Pushed dtoro/caddy-conf@c195142: oikos.hubris.network -> 192.168.8.205:8091, Authentik-gated (matches paperless.hubris.network's live pattern — confirmed exact snippet syntax against the real Caddyfile rather than trusting the paraphrase in the original README, which turned out to have the wrong forward_auth target: the live snippet points at 127.0.0.1:8099 on Caddy's own LXC, not 192.168.8.6:9000 as containers/106-auth-outpost.md's older text suggested). Reload verified clean — an unrelated existing route stayed healthy through it. Found and fixed a real deploy-blocking bug in the process: oikos-console.service bound 127.0.0.1 only, but Caddy runs on a different host (121) and can only reach apps (105) over the LAN — the console would have been completely unreachable once deployed. Now binds 0.0.0.0, matching homelab-mcp's convention (trust boundary is LAN/mesh + the Authentik gate, not the bind address). Encountered and deliberately left alone: a pre-existing local clone at /tmp/caddy-conf with an unpushed commit + uncommitted diff about jellyfin's auth gating, from before this clone fell 12 commits behind origin. That work turned out to be superseded (origin already reached the same conclusion — SSO plugin handles jellyfin auth, no forward-auth gate — via a different, already-merged path). Didn't touch it; used a fresh clone instead to avoid any risk of losing or corrupting that state. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
4 lines
771 B
JSON
4 lines
771 B
JSON
{"ts": "2026-07-06T11:05:35+00:00", "agent": "mac-mini", "entity": "host:teddycloud", "action": "activate", "risk": "config_mutation", "verification": "homelab node teddycloud relations", "result": "ok"}
|
|
{"ts": "2026-07-06T11:15:04+00:00", "agent": "mac-mini", "entity": "repo:Homelab-Docs", "action": "register-webhook", "risk": "config_mutation", "result": "ok", "notes": "webhook id 14 for oikos-console deploy"}
|
|
{"ts": "2026-07-06T11:29:56+00:00", "agent": "mac-mini", "entity": "service:caddy", "action": "add-site-block", "risk": "config_mutation", "verification": "curl -s https://git.hubris.network (unrelated route still healthy after reload)", "result": "ok", "notes": "oikos.hubris.network -> 192.168.8.205:8091, Authentik-gated, in dtoro/caddy-conf@c195142"}
|