Commit Graph
21 Commits
Author SHA1 Message Date
m3ta-chiron 1772ab207e fix: pin SEMAPHORE_ACCESS_KEY_ENCRYPTION in semaphore env secret 2026-08-24 08:22:43 +02:00
m3ta-chiron a245e97136 feat: Semaphore UI on AZ-PRM-1 (AZ-NIX-4ux) 2026-08-24 06:43:28 +02:00
sascha.koenig 7595e7c9c8 chore: flake update, pgbouncer SSL fix 2026-08-20 12:36:16 +02:00
m3ta-chiron f1481dc256 feat: AtroPIM deployment config for AZ-PRM-1 (AZ-NIX-ava.2)
- port registry: atrocore = 3058
- oci-container atrocore: Gitea-registry image, 127.0.0.1:3058:80,
  web network, static ip 10.89.0.16, db alias to host pg, env-file
  from agenix, named volume for instance data, registry login via
  token secret
- agenix secrets: atrocore-env (ATRO_DB_*) + atrocore-registry-token,
  age-encrypted to AZ-PRM-1 + user, non-interactive creation
- host postgres 17: idempotent atrocore-db-init oneshot (psql peer,
  secret only at runtime), pg_hba 10.89.0.0/24 scram-sha-256,
  atrocore in 03:10 backup list
- traefik: pim.l.az-gruppe.com -> localhost:3058 (ionos, websecure)
2026-08-17 13:45:21 +02:00
sascha.koenig 5132a4de2f feat: change zammad domain 2026-08-15 09:33:28 +02:00
m3tam3re f8f0d0eba3 feat: pgbounce, librechat upgrade, homarr 2026-08-08 15:37:50 +02:00
sascha.koenig 165ac75ba9 fix: enable netbird agent network on existing proxy
Agent Network needs NB_PROXY_PRIVATE=true on the single existing
reverse-proxy, not a separate container. The previous standalone
an-proxy had no TLS cert (removed certs volume + ACME) and crashed
with 'open certs/tls.crt: no such file', so its overlay peer IP
(100.91.226.149) never came up and drop.p.az-gruppe.com timed out.

The auto-generated endpoint under the existing *.p.az-gruppe.com
wildcard (drop.p.az-gruppe.com -> overlay peer IP via MagicDNS) is
the correct URL; the invented a.az-gruppe.com had no DNS.

- set NB_PROXY_PRIVATE=true on netbird-proxy (keeps ACME + certs)
- remove standalone netbird-an-proxy container, anProxyIp, anProxyDomain
- drop netbird-an-proxy-env secret (nix refs + age file)
2026-08-04 12:47:23 +02:00
sascha.koenig f7a5eeefa1 feat: netbird agent network private proxy
Add dedicated NB_PROXY_PRIVATE=true reverse-proxy (netbird-an-proxy)
serving agent-network synth endpoints over the WireGuard overlay only.
Configured via NB_PROXY_* env vars, no domain/ACME/Traefik/host port.
Register netbird-an-proxy-env secret.
2026-08-04 09:37:51 +02:00
m3tam3re e836b23c66 +phishboard 2026-07-16 16:35:58 +02:00
sascha.koenig d58173760d fix: litellm -> grafana 2026-07-13 10:32:34 +02:00
sascha.koenig 8d57aa4bc0 feat: grafana loki 2026-07-10 13:10:58 +02:00
sascha.koenig 61fe3f4338 feat: prometheus + grafana 2026-07-09 13:25:15 +02:00
sascha.koenig e02b187bfa snipe-it mail setup 2026-06-22 14:32:34 +02:00
m3tam3re 14008a4bc9 fix: encrypt backup sync ssh key correctly 2026-06-20 09:32:19 +02:00
m3tam3re fdb79b8763 feat: mirror cld var backups to prm 2026-06-20 09:10:48 +02:00
sascha.koenig a3d4bd7ab5 feat(az-cld-1): add snipe-it service 2026-06-18 10:28:14 +02:00
sascha.koenig e344edfe2c n8n update 2026-06-11 08:55:46 +02:00
sascha.koenig f13b50a161 feat(n8n): enable task runners 2026-06-09 07:09:37 +02:00
sascha.koenig 8a57c6da37 feat: kuma agent for baserow 2026-05-19 07:50:50 +02:00
sascha.koenig c40da75f66 feat: samba mounts 2026-05-05 09:27:45 +02:00
sascha.koenig c0e781bf00 first commit 2026-05-05 08:30:51 +02:00