Commit Graph

70 Commits

Author SHA1 Message Date
fkrebs 13bc1ecc12 RESUME + pocket-id: reflect 2026-05-24 → 26 state
RESUME:
- Backrest 3-for-3 success on 2026-05-26 (video-projects-plan recovered)
- Vault dedup + 234 link rewrites + cleanup
- Plugin audit + Memos Sync + Obsidian Git + streamlined-ui
- Config-to-git fleet now 8 repos
- AdGuard *.nuclide.lan zone (30 A-records)
- 3 new Homarr boards (home/admin/command)
- Pocket-ID LAN callback URLs
- Immich HTTP/2 Keep-Alive diagnosed
- New constraints: use LAN aliases; daily-note merge policy

pocket-id.md: LAN callback URLs added for Homarr/Grafana/Infisical/Proxmox.
Filed earlier as part of 2026-05-24 work, committing now.
2026-05-26 06:03:28 +02:00
fkrebs 3638e368b1 adguard: document new *.nuclide.lan zone (30 A-records)
Per-host + per-service LAN-only aliases added 2026-05-24 on CT 102.
Stable names → host IPs; clients use names instead of bare IPs so
service moves only require an AdGuard edit, not N app updates.

Use case driver: Immich Android HTTP/2 Keep-Alive bug — per-SSID
'nuclide' local URL https://immich.nuclide.lan:12000 bypasses Zoraxy.
2026-05-24 15:42:10 +02:00
fkrebs 3fa4608266 config-to-git: add CT 103/109/113 + obsidian-vault + obsidian-config
CT 103/109/113-conf were deployed earlier today, table updated.
Add obsidian-vault (CT 103, daily 04:00, rolling 2-commit window) and
obsidian-config (manual zip-drop workflow, see README in repo).
2026-05-24 10:27:49 +02:00
fkrebs a422bbfb13 obsidian MCP: document vault paths across CT 104/105/UNAS 2026-05-24 08:51:04 +02:00
fkrebs aab7f3a6c6 services-overview: make internal IP:port entries clickable 2026-05-24 08:45:22 +02:00
fkrebs 688f3cac45 docker-internal-inventory: 3-tier model with per-container recommendation
Lists all containers without LAN-published ports across CT 104/105/109/110/111/112/113.
Recommends keep-internal vs expose for each. Confirms the public/LAN/docker-internal
tiering is clean across the fleet.
2026-05-24 08:41:46 +02:00
fkrebs d76d766c0a services-overview: full inventory with external + internal URLs
Living doc at http://192.168.1.8:13080/services-overview/.
Categorised by AI/files/identity/dev/home/ops/network with external
Zoraxy routes, internal LAN IP:port, host, and doc cross-links.
2026-05-24 08:39:29 +02:00
fkrebs 7af18a82f1 config-to-git: document fleet (PVE, Zoraxy, AdGuard, HAOS)
Add /docs/infra/config-to-git.md listing all 4 repos, schedules,
script paths, and HAOS-specific addon init_commands pattern.
RESUME updated to reflect HAOS bootstrap done 2026-05-24.
2026-05-24 08:21:52 +02:00
fkrebs 710c8afe3c RESUME: arcane auto-update notifications done 2026-05-24 08:14:52 +02:00
fkrebs 829dd8f339 homarr OIDC: correct env var to AUTH_PROVIDERS (plural)
Homarr v1 ignores singular AUTH_PROVIDER; OIDC button only appears
when AUTH_PROVIDERS=credentials,oidc is set. Fixed live on CT 109.
2026-05-24 07:47:13 +02:00
fkrebs 8aa807bb94 docs: AdGuard split-horizon DNS done
*.nuclide.systems → 192.168.1.4 rewrite active

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 22:45:25 +02:00
fkrebs e160e3dba8 docs: dozzle is LAN-only, clean up route notes
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 19:10:57 +02:00
fkrebs 895658a115 docs: consistency pass 2026-05-23 (session ×4)
- zoraxy.md: fix arcane upstream to CT109 (192.168.1.8:10002), add
  SkipWebSocketOriginCheck column, note missing routes (dozzle, etc.)
- arcane.md: reflect CT109 migration complete, expand agent table to
  all 8 environments, fix MANAGER_API_URL and DB paths
- ct-inventory.md: CT103 RAM 512→4096+swap; CT109 footnote complete
- proxmox-memory-audit.md: CT103 bump, add CT109+CT113 rows, fix sum
- portmap.md: add Wetty row, fix arcane backend, WAL-G scrape target,
  homepage decommissioned, dozzle LAN-only note
- mcp-gateway.md: add gitea/paperless/proxmox, count 26→29 servers
- RESUME.md: check off WAL-G, Loki, Zoraxy audit; CT109 in key state
  table; session ×4 completed items block

