Commit Graph

  • 900e46c667 add VPS Traefik dynamic config — hubris.network fallback routes master dtoro 2026-08-12 18:26:12 +02:00
  • 6e6bfe3aa0 Revert "test: end-to-end deploy pipeline (both hosts)" root 2026-08-12 14:52:48 +02:00
  • 28543e1662 test: end-to-end deploy pipeline (both hosts) root 2026-08-12 14:52:29 +02:00
  • 3d52e9d1c1 Revert "test: debug sig v3" root 2026-08-12 14:51:25 +02:00
  • fa1dff62c6 test: debug sig v3 root 2026-08-12 14:50:27 +02:00
  • 2faea41d3e Revert "test: debug webhook signature v2" root 2026-08-12 14:49:40 +02:00
  • 3cebb8fd11 test: debug webhook signature v2 root 2026-08-12 14:48:29 +02:00
  • 4635001feb Revert "test: verify auto-deploy pipeline" root 2026-08-12 14:47:53 +02:00
  • 1ea60a9aca test: verify auto-deploy pipeline root 2026-08-12 14:45:11 +02:00
  • e7bf4f9d93 fix: clean shared/authentik (fix tab escaping) + add :8080 webhook endpoint root 2026-08-12 14:42:40 +02:00
  • 2c418d395d refactor: split Caddyfile into per-host configs with shared snippets root 2026-08-12 14:37:30 +02:00
  • 86e727255b chore: add .gitignore for backup and env files root 2026-08-12 14:33:33 +02:00
  • 2b8bddc488 split: move 10 strong-hosted services to dedicated Caddy on CT 140 (.250) root 2026-08-12 14:33:03 +02:00
  • 4238adb81c fix: zimaos.hubris.network reverse_proxy target IP .102→.195 (VM serving at original .195) dtoro 2026-08-06 22:05:17 +02:00
  • f266f0605f add matrix.hubris.network reverse proxy to Synapse (192.168.8.242:8008) dtoro 2026-08-05 17:11:34 +02:00
  • 48549d0072 fix(zimaos): update reverse_proxy to 192.168.8.102:80 (correct ZimaOS VM IP) dtoro 2026-08-04 21:27:56 +02:00
  • d17ee47ce5 add pascal.hubris.network → 192.168.8.100:3001 root 2026-08-04 14:39:16 +02:00
  • 25b81b2dce Add /oidc-callback to enroll bypass for desktop OIDC flow dtoro 2026-07-13 23:21:41 +02:00
  • a3d9368a54 Merge branch 'master' of http://192.168.8.121:3000/dtoro/caddy-conf root 2026-07-12 23:15:18 +02:00
  • 89ff86e36e add tube.hubris.network -> 192.168.178.44:8082 root 2026-07-12 23:11:13 +02:00
  • e026ba867a oikos: split SPA off to its own :8091 container dtoro 2026-07-12 23:03:46 +02:00
  • 8e48911e1f fix: close mcp.hubris.network block properly, remove dangling comment dtoro 2026-07-08 11:59:24 +02:00
  • fc50aa3bda oikos: remove old mcp+secrets blocks pointing to decommissioned apps/105 dtoro 2026-07-08 11:58:12 +02:00
  • 5401d77bab oikos: remove duplicate block, switch to mac-mini :8090, bypass Authentik for /api/v1/clients/enroll dtoro 2026-07-08 11:56:53 +02:00
  • ed20908d34 dns: add oikos/mcp/hermes → mac-mini Docker (Go Phase 6 cutover) dtoro 2026-07-07 19:15:39 +02:00
  • c195142827 Add oikos.hubris.network -> Oikos Console on apps (105:8091) dtoro 2026-07-06 13:26:24 +02:00
  • 205cbf00f3 roms.hubris.network → .249 (fixed IP conflict with seanime) dtoro 2026-07-05 17:19:49 +02:00
  • c937c03da3 Add roms.hubris.network → 192.168.8.248:80 (RomM LXC 134 on strong) dtoro 2026-07-05 17:12:14 +02:00
  • 9dcac60a08 add seanime.hubris.network proxy to seanime LXC 133 on strong :43211 root 2026-07-05 16:56:46 +02:00
  • dfe4e7bf80 migrate grimmory (130) to strong - update books backend root 2026-07-05 15:03:34 +02:00
  • 468c2e7d93 migrate arriman (122) and jellyfin (101) to strong - update backends root 2026-07-05 14:37:32 +02:00
  • 9b99dbb641 update house+teddy backends after LXC 129 migration to strong + teddycloud static IP root 2026-07-05 13:18:03 +02:00
  • 0b703fa192 update house.hubris.network backend to strong (192.168.8.244) after LXC 129 migration root 2026-07-05 13:04:16 +02:00
