Commit graph

119 commits

Author SHA1 Message Date
Brian Pooe
6a2af1c91e feat(homeassistant): add mpho night-light dim and switch to sunrise off
Dims mpho_lamb to 10% warm at 02:00 as a night light, and replaces the
fixed 06:00 off trigger with a sun sunrise event so the light goes off
at actual daybreak year-round.
2026-06-28 18:02:57 +02:00
Brian Pooe
8081e0c753 feat(homeassistant): add kids_lambs light group and daily automations
Creates a light group combining mpho_lamb and hloni_lamb, and sets up
four daily automations: on at sunset/18:00 (full cool white), warm dim
at 20:30, hloni off at 22:00, mpho off at 06:00 — all with fade transitions.
setup-homeassistant.sh now deploys automations.yaml alongside configuration.yaml.
2026-06-28 17:59:26 +02:00
Brian Pooe
e2f62deb2d Document Youtarr SMB storage mount 2026-06-28 13:40:08 +02:00
Brian Pooe
cdd4874bf1 Document and proxy Youtarr deployment 2026-06-28 11:59:59 +02:00
Brian Pooe
0fca695aa4 Add Youtarr stack and document PhotoSync storage 2026-06-28 11:47:24 +02:00
Brian Pooe
d59814c8fe fix(homeassistant): harden blueprint for fresh installs and public repo safety
- Add SLZB06_HOST and CADDY_HOST_IP stubs to root .env.sample so cp -n covers all required vars
- Remove dead :-10.0.15.5 default from ha_configuration.yaml (CADDY_HOST_IP is required; default was unreachable)
- Genericise CADDY_HOST_IP comment in ha_configuration.yaml (removed hardcoded personal IP)
- Default zigbee2mqtt pan_id and network_key to GENERATE (remove personal network credentials from public blueprint)
- Remove hardcoded device list from zigbee2mqtt_configuration.yaml (Z2M builds this on pairing)
- Clarify README installation steps: root .env path, missing-var behaviour for SLZB06_HOST and CADDY_HOST_IP
2026-06-27 17:38:04 +02:00
Brian Pooe
86cfe2aecc docs(immich): add phone-to-NAS mobile sync guide and wire mobile_photos share
Documents the FolderSync/PhotoSync → UNAS Pro → Immich external library
pattern as the workaround for immich-app/immich#4282 (deleted photos
re-uploading on next mobile sync). Includes all steps: UNAS share creation,
Proxmox NFS mount, LXC bind mount, docker-compose volume, Immich library
import path update, and per-app config for Android (FolderSync) and iOS
(PhotoSync).

- Adds docs/immich/mobile-sync.md with full step-by-step guide
- Adds mobile_photos to share map in docs/unas/nfs-mounts.md
- Adds IMMICH_MOBILE_SYNC_DIR volume (/mnt/mobile:ro) to template.yaml
- Documents IMMICH_MOBILE_SYNC_DIR in README.md and .env.sample
2026-06-27 15:31:08 +02:00
Brian Pooe
eb3c0a0f00 feat(immich): switch to NVENC for transcoding and CUDA for ML inference
- immich-server: add runtime: nvidia + NVIDIA_DRIVER_CAPABILITIES=video,
  compute,utility to enable NVENC hardware H.264 transcoding
- immich-machine-learning: change image tag to :release-cuda so
  CUDAExecutionProvider is selected over CPUExecutionProvider for CLIP,
  face detection, and OCR
- Update GPU Verification section in README with verification commands
  and note on resetting QSV → NVENC in the admin UI
2026-06-27 12:31:30 +02:00
Brian Pooe
11935bd02a docs(immich): document OIDC-only login, external library setup, and firewall rule
- Adds OIDC disable-password-login workflow to README (enforce SSO after
  confirming Zitadel PKCE works; clarifies client secret is not needed)
- Expands external library section with user UUID lookup and warning about
  Immich blocking paths under the upload volume
- Adds Allow Caddy to Immich rule (10.0.15.5 → 10.0.10.15:2283) to
  firewall-rules.md
2026-06-27 12:18:12 +02:00
Brian Pooe
2fa6de1d4c feat(immich): add external library volume mount for NAS photo recovery
Adds IMMICH_EXTERNAL_LIBRARY volume (mounted read-only at /mnt/external
in the container) so existing photos stored outside the upload folder
can be imported as an external library without triggering Immich's
upload-folder restriction.

