This website requires JavaScript.
2a7876c711
add caveman compression mode to agent bootstrap
dtoro
2026-05-25 22:44:06 +02:00
f5e23bea0a
DNS Phase 4 COMPLETE: single zone — managed zone removed
claude/wizardly-sinoussi-1dda3e
dtoro
2026-06-21 15:49:36 +02:00
0ff592d237
DNS Phase 4: attempted single-zone, reverted (managed zone load-bearing)
dtoro
2026-06-21 15:33:33 +02:00
f9f2e8ab5e
DNS Phase 2: fix roaming-peer resolution via route distribution
dtoro
2026-06-21 15:28:08 +02:00
85457095e4
DNS single-source Phase 1 + decommission Tailscale fleet-wide
dtoro
2026-06-21 15:14:07 +02:00
a5da521751
docs: Fritz!Box DNSv4 set to Technitium (192.168.8.2) — household LAN now resolves *.hubris.network
dtoro
2026-06-18 00:41:36 +02:00
4c83960035
docs: sab.hubris.network Authentik auth — update arriman + caddy pages
dtoro
2026-06-13 11:58:21 +02:00
ddc5e8771a
docs: Authentik session lifetime investigation, fix docs, changelog
dtoro
2026-06-06 23:45:59 +02:00
ebf521007d
docs: emphasize Caddyfile must be edited via dtoro/caddy-conf repo, not directly on LXC
dtoro
2026-06-06 14:17:12 +02:00
ab3d484824
docs: add investigation entry for 2026-06-05 authentik ident stage skip (broken Trust me policy)
dtoro
2026-06-05 20:08:28 +02:00
35b1a25f08
fix: remaining DHCP drifts + improve validation script
dtoro
2026-06-05 17:59:46 +02:00
b3729a941e
fix: gitea DHCP drift + add caddy backend validation script
dtoro
2026-06-05 13:21:58 +02:00
3a2270ba86
fix: update paperless (192.168.8.130→243) and haos (192.168.8.101→241) after DHCP lease changes
dtoro
2026-06-05 10:51:51 +02:00
6d808a1fd8
arriman: SABnzbd HTTPS enabled on port 9090
dtoro
2026-06-05 00:21:56 +02:00
6b5fed040f
arriman: all services behind gluetun, SAB port 8082 fix
dtoro
2026-06-05 00:14:06 +02:00
2f81287eb1
cleanup: destroy LXC 124, remove stale docs, update DNS refs to Technitium
dtoro
2026-06-04 23:12:06 +02:00
699fd94746
inventory: remove retired LXC 124 (authentik), update dnsmasq→dns service ref
dtoro
2026-06-04 23:02:31 +02:00
2d3e979d67
docs: note 2026-06-04 Caddy proxy fixes (auth.hubris.network, sso, forward-auth)
dtoro
2026-06-04 22:57:02 +02:00
b4500cafc7
mac-mini wired to LAN: update IPs and revert WiFi moonlight/sunshine configs
dtoro
2026-06-04 22:05:51 +02:00
728e501435
investigations: add moonlight/sunshine WiFi jitter report + index entry
dtoro
2026-06-04 21:05:20 +02:00
e32b21072d
claudio-bot: decommission LXC 123, archive repos, migrate monitoring to Hermes
dtoro
2026-06-04 10:14:56 +02:00
fbe76c84d4
fix: ZimaOS static IP set to .195 via systemd-networkd overlay injection
dtoro
2026-06-03 23:01:34 +02:00
edac189aa7
docs: DHCP pool narrowed to .241-.254; ZimaOS IP drift documented
dtoro
2026-06-03 22:50:33 +02:00
4c4cfb56cd
fix: remove stray merge marker in .sops.yaml; rekey netbird-pat to 4 recipients
dtoro
2026-06-03 22:03:36 +02:00
cb1d8b39b9
Merge branch 'main' of git-ssh.hubris.network:dtoro/Homelab-Docs
dtoro
2026-06-03 22:02:52 +02:00
f81310ae6b
dns: Technitium-master sync to NetBird managed zone + cleanup
dtoro
2026-06-03 21:59:54 +02:00
ce1bf4d0d2
docs: gluetun VPN + static IP migration (2026-06-02)
dtoro
2026-06-02 22:42:46 +02:00
41de395240
docs: post-migration changelog entries on hubris, caddy, dns
dtoro
2026-06-02 22:02:34 +02:00
99d412370b
network: migration complete — Proxmox as subnet router, Technitium DHCP live
dtoro
2026-06-02 21:34:56 +02:00
1e7c5a7153
hermes-soul: auto-provision SOUL.md from HERMES.md via setup-hermes-soul.sh
dtoro
2026-06-02 00:54:03 +02:00
c7f68a095b
tools: post-pull auto-setup hook + caveman (RTK-style token optimization)
dtoro
2026-06-02 00:31:48 +02:00
