Rename CT 109 observe → ops across all docs
Also updates IP conflict note: .6=CT113, .7=CT112, so CT 109 gets .8. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -651,7 +651,7 @@ Both log to `/var/log/{adguard,zoraxy}-update.log` and journal. Manual invoke: `
|
||||
|
||||
### Layer 5 — Docker images (the ~75 containers)
|
||||
|
||||
**Plan: deploy Diun on CT 109** (observability LXC, see §16). Diun watches image tags on registries, posts to Gotify when a new image is available. Pulls remain manual (`docker compose pull && up -d`) — protects against latest-tag drift like the n8n incident pinned in `/opt/stacks/n8n/docker-compose.yaml`.
|
||||
**Plan: deploy Diun on CT 109** (ops LXC, see §16). Diun watches image tags on registries, posts to Gotify when a new image is available. Pulls remain manual (`docker compose pull && up -d`) — protects against latest-tag drift like the n8n incident pinned in `/opt/stacks/n8n/docker-compose.yaml`.
|
||||
|
||||
**Layer 6 — Nextcloud-AIO**: self-updates via the mastercontainer (CT 105). No external mechanism needed.
|
||||
|
||||
@@ -710,11 +710,11 @@ Recovery latency improved from 5 min → 1 min; logging structured in `journalct
|
||||
|
||||
---
|
||||
|
||||
## 16. CT 109 "observe" — planned observability + ops LXC
|
||||
## 16. CT 109 "ops" — planned observability + ops LXC
|
||||
|
||||
Single LXC holding everything monitoring/ops-shaped. Sizing target: **4 cores / 8 GiB RAM / 50 GiB rootfs**, unprivileged, nesting=1. RAM bumped from 6 → 8 GiB to accommodate Loki. Disk bumped from 30 → 50 GiB for Loki log retention (30d) alongside Prometheus TSDB.
|
||||
|
||||
⚠️ **IP conflict:** inventory originally assigned `192.168.1.6` but CT 113 (db) is already live at `.6`. CT 109 needs the next free infra IP — likely `.7` or `.8` (verify against UniFi DHCP table before provisioning).
|
||||
⚠️ **IP conflict:** inventory originally assigned `192.168.1.6` but CT 113 (db) took `.6` and CT 112 (secrets) took `.7`. CT 109 needs the next free infra IP — likely `.8` (verify against UniFi DHCP table before provisioning).
|
||||
|
||||
**Access model (initial):** LAN-only. No Zoraxy routes until Tinyauth is deployed. Services reachable directly by IP.
|
||||
|
||||
@@ -881,7 +881,7 @@ Captured here so the eventual Homarr config can be assembled in one pass. Groups
|
||||
| **D-Link DGS-1210-28P** | `http://192.168.1.10/` | core L2 switch; host on port 10 |
|
||||
| UNAS Pro | `https://192.168.1.31/` | UniFi NAS |
|
||||
|
||||
### Group: `observability` (to populate when CT 109 lands)
|
||||
### Group: `ops` (to populate when CT 109 lands)
|
||||
|
||||
| Service | URL |
|
||||
|---|---|
|
||||
@@ -924,7 +924,7 @@ Immich, Nextcloud, Vaultwarden, Karakeep, Memos, Paperless-ngx, n8n, ComfyUI, Lo
|
||||
- **Wire Postfix relayhost** (Gmail/Postmark/your SMTP) so unattended-upgrades + zfs-zed + cron failures actually mail you.
|
||||
- **Rotate Backrest plan** to back up real data (currently still pointed at `/media/data-dir` — a 50 KB test file from August 2025); see §7.
|
||||
4. **Medium term**:
|
||||
- **Build CT 109** observability LXC (§16) — Prometheus + Grafana + Arcane Manager + Dozzle + Homarr + Diun + Tinyauth
|
||||
- **Build CT 109** ops LXC (§16) — Prometheus + Grafana + Arcane Manager + Dozzle + Homarr + Diun + Tinyauth
|
||||
- Migrate Gotify from CT 104 to CT 109 (~30 min of env-var updates)
|
||||
- **Rotate exposed secrets** that appeared in this transcript: Arcane `OIDC_CLIENT_SECRET`, `ENCRYPTION_KEY`, `JWT_SECRET`; Immich `IMMICH_API_KEY`
|
||||
- Backrest: enable auth, redesign plans to cover all data tiers (§7), front via Tinyauth for OIDC
|
||||
|
||||
Reference in New Issue
Block a user