Commit Graph

  • 2a7876c711 add caveman compression mode to agent bootstrap dtoro 2026-05-25 22:44:06 +02:00
  • f5e23bea0a DNS Phase 4 COMPLETE: single zone — managed zone removed claude/wizardly-sinoussi-1dda3e dtoro 2026-06-21 15:49:36 +02:00
  • 0ff592d237 DNS Phase 4: attempted single-zone, reverted (managed zone load-bearing) dtoro 2026-06-21 15:33:33 +02:00
  • f9f2e8ab5e DNS Phase 2: fix roaming-peer resolution via route distribution dtoro 2026-06-21 15:28:08 +02:00
  • 85457095e4 DNS single-source Phase 1 + decommission Tailscale fleet-wide dtoro 2026-06-21 15:14:07 +02:00
  • a5da521751 docs: Fritz!Box DNSv4 set to Technitium (192.168.8.2) — household LAN now resolves *.hubris.network dtoro 2026-06-18 00:41:36 +02:00
  • 4c83960035 docs: sab.hubris.network Authentik auth — update arriman + caddy pages dtoro 2026-06-13 11:58:21 +02:00
  • ddc5e8771a docs: Authentik session lifetime investigation, fix docs, changelog dtoro 2026-06-06 23:45:59 +02:00
  • ebf521007d docs: emphasize Caddyfile must be edited via dtoro/caddy-conf repo, not directly on LXC dtoro 2026-06-06 14:17:12 +02:00
  • ab3d484824 docs: add investigation entry for 2026-06-05 authentik ident stage skip (broken Trust me policy) dtoro 2026-06-05 20:08:28 +02:00
  • 35b1a25f08 fix: remaining DHCP drifts + improve validation script dtoro 2026-06-05 17:59:46 +02:00
  • b3729a941e fix: gitea DHCP drift + add caddy backend validation script dtoro 2026-06-05 13:21:58 +02:00
  • 3a2270ba86 fix: update paperless (192.168.8.130→243) and haos (192.168.8.101→241) after DHCP lease changes dtoro 2026-06-05 10:51:51 +02:00
  • 6d808a1fd8 arriman: SABnzbd HTTPS enabled on port 9090 dtoro 2026-06-05 00:21:56 +02:00
  • 6b5fed040f arriman: all services behind gluetun, SAB port 8082 fix dtoro 2026-06-05 00:14:06 +02:00
  • 2f81287eb1 cleanup: destroy LXC 124, remove stale docs, update DNS refs to Technitium dtoro 2026-06-04 23:12:06 +02:00
  • 699fd94746 inventory: remove retired LXC 124 (authentik), update dnsmasq→dns service ref dtoro 2026-06-04 23:02:31 +02:00
  • 2d3e979d67 docs: note 2026-06-04 Caddy proxy fixes (auth.hubris.network, sso, forward-auth) dtoro 2026-06-04 22:57:02 +02:00
  • b4500cafc7 mac-mini wired to LAN: update IPs and revert WiFi moonlight/sunshine configs dtoro 2026-06-04 22:05:51 +02:00
  • 728e501435 investigations: add moonlight/sunshine WiFi jitter report + index entry dtoro 2026-06-04 21:05:20 +02:00
  • e32b21072d claudio-bot: decommission LXC 123, archive repos, migrate monitoring to Hermes dtoro 2026-06-04 10:14:56 +02:00
  • fbe76c84d4 fix: ZimaOS static IP set to .195 via systemd-networkd overlay injection dtoro 2026-06-03 23:01:34 +02:00
  • edac189aa7 docs: DHCP pool narrowed to .241-.254; ZimaOS IP drift documented dtoro 2026-06-03 22:50:33 +02:00
  • 4c4cfb56cd fix: remove stray merge marker in .sops.yaml; rekey netbird-pat to 4 recipients dtoro 2026-06-03 22:03:36 +02:00
  • cb1d8b39b9 Merge branch 'main' of git-ssh.hubris.network:dtoro/Homelab-Docs dtoro 2026-06-03 22:02:52 +02:00
  • f81310ae6b dns: Technitium-master sync to NetBird managed zone + cleanup dtoro 2026-06-03 21:59:54 +02:00
  • ce1bf4d0d2 docs: gluetun VPN + static IP migration (2026-06-02) dtoro 2026-06-02 22:42:46 +02:00
  • 41de395240 docs: post-migration changelog entries on hubris, caddy, dns dtoro 2026-06-02 22:02:34 +02:00
  • 99d412370b network: migration complete — Proxmox as subnet router, Technitium DHCP live dtoro 2026-06-02 21:34:56 +02:00
  • 1e7c5a7153 hermes-soul: auto-provision SOUL.md from HERMES.md via setup-hermes-soul.sh dtoro 2026-06-02 00:54:03 +02:00
  • c7f68a095b tools: post-pull auto-setup hook + caveman (RTK-style token optimization) dtoro 2026-06-02 00:31:48 +02:00
