m3ta-chiron
a245e97136
feat: Semaphore UI on AZ-PRM-1 (AZ-NIX-4ux)
2026-08-24 06:43:28 +02:00
sascha.koenig
7595e7c9c8
chore: flake update, pgbouncer SSL fix
2026-08-20 12:36:16 +02:00
sascha.koenig
f06c9164e8
fix: default podman network
2026-08-17 14:20:09 +02:00
m3ta-chiron
6c9cb7b0e7
fix: atrocore-env ownership for atrocore-db-init (AZ-NIX-ava.2)
...
First deploy failed: atrocore-db-init (User=postgres) could not read
/run/agenix/atrocore-env because agenix defaults to root:root:0400.
Follow the pg-cert/pg-key precedent: owner/group postgres, mode 0400.
Podman still reads the env-file and registry token as root (root
bypasses DAC), container pull/run unaffected. Agenix applies
ownership at activation time - no rekey needed. Validated on AZ-PRM-1.
2026-08-17 14:16:09 +02:00
m3ta-chiron
f1481dc256
feat: AtroPIM deployment config for AZ-PRM-1 (AZ-NIX-ava.2)
...
- port registry: atrocore = 3058
- oci-container atrocore: Gitea-registry image, 127.0.0.1:3058:80,
web network, static ip 10.89.0.16, db alias to host pg, env-file
from agenix, named volume for instance data, registry login via
token secret
- agenix secrets: atrocore-env (ATRO_DB_*) + atrocore-registry-token,
age-encrypted to AZ-PRM-1 + user, non-interactive creation
- host postgres 17: idempotent atrocore-db-init oneshot (psql peer,
secret only at runtime), pg_hba 10.89.0.0/24 scram-sha-256,
atrocore in 03:10 backup list
- traefik: pim.l.az-gruppe.com -> localhost:3058 (ionos, websecure)
2026-08-17 13:45:21 +02:00
sascha.koenig
5132a4de2f
feat: change zammad domain
2026-08-15 09:33:28 +02:00
m3tam3re
f8f0d0eba3
feat: pgbounce, librechat upgrade, homarr
2026-08-08 15:37:50 +02:00
sascha.koenig
a97e87944b
fix: baserow
2026-08-08 07:34:05 +02:00
sascha.koenig
165ac75ba9
fix: enable netbird agent network on existing proxy
...
Agent Network needs NB_PROXY_PRIVATE=true on the single existing
reverse-proxy, not a separate container. The previous standalone
an-proxy had no TLS cert (removed certs volume + ACME) and crashed
with 'open certs/tls.crt: no such file', so its overlay peer IP
(100.91.226.149) never came up and drop.p.az-gruppe.com timed out.
The auto-generated endpoint under the existing *.p.az-gruppe.com
wildcard (drop.p.az-gruppe.com -> overlay peer IP via MagicDNS) is
the correct URL; the invented a.az-gruppe.com had no DNS.
- set NB_PROXY_PRIVATE=true on netbird-proxy (keeps ACME + certs)
- remove standalone netbird-an-proxy container, anProxyIp, anProxyDomain
- drop netbird-an-proxy-env secret (nix refs + age file)
2026-08-04 12:47:23 +02:00
sascha.koenig
bdfeb1f36c
chore: bump baserow 2.3.3, litellm 1.95.0, flake inputs
2026-08-04 09:37:57 +02:00
sascha.koenig
f7a5eeefa1
feat: netbird agent network private proxy
...
Add dedicated NB_PROXY_PRIVATE=true reverse-proxy (netbird-an-proxy)
serving agent-network synth endpoints over the WireGuard overlay only.
Configured via NB_PROXY_* env vars, no domain/ACME/Traefik/host port.
Register netbird-an-proxy-env secret.
2026-08-04 09:37:51 +02:00
m3tam3re
e836b23c66
+phishboard
2026-07-16 16:35:58 +02:00
sascha.koenig
d58173760d
fix: litellm -> grafana
2026-07-13 10:32:34 +02:00
sascha.koenig
8d57aa4bc0
feat: grafana loki
2026-07-10 13:10:58 +02:00
sascha.koenig
b800bfe08b
use grafana default message for ntfy alerts
2026-07-09 21:17:17 +02:00
sascha.koenig
ff9fce1875
chore: baserow to 2.3.0
2026-07-09 21:13:16 +02:00
sascha.koenig
2e316813f5
render all grafana alert annotations in ntfy
2026-07-09 21:11:03 +02:00
sascha.koenig
b8cd1c421c
include grafana alert annotations in ntfy messages
2026-07-09 21:04:46 +02:00
sascha.koenig
4c09725317
format grafana ntfy alerts
2026-07-09 20:46:07 +02:00
sascha.koenig
4c69d2476a
monitor kestra with prometheus alerts
2026-07-09 20:38:19 +02:00
sascha.koenig
61fe3f4338
feat: prometheus + grafana
2026-07-09 13:25:15 +02:00
sascha.koenig
800a78848d
fix: zammad startup restart-always
2026-07-01 06:30:39 +02:00
sascha.koenig
10b778fa8e
+ 3dviewer
2026-06-26 09:19:34 +02:00
sascha.koenig
793ae12d24
+ excalidraw
2026-06-24 19:45:41 +02:00
sascha.koenig
e02b187bfa
snipe-it mail setup
2026-06-22 14:32:34 +02:00
m3tam3re
4bbea5a7f0
chore: litellm update
2026-06-20 10:38:20 +02:00
m3tam3re
b266deedb8
feat: prune old cld backups after sync
2026-06-20 10:20:29 +02:00
m3tam3re
14008a4bc9
fix: encrypt backup sync ssh key correctly
2026-06-20 09:32:19 +02:00
m3tam3re
775bd59613
fix: run backup mirror exactly at five
2026-06-20 09:12:03 +02:00
m3tam3re
fdb79b8763
feat: mirror cld var backups to prm
2026-06-20 09:10:48 +02:00
m3tam3re
a8ef749312
chore: zammad upgrade
2026-06-20 06:43:39 +02:00
m3tam3re
4e9fca4513
chore: snipe-it fix postInstall script
2026-06-19 09:01:22 +02:00
sascha.koenig
0147b42ce3
feat: snipe-it on AZ-CLD-1
2026-06-19 04:51:53 +02:00
sascha.koenig
a3d4bd7ab5
feat(az-cld-1): add snipe-it service
2026-06-18 10:28:14 +02:00
sascha.koenig
f13b50a161
feat(n8n): enable task runners
2026-06-09 07:09:37 +02:00
sascha.koenig
3c67abafd8
dist upgrade 26.05
2026-06-09 07:09:37 +02:00
m3tam3re
3ed5c46867
chore: librechat update
2026-05-26 20:56:37 +02:00
sascha.koenig
d20160b708
chore: update baserow
2026-05-19 06:50:06 +02:00
sascha.koenig
cbd4ffd4ee
chore: update n8n
2026-05-19 06:42:51 +02:00
sascha.koenig
8aac2a5e48
chore: flake update
2026-05-09 04:42:59 +02:00
sascha.koenig
c40da75f66
feat: samba mounts
2026-05-05 09:27:45 +02:00
sascha.koenig
c0e781bf00
first commit
2026-05-05 08:30:51 +02:00