Phase 1 — fix stale state after strong migration (Phase 1+2, 2026-07-05)
- README: corrected IPs (jellyfin 206→246, arriman 132→245, etc.),
added missing containers (128 trmnl, 129 house, 133 seanime, 134 romm,
124 authentik), updated last-refreshed date, added strong host context
- containers/101-jellyfin.md: IP 206→246, host hubris→strong, mount
/mnt/library→/mnt/media_local, GPU 760M→680M+RX7600, privilege→priv
- containers/118-elementsynapse.md: IP 239→242, added Host: strong
- containers/122-arriman.md: IP 132→245, mount→/mnt/media_local, added Host
- containers/129-house.md: IP 212→244, added Host: strong
- containers/130-grimmory.md: IP 213→247, mount→/mnt/media_local, added Host
- containers/121-caddy.md: fixed site list (books→grimmory, removed auth→VPS,
added house, roms, teddy, trmnl)
- hosts/strong.md: updated At-a-glance to reflect 7 LXCs hosted
- containers/123-claudio-bot.md, 127-mule-photos-new.md: archived to
containers/archive/ (were destroyed LXCs with living pages)
- inventory.yaml: verified correct — no changes needed
Phase 2 — structural cleanup
- infrastructure/index.md: one-page overview of all cross-cutting systems
- runbooks/: moved runbook-budget-from-csv.md and runbook-dpkg-interrupted.md
from operations/ with YAML frontmatter added
- plans/done/: moved 4 completed plans out of active view; updated index
- vms/index.md: added VM index page
Phase 3 — navigation & discoverability
- GLOSSARY.md: term definitions (Authentik, Caddy, LXC, VAAPI, etc.)
- README: added table of contents, links to glossary + infrastructure index
- investigations/: archived 2 resolved cases (crash-loop, authentik-migration)
to investigations/archive/; updated index with active vs archived sections
Phase 4 — ongoing discipline
- CONTRIBUTING.md: documented same-session update rule with explicit checklist
- README: replaced full LXC table with summary + link to containers/index.md
(single source of truth; de-duplication)
6.3 KiB
6.3 KiB
LXC containers — index
Most containers live on hubris. Some have been
migrated to strong (Phase 1+2, 2026-07-05).
| ID | Name | Host | IP | Priv | Cores | RAM | Disk | Mounts | Public hostname | Status |
|---|---|---|---|---|---|---|---|---|---|---|
| 101 | jellyfin | strong | 192.168.8.246 | priv | 4 | 8 GiB | 16 GiB | /mnt/media_local (via mp0) |
media.hubris.network |
running |
| 103 | paperless | hubris | 192.168.8.130 | priv | 2 | 3 GiB | 8 GiB | /mnt/library |
paperless.hubris.network |
running |
| 104 | gitea | hubris | 192.168.8.121 | priv | 1 | 1 GiB | 8 GiB | /mnt/library |
git.hubris.network |
running |
| 105 | apps | hubris | 192.168.8.205 | priv | 2 | 4 GiB | 30 GiB | /mnt/library |
docker / artifacto / blog |
running |
| 114 | nextcloud | hubris | 192.168.8.224 | priv | 4 | 6 GiB | 25 GiB | /mnt/library |
cloud.hubris.network |
running |
| 118 | elementsynapse | strong | 192.168.8.242 | unpriv | 2 | 4 GiB | 32 GiB | — | matrix.hubris.network |
running |
| 119 | sophia | hubris | 192.168.8.157 | priv | 2 | 1 GiB | 10 GiB | /mnt/library |
— | running |
| 120 | mule-images | hubris | 192.168.8.136 | priv | 6 | 12 GiB | 60 GiB | /mnt/library + /dev/dri (iGPU) |
photos.hubris.network |
running |