  • 3154b3ca02 docs: mark MCP streamable-http migration resolved (#4) dtoro 2026-06-02 00:30:06 +02:00
  • 520a86c986 fix: agent-enrollment.md doc references to use /mcp path dtoro 2026-06-02 00:28:43 +02:00
  • ec48041b54 fix: correct endpoint path to /mcp for streamable-http transport dtoro 2026-06-02 00:25:34 +02:00
  • c299409431 docs: update ssh-access.md + agent-enrollment.md with universal SSH setup dtoro 2026-06-02 00:20:28 +02:00
  • bebebf486a ssh-config: add gen-config.py + homelab ssh-config CLI subcommand dtoro 2026-06-02 00:16:15 +02:00
  • e7bdf9fca7 fix: streamable-http (hyphen, not underscore) in FastMCP transport dtoro 2026-06-02 00:12:59 +02:00
  • 00a891b154 ssh: fix LXC name parsing in deploy-keys.sh (Lock column edge case) dtoro 2026-06-02 00:06:58 +02:00
  • 5adb66237e ssh: add authorized_keys dir + deploy-keys.sh for key distribution dtoro 2026-06-02 00:05:03 +02:00
  • 0a3e43473e inventory: add lan_ip for mac-mini (192.168.8.174) dtoro 2026-06-02 00:00:47 +02:00
  • daf4747c5c post-mortem: mac-mini onboarding — 12 issues found dtoro 2026-06-01 23:45:22 +02:00
  • e615599a2c revert test dtoro 2026-06-01 23:41:19 +02:00
  • 19b2109efc test dtoro 2026-06-01 23:41:06 +02:00
  • 10fdb0fe09 revert: test commit dtoro 2026-06-01 23:34:32 +02:00
  • 946ded6d08 test credential dtoro 2026-06-01 23:34:19 +02:00
  • 95a3ae75c3 hermes-agent: update model to deepseek/deepseek-v4-flash (tool-use support) dtoro 2026-06-01 23:28:43 +02:00
  • 9be6f7f31d openrouter-api-key: seed real key dtoro 2026-06-01 23:24:36 +02:00
  • 5f929ce3ee openrouter-api-key: seed real key root 2026-06-01 23:09:41 +02:00
  • 76bbe99798 client-add: mac-mini (finalize age_pubkey + grant shared + hermes secrets) root 2026-06-01 22:49:01 +02:00
  • 543745cad9 network: retire Slate AX; add SODOLA switch migration plan and network topology doc dtoro 2026-06-01 22:48:02 +02:00
  • ce6df85bb5 Merge pull request 'hermes-agent: onboard Nous-Hermes-on-Goose to homelab clients' (#1) from hermes-onboarding into main authentik Default Admin 2026-06-01 22:27:09 +02:00
  • f25d9e0648 hermes-agent: onboard Nous-Hermes-on-Goose to homelab clients dtoro 2026-05-31 01:18:43 +02:00
  • 563dbe21b1 arch-migration P2: Technitium dns LXC (107); retire LXC 124 dtoro 2026-06-01 22:10:18 +02:00
  • 4b713d7805 arch-migration P1: document sso.hubris.network outpost callback domain dtoro 2026-06-01 00:45:25 +02:00
  • 2762dcbdb8 arch-migration P1: dedicated forward-auth outpost (LXC 106) dtoro 2026-06-01 00:33:26 +02:00
  • 8dbba323c1 authentik: migrate from LXC 124 to VPS; eliminate mesh bootstrap deadlock dtoro 2026-05-31 23:17:00 +02:00
  • 4560e25bd7 hermes-agent: onboard Nous-Hermes-on-Goose to homelab clients hermes-onboarding dtoro 2026-05-31 01:18:43 +02:00
  • 04d1f39e7b mesh: document 2026-05-31 recovery + auth.hubris.network Traefik route root 2026-05-31 00:05:55 +02:00
  • b34d362c19 photos: mule-image cutover to PhotoPrism stack on 120, retire 127 dtoro 2026-05-22 00:53:34 +02:00
  • 0260f01b74 render-vps-configs: drop _comment from management.json template dtoro 2026-05-21 22:30:46 +02:00
  • b12f80933d render-vps-configs: print masked unified diff in --dry-run dtoro 2026-05-21 22:29:10 +02:00
  • 8ef17dba3d sops-encrypt TURN password + Authentik client secret; homelab render-vps-configs dtoro 2026-05-21 22:21:06 +02:00
  • 21063015c7 homelab CLI: per-host ssh.user + LAN→mesh fallback; wiki for netbird-ssh JWT issuer fix dtoro 2026-05-21 21:57:19 +02:00
  • d41d73f323 device-code onboarding: bootstrap auto-installs deps + netbird; Authentik device flow wired dtoro 2026-05-21 15:05:27 +02:00
  • b42a986cc0 wiki: document 2026-05-21 netbird vanilla migration dtoro 2026-05-21 13:48:01 +02:00
