todo sync: update Backrest media-repo status, Vaultwarden OIDC status, UNAS off-host context

- video-projects-plan has never completed; media-backup-plan last OK 2026-05-21
- Both plans have orphaned runs since 19:10; Backrest restarted at 21:23
- Next runs scheduled 2026-05-25
- Vaultwarden OIDC: no env vars wired in .env as of 2026-05-22
- UNAS off-host: Backrest is the right vehicle; reliability fix is prerequisite

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-05-22 23:50:38 +02:00
parent dd806f86b8
commit 377f20a817
+3 -3
View File
@@ -6,12 +6,12 @@ Last updated: 2026-05-22. Update this at the end of every session.
### 🔴 Critical — security risk or unrecoverable data loss ### 🔴 Critical — security risk or unrecoverable data loss
- [ ] **Password rotation: `tapirnase`** — shared across WiFi PSK, LiteLLM root key (`sk-tapirnase`), D-Link admin, Backrest repo password. Single sniff = broad blast radius. Rotate per-service. See `services/homelab-architecture.md` §operational rules. - [ ] **Password rotation: `tapirnase`** — shared across WiFi PSK, LiteLLM root key (`sk-tapirnase`), D-Link admin, Backrest repo password. Single sniff = broad blast radius. Rotate per-service. See `services/homelab-architecture.md` §operational rules.
- [ ] **UNAS personal data off-host** — ~820 GB Immich library + UNAS bulk have zero off-host copy. Deploy rclone sync: `media/images/library` → jottacloud:Photos + full UNAS → jottacloud:UNAS. See `services/backrest.md` phase 1a. - [ ] **UNAS personal data off-host** — ~820 GB Immich library partially covered by `media-backup-plan` in Backrest (last OK 2026-05-21 but failing/orphaned). `video-projects-plan` never completed. Backrest is the right vehicle — fix reliability first (see 🟠 Backrest item), then verify JottaCloud coverage. See `services/backrest.md` phase 1a.
- [ ] **Nextcloud Borg passphrase → Vaultwarden** — passphrase only in container env; CT 105 loss = unrecoverable backup. Move to Vaultwarden. See `services/backrest.md` blind spot #4b. - [ ] **Nextcloud Borg passphrase → Vaultwarden** — passphrase only in container env; CT 105 loss = unrecoverable backup. Move to Vaultwarden. See `services/backrest.md` blind spot #4b.
### 🟠 High — known broken / verification needed ### 🟠 High — known broken / verification needed
- [ ] **Arcane OIDC secret** — rotation done 2026-05-22 but Arcane has known OIDC issues. Verify it still authenticates. - [ ] **Arcane OIDC secret** — rotation done 2026-05-22 but Arcane has known OIDC issues. Verify it still authenticates.
- [ ] **Backrest media-repo**`video-projects-plan` and `media-backup-plan` were at 0 snapshots as of 2026-05-22 19:10. Verify snapshots landed. - [ ] **Backrest media-repo**`video-projects-plan` has NEVER completed a successful snapshot. `media-backup-plan` last OK 2026-05-21; failed 2026-05-22 01:30; orphaned restic run in progress since 19:10 (Backrest restarted 21:23, orphaned it). Both plans next scheduled 2026-05-25 02:00/01:30. Monitor for completion; if they fail again, investigate rclone:jottacloud:media auth.
- [ ] **AdGuard split-horizon DNS** — internal clients still resolve to public IPs. Rewrite rules audit. See `services/adguard-dns.md`. - [ ] **AdGuard split-horizon DNS** — internal clients still resolve to public IPs. Rewrite rules audit. See `services/adguard-dns.md`.
- [ ] **WAL-G monitoring** — silent stall went undetected for 13 h. Add textfile collector + alert for hung archiver. See `services/homelab-architecture.md` roadmap. - [ ] **WAL-G monitoring** — silent stall went undetected for 13 h. Add textfile collector + alert for hung archiver. See `services/homelab-architecture.md` roadmap.
- [ ] **Zoraxy audit** — CT 108 routes: WS headers, ACME coverage, decommissioned routes, auth consistency. See `services/zoraxy.md`. - [ ] **Zoraxy audit** — CT 108 routes: WS headers, ACME coverage, decommissioned routes, auth consistency. See `services/zoraxy.md`.
@@ -21,7 +21,7 @@ Last updated: 2026-05-22. Update this at the end of every session.
- [ ] **Dormant stacks audit** — ~10 stacks defined but not running (homepage, dozzle, arr-stack, qdrant, etc.). Document: parked vs. abandoned. See `infra/proxmox-state.md` §10c. - [ ] **Dormant stacks audit** — ~10 stacks defined but not running (homepage, dozzle, arr-stack, qdrant, etc.). Document: parked vs. abandoned. See `infra/proxmox-state.md` §10c.
- [ ] **Config-to-git** — push zoraxy, adguard, pve, ha configs daily to Gitea repos (repos exist, cron not deployed). See `services/backrest.md` phase 3. - [ ] **Config-to-git** — push zoraxy, adguard, pve, ha configs daily to Gitea repos (repos exist, cron not deployed). See `services/backrest.md` phase 3.
- [ ] **D-Link hardening** — admin UI open to full LAN, SNMP unverified, HTTP-only. Enable trusted-host allowlist, harden SNMP, add TLS. See `services/homelab-architecture.md`. - [ ] **D-Link hardening** — admin UI open to full LAN, SNMP unverified, HTTP-only. Enable trusted-host allowlist, harden SNMP, add TLS. See `services/homelab-architecture.md`.
- [ ] **Vaultwarden OIDC SSO** — Pocket-ID client created 2026-05-21, auth flow not wired up. - [ ] **Vaultwarden OIDC SSO** — Pocket-ID client created 2026-05-21, auth flow not wired up. Confirmed no OIDC vars in `/opt/stacks/vaultwarden/.env` as of 2026-05-22.
### 🔵 Planned — requires infrastructure or significant effort ### 🔵 Planned — requires infrastructure or significant effort
- [ ] **CT 109 "ops"** — LXC for Prometheus, Loki, Grafana, Alloy, Homarr, sshwifty, Gotify. Blocks monitoring stack + Arcane migration. See `infra/proxmox-state.md` §16. - [ ] **CT 109 "ops"** — LXC for Prometheus, Loki, Grafana, Alloy, Homarr, sshwifty, Gotify. Blocks monitoring stack + Arcane migration. See `infra/proxmox-state.md` §16.