
    • edge2 host Caddy proxies vpn.echo6.co100.64.0.38:8084 (headscale) / vpn.echo6.co/admin100.64.0.38:3100 (headplane)
    • noise_private.key carried byte-for-byte (server identity preserved); 39 nodes
    • Public direct bind 5.189.158.149:8084 DROPPED — all clients use vpn.echo6.co via Caddy
    • Source on Contabo wiped with edge1 rebuild 2026-06-19
    • Resources: 1 core / 512 MB RAM / 256 MB swap / 4 GB rootfs on local; unprivileged; onboot

edge2 - CT 102 (10.10.10.20 / Tailscale: 100.64.0.33, node 45 vaultwarden)

  • Vaultwarden password manager (port 8086, https://vault.echo6.co, Docker)
    • Version: 1.37.1 (web vault 2026.6.4) — updated from 1.36.0 on 2026-08-04 (9 medium security advisories in 1.37.0; required for Bitwarden clients 2026.7.0+)
    • Headscale node id 45, name vaultwarden, user echo6
    • Compose path: /opt/vaultwarden/docker-compose.yml; data: ./data/
    • Binds to tailnet IP 100.64.0.33:8086:80; edge2 host Caddy proxies here over tailnet
    • SSO via Authentik (SSO_ONLY=false — local email+master-password login also works)
    • Source on Contabo wiped with edge1 rebuild 2026-06-19
    • Migrated from Contabo to edge2 CT 102 on 2026-06-16

edge1 (5.189.158.149 / Tailscale: 100.64.0.40) — MAIL-ONLY host (rebuilt Contabo VPS, 2026-06-19)

Rebuilt in-place 2026-06-19. Former Contabo VPS (tailnet node previously contabo / 100.64.0.1) was OS-reinstalled as Debian 12 + Proxmox 8.4.19. Renamed edge1. All evacuated services now live on edge2. Tailnet identity re-registered as contabo at 100.64.0.40.

  • Role: MAIL ONLY. All non-mail services (vault/forge/notes/auth/matrix/element/vpn/proxmox) are fronted by edge2 (184.174.35.153).
  • Host Caddy serves mail.echo6.co, autodiscover.echo6.co, autoconfig.echo6.co → Mailcow CT 101 at 10.10.10.2:8453; includes header_up Host {host} to prevent nginx leaking internal address in redirects.
  • mailcow-dnat.service — source-IP-preserving DNAT for raw mail ports 25/465/587/110/143/993/995/4190 → 10.10.10.2 (systemd oneshot, reboot-persistent).
  • staticroute.service — systemd oneshot for 10.10.10.0/24 route (reboot-persistent).
  • Netfilter modules (nf_conntrack, nf_nat, etc.) persisted via /etc/modules-load.d/.
  • Tailscale on host (node contabo, 100.64.0.40).
  • unattended-upgrades enabled.
  • SSH: ssh -i ~/.ssh/contabo2_ed25519 root@5.189.158.149

edge1 — CT 101 (10.10.10.2) — Mailcow

  • Mailcow email server (privileged LXC, updated to commit 52a41b4d, SOGo 5.12.8)
  • Accessible at mail.echo6.co / 5.189.158.149 (via host Caddy + DNAT)
  • mail_crypt secondary key in data/conf/dovecot/extra.conf (ecprivkey.pem.fresh-20260619 as secondary; both primary + secondary loaded for decryption of old mail)
  • dns: mail/autodiscover/autoconfig.echo6.co → 5.189.158.149

Previously on Contabo (now evacuated or decommissioned)

