HA 2026 rejects color_temp (mireds) via the service API with 400 Bad
Request, silently breaking automation actions. Switch all color
parameters to color_temp_kelvin: 6500 (cool white) and 2200 (warm white).
Dims mpho_lamb to 10% warm at 02:00 as a night light, and replaces the
fixed 06:00 off trigger with a sun sunrise event so the light goes off
at actual daybreak year-round.
Creates a light group combining mpho_lamb and hloni_lamb, and sets up
four daily automations: on at sunset/18:00 (full cool white), warm dim
at 20:30, hloni off at 22:00, mpho off at 06:00 — all with fade transitions.
setup-homeassistant.sh now deploys automations.yaml alongside configuration.yaml.
- Add SLZB06_HOST and CADDY_HOST_IP stubs to root .env.sample so cp -n covers all required vars
- Remove dead :-10.0.15.5 default from ha_configuration.yaml (CADDY_HOST_IP is required; default was unreachable)
- Genericise CADDY_HOST_IP comment in ha_configuration.yaml (removed hardcoded personal IP)
- Default zigbee2mqtt pan_id and network_key to GENERATE (remove personal network credentials from public blueprint)
- Remove hardcoded device list from zigbee2mqtt_configuration.yaml (Z2M builds this on pairing)
- Clarify README installation steps: root .env path, missing-var behaviour for SLZB06_HOST and CADDY_HOST_IP
Documents the FolderSync/PhotoSync → UNAS Pro → Immich external library
pattern as the workaround for immich-app/immich#4282 (deleted photos
re-uploading on next mobile sync). Includes all steps: UNAS share creation,
Proxmox NFS mount, LXC bind mount, docker-compose volume, Immich library
import path update, and per-app config for Android (FolderSync) and iOS
(PhotoSync).
- Adds docs/immich/mobile-sync.md with full step-by-step guide
- Adds mobile_photos to share map in docs/unas/nfs-mounts.md
- Adds IMMICH_MOBILE_SYNC_DIR volume (/mnt/mobile:ro) to template.yaml
- Documents IMMICH_MOBILE_SYNC_DIR in README.md and .env.sample
- immich-server: add runtime: nvidia + NVIDIA_DRIVER_CAPABILITIES=video,
compute,utility to enable NVENC hardware H.264 transcoding
- immich-machine-learning: change image tag to :release-cuda so
CUDAExecutionProvider is selected over CPUExecutionProvider for CLIP,
face detection, and OCR
- Update GPU Verification section in README with verification commands
and note on resetting QSV → NVENC in the admin UI
- Adds OIDC disable-password-login workflow to README (enforce SSO after
confirming Zitadel PKCE works; clarifies client secret is not needed)
- Expands external library section with user UUID lookup and warning about
Immich blocking paths under the upload volume
- Adds Allow Caddy to Immich rule (10.0.15.5 → 10.0.10.15:2283) to
firewall-rules.md
Adds IMMICH_EXTERNAL_LIBRARY volume (mounted read-only at /mnt/external
in the container) so existing photos stored outside the upload folder
can be imported as an external library without triggering Immich's
upload-folder restriction.
Documents the API-based external library creation workflow in README.
Updated rack order reflects current hardware (UDM Pro SE in place, dual Pi 4B shelf,
USW-Lite moved to shelf 9). Removed udm-pro-zones-migration.md — migration complete.
README links updated to point to firewall-rules.md instead.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- qbittorrent memory limit 1G → 3G: piece-verification buffers for 25 GB+
torrents exceed 1G and trigger cgroup OOM kill mid-download
- bazarr, prowlarr, seerr limits 512M → 1G: all three were at 40-67% at
idle with insufficient headroom for subtitle batch events, RSS floods,
and Emby library syncs respectively
- Add *media-data-mount and storage-guard dependency to decluttarr so
detect_deletions can access /data/media paths
- Fix decluttarr auth ban loop: add Docker bridge 172.18.0.0/16 to
qBittorrent WebUI auth subnet whitelist (applied live via API)
- Update README mount table (Decluttarr now gets /data/media), memory
limit table with per-service rationale sized for 25 GB average files
- Add TROUBLESHOOTING sections 5e-5j covering qBittorrent path issues,
OOM kill pattern, and decluttarr auth ban loop with fixes
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
nvidia-smi must run before LXC 101 starts to create /dev/nvidia0 and
/dev/nvidia-caps/*. Without it emby fails with nvml insufficient
permissions even though kernel modules are loaded. Documents the
nvidia-init.service and the updated LXC 101 drop-in that requires both
NFS and NVIDIA to be ready before the container starts.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
arr-stack (LXC 101) failed to start on boot because the UNAS NFS mount
was not ready when the Proxmox pre-start hook ran. Documents the root
cause, the global fstab timeout fix, and the per-container systemd
drop-in pattern with a checklist for future containers.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Removing Allow TRUSTED to TRUSTED Any broke SSH to Technitium,
proving UniFi custom zones do not get the default intra-zone allow.