  • 751feefe4c update element.hubris.network backend to strong (192.168.8.242) after migrating LXC 118 root 2026-07-05 12:06:03 +02:00
  • 8c92428b42 fix: remove forward-auth gate for jellyfin, use SSO plugin OIDC flow instead root 2026-07-04 21:24:51 +02:00
  • ae854e563d fix: add /sso/* and /SSO-Auth/* to jellyfin api bypass for SSO plugin root 2026-07-04 20:24:54 +02:00
  • acc5af8477 feat: add authentik forward-auth gate for media.hubris.network (API bypass for apps) root 2026-07-04 19:45:14 +02:00
  • e01a39175f teddy.hubris.network: fix backend to https://192.168.8.243:8443 root 2026-06-29 22:11:21 +02:00
  • 3824faf11c add teddy.hubris.network for TeddyCloud LXC 131 root 2026-06-29 21:52:04 +02:00
  • 06d9452741 books.hubris.network: migrate backend to grimmory LXC 130 (192.168.8.213) root 2026-06-29 01:20:11 +02:00
  • e0973bfeeb add house.hubris.network for Yuvomi root 2026-06-26 17:24:33 +02:00
  • 85e9a92059 remove matrix.hubris.network — moved to VPS traefik root 2026-06-25 10:38:49 +02:00
  • d2d9ef8da0 add trmnl.hubris.network -> 192.168.8.211:9851 (TRMNL plugins LXC 128) dtoro 2026-06-24 17:14:08 +02:00
  • 6786f07c76 Add element.hubris.network (Element Web client) root 2026-06-23 23:30:09 +02:00
  • 0f472e9088 remove papers.hubris.network (zimaos paperless removed) root 2026-06-21 23:29:17 +02:00
  • f9783571a1 revert paperless.hubris.network to LXC 103 root 2026-06-21 23:18:08 +02:00
  • b3e7385754 add papers.hubris.network for paperless on zimaos root 2026-06-21 21:58:57 +02:00
  • 8d14ef80fa point paperless to zimaos (192.168.8.195:8000) root 2026-06-21 21:14:40 +02:00
  • d49a844941 feat: gate sab.hubris.network with Authentik forward-auth root 2026-06-13 11:15:04 +02:00
  • 32575ce73f fix: sab.hubris.network reverse proxy port 8081 -> 8082 root 2026-06-06 14:13:42 +02:00
  • 1b977aabfa photos: clean up routing for Mulimage 2.0, add prism subdomain dtoro 2026-06-06 12:36:26 +02:00
  • 408a11c856 fix: add internal HTTP proxy for forward-auth (avoids TLS routing issues) root 2026-06-04 23:43:48 +02:00
  • fec102895f fmt: clean up sso.hubris.network block formatting root 2026-06-04 22:51:58 +02:00
  • 2962a6e485 cleanup: point authentik forward-auth and sso to VPS root 2026-06-04 22:47:28 +02:00
  • f520afad60 fix: proxy auth.hubris.network to VPS (82.165.190.79), strip port from Host header root 2026-06-04 22:37:45 +02:00
  • c906a5acc7 authentik: add sso.hubris.network site for LAN forward-auth outpost callback dtoro 2026-06-01 00:41:55 +02:00
  • 6ea8e727d4 authentik: point forward-auth snippet at LAN outpost (192.168.8.6) dtoro 2026-06-01 00:31:08 +02:00
  • db7f8fbf4e photos: revert /library/login proxy — OIDC starts at /api/v1/oidc/login dtoro 2026-05-22 01:08:10 +02:00
  • a52cf68d0f photos: wrap site block in route{} to force literal directive order dtoro 2026-05-22 01:02:11 +02:00
  • e535f93dcc photos: stop caddy from eating /library/login (OIDC initiation) dtoro 2026-05-22 01:01:21 +02:00
  • 730334c3df photos: cut over to PhotoPrism stack on LXC 120, drop photos-new photos-cutover-to-120 dtoro 2026-05-21 23:50:22 +02:00
  • 708556fd1e Add mcp.hubris.network + secrets.hubris.network vhosts root 2026-05-20 17:12:51 +02:00
  • a3d7e6a61c photos-new: bounce /library/* to / after OIDC Claudio 2026-05-17 22:03:35 +02:00
  • e90f9078d8 Add photos-new.hubris.network -> LXC 127 (PhotoPrism M0 test) Claudio 2026-05-17 21:36:39 +02:00
  • a219176c95 Add zimaos.hubris.network -> VM 100 (192.168.8.195) Claudio 2026-05-14 13:29:26 +02:00
  • ba935abbfb Add plato.hubris.network → LXC 126:8080 claudio 2026-05-13 01:14:44 +02:00
