4560e25bd771e6f492bcf74bab34a63c33ae56e5
`bootstrap.sh --with-hermes` installs the Goose CLI, drops a Goose config pinning the OpenRouter provider + Nous Hermes model + the homelab MCP extension, symlinks `bin/hermes` and HERMES.md, and links HERMES.md as `.goosehints` so the persona is injected as the system prompt every session. `bin/hermes` decrypts `secrets/openrouter-api-key.yaml` via the existing `homelab secret` flow and execs `goose session`. `homelab client add --with-hermes` grants the new sops secret to the host's age_pubkey at finalize time (parallel to the existing shared-secrets grant). `client remove` revokes it. `operations/hermes-agent.md` covers the end-to-end flow, verification, troubleshooting, and queues one follow-up: the MCP server still runs SSE-only but Goose 1.x deprecated SSE — the Goose config targets `streamable_http` and the `homelab` extension won't connect until `mcp/server.py` migrates. The `developer` extension (shell + edit + `homelab` CLI) carries the agent in the meantime. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Homelab Wiki — hubris
Living documentation for the hubris Proxmox homelab. Every node, every cross-cutting system, and every meaningful incident is its own page; pages are linked so you can start anywhere and walk the graph.
Last refreshed against live state: 2026-04-28.
Map
Hosts
hubris— single Proxmox VE node, GMKtec NucBox M6 Ultra,192.168.8.77
VMs
- 100 —
zimaos— ZimaOS 1.6.1, NAS frontend (evaluation) - 108 —
haos-16.3— Home Assistant OS
LXC containers
See the full table in containers/index.md. Quick links:
| ID | Name | IP | Role |
|---|---|---|---|
| 101 | jellyfin | 192.168.8.206 | Media server |
| 102 | nfs-export | 192.168.8.200 | NFSv4 re-export of /mnt/library for ZimaOS |
| 103 | paperless | 192.168.8.130 | Document mgmt |
| 104 | gitea | 192.168.8.121 | Git server |
| 105 | apps | 192.168.8.205 | Docker host (Artifacto / Booklore / PlantUML / Portainer / WriteFreely) |
| 114 | nextcloud | 192.168.8.224 | Personal cloud |
| 118 | elementsynapse | 192.168.8.239 | Matrix Synapse |
| 119 | sophia | 192.168.8.157 | Sophia |
| 120 | mule-images | 192.168.8.136 | Mule-image / mulita photos |
| 121 | caddy | 192.168.8.175 | Reverse proxy |
| 122 | arriman | 192.168.8.132 | Docker host (*arr stack) |
| 123 | claudio-bot | 192.168.8.230 | Matrix control plane |
| 124 | authentik | 192.168.8.180 | SSO + split-horizon DNS |
| 126 | plato | 192.168.8.190 | Plato (notes/discovery workspace) |
Cross-cutting infrastructure
- DNS — split-horizon
- Ingress — Caddy + VPS traefik
- Mesh — Tailscale → Netbird migration
- Monitoring — claudio-monitor
- Media permissions —
mediaGID 10000 - SSH access
- Backups — restic on external drive (disabled)
- Auto-deploy — gitea-webhook pipelines
- VPS hardening — IONOS / netbird control plane
- Homelab context distribution — cross-client
/opt/homelab-context+ MCP + secrets-issuance
Investigations
Time-stamped incident notes / experiments in investigations/.
Operations
- Command cheatsheet
- Agent enrollment — bootstrap a new client (workstation, LXC, VM) into the homelab context system
Conventions
- Each node page ends with a
## Changelogsection. Reverse-chronological. Entry format:### YYYY-MM-DD — short title one or two lines on what changed and why. - Cross-linking is mandatory. If a page references another node or system, link to it. Treat orphans as a bug.
- Live state wins. When something here disagrees with
pct config/docker inspect/ running config, fix the wiki and note the change in the relevant changelog. - Tracked configs. A node whose config lives in a Gitea repo (Caddy, Gitea customizations, Artifacto, mule-image, claudio-bot) is auto-deployed via webhook — see auto-deploy. Edits there must be pushed, not left local.
- No secrets. This is a private repo on
git.hubris.network, but still: paths to secret files are fine, secret values are not.
Maintaining this wiki
When you change a node:
- Update the relevant page (config snapshot, ports, mounts).
- Add a changelog entry at the bottom of that page.
- If the change touches a cross-cutting system (DNS, Caddy, Authentik, mesh), update that page too and link it from the changelog entry.
- If it's an incident, add an entry to
investigations/.
See also
CONTRIBUTING.md— page templates and tone
Description
Languages
Go
53.1%
Svelte
25.7%
TypeScript
14%
Shell
3.8%
Python
1.7%
Other
1.5%