Mark both intra-zone rules as required, not redundant.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Redundant rules to delete (TRUSTED to TRUSTED, IoT to IoT, CADDY to
Gateway DNS), the FAMILY to CADDY action fix, and a review table for
the direct Emby pinholes that bypass Caddy.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Documents the missing and incorrect UniFi policies found during zone
policy review: FAMILY to CADDY action fix, all CADDY to TRUSTED backend
app policies, CADDY to IoT policies, and public DNS block policies per
zone.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reflects the actual deployed zone name in UniFi. Preserves the one
reference to UniFi's built-in DMZ zone in the defaults list (§4).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
UniFi devices validate the Origin header on WebSocket upgrades and reject
connections where it doesn't match their own hostname, causing real-time
dashboard stats to show N/A. Add unifi-upstream snippet that strips Origin
before forwarding, and apply it to both udm and unas proxy blocks.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Both use self-signed TLS backends so they get the office-admin-upstream
snippet (tls_insecure_skip_verify). Update firewall backend policy table
in network docs to match.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- switchlite8poe moved to 10.0.1.6
- tplink16de removed (device no longer exists)
- speedtest removed (no longer needed)
- Update firewall backend policy table in network docs to match
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Explicit ufw deny 22/tcp is dangerous — if run before the targeted
allows it lands at the top of the list and locks out SSH. Replace with
default deny incoming policy, consolidate all UFW commands into a single
ordered sequence, and add verification steps and a note explaining why
order matters.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Four issues encountered during the arr-stack LXC 101 deployment that were not
covered or not clear enough in existing docs:
PROXMOX-NVIDIA-LXC.md — expanded Section 4 into four explicit sub-steps:
4a: copy installer into LXC via pct push (it lives on the Proxmox host)
4b: install userspace libs with --no-kernel-module then run ldconfig
4c: install Container Toolkit (must come after libs, not before)
4d: switch runtime mode auto→legacy with clear explanation of why CDI fails
in an LXC even after the libraries are installed
TROUBLESHOOTING.md — new section 5c for the stale gluetun namespace error:
"joining network namespace of container: No such container"
Cause: gluetun recreated with new container ID, qbittorrent holds old ID
Fix: docker rm -f qbittorrent && docker compose up -d qbittorrent
Renumbered old 5c (HTTPS 502) to 5d
arr-stack README.md — AirVPN preshared key warning in the Installation section:
AirVPN generates per-server preshared keys; the built-in airvpn provider
selects a server dynamically so the key never matches → silent VPN failure.
Documents when and how to use VPN_SERVICE_PROVIDER=custom with a pinned server.
DEPLOYMENT.md — two new sections:
Section 9: Set a Static IP — via Proxmox .conf net0 line, not inside the LXC
Section 10: Rename a Container (VMID change) — lvrename + conf file swap
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add optional WIREGUARD_PUBLIC_KEY, WIREGUARD_ENDPOINT_IP, WIREGUARD_ENDPOINT_PORT
to gluetun template so custom provider renders cleanly without manual patching
- Make SERVER_COUNTRIES optional (:-) so re-renders don't fail for custom provider
- Document the required mode = "legacy" change in /etc/nvidia-container-runtime/config.toml
for NVIDIA Container Toolkit in a privileged LXC; the default "auto" CDI mode fails
until userspace libraries are installed and the mode is explicitly set to legacy
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Correct DEPLOYMENT.md fstab entry (vers=3, UUID path, 10.0.10.25) and
add No Root Squash requirement note to the chown step. Fix arr-stack
README to document host-side chown from a privileged LXC instead of
the incorrect unprivileged-LXC warning. Also carries forward nfs-mounts.md
from the previous session.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add docs/unas/nfs-mounts.md: step-by-step guide covering the UUID-based
volume path structure, enabling NFS per share in UniFi Drive 4.3.6,
fstab entries for all six shares, per-LXC bind mount commands, and
PBS datastore setup for pbs_backup
- Update DOCKERSTORAGEDIR in .env.sample to /mnt/unas/arr_data (was the
generic /mnt/storage placeholder)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>