  • 65507e68f7 Remove files.hubris.network (Seafile decommissioned) claudio 2026-05-13 00:29:55 +02:00
  • f0a8835d8c Route /thumbnail/* on files.hubris.network to Seafile Pro thumbnail-server (LXC 125:8081) Caddy on hubris 2026-05-12 18:57:57 +02:00
  • c1c161d1b8 Strip IETF resumable-upload headers for Seafile iOS app (LXC 125) Caddy on hubris 2026-05-12 18:10:40 +02:00
  • 139f889c23 Add files.hubris.network for Seafile (LXC 125) Caddy on hubris 2026-05-12 12:21:29 +02:00
  • 7e856d85a6 Gate artifacto admin with Authentik + forward gateway header claudio 2026-04-22 22:20:56 +02:00
  • a6b12a4e64 Revert photos.hubris.network forward-auth root 2026-04-22 22:15:24 +02:00
  • 8ed2631f6b Gate photos.hubris.network behind Authentik forward-auth root 2026-04-22 22:13:06 +02:00
  • 31eb41a05a Add artifacto.hubris.network → LXC 105:3100 claudio 2026-04-22 21:04:09 +02:00
  • 8be7291059 Remove temp keys.hubris.network (bootstrap done) claudio 2026-04-22 17:47:49 +02:00
  • 55c7a8e8f2 TEMP: keys.hubris.network for netbird bootstrap claudio 2026-04-22 16:24:11 +02:00
  • 18343396aa blog: drop forward-auth, WriteFreely has native OIDC claudio 2026-04-22 14:20:00 +02:00
  • c6a3707363 blog: gate only admin/login paths with Authentik; leave public reading open claudio 2026-04-22 14:17:57 +02:00
  • 2663401d26 Gate blog.hubris.network with Authentik forward-auth claudio 2026-04-22 14:10:22 +02:00
  • 9a002648cc Gate qbit.hubris.network with Authentik forward-auth, bypass /api/* for clients claudio 2026-04-22 13:33:51 +02:00
  • 8727399e84 Drop forward-auth on books.hubris.network — Booklore has native OIDC claudio 2026-04-22 10:57:53 +02:00
  • 2916449322 Gate books.hubris.network (Booklore) with Authentik forward-auth claudio 2026-04-22 10:48:00 +02:00
  • f04a82f451 paperless: bypass Authentik forward-auth for /api/* so mobile apps (own token auth) can work claudio 2026-04-22 10:12:53 +02:00
  • f2fd96e336 Forward-auth snippet final (dynamic X-Forwarded-Host, caddy fmt) claudio 2026-04-22 01:05:31 +02:00
  • b2b6c86437 Explicitly set X-Forwarded-Host for forward_auth (Authentik needs it) claudio 2026-04-22 01:02:35 +02:00
  • cb124a1cd2 Drop header_up Host from forward_auth so Authentik sees X-Forwarded-Host claudio 2026-04-22 01:00:27 +02:00
  • a767cbf034 Gate paperless.hubris.network with Authentik forward-auth claudio 2026-04-22 00:55:59 +02:00
  • ea4371089c Add (authentik) forward-auth snippet for domain-level SSO claudio 2026-04-22 00:45:30 +02:00
  • d74053bbd4 Add auth.hubris.network → Authentik on LXC 124:9000 claudio 2026-04-21 22:53:51 +02:00
  • 877d025ceb Rename images.hubris.network → photos.hubris.network Claudio 2026-04-21 20:56:59 +02:00
  • 1b063b9cb4 Add images.hubris.network → mule-image frontend on mule-images:3000 Claudio 2026-04-21 20:53:00 +02:00
  • 07a2d071d1 Add blog.hubris.network → WriteFreely on apps:8080 dtoro 2026-04-21 16:16:55 +02:00
  • 8ce7a82fd4 add jellyseerr, qbit, sab entries (arriman 192.168.8.132) hubris-root 2026-04-21 13:17:25 +02:00
  • c2a1ab464b Webhook service: allow writes to /etc/caddy Claudio 2026-04-20 17:11:39 +02:00
  • b6dec2a894 Add deploy.sh + webhook receiver Claudio 2026-04-20 17:10:15 +02:00
  • 24c66803e4 Proxy /_plantuml to self-hosted plantuml-server Claudio 2026-04-20 16:54:55 +02:00
  • e5bc81b911 Remove unused blog dtoro 2026-04-20 16:31:39 +02:00
  • cef27b9a64 Add Booklore dtoro 2026-04-20 00:03:09 +02:00
  • c29194a17e Add paperless dtoro 2026-04-19 22:59:01 +02:00
  • 13d70c59b5 Add nextcloud dtoro 2026-04-19 22:32:16 +02:00