Problem: docs-lint (added in the wiki-hq reorg) surfaced 126 broken relative
links that predated this session — a container rename, incident/plan docs
that moved into archive/done subfolders without their inbound links being
updated, and a handful of relative-depth bugs in files nested under
containers/archive/ and plans/done/.
Fixes applied, by category:
- 124-authentik.md -> 106-auth-outpost.md (container was renamed; ~40 refs).
- investigations/{2026-04-21-hubris-crash-loop,2026-05-31-authentik-vps-migration}.md
-> archive/ prefix (both moved to investigations/archive/ previously).
- plans/{2026-06-01-slate-ax-to-sodola-migration,2026-06-04_130000-deprecate-claudio-bot,
2026-06-25-yuvomi-deployment}.md -> plans/done/ prefix.
- Depth bugs in files nested one level deeper than their siblings assumed
(investigations/archive/*, knowledge/wiki/containers/archive/*,
plans/done/*) — corrected relative-path depth.
- Destroyed containers with no surviving page (126-plato) delinked to the
containers/index.md archaeology row instead of a 404.
- ludo-mini.yaml -> strong.yaml (host was renamed, same physical machine).
- netbird-vps.md (no narrative page exists) -> netbird-vps.yaml (substrate
record, matching the existing convention for hosts without a wiki page).
- runbook-dpkg-interrupted.md refs -> .agents/skills/runbook-dpkg-interrupted/SKILL.md
(missed in the phase-4 runbook move because the referencing files used a
bare filename, not a runbooks/ prefix).
- One dangling forward-reference to a never-written investigation delinked
to the actual incident record it was describing.
Left alone: two links in knowledge/wiki/containers/101-jellyfin.md into
devops/homelab-authentik-admin/ — an intentional reference to a sibling repo,
not present in this checkout.
Verification: broken-link count 126 -> 2 (real remainder is the cross-repo
reference above); gen-topology.py --check still exit 0; build_host_files.py
still idempotent; all inventory.yaml doc_page targets still resolve.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
45 lines
2.0 KiB
Markdown
45 lines
2.0 KiB
Markdown
# 108 — `haos-16.3`
|
|
|
|
Home Assistant OS — the only VM on hubris (HAOS doesn't run cleanly in an LXC, hence the qm tenant).
|
|
|
|
## At a glance
|
|
- **Type:** QEMU VM
|
|
- **HAOS version:** 16.3 (last verified)
|
|
- **IP:** `192.168.8.101`
|
|
- **Resources:** 4 GiB RAM, 32 GiB boot disk
|
|
- **Public hostname:** [`home.hubris.network`](../infrastructure/dns.md) → [caddy (121)](../containers/121-caddy.md) → `192.168.8.101:8123`
|
|
|
|
## Auth
|
|
|
|
Native OIDC via the HACS integration `christiaangoossens/hass-oidc-auth` (repo `https://github.com/christiaangoossens/hass-oidc-auth`).
|
|
|
|
Key gotchas:
|
|
- HAOS containers don't honor the Network-panel DNS. Set Supervisor DNS via:
|
|
```
|
|
ha dns options --servers "dns://192.168.8.180" --servers "dns://1.1.1.1"
|
|
```
|
|
so OIDC discovery resolves internally to [authentik (124)](../containers/106-auth-outpost.md).
|
|
- Authentik app slug in the discovery URL is whatever was set in Authentik — confirm via the DB rather than guessing. User set `home-assistant` (with hyphen).
|
|
- YAML config:
|
|
- `features.automatic_user_linking: true` — link to existing HA users by `preferred_username` match (otherwise a duplicate is created).
|
|
- `features.default_redirect: true` — skip the welcome-splash so users land on the normal HA login page.
|
|
- Run `ha core restart` after each config change — HA caches DNS and OIDC discovery across frontend reloads.
|
|
|
|
## Telemetry
|
|
|
|
HA pulls Proxmox metrics via the official Proxmox VE integration. As of 2026-04-21 [claudio-monitor](../infrastructure/monitoring.md) stopped publishing to MQTT/REST (commit `82f0596`) — HA gets metrics from PVE directly; claudio-monitor focuses on alerting.
|
|
|
|
## Related
|
|
- [Authentik (124)](../containers/106-auth-outpost.md)
|
|
- [Caddy (121)](../containers/121-caddy.md)
|
|
- [DNS](../infrastructure/dns.md)
|
|
- [Monitoring](../infrastructure/monitoring.md)
|
|
|
|
## Changelog
|
|
|
|
### 2026-04-28 — wiki entry created
|
|
Initial documentation.
|
|
|
|
### 2026-04-21 — wired into Authentik via HACS hass-oidc-auth
|
|
Supervisor DNS pointed at LXC 124 dnsmasq; YAML features for auto-linking + default redirect.
|