  • Authentikmigrated to edge2 CT 105 on 2026-06-18 (edge2 Caddy now proxies auth.echo6.co → 100.64.0.36:9000)
  • Forge (Git)migrated to edge2 CT 103 on 2026-06-16 (edge2 Caddy proxies to 100.64.0.34:3001; SSH DNAT via forgejo-ssh-dnat.service on edge2)
  • Headscalemigrated to edge2 CT 107 on 2026-06-19 (edge2 Caddy proxies vpn.echo6.co → 100.64.0.38:8084; noise_private.key carried byte-for-byte; direct public bind 5.189.158.149:8084 DROPPED)
  • Vaultwardenmigrated to edge2 CT 102 on 2026-06-16 (edge2 Caddy proxies to 100.64.0.33:8086)
  • Syncthingdecommissioned 2026-06-19 with edge1 OS rebuild (Syncthing state removed; Forge is now the durable backup via autocommit cron)
  • WATCHTOWERdecommissioned 2026-06-16
  • Matrix synapsemigrated to edge2 CT 106 on 2026-06-18
  • Element Webmigrated to edge2 CT 106 on 2026-06-18
  • mautrix_signal bridgemigrated to edge2 CT 106 on 2026-06-18
  • LiveSyncmigrated to edge2 CT 104 on 2026-06-16
  • TAK Serverdecommissioned 2026-06-16 (archived to forge.echo6.co/matt/archive-tak-server)
  • SIGILdecommissioned 2026-06-16
  • echo6-agentdecommissioned 2026-06-16
  • nexus-hub + nexus-agentdecommissioned 2026-06-16
  • Termixwiped with edge1 rebuild 2026-06-19

Decommissioned Services

Services stopped, archived, and removed from Caddy/dns as of their decommission date. On-disk dirs on Contabo retained until edge1 rebuild wipes them.

Service Decommissioned Archive Repo Notes
TAK Server 2026-06-16 forge.echo6.co/matt/archive-tak-server Was Docker /opt/tak-server-deploy on Contabo; tak.echo6.co Caddy block + GoDaddy A record removed
SIGIL 2026-06-16 forge.echo6.co/matt/archive-tak-server Was Docker /opt/sigil on Contabo; served at tak.echo6.co/sigil
WATCHTOWER 2026-06-16 forge.echo6.co/matt/archive-watchtower Was Docker /opt/watchtower on Contabo; wt.echo6.co Caddy block + GoDaddy A record removed
echo6-agent 2026-06-16 forge.echo6.co/matt/archive-echo6-agent Was systemd unit at /opt/echo6-agent/ on Contabo; unit disabled
nexus-hub 2026-06-16 forge.echo6.co/matt/archive-nexus-hub Was systemd unit at /root/nexus-hub on Contabo; unit disabled
nexus-agent 2026-06-16 forge.echo6.co/matt/archive-nexus-agent Was systemd unit at /root/nexus-agent on Contabo; unit disabled

Adding New Services

When deploying a new service, update this file with:

  1. Service name
  2. Host location (server + container if applicable)
  3. IP:Port
  4. Access method (internal only vs public URL)
  5. Brief description

Naming Conventions

  • Internal services: Access via Tailscale IP (100.64.x.x) or local IP
  • Public services: Access via *.echo6.co subdomain through Caddy reverse proxy

Lidarr on Steroids (lidarr.echo6.co)

  • Container: lidarr (youegraillot/lidarr-on-steroids:latest)
  • Host: media VM 105 (192.168.1.160)
  • Ports: 8686 (Lidarr), 6595 (Deemix)
  • Network: arr-net
  • Config: /opt/arr/lidarr/config (Lidarr), /opt/arr/lidarr/config_deemix (Deemix)
  • Compose: /opt/arr/docker-compose.yml
  • Music root: /mnt/arr/music (NFS from pi-nas)
  • Downloads: /mnt/arr/downloads (shared with SABnzbd)
  • API key: 78f026ec93a94d8eb3177816b74a57b7
  • Caddy: lidarr.echo6.co -> 100.64.0.18:8686 (Authentik forward auth)
  • Prowlarr: fullSync configured
  • SABnzbd: configured (music category)
  • Deemix: port 6595, NOT exposed via Caddy (Tailscale-only access)
  • PUID/PGID: 1000/1000, TZ: America/Boise

Navidrome (navidrome.echo6.co)

  • Container: navidrome (deluan/navidrome:latest)
  • Host: media VM 105 (192.168.1.160)
  • Port: 4533
  • Network: arr-net
  • Data volume: arr_navidrome-data (named Docker volume)
  • Music volume: /mnt/arr/music (read-only, shared with Lidarr)
  • Compose: /opt/arr/docker-compose.yml
  • Caddy: navidrome.echo6.co -> 100.64.0.18:4533 (Authentik forward auth)
  • User: 1000:1000
  • Scan schedule: every 1 hour
  • Admin setup: First login at https://navidrome.echo6.co creates admin account