Documents the API-based external library creation workflow in README.
2026-06-27 12:10:25 +02:00
Brian Pooe
ac6726c880 fix(immich): fix duplicate reservations key in machine-learning deploy block 2026-06-27 11:18:40 +02:00
Brian Pooe
6099da80f8 fix(immich): add DISABLE_PASSWORD_LOGIN, fix OIDC_AUTO_REDIRECT default, document PKCE 2026-06-27 11:17:22 +02:00
Brian Pooe
c1403bf9b3 fix(immich): align template and docs with official install guide
- Fix upload container path: /usr/src/app/upload -> /data
- Update Redis image: redis:6.2-alpine -> valkey/valkey:9
- Update DB image: tensorchord/pgvecto-rs -> ghcr.io/immich-app/postgres vectorchord
- Fix DB_HOSTNAME: immich-postgres -> database (Docker service name)
- Fix REDIS_HOSTNAME: immich-redis -> redis (Docker service name)
- Replace DOCKERCONFDIR with dedicated IMMICH_DATA_DIR variable
2026-06-27 11:08:09 +02:00
Brian Pooe
f2466096f1 docs(immich): remove arr-stack references, use /opt/immich/appdata paths 2026-06-27 11:00:54 +02:00
Brian Pooe
bba03c675a Fix arr-stack OOM kills and decluttarr auth for 25 GB downloads
- qbittorrent memory limit 1G → 3G: piece-verification buffers for 25 GB+
  torrents exceed 1G and trigger cgroup OOM kill mid-download
- bazarr, prowlarr, seerr limits 512M → 1G: all three were at 40-67% at
  idle with insufficient headroom for subtitle batch events, RSS floods,
  and Emby library syncs respectively
- Add *media-data-mount and storage-guard dependency to decluttarr so
  detect_deletions can access /data/media paths
- Fix decluttarr auth ban loop: add Docker bridge 172.18.0.0/16 to
  qBittorrent WebUI auth subnet whitelist (applied live via API)
- Update README mount table (Decluttarr now gets /data/media), memory
  limit table with per-service rationale sized for 25 GB average files
- Add TROUBLESHOOTING sections 5e-5j covering qBittorrent path issues,
  OOM kill pattern, and decluttarr auth ban loop with fixes

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-21 17:52:19 +02:00
Brian Pooe
4db6fdc36b Fix WebSocket for UDM and UNAS by stripping Origin header
UniFi devices validate the Origin header on WebSocket upgrades and reject
connections where it doesn't match their own hostname, causing real-time
dashboard stats to show N/A. Add unifi-upstream snippet that strips Origin
before forwarding, and apply it to both udm and unas proxy blocks.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-20 22:15:22 +02:00
Brian Pooe
c4b6fd0783 Add UDM Pro SE and UNAS Pro to Caddyfile
Both use self-signed TLS backends so they get the office-admin-upstream
snippet (tls_insecure_skip_verify). Update firewall backend policy table
in network docs to match.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-20 21:43:01 +02:00
Brian Pooe
59f41d8964 Update Caddyfile: switchlite8poe IP, remove tplink16de and speedtest
- switchlite8poe moved to 10.0.1.6
- tplink16de removed (device no longer exists)
- speedtest removed (no longer needed)
- Update firewall backend policy table in network docs to match

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-20 21:37:32 +02:00
Brian Pooe
34da2eb196 Document deployment lessons from arr-stack LXC build
Four issues encountered during the arr-stack LXC 101 deployment that were not
covered or not clear enough in existing docs:

PROXMOX-NVIDIA-LXC.md — expanded Section 4 into four explicit sub-steps:
  4a: copy installer into LXC via pct push (it lives on the Proxmox host)
  4b: install userspace libs with --no-kernel-module then run ldconfig
  4c: install Container Toolkit (must come after libs, not before)
  4d: switch runtime mode auto→legacy with clear explanation of why CDI fails
      in an LXC even after the libraries are installed

TROUBLESHOOTING.md — new section 5c for the stale gluetun namespace error:
  "joining network namespace of container: No such container"
  Cause: gluetun recreated with new container ID, qbittorrent holds old ID
  Fix: docker rm -f qbittorrent && docker compose up -d qbittorrent
  Renumbered old 5c (HTTPS 502) to 5d

arr-stack README.md — AirVPN preshared key warning in the Installation section:
  AirVPN generates per-server preshared keys; the built-in airvpn provider
  selects a server dynamically so the key never matches → silent VPN failure.
  Documents when and how to use VPN_SERVICE_PROVIDER=custom with a pinned server.

DEPLOYMENT.md — two new sections:
  Section 9: Set a Static IP — via Proxmox .conf net0 line, not inside the LXC
  Section 10: Rename a Container (VMID change) — lvrename + conf file swap

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-20 15:44:30 +02:00
Brian Pooe
adf98ff727 Move arr-stack from Synology (10.0.10.24) to LXC 101 (10.0.10.20)
Update all media stack reverse proxy upstreams from .24 to .20 and rename
the section header from "Synology Media Stack" to "Arr Stack (LXC 101, 10.0.10.20)".