| 121 | caddy | hubris | 192.168.8.175 | unpriv | 1 | 512 MiB | 6 GiB | — | (terminates all *.hubris.network) |
running |
| 122 | arriman | strong | 192.168.8.245 | priv | 4 | 8 GiB | 24 GiB | /mnt/media_local (via mp0) |
jellyseerr / qbit / sab |
running |
| 124 | authentik | hubris | 192.168.8.180 | priv | 2 | 4 GiB | 20 GiB | — | auth.hubris.network |
running |
| 128 | trmnl | hubris | 192.168.8.211 | unpriv | 1 | 768 MiB | 8 GiB | — | trmnl.hubris.network |
running |
| 129 | house | strong | 192.168.8.244 | unpriv | 2 | 3 GiB | 8 GiB | — | house.hubris.network |
running |
| 130 | grimmory | strong | 192.168.8.247 | priv | 1 | 2 GiB | 16 GiB | /mnt/media_local (via mp0) |
books.hubris.network |
running |
| 132 | rclone | hubris | 192.168.8.214 | priv | 1 | 1 GiB | 8 GiB | /mnt/library (ro) |
— (LAN-only UI :5572) |
|
| 134 | romm | strong | 192.168.8.249 | priv | 1 | 2 GiB | 16 GiB | /mnt/media_local (via mp0) |
roms.hubris.network |
Recently destroyed (kept for archaeology)
| ID | Name | Destroyed | Reason |
|---|---|---|---|
| 127 | mule-photos-new | 2026-05-22 | PhotoPrism + sidecar + SvelteKit stack promoted to LXC 120 via Mulimage 2.0 merge (70dc1b6); M0 test LXC retired. Caddy + dnsmasq + gitea webhook + NC webhook listeners all cleaned up in the same cutover. |
| 100 | arr (yunohost) | ~2026-04-28 | Migrated to docker stack on arriman; planned retention window expired |
| 106 | flaresolverr | ~2026-04-28 | Folded into the arriman docker compose |
| 116 | heaper | 2026-05-14 | Decommissioned by user; data subtree at /mnt/library/heaper (224 MiB) retained |
| 126 | plato | 2026-06-28 | Notes/discovery workspace decommissioned; data at /mnt/library/documents/plato retained for archaeology |
| 123 | claudio-bot (destroyed — see archive) | 2026-06-04 | Replaced by Hermes Agent on mac-mini; monitoring migrated to homelab-health-watchdog cron. See deprecation plan |
| 109 | syncthing | 2026-05-14 | Decommissioned by user; /mnt/library/syncthing was already empty |
| 125 | seafile | 2026-05-13 | Seafile Pro evaluation, user disliked the product; teardown also removed files.hubris.network from caddy + dnsmasq |
| 107 | marimo | between 2026-04-21 and 2026-04-28 | Decommissioned |
| 110 | photoprism | between 2026-04-21 and 2026-04-28 | Replaced by mulita |
| 111 | karakeep | between 2026-04-21 and 2026-04-28 | Decommissioned |
| 112 | immich | between 2026-04-21 and 2026-04-28 | Replaced by mulita |
| 115 | reticulum | between 2026-04-21 and 2026-04-28 | Decommissioned |
Several
.conf.bakfiles survive under/etc/pve/lxc/if you need to recover any of the configs.
Conventions
- All net0 are
bridge=vmbr0,ip=dhcpexcept 124 (authentik) which is statically192.168.8.180/24. Containers on strong usebridge=vmbr1with static IPs in the192.168.8.240/28range. onboot=1on every container — the host brings them up afterpve-guests.service.- Bind mounts are declared as
mp0: /mnt/library,mp=/mnt/libraryon hubris, ormp0: /mnt/media_local,mp=/mnt/libraryon strong. - Most containers are privileged. Unprivileged ones require an idmap block in their conf to participate in the media GID 10000 standard.
Related
- Hubris host
- Media permissions
- Caddy — terminates every public hostname
- DNS — split-horizon entries for each subdomain