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 16:42:45 +02:00
fkrebs 14137c32a7 docs(mcp): add gitea, paperless, proxmox MCP servers (2026-05-23)
Wire three new community MCP servers into the gateway on CT104:
- gitea: official Gitea MCP (53 tools), static upstream gitea-mcp:8000
- paperless: @nloui/paperless-mcp via mcp-proxy (12 tools), static upstream
- proxmox: proxmox-mcp-plus PyPI (39 tools), read-only PVEAuditor token

Total: 27 → 30 servers. Skipped: karakeep (API key unset), audiobookshelf
(Go binary only), vaultwarden (master password exposure risk).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 15:02:26 +02:00
fkrebs 10e138b677 docs: document WAL-G monitoring setup on CT113/CT109
Add WAL-G monitoring section to databases.md covering the textfile
collector script, walg-metrics.timer, node_exporter config, and
Prometheus alert rules added to prevent silent backup stalls.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 14:50:39 +02:00
fkrebs f8d8ee3ac0 docs: add Nexa service doc — synopsis, nuclide.systems mapping, phased roadmap
Covers what Nexa is, which existing services it depends on, what is
genuinely missing (TEI, Qdrant collection, GraphDB), and alternative
tool choices for embeddings, web-search, and the graph pillar.

Repo: https://git.nuclide.systems/fkrebs/nexa

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 14:32:02 +02:00
fkrebs 1a68be98e4 docs: session ×3 — Homarr board, Arcane environments, Infisical OIDC
- Homarr board 'nuclide' deployed (6 sections, 27 apps, correct SQLite schema)
- Arcane 8 environments online with unique agent tokens per host
- Infisical SITE_URL → internal IP; Pocket-ID OIDC client created
- RESUME: Arcane OIDC closed, new open items for Infisical config + Loki + Gotify
- Claude settings: SSH allowlist expanded

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 13:41:48 +02:00
fkrebs f441e8b762 2026-05-23: UNAS SSH key auth, unas-conf repo, NFSv4 status 2026-05-23 11:29:25 +02:00
fkrebs 3de4d5db63 2026-05-23: PVE optimizations, LXC watchdog, KSM, startup order 2026-05-23 11:19:21 +02:00
fkrebs 7927390359 docs: add all config-tracking repos to related repos table 2026-05-23 09:48:22 +02:00
fkrebs c3fd649f68 docs: 2026-05-23 session — CT109 ops, Arcane/Dozzle migration, OIDC wired, OOM fix, n8n tracking 2026-05-23 09:44:15 +02:00
fkrebs 4c97732720 docs: Homarr + Grafana OIDC wired via Pocket-ID API (2026-05-23)
Client IDs created programmatically via Pocket-ID /api/oidc/clients endpoint.
Env vars injected into both compose files and force-recreated.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 09:14:20 +02:00
fkrebs ff398a592f docs: Arcane + Dozzle migrated to CT 109; agents on all Docker hosts
- Arcane server moved CT 104 → CT 109:10002; DB migrated; Zoraxy upstream updated
- Dozzle server moved CT 104 → CT 109:10001; remote agents on all 7 Docker hosts
- Headless agents (arcane-headless + dozzle agent) deployed to:
  CT 101, 104, 105, 110, 111, 112 via /opt/stacks/ops-agents/
  CT 113 updated in-place (was pointing at CT 104, now CT 109)
- homelab-configs sync script expanded: ops/{arcane,dozzle,monitoring} + all agent configs
- portmap: updated CT 104 entries as decommissioned, added CT 109 entries
- ct-inventory: CT 109 role description updated

