root
8ed2631f6b
Gate photos.hubris.network behind Authentik forward-auth
...
Bypass /api/* for JWT/mobile clients (mulita uses Bearer tokens;
SPA login POSTs /api/v1/auth/login). Browser UI goes through the
embedded outpost.
2026-04-22 22:13:06 +02:00
claudio
31eb41a05a
Add artifacto.hubris.network → LXC 105:3100
2026-04-22 21:04:09 +02:00
claudio
8be7291059
Remove temp keys.hubris.network (bootstrap done)
2026-04-22 17:47:49 +02:00
claudio
55c7a8e8f2
TEMP: keys.hubris.network for netbird bootstrap
2026-04-22 16:24:11 +02:00
claudio
18343396aa
blog: drop forward-auth, WriteFreely has native OIDC
2026-04-22 14:20:00 +02:00
claudio
c6a3707363
blog: gate only admin/login paths with Authentik; leave public reading open
2026-04-22 14:17:57 +02:00
claudio
2663401d26
Gate blog.hubris.network with Authentik forward-auth
2026-04-22 14:10:22 +02:00
claudio
9a002648cc
Gate qbit.hubris.network with Authentik forward-auth, bypass /api/* for clients
2026-04-22 13:33:51 +02:00
claudio
8727399e84
Drop forward-auth on books.hubris.network — Booklore has native OIDC
2026-04-22 10:57:53 +02:00
claudio
2916449322
Gate books.hubris.network (Booklore) with Authentik forward-auth
2026-04-22 10:48:00 +02:00
claudio
f04a82f451
paperless: bypass Authentik forward-auth for /api/* so mobile apps (own token auth) can work
2026-04-22 10:12:53 +02:00
claudio
f2fd96e336
Forward-auth snippet final (dynamic X-Forwarded-Host, caddy fmt)
2026-04-22 01:05:31 +02:00
claudio
b2b6c86437
Explicitly set X-Forwarded-Host for forward_auth (Authentik needs it)
2026-04-22 01:02:35 +02:00
claudio
cb124a1cd2
Drop header_up Host from forward_auth so Authentik sees X-Forwarded-Host
2026-04-22 01:00:27 +02:00
claudio
a767cbf034
Gate paperless.hubris.network with Authentik forward-auth
2026-04-22 00:55:59 +02:00
claudio
ea4371089c
Add (authentik) forward-auth snippet for domain-level SSO
2026-04-22 00:45:30 +02:00
claudio
d74053bbd4
Add auth.hubris.network → Authentik on LXC 124:9000
2026-04-21 22:53:51 +02:00
Claudio
877d025ceb
Rename images.hubris.network → photos.hubris.network
2026-04-21 20:56:59 +02:00
Claudio
1b063b9cb4
Add images.hubris.network → mule-image frontend on mule-images:3000
2026-04-21 20:53:00 +02:00
dtoro
07a2d071d1
Add blog.hubris.network → WriteFreely on apps:8080
2026-04-21 16:16:55 +02:00
hubris-root
8ce7a82fd4
add jellyseerr, qbit, sab entries (arriman 192.168.8.132)
2026-04-21 13:17:25 +02:00
Claudio
c2a1ab464b
Webhook service: allow writes to /etc/caddy
...
git pull inside the deploy needs to update .git/FETCH_HEAD, but
ProtectSystem=full makes /etc read-only. ReadWritePaths=/etc/caddy
opens just the repo directory.
2026-04-20 17:11:39 +02:00
Claudio
b6dec2a894
Add deploy.sh + webhook receiver
...
deploy.sh runs on LXC 121: git pull, caddy validate, systemctl reload.
webhook.py is a small HTTP receiver on :9797/deploy that verifies the
gitea HMAC-SHA256 signature and triggers deploy.sh.
install.sh provisions /etc/caddy-deploy/secret and the systemd unit.
2026-04-20 17:10:15 +02:00
Claudio
24c66803e4
Proxy /_plantuml to self-hosted plantuml-server
...
Adds handle_path /_plantuml/* in git.hubris.network that rewrites to
/plantuml{uri} and proxies to 192.168.8.205:8079 (plantuml-server
docker container on LXC 105). Used by gitea footer.tmpl to render
PlantUML markdown code blocks without hitting the public demo server.
2026-04-20 17:04:03 +02:00
e5bc81b911
Remove unused blog
2026-04-20 16:31:39 +02:00
cef27b9a64
Add Booklore
2026-04-20 00:03:09 +02:00
c29194a17e
Add paperless
2026-04-19 22:59:01 +02:00
13d70c59b5
Add nextcloud
2026-04-19 22:32:16 +02:00
cf8f8d8966
Add Matrix
2026-04-19 22:17:15 +02:00
de45bfceeb
Add homeassitant
2026-04-19 21:48:05 +02:00
68ee03b2e8
Update proxmox
2026-04-19 21:35:37 +02:00
28a88fdb7f
Update proxmox
2026-04-19 21:33:48 +02:00
d9ddfd8679
Update proxmox to https
2026-04-19 21:22:29 +02:00
8d5e12b240
Add proxmox
2026-04-19 21:14:34 +02:00
root
39f0384ec9
initialize
2026-04-19 15:19:54 +02:00