Commit Graph
51 Commits
Author SHA1 Message Date
m3ta-chiron f1481dc256 feat: AtroPIM deployment config for AZ-PRM-1 (AZ-NIX-ava.2)
- port registry: atrocore = 3058
- oci-container atrocore: Gitea-registry image, 127.0.0.1:3058:80,
  web network, static ip 10.89.0.16, db alias to host pg, env-file
  from agenix, named volume for instance data, registry login via
  token secret
- agenix secrets: atrocore-env (ATRO_DB_*) + atrocore-registry-token,
  age-encrypted to AZ-PRM-1 + user, non-interactive creation
- host postgres 17: idempotent atrocore-db-init oneshot (psql peer,
  secret only at runtime), pg_hba 10.89.0.0/24 scram-sha-256,
  atrocore in 03:10 backup list
- traefik: pim.l.az-gruppe.com -> localhost:3058 (ionos, websecure)
2026-08-17 13:45:21 +02:00
sascha.koenig 705702abee feat: AtroPIM image pipeline with secret-free build (AZ-NIX-ava.1)
- flake input atrocore-docker rev-pinned (e1e9bed)
- pkgs/atropim-image: atropim-build/atropim-push scripts + 2-stage
  podman build (vendor pdf target + entrypoint wrapper)
- entrypoint writes ATRO_DB_* to data/config.php at runtime,
  guarded by isInstalled (idempotent); no DB credentials in layers
- devShell documents build/push commands and ENV variables
2026-08-17 13:00:06 +02:00
sascha.koenig 5132a4de2f feat: change zammad domain 2026-08-15 09:33:28 +02:00
m3tam3re f8f0d0eba3 feat: pgbounce, librechat upgrade, homarr 2026-08-08 15:37:50 +02:00
sascha.koenig a97e87944b fix: baserow 2026-08-08 07:34:05 +02:00
sascha.koenig 165ac75ba9 fix: enable netbird agent network on existing proxy
Agent Network needs NB_PROXY_PRIVATE=true on the single existing
reverse-proxy, not a separate container. The previous standalone
an-proxy had no TLS cert (removed certs volume + ACME) and crashed
with 'open certs/tls.crt: no such file', so its overlay peer IP
(100.91.226.149) never came up and drop.p.az-gruppe.com timed out.

The auto-generated endpoint under the existing *.p.az-gruppe.com
wildcard (drop.p.az-gruppe.com -> overlay peer IP via MagicDNS) is
the correct URL; the invented a.az-gruppe.com had no DNS.

- set NB_PROXY_PRIVATE=true on netbird-proxy (keeps ACME + certs)
- remove standalone netbird-an-proxy container, anProxyIp, anProxyDomain
- drop netbird-an-proxy-env secret (nix refs + age file)
2026-08-04 12:47:23 +02:00
sascha.koenig bdfeb1f36c chore: bump baserow 2.3.3, litellm 1.95.0, flake inputs 2026-08-04 09:37:57 +02:00
sascha.koenig f7a5eeefa1 feat: netbird agent network private proxy
Add dedicated NB_PROXY_PRIVATE=true reverse-proxy (netbird-an-proxy)
serving agent-network synth endpoints over the WireGuard overlay only.
Configured via NB_PROXY_* env vars, no domain/ACME/Traefik/host port.
Register netbird-an-proxy-env secret.