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 08:53:37 +02:00
fkrebs 96df6e7bd0 docs: migrate docs-server CT 111 → CT 109; update nav and URLs
- docs-server now runs on ops (192.168.1.8:13080), not dev (192.168.1.42)
- mkdocs.yml: fix site_url (was pointing at .111 instead of .42, now .8)
- mkdocs.yml: add all services added since last nav update (pocket-id,
  backrest, databases, arcane, mcp-servers, llm-benchmark, RESUME, connection-hosts)
- portmap.md: move :13080 entry from CT 111 to CT 109 section; add Homarr :7575;
  fix stale Promtail note → Alloy add-on
- README.md: update rendered docs URL to 192.168.1.8:13080

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 08:16:09 +02:00
fkrebs dc7ceab724 docs: correct Zigbee integration — Zigbee2MQTT + Mosquitto, not ZHA
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 08:05:25 +02:00
fkrebs 474af687af docs: 2026-05-23 session — observability stack, Pocket-ID guide, secrets scrub
- CHANGELOG: full 2026-05-23 backfill (Loki, Alloy×12 hosts, pve-exporter,
  HA prometheus integration, 5 dashboards, 3 alert rules, Homarr, homelab-configs repo)
- services/pocket-id.md: new — OIDC endpoints, client creation walkthrough,
  per-service env var patterns, current client registry, backup notes
- infra/proxmox-state.md: redact D-Link credentials from plaintext (pelican/pinkpanther)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 08:03:01 +02:00
fkrebs 3d114c6873 docs: expand README with monitoring links, service index, config repos
Add Homarr/Grafana/Loki/Prometheus quick links, full public service table,
operator-only LAN links, layout additions, and related repos table.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 07:48:23 +02:00
fkrebs b2cb123414 monitoring: document Loki/Alloy/pve-exporter, dashboards and alerts
CT 109 ops stack now includes Loki (log agg), Grafana Alloy (log agent on
all 12 hosts), prometheus-pve-exporter. 5 Grafana dashboards imported;
3 alert rules wired to Gotify.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 07:03:51 +02:00
fkrebs 80647c1a6b monitoring: add pve-exporter to portmap
Proxmox VE metrics via prometheus-pve-exporter on CT 109 :9221.
monitor@pve!prometheus token with Monitor (read-only) role.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 04:32:37 +02:00
fkrebs 0979f71857 monitoring: add Loki + Alloy log aggregation to portmap
Loki (CT 109 :3100, 30d retention) and Grafana Alloy deployed across
all 12 hosts. Portmap updated with new services and agent deployment notes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 04:28:15 +02:00
fkrebs a8ed4350f0 ops: CT 109 provisioned — Prometheus + Grafana monitoring
- Debian 13, Docker 29.5, 4c/4G/32G at 192.168.1.8
- Prometheus :9090 (90d retention), Grafana :3000 (LAN only)
- Scrapes: litellm CT104:14000, node-ct104:9100, node-ct109:9100
- CT 104 standalone node-exporter retained at /opt/stacks/monitoring/
- All 4 targets confirmed up

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 03:44:05 +02:00
fkrebs 644ba72d77 ops: add Prometheus + Grafana monitoring stack on CT 104
- Prometheus :9090, Grafana :9091, node-exporter :9100
- LiteLLM /metrics/ enabled via prometheus callback
- Scrapes: litellm (bearer auth), node-ct104, prometheus self
- 14 litellm_* metrics confirmed flowing
- Stack: /opt/stacks/monitoring; migrate to CT 109 ops when built

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 03:35:22 +02:00
fkrebs c7529bd867 docs: Nextcloud completion model → qwen3.5-122b-a10b (vision+tools)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 03:29:06 +02:00
fkrebs 6309286b96 docs: Nextcloud assistant model config — occ method, current assignments
integration_openai points to LiteLLM at ai.nuclide.systems/v1.
Fixed completion=llama-3.3-70b-instruct, T2I=saia-flux (was devstral).
occ snippet for future model changes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 03:10:58 +02:00
fkrebs c3c40dc07b docs: add model management UI, catalog API, and 4K improvements to mcp-gateway
- New /ui/models page (sortable model catalog + service assignments)
- model_assignments.json: 35-model catalog with latency/cost/capability metadata
- API: GET/PATCH /api/model-assignments
- Model evaluator agent added to agents.json
- ui.html: widen max-width to 1600px, 4K breakpoints at 1920/2560/3840px