3154b3ca02
docs: mark MCP streamable-http migration resolved (#4 )
dtoro
2026-06-02 00:30:06 +02:00
520a86c986
fix: agent-enrollment.md doc references to use /mcp path
dtoro
2026-06-02 00:28:43 +02:00
ec48041b54
fix: correct endpoint path to /mcp for streamable-http transport
dtoro
2026-06-02 00:25:34 +02:00
c299409431
docs: update ssh-access.md + agent-enrollment.md with universal SSH setup
dtoro
2026-06-02 00:20:28 +02:00
bebebf486a
ssh-config: add gen-config.py + homelab ssh-config CLI subcommand
dtoro
2026-06-02 00:16:15 +02:00
e7bdf9fca7
fix: streamable-http (hyphen, not underscore) in FastMCP transport
dtoro
2026-06-02 00:12:59 +02:00
00a891b154
ssh: fix LXC name parsing in deploy-keys.sh (Lock column edge case)
dtoro
2026-06-02 00:06:58 +02:00
5adb66237e
ssh: add authorized_keys dir + deploy-keys.sh for key distribution
dtoro
2026-06-02 00:05:03 +02:00
0a3e43473e
inventory: add lan_ip for mac-mini (192.168.8.174)
dtoro
2026-06-02 00:00:47 +02:00
daf4747c5c
post-mortem: mac-mini onboarding — 12 issues found
dtoro
2026-06-01 23:45:22 +02:00
e615599a2c
revert test
dtoro
2026-06-01 23:41:19 +02:00
19b2109efc
test
dtoro
2026-06-01 23:41:06 +02:00
10fdb0fe09
revert: test commit
dtoro
2026-06-01 23:34:32 +02:00
946ded6d08
test credential
dtoro
2026-06-01 23:34:19 +02:00
95a3ae75c3
hermes-agent: update model to deepseek/deepseek-v4-flash (tool-use support)
dtoro
2026-06-01 23:28:43 +02:00
9be6f7f31d
openrouter-api-key: seed real key
dtoro
2026-06-01 23:24:36 +02:00
5f929ce3ee
openrouter-api-key: seed real key
root
2026-06-01 23:09:41 +02:00
76bbe99798
client-add: mac-mini (finalize age_pubkey + grant shared + hermes secrets)
root
2026-06-01 22:49:01 +02:00
543745cad9
network: retire Slate AX; add SODOLA switch migration plan and network topology doc
dtoro
2026-06-01 22:48:02 +02:00
ce6df85bb5
Merge pull request 'hermes-agent: onboard Nous-Hermes-on-Goose to homelab clients' (#1 ) from hermes-onboarding into main
authentik Default Admin
2026-06-01 22:27:09 +02:00
f25d9e0648
hermes-agent: onboard Nous-Hermes-on-Goose to homelab clients
dtoro
2026-05-31 01:18:43 +02:00
563dbe21b1
arch-migration P2: Technitium dns LXC (107); retire LXC 124
dtoro
2026-06-01 22:10:18 +02:00
4b713d7805
arch-migration P1: document sso.hubris.network outpost callback domain
dtoro
2026-06-01 00:45:25 +02:00
2762dcbdb8
arch-migration P1: dedicated forward-auth outpost (LXC 106)
dtoro
2026-06-01 00:33:26 +02:00
8dbba323c1
authentik: migrate from LXC 124 to VPS; eliminate mesh bootstrap deadlock
dtoro
2026-05-31 23:17:00 +02:00
4560e25bd7
hermes-agent: onboard Nous-Hermes-on-Goose to homelab clients
hermes-onboarding
dtoro
2026-05-31 01:18:43 +02:00
04d1f39e7b
mesh: document 2026-05-31 recovery + auth.hubris.network Traefik route
root
2026-05-31 00:05:55 +02:00
b34d362c19
photos: mule-image cutover to PhotoPrism stack on 120, retire 127
dtoro
2026-05-22 00:53:34 +02:00
0260f01b74
render-vps-configs: drop _comment from management.json template
dtoro
2026-05-21 22:30:46 +02:00
b12f80933d
render-vps-configs: print masked unified diff in --dry-run
dtoro
2026-05-21 22:29:10 +02:00
8ef17dba3d
sops-encrypt TURN password + Authentik client secret; homelab render-vps-configs
dtoro
2026-05-21 22:21:06 +02:00
21063015c7
homelab CLI: per-host ssh.user + LAN→mesh fallback; wiki for netbird-ssh JWT issuer fix
dtoro
2026-05-21 21:57:19 +02:00
d41d73f323
device-code onboarding: bootstrap auto-installs deps + netbird; Authentik device flow wired
dtoro
2026-05-21 15:05:27 +02:00
b42a986cc0
wiki: document 2026-05-21 netbird vanilla migration
dtoro
2026-05-21 13:48:01 +02:00
7a062bdb6b
