2084a1583e5aa297a11cfb05c4a591ac4bac10b7
New kernel modules, all wired into `homelab` CLI + tested against live
production where reachable:
- oikos/scheduler.py — Observe stage: HTTP health probes for every
service, disk-usage probes on hubris/strong, writes oikos/state.json
(gitignored — regenerates every run). `homelab service <name> health`
is now cache-first; `--live` forces a fresh probe. Deploys via
oikos/systemd/oikos-scheduler.{timer,service} on LXC 105.
- oikos/drift.py — SOPS-recipient-vs-inventory and lifecycle-consistency
detectors (fully local, no SSH) plus pct-list and Caddy-backend
detectors (best-effort SSH, degrade to an info finding when
unreachable rather than a false drift alarm). Found real, currently-
true drift on first run: republic-laptop's age key granted on every
secret but missing from inventory.yaml, grimmory missing from
hello.yaml's recipients, and an undocumented pve_id 131 on hubris —
recorded in OIKOS.md for the operator, not auto-fixed (each is a
config_mutation/destructive decision).
- oikos/signal.py — the attention layer: raised -> acknowledged ->
acting -> resolved|muted lifecycle, severity-based routing, dedup via
open_signal_for(). `homelab signal list|raise|ack|resolve|mute`.
- oikos/decide.py — the Decide-stage classifier: risk class x blast
radius x ledger-history confidence -> auto-act/escalate. Adds an
action-alias layer (oikos/policy.py ACTION_ALIASES) and auto-infers
service_name from the entity for per-service policy overrides.
`homelab decide <action> <entity>`.
- oikos/approve.py — the escalate route. No dedicated Matrix bot exists
in this homelab, so this is the repo-side half only: request/reply/
grant lifecycle with short-TTL HMAC-signed tokens (new secret
secrets/oikos-approval-hmac.yaml, recipients apps+hubris). Matrix
delivery is Hermes's existing @dtoro:avispero send path (documented
integration contract in the module docstring), not a new bot.
`homelab restart` now mechanically refuses config_mutation/destructive
services without a valid --approval-id, regardless of -y/interactivity.
- oikos/report.py — daily brief + weekly report from signal/approval/
ledger state (no Prometheus yet, so point-in-time counts only).
- plans/2026-07-05-oikos-prometheus-lxc.md — Prometheus is `planned`,
not provisioned: no pve_id is guessed here since Proxmox assigns real
IDs at creation time, and drift already found an unclaimed ID (131) to
investigate first.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Homelab Wiki — hubris
Living documentation for the hubris Proxmox homelab. Every node, every cross-cutting system, and every meaningful incident is its own page; pages are linked so you can start anywhere and walk the graph.
Last refreshed against live state: 2026-04-28.
Map
Hosts
hubris— Proxmox VE node, GMKtec NucBox M6 Ultra,192.168.8.77— runs everything todaystrong— Proxmox VE node (cluster hostnamestrong),192.168.178.181— 2nd member of theHomelabcluster as of 2026-07-01, hosts no guests yet
VMs
- 100 —
zimaos— ZimaOS 1.6.1, NAS frontend (evaluation) - 108 —
haos-16.3— Home Assistant OS
LXC containers
See the full table in containers/index.md. Quick links:
| ID | Name | IP | Role |
|---|---|---|---|
| 101 | jellyfin | 192.168.8.206 | Media server |
| 102 | nfs-export | 192.168.8.200 | NFSv4 re-export of /mnt/library for ZimaOS |
| 103 | paperless | 192.168.8.130 | Document mgmt |
| 104 | gitea | 192.168.8.121 | Git server |
| 105 | apps | 192.168.8.205 | Docker host (Artifacto / PlantUML / Portainer / WriteFreely) |
| 114 | nextcloud | 192.168.8.224 | Personal cloud |
| 118 | elementsynapse | 192.168.8.239 | Matrix Synapse |
| 119 | sophia | 192.168.8.157 | Sophia |
| 120 | mule-images | 192.168.8.136 | Mule-image / mulita photos |
| 121 | caddy | 192.168.8.175 | Reverse proxy |
| 122 | arriman | 192.168.8.132 | Docker host (*arr stack) |
| 124 | authentik | 192.168.8.180 | SSO + split-horizon DNS |
| 130 | grimmory | 192.168.8.213 | Digital library (Grimmory — fork of Booklore) |
| 132 | rclone | 192.168.8.214 | Off-host backup → Proton Drive (rclone + Web GUI) |
Cross-cutting infrastructure
- DNS — split-horizon
- Ingress — Caddy + VPS traefik
- Mesh — Tailscale → Netbird migration
- Monitoring — Hermes health watchdog
- Media permissions —
mediaGID 10000 - SSH access
- Backups — rclone → Proton Drive (LXC 132); restic-on-USB deprecated
- Auto-deploy — gitea-webhook pipelines
- VPS hardening — IONOS / netbird control plane
- Homelab context distribution — cross-client
/opt/homelab-context+ MCP + secrets-issuance
Investigations
Time-stamped incident notes / experiments in investigations/.
Operations
- Command cheatsheet
- Agent enrollment — bootstrap a new client (workstation, LXC, VM) into the homelab context system
Conventions
- Each node page ends with a
## Changelogsection. Reverse-chronological. Entry format:### YYYY-MM-DD — short title one or two lines on what changed and why. - Cross-linking is mandatory. If a page references another node or system, link to it. Treat orphans as a bug.
- Live state wins. When something here disagrees with
pct config/docker inspect/ running config, fix the wiki and note the change in the relevant changelog. - Tracked configs. A node whose config lives in a Gitea repo (Caddy, Gitea customizations, Artifacto, mule-image) is auto-deployed via webhook — see auto-deploy. Edits there must be pushed, not left local.
- No secrets. This is a private repo on
git.hubris.network, but still: paths to secret files are fine, secret values are not.
Maintaining this wiki
When you change a node:
- Update the relevant page (config snapshot, ports, mounts).
- Add a changelog entry at the bottom of that page.
- If the change touches a cross-cutting system (DNS, Caddy, Authentik, mesh), update that page too and link it from the changelog entry.
- If it's an incident, add an entry to
investigations/.
See also
CONTRIBUTING.md— page templates and tone
Description
Languages
Go
53.1%
Svelte
25.7%
TypeScript
14%
Shell
3.8%
Python
1.7%
Other
1.5%