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 02:19:28 +02:00
fkrebs 25da11b53a Add connection-hosts and mcp-servers maintained docs
- infra/connection-hosts.md: every host, LAN IP, port, and public URL
  across all Proxmox guests, Docker services, network infra, and
  external hardware; OIDC client registry; SSH cheat-sheet
- services/mcp-servers.md: all 27 MCP servers with full credentials,
  upstream URLs, transport, group, gateway management API examples,
  and gateway .env token inventory

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 01:03:59 +02:00
fkrebs 396aa0e48e docs: remove claude high-effort variants, set temperature=0.7 on Claude models (58 total) 2026-05-23 00:41:26 +02:00
fkrebs 9ab9033ab0 docs: fix voxtral-mini proxy status + remove realtime model entry 2026-05-23 00:26:32 +02:00
fkrebs 6aa55fdf2d docs: add LLM model benchmark + service catalogue (60 models) 2026-05-23 00:23:04 +02:00
fkrebs 8ccf76b37c 2026-05-23: config-to-git deployed, syncstack consolidated, secrets backlog detailed
- Config-to-git crons live on CT 108/102/PVE; HA pending
- Syncstack retired; litellm_sync.py in MCP gateway loop
- Infisical migration phases 2-4 detailed in backlog

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 00:09:59 +02:00
fkrebs 377f20a817 todo sync: update Backrest media-repo status, Vaultwarden OIDC status, UNAS off-host context
- video-projects-plan has never completed; media-backup-plan last OK 2026-05-21
- Both plans have orphaned runs since 19:10; Backrest restarted at 21:23
- Next runs scheduled 2026-05-25
- Vaultwarden OIDC: no env vars wired in .env as of 2026-05-22
- UNAS off-host: Backrest is the right vehicle; reliability fix is prerequisite

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 23:50:38 +02:00
fkrebs dd806f86b8 crawl4ai: mark SSE StreamConsumed resolved — clean restart, 7 tools, 27/27 lobe-sync 2026-05-22 23:34:46 +02:00
fkrebs 05ad2b7d26 backlog: sync to truth — drop 4 already-done items, correct disk numbers 2026-05-22 23:27:07 +02:00
fkrebs b090b4a4a8 backlog: reorder by urgency (critical/high/medium/planned) 2026-05-22 23:25:39 +02:00
fkrebs 3881f95e28 backlog: add 20 items from docs scan (security, backups, db cleanup, infra, services) 2026-05-22 23:22:21 +02:00
fkrebs f86135f683 backlog: remove v5 import generalize (not a Claude task) 2026-05-22 23:19:36 +02:00
fkrebs 811bc1af94 backlog: add crawl4ai SSE fix, syncstack consolidation, v5 import generalize
- crawl4ai MCP (SSE transport) fixed and working — 27/27 servers in LobeChat
- syncstack cron fixed (missing cd prefix)
- Backlog section added for: syncstack→gateway consolidation, SSE StreamConsumed
  investigation, v5 collection import generalization

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 23:18:44 +02:00
fkrebs 143343decf docs: session continuity file + claude-max-bridge /v1/responses fix
- Add RESUME.md for cross-session continuity (open items, key state, constraints)
- claude-max-bridge: implement /v1/responses (OpenAI Responses API) with
  previous_response_id chaining via server-side history injection into system prompt.
  Root cause of "session already in use": CLI leaves JSONL in un-resumable
  "dequeued" state after each --print run; fix avoids session reuse entirely.
  Also fixed: assistant content must be array-of-blocks not plain string (silent
  JS crash otherwise).
- LiteLLM: add pass_through_endpoints for /v1/responses → claude-max-bridge
- Storage, volumes, architecture docs reconciled (Vaultwarden → local zfs,
  Pocket-ID backup, WAL-G fix, apps/ decommission, Nextcloud CIFS→NFS)
- Add ideas/, proxmox-memory-audit.md, llm-benchmark.md (new docs this session)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 22:42:17 +02:00
fkrebs e0199042c1 Re-enable nextcloud MCP: single_user_basic + NEXTCLOUD_VERIFY_SSL=false
App-password generated via occ for fkrebs@nucli.de. Gateway patched
to persist enabled flag from config.json across restarts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 13:41:51 +02:00
fkrebs 6e46b894cb CT 101 shepard rootfs 100G → 500G
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 13:21:41 +02:00