Rename CT 109 observe → ops across all docs

Also updates IP conflict note: .6=CT113, .7=CT112, so CT 109 gets .8.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-05-22 10:38:57 +02:00
parent b0160322b3
commit c2979f7c9d
3 changed files with 10 additions and 10 deletions
+5 -5
View File
@@ -651,7 +651,7 @@ Both log to `/var/log/{adguard,zoraxy}-update.log` and journal. Manual invoke: `
### Layer 5 — Docker images (the ~75 containers)
**Plan: deploy Diun on CT 109** (observability LXC, see §16). Diun watches image tags on registries, posts to Gotify when a new image is available. Pulls remain manual (`docker compose pull && up -d`) — protects against latest-tag drift like the n8n incident pinned in `/opt/stacks/n8n/docker-compose.yaml`.
**Plan: deploy Diun on CT 109** (ops LXC, see §16). Diun watches image tags on registries, posts to Gotify when a new image is available. Pulls remain manual (`docker compose pull && up -d`) — protects against latest-tag drift like the n8n incident pinned in `/opt/stacks/n8n/docker-compose.yaml`.
**Layer 6 — Nextcloud-AIO**: self-updates via the mastercontainer (CT 105). No external mechanism needed.
@@ -710,11 +710,11 @@ Recovery latency improved from 5 min → 1 min; logging structured in `journalct
---
## 16. CT 109 "observe" — planned observability + ops LXC
## 16. CT 109 "ops" — planned observability + ops LXC
Single LXC holding everything monitoring/ops-shaped. Sizing target: **4 cores / 8 GiB RAM / 50 GiB rootfs**, unprivileged, nesting=1. RAM bumped from 6 → 8 GiB to accommodate Loki. Disk bumped from 30 → 50 GiB for Loki log retention (30d) alongside Prometheus TSDB.
⚠️ **IP conflict:** inventory originally assigned `192.168.1.6` but CT 113 (db) is already live at `.6`. CT 109 needs the next free infra IP — likely `.7` or `.8` (verify against UniFi DHCP table before provisioning).
⚠️ **IP conflict:** inventory originally assigned `192.168.1.6` but CT 113 (db) took `.6` and CT 112 (secrets) took `.7`. CT 109 needs the next free infra IP — likely `.8` (verify against UniFi DHCP table before provisioning).
**Access model (initial):** LAN-only. No Zoraxy routes until Tinyauth is deployed. Services reachable directly by IP.
@@ -881,7 +881,7 @@ Captured here so the eventual Homarr config can be assembled in one pass. Groups
| **D-Link DGS-1210-28P** | `http://192.168.1.10/` | core L2 switch; host on port 10 |
| UNAS Pro | `https://192.168.1.31/` | UniFi NAS |
### Group: `observability` (to populate when CT 109 lands)
### Group: `ops` (to populate when CT 109 lands)
| Service | URL |
|---|---|
@@ -924,7 +924,7 @@ Immich, Nextcloud, Vaultwarden, Karakeep, Memos, Paperless-ngx, n8n, ComfyUI, Lo
- **Wire Postfix relayhost** (Gmail/Postmark/your SMTP) so unattended-upgrades + zfs-zed + cron failures actually mail you.
- **Rotate Backrest plan** to back up real data (currently still pointed at `/media/data-dir` — a 50 KB test file from August 2025); see §7.
4. **Medium term**:
- **Build CT 109** observability LXC (§16) — Prometheus + Grafana + Arcane Manager + Dozzle + Homarr + Diun + Tinyauth
- **Build CT 109** ops LXC (§16) — Prometheus + Grafana + Arcane Manager + Dozzle + Homarr + Diun + Tinyauth
- Migrate Gotify from CT 104 to CT 109 (~30 min of env-var updates)
- **Rotate exposed secrets** that appeared in this transcript: Arcane `OIDC_CLIENT_SECRET`, `ENCRYPTION_KEY`, `JWT_SECRET`; Immich `IMMICH_API_KEY`
- Backrest: enable auth, redesign plans to cover all data tiers (§7), front via Tinyauth for OIDC