  • 7a062bdb6b docs: dpkg-interrupted runbook + apt-fleet ops + non-apt-binary pattern + Claude Code settings + chat-sudo gotcha dtoro 2026-05-21 09:32:06 +02:00
  • 8f76338b05 bootstrap: install mcp CLI via pipx on workstation enrollment dtoro 2026-05-21 09:25:58 +02:00
  • 306c397ce1 homelab apt-upgrade: add --safe (pct snapshot + vzdump fallback) dtoro 2026-05-21 09:24:45 +02:00
  • 2ff7263f3d homelab: add apt-audit + apt-upgrade subcommands; fix hubris_ssh dtoro 2026-05-21 09:08:25 +02:00
  • 35c688c56f bootstrap: install ssh ControlMaster block for netbird peers dtoro 2026-05-21 08:53:24 +02:00
  • dd4072f1d4 bootstrap: enable netbird ssh-jwt-cache-ttl on workstation enrollment dtoro 2026-05-21 08:12:55 +02:00
  • 4c16de8102 secrets-issuance/backup.sh: chmod +x root 2026-05-20 21:40:10 +02:00
  • 419ab475b1 secrets-issuance backup + homelab doctor smoke-test root 2026-05-20 21:37:42 +02:00
  • b4ca21b2b3 inventory: zimaos lan_ip 192.168.8.195 root 2026-05-20 21:31:36 +02:00
  • dd92c5fd88 inventory: haos has lan_ip 192.168.8.101 root 2026-05-20 21:31:03 +02:00
  • 36a686d953 inventory: real mesh state per host (no more placeholder netbird FQDNs) root 2026-05-20 21:28:03 +02:00
  • e7a74f795d bootstrap.sh: auto-call refresh-creds when the client is a PAT recipient root 2026-05-20 21:14:03 +02:00
  • 6ed04dd1b0 inventory: declare systemd_unit for the underscore-named services root 2026-05-20 20:24:31 +02:00
  • a5ee017291 homelab-mcp.service: SSH as root, the restricted shell is the boundary root 2026-05-20 20:23:49 +02:00
  • 3f41416805 mcp/server: log ssh failures so silent empties are debuggable root 2026-05-20 20:23:03 +02:00
  • 2d2446b36e mcp/server: pre-populated known_hosts for the restricted SSH root 2026-05-20 20:20:25 +02:00
  • b5dfbb68ae mcp: restricted-shell SSH proxy through hubris for management tools root 2026-05-20 20:18:07 +02:00
  • 2599c28104 homelab client add/remove: surgical inventory edits (preserve comments) root 2026-05-20 20:14:37 +02:00
  • aed977aa56 client-remove: test-victim root 2026-05-20 19:29:47 +02:00
  • ea3100f091 client-add: test-victim (finalize age_pubkey + grant shared secrets) root 2026-05-20 19:29:36 +02:00
  • 5a8d6cfd4f homelab: stop sops-policy scan resetting state on the next rule root 2026-05-20 19:29:20 +02:00
  • 098d4cfd6e client-add: test-victim (finalize age_pubkey + grant shared secrets) root 2026-05-20 19:27:22 +02:00
  • e016f512b2 client-add: test-victim root 2026-05-20 19:26:35 +02:00
  • 4316acadaa homelab client remove: also revoke pubkey from .sops.yaml rules root 2026-05-20 19:26:07 +02:00
  • 047138a81d client-add: claudio-bot (finalize age_pubkey + grant shared secrets) root 2026-05-20 18:39:27 +02:00
  • af8961d194 bootstrap.sh: LAN probe uses GET not HEAD (issuance only handles GET) root 2026-05-20 18:39:11 +02:00
  • ab6b8fabc4 bootstrap.sh: accept LAN reachability as a mesh-equivalent root 2026-05-20 18:38:41 +02:00
  • e8c2ccf7bb wiki: document homelab-context distribution system root 2026-05-20 18:34:45 +02:00
  • 0b6be9f42d homelab client add --finalize-pubkey: grant shared secrets atomically root 2026-05-20 18:30:22 +02:00
  • 65ece6f447 secrets: distribute write-scoped Gitea PAT + homelab refresh-creds root 2026-05-20 18:25:36 +02:00
  • 90a65bd5a1 noop: verify webhook auto-deploy root 2026-05-20 18:16:57 +02:00
  • ce25e73625 bootstrap.sh: store gitea cred helper in /etc/gitconfig, not /root/.gitconfig root 2026-05-20 18:01:47 +02:00
  • ae7eb8c649 bootstrap.sh: symlink homelab CLI instead of copy root 2026-05-20 17:54:24 +02:00
  • df6aca888c homelab: re-exec 'secret' via sudo for non-root users root 2026-05-20 17:48:32 +02:00
  • 58bd4df3b1 client-enrol: republic-laptop pubkey + hello.yaml recipient root 2026-05-20 17:34:30 +02:00