wiki: document homelab-context distribution system
Adds infrastructure/homelab-context.md as the architecture reference for the cross-client context + MCP + secrets-issuance system. Updates: - 105-apps.md: two new ## Stacks sections (homelab-mcp, secrets-issuance) with their deploy pipelines + a row each in the public-hostname table; changelog entry. - auto-deploy.md: both new pipelines added to the table (one repo, two webhooks, same push); per-pipeline notes covering the clone-per-service pattern and the deploy.sh self-restart caveat; changelog entry. - README.md: link to the new infrastructure page. Operational walkthrough already lives at operations/agent-enrollment.md; this commit is the architecture side of the same story. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -40,6 +40,12 @@ The app repo at `/opt/<thing>` is the working tree, but the deploy tooling (`web
|
||||
| `dtoro/Plato` | [plato (126)](../containers/126-plato.md) `/opt/plato/app/` | B | `http://192.168.8.190:9799/deploy` | 8 | `docker compose up -d --build` |
|
||||
| `dtoro/claudio-bot` | [claudio-bot (123)](../containers/123-claudio-bot.md) `/opt/claudio-bot/` | A | `http://192.168.8.230:9797/deploy` | (orig) | `pip install` + `systemctl restart claudio-bot` |
|
||||
| `dtoro/backup-library` | [hubris host](../hosts/hubris.md) `/opt/backup-library/` | A | `http://192.168.8.77:9798/deploy` | (orig) | runs `deploy.sh` (preserves admin-edited `/etc/restic/include-*.list`) |
|
||||
| `dtoro/Homelab-Docs` → homelab-mcp | [apps (105)](../containers/105-apps.md) `/opt/homelab-mcp/` | B | `http://192.168.8.205:9811/deploy` | 10 | reinstalls `homelab-mcp.service` + restart |
|
||||
| `dtoro/Homelab-Docs` → secrets-issuance | [apps (105)](../containers/105-apps.md) `/opt/secrets-issuance/` | B | `http://192.168.8.205:9821/deploy` | 11 | reinstalls `secrets-issuance.service` + restart |
|
||||
|
||||
> Note: `dtoro/Homelab-Docs` has **two webhooks** firing on the same push.
|
||||
> Each owns its own clone on LXC 105. They don't conflict because each
|
||||
> deploy.sh only touches its own service unit + venv.
|
||||
|
||||
> **Not yet wired:** `dtoro/claudio-monitor` (push, then `/opt/claudio-monitor/scripts/deploy.sh` manually). `dtoro/authentik-conf` is reserved but the LXC stack is not git-tracked yet. The dnsmasq config on [authentik (124)](../containers/124-authentik.md) is also not tracked — if it gets a `dtoro/dnsmasq-conf`, mirror the caddy-conf pattern.
|
||||
|
||||
@@ -54,6 +60,7 @@ Always commit + push. Local-only edits drift. Common ones:
|
||||
- `/opt/plato/app/` ↔ `dtoro/Plato` (auto-deploys)
|
||||
- `/opt/claudio-bot/` ↔ `dtoro/claudio-bot` (auto-deploys)
|
||||
- `/opt/backup-library/` ↔ `dtoro/backup-library` (auto-deploys)
|
||||
- `/opt/homelab-mcp/` + `/opt/secrets-issuance/` ↔ `dtoro/Homelab-Docs` (auto-deploys both, see [homelab-context](homelab-context.md))
|
||||
|
||||
## Per-pipeline notes / gotchas
|
||||
|
||||
@@ -81,6 +88,21 @@ Always commit + push. Local-only edits drift. Common ones:
|
||||
- Currently the only deploy that targets the host directly (`192.168.8.77:9798`).
|
||||
- `deploy.sh` is careful to preserve admin edits to `/etc/restic/include-*.list` — canonical source is `config/` in the repo, but the install path is treated as authoritative once `deploy.sh` has run.
|
||||
|
||||
### homelab-mcp / secrets-issuance
|
||||
- Both ride a single push to `dtoro/Homelab-Docs`. Two clones on LXC 105
|
||||
(`/opt/homelab-mcp`, `/opt/secrets-issuance`) — each is an independent
|
||||
Shape-B target with its own webhook receiver.
|
||||
- The deploy script restarts the service it just updated. Because the
|
||||
webhook receiver itself is a separate systemd unit (`*-deploy.service`),
|
||||
it does NOT restart itself — but `deploy.sh` running `systemctl
|
||||
restart homelab-mcp-deploy.service` (or the secrets-issuance one)
|
||||
would create a kill-self loop. The current `deploy.sh` is careful
|
||||
to only restart the main service.
|
||||
- Both services consume `/opt/homelab-context` for their runtime data
|
||||
(inventory, secret recipient lookup). That clone is **the same clone
|
||||
every other client has** — kept fresh by `homelab-context-sync.timer`,
|
||||
not by these webhooks.
|
||||
|
||||
## Related
|
||||
- [Gitea (104)](../containers/104-gitea.md) — webhook source for all of these
|
||||
- [Caddy (121)](../containers/121-caddy.md), [apps (105)](../containers/105-apps.md), [mule-images (120)](../containers/120-mule-images.md), [claudio-bot (123)](../containers/123-claudio-bot.md), [hubris host](../hosts/hubris.md) — webhook targets
|
||||
@@ -88,6 +110,9 @@ Always commit + push. Local-only edits drift. Common ones:
|
||||
|
||||
## Changelog
|
||||
|
||||
### 2026-05-20 — homelab-mcp + secrets-issuance pipelines added
|
||||
Webhook ids 10 + 11 on `dtoro/Homelab-Docs` (ports `9811` + `9821` on [apps (105)](../containers/105-apps.md)). Two webhooks on one repo — each owns its own clone (`/opt/homelab-mcp`, `/opt/secrets-issuance`) and only restarts its own service. See [homelab-context](homelab-context.md) for why both services live in one repo.
|
||||
|
||||
### 2026-05-13 — Plato pipeline added
|
||||
Webhook id 8 on `dtoro/Plato` (port `9799` on [plato (126)](../containers/126-plato.md)). `app.ini` `ALLOWED_HOST_LIST` extended to include `192.168.8.190`.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user