2026-08-04 09:37:51 +02:00
m3tam3re e836b23c66 +phishboard 2026-07-16 16:35:58 +02:00
sascha.koenig d58173760d fix: litellm -> grafana 2026-07-13 10:32:34 +02:00
sascha.koenig 8d57aa4bc0 feat: grafana loki 2026-07-10 13:10:58 +02:00
sascha.koenig b800bfe08b use grafana default message for ntfy alerts 2026-07-09 21:17:17 +02:00
sascha.koenig ff9fce1875 chore: baserow to 2.3.0 2026-07-09 21:13:16 +02:00
sascha.koenig 2e316813f5 render all grafana alert annotations in ntfy 2026-07-09 21:11:03 +02:00
sascha.koenig b8cd1c421c include grafana alert annotations in ntfy messages 2026-07-09 21:04:46 +02:00
sascha.koenig 4c09725317 format grafana ntfy alerts 2026-07-09 20:46:07 +02:00
sascha.koenig 4c69d2476a monitor kestra with prometheus alerts 2026-07-09 20:38:19 +02:00
sascha.koenig de873eba19 chore: cleanup 2026-07-09 13:25:57 +02:00
sascha.koenig 61fe3f4338 feat: prometheus + grafana 2026-07-09 13:25:15 +02:00
sascha.koenig 800a78848d fix: zammad startup restart-always 2026-07-01 06:30:39 +02:00
sascha.koenig 10b778fa8e + 3dviewer 2026-06-26 09:19:34 +02:00
sascha.koenig 793ae12d24 + excalidraw 2026-06-24 19:45:41 +02:00
sascha.koenig e02b187bfa snipe-it mail setup 2026-06-22 14:32:34 +02:00
sascha.koenig 117816da1a feat(overlays): pin snipe-it 8.6.3 2026-06-22 07:48:44 +02:00
sascha.koenig 5ab3534317 Delete directory 'docs/superpowers' 2026-06-20 10:47:15 +02:00
m3tam3re 4bbea5a7f0 chore: litellm update 2026-06-20 10:38:20 +02:00
m3tam3re b266deedb8 feat: prune old cld backups after sync 2026-06-20 10:20:29 +02:00
m3tam3re 14008a4bc9 fix: encrypt backup sync ssh key correctly 2026-06-20 09:32:19 +02:00
m3tam3re 775bd59613 fix: run backup mirror exactly at five 2026-06-20 09:12:03 +02:00
m3tam3re fdb79b8763 feat: mirror cld var backups to prm 2026-06-20 09:10:48 +02:00
m3tam3re a8ef749312 chore: zammad upgrade 2026-06-20 06:43:39 +02:00
m3tam3re 4e9fca4513 chore: snipe-it fix postInstall script 2026-06-19 09:01:22 +02:00
sascha.koenig 0147b42ce3 feat: snipe-it on AZ-CLD-1 2026-06-19 04:51:53 +02:00
sascha.koenig a3d4bd7ab5 feat(az-cld-1): add snipe-it service 2026-06-18 10:28:14 +02:00
sascha.koenig e344edfe2c n8n update 2026-06-11 08:55:46 +02:00
sascha.koenig 3eb3dd5e22 chore: ignore local worktrees 2026-06-09 08:29:55 +02:00
sascha.koenig 2948f8878f docs: plan frappe bench infrastructure 2026-06-09 07:46:54 +02:00
sascha.koenig f13b50a161 feat(n8n): enable task runners 2026-06-09 07:09:37 +02:00
sascha.koenig e5d7c2b22b docs: require agenix for frappe secrets 2026-06-09 07:09:37 +02:00
sascha.koenig 1c3ecce5ca docs: design frappe bench infrastructure 2026-06-09 07:09:37 +02:00
sascha.koenig 712feb1fa3 changes zugferd service 2026-06-09 07:09:37 +02:00
sascha.koenig 3c67abafd8 dist upgrade 26.05 2026-06-09 07:09:37 +02:00
sascha.koenig 533a2d8cb4 chore: n8n update 2026-06-09 07:09:37 +02:00
m3tam3re 3ed5c46867 chore: librechat update 2026-05-26 20:56:37 +02:00
sascha.koenig af282e0759 chore: zugferd-service update 2026-05-21 14:51:17 +02:00
sascha.koenig 8a57c6da37 feat: kuma agent for baserow 2026-05-19 07:50:50 +02:00
sascha.koenig d20160b708 chore: update baserow 2026-05-19 06:50:06 +02:00
sascha.koenig cbd4ffd4ee chore: update n8n 2026-05-19 06:42:51 +02:00
sascha.koenig 8aac2a5e48 chore: flake update 2026-05-09 04:42:59 +02:00
sascha.koenig c40da75f66 feat: samba mounts 2026-05-05 09:27:45 +02:00