docs: dpkg-interrupted runbook + apt-fleet ops + non-apt-binary pattern + Claude Code settings + chat-sudo gotcha
dtoro
2026-05-21 09:32:06 +02:00
8f76338b05
bootstrap: install mcp CLI via pipx on workstation enrollment
dtoro
2026-05-21 09:25:58 +02:00
306c397ce1
homelab apt-upgrade: add --safe (pct snapshot + vzdump fallback)
dtoro
2026-05-21 09:24:45 +02:00
2ff7263f3d
homelab: add apt-audit + apt-upgrade subcommands; fix hubris_ssh
dtoro
2026-05-21 09:08:25 +02:00
35c688c56f
bootstrap: install ssh ControlMaster block for netbird peers
dtoro
2026-05-21 08:53:24 +02:00
dd4072f1d4
bootstrap: enable netbird ssh-jwt-cache-ttl on workstation enrollment
dtoro
2026-05-21 08:12:55 +02:00
4c16de8102
secrets-issuance/backup.sh: chmod +x
root
2026-05-20 21:40:10 +02:00
419ab475b1
secrets-issuance backup + homelab doctor smoke-test
root
2026-05-20 21:37:42 +02:00
b4ca21b2b3
inventory: zimaos lan_ip 192.168.8.195
root
2026-05-20 21:31:36 +02:00
dd92c5fd88
inventory: haos has lan_ip 192.168.8.101
root
2026-05-20 21:31:03 +02:00
36a686d953
inventory: real mesh state per host (no more placeholder netbird FQDNs)
root
2026-05-20 21:28:03 +02:00
e7a74f795d
bootstrap.sh: auto-call refresh-creds when the client is a PAT recipient
root
2026-05-20 21:14:03 +02:00
6ed04dd1b0
inventory: declare systemd_unit for the underscore-named services
root
2026-05-20 20:24:31 +02:00
a5ee017291
homelab-mcp.service: SSH as root, the restricted shell is the boundary
root
2026-05-20 20:23:49 +02:00
3f41416805
mcp/server: log ssh failures so silent empties are debuggable
root
2026-05-20 20:23:03 +02:00
2d2446b36e
mcp/server: pre-populated known_hosts for the restricted SSH
root
2026-05-20 20:20:25 +02:00
b5dfbb68ae
mcp: restricted-shell SSH proxy through hubris for management tools
root
2026-05-20 20:18:07 +02:00
2599c28104
homelab client add/remove: surgical inventory edits (preserve comments)
root
2026-05-20 20:14:37 +02:00
aed977aa56
client-remove: test-victim
root
2026-05-20 19:29:47 +02:00
ea3100f091
client-add: test-victim (finalize age_pubkey + grant shared secrets)
root
2026-05-20 19:29:36 +02:00
5a8d6cfd4f
homelab: stop sops-policy scan resetting state on the next rule
root
2026-05-20 19:29:20 +02:00
098d4cfd6e
client-add: test-victim (finalize age_pubkey + grant shared secrets)
root
2026-05-20 19:27:22 +02:00
e016f512b2
client-add: test-victim
root
2026-05-20 19:26:35 +02:00
4316acadaa
homelab client remove: also revoke pubkey from .sops.yaml rules
root
2026-05-20 19:26:07 +02:00
047138a81d
client-add: claudio-bot (finalize age_pubkey + grant shared secrets)
root
2026-05-20 18:39:27 +02:00
af8961d194
bootstrap.sh: LAN probe uses GET not HEAD (issuance only handles GET)
root
2026-05-20 18:39:11 +02:00
ab6b8fabc4
bootstrap.sh: accept LAN reachability as a mesh-equivalent
root
2026-05-20 18:38:41 +02:00
e8c2ccf7bb
wiki: document homelab-context distribution system
root
2026-05-20 18:34:45 +02:00
0b6be9f42d
homelab client add --finalize-pubkey: grant shared secrets atomically
root
2026-05-20 18:30:22 +02:00
65ece6f447
secrets: distribute write-scoped Gitea PAT + homelab refresh-creds
root
2026-05-20 18:25:36 +02:00
90a65bd5a1
noop: verify webhook auto-deploy
root
2026-05-20 18:16:57 +02:00
ce25e73625
bootstrap.sh: store gitea cred helper in /etc/gitconfig, not /root/.gitconfig
root
2026-05-20 18:01:47 +02:00
ae7eb8c649
bootstrap.sh: symlink homelab CLI instead of copy
root
2026-05-20 17:54:24 +02:00
df6aca888c
homelab: re-exec 'secret' via sudo for non-root users
root
2026-05-20 17:48:32 +02:00
58bd4df3b1
client-enrol: republic-laptop pubkey + hello.yaml recipient
root
2026-05-20 17:34:30 +02:00