On the Caddy host: git pull, re-render Caddyfile, validate, and reload:
  ./substitute_env.sh docker-compose-files/caddy/Caddyfile_template docker-compose-files/caddy/Caddyfile .env
  chmod 644 docker-compose-files/caddy/Caddyfile
  docker compose -f docker-compose.caddy.yml exec caddy caddy validate --config /etc/caddy/Caddyfile
  docker compose -f docker-compose.caddy.yml exec caddy caddy reload --config /etc/caddy/Caddyfile

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-20 15:39:07 +02:00
Brian Pooe
8b546ac123 Support Gluetun custom provider and document NVIDIA legacy mode for LXC
- Add optional WIREGUARD_PUBLIC_KEY, WIREGUARD_ENDPOINT_IP, WIREGUARD_ENDPOINT_PORT
  to gluetun template so custom provider renders cleanly without manual patching
- Make SERVER_COUNTRIES optional (:-) so re-renders don't fail for custom provider
- Document the required mode = "legacy" change in /etc/nvidia-container-runtime/config.toml
  for NVIDIA Container Toolkit in a privileged LXC; the default "auto" CDI mode fails
  until userspace libraries are installed and the mode is explicitly set to legacy

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-20 15:20:54 +02:00
Brian Pooe
e02f79092f Fix arr-stack docs for real-world UNAS NFSv3 constraints
Correct DEPLOYMENT.md fstab entry (vers=3, UUID path, 10.0.10.25) and
add No Root Squash requirement note to the chown step. Fix arr-stack
README to document host-side chown from a privileged LXC instead of
the incorrect unprivileged-LXC warning. Also carries forward nfs-mounts.md
from the previous session.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-20 14:23:25 +02:00
Brian Pooe
b67c32c2e9 Harden strict substitution workflow 2026-06-17 22:15:54 +02:00
Brian Pooe
78f42fc7ca Remove Node-RED stack and associated configurations 2026-06-17 18:42:57 +02:00
Brian Pooe
fc2d5b24ca Standardize UNAS share naming to underscores (arr_data) 2026-06-16 18:08:58 +02:00
Brian Pooe
7dd49a94ab Streamline documentation for privileged LXC and GPU support 2026-06-16 18:01:02 +02:00
Brian Pooe
2bedd9f7b2 Update Immich data share naming to immich_data 2026-06-16 17:52:03 +02:00
Brian Pooe
fccb2220ad Update Immich configuration for dedicated UNAS share 2026-06-16 17:51:19 +02:00
Brian Pooe
b972e3fe07 Add Immich template with NVIDIA GPU acceleration support 2026-06-16 17:48:36 +02:00
Brian Pooe
a8c22c8267 Integrate NVIDIA GPU passthrough for Proxmox 9 and arr-stack 2026-06-16 17:15:53 +02:00
Brian Pooe
396df066d4 Document Recyclarr bootstrap sequence 2026-06-15 22:16:56 +02:00
Brian Pooe
b0730b342f Align Arr Stack storage with TRaSH Guides 2026-06-15 22:12:17 +02:00
Brian Pooe
21db349dbd Document Arr Stack environment variables 2026-06-15 21:54:29 +02:00
Brian Pooe
2547531125 Document LXC sizing and Gateway exceptions 2026-06-15 21:49:28 +02:00
Brian Pooe
20e4ad095d Use named volumes for application state 2026-06-15 20:07:48 +02:00
Brian Pooe
7de1c4dd60 Document Caddyfile read permissions 2026-06-15 19:53:13 +02:00
Brian Pooe
84be803d1a Correct UniFi DNS enforcement guidance 2026-06-15 19:49:52 +02:00
Brian Pooe
1a851eb5dd Document VLAN DNS DNAT rules and Caddy client VLAN access
Add exact UniFi 9.x NAT panel steps for DNS DNAT redirect (FAMILY, MEDIA,
IOT, GUEST) and verification procedure to the zone migration guide. Add
Client VLAN Access section to the Caddy README with firewall rules for
FAMILY and MEDIA to reach Caddy over HTTPS.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-15 18:40:23 +02:00
Brian Pooe
1ac9c72619 Clarify latest Technitium UDM setup 2026-06-15 16:08:52 +02:00
Brian Pooe
beb6eb1ed3 Document UDM Technitium DNS rollout 2026-06-15 11:27:32 +02:00
Brian Pooe
7628ddac36 Update DNS host deployment details 2026-06-15 11:19:21 +02:00
Brian Pooe
708f260cfc Standardize stack deployment guides 2026-06-15 10:53:29 +02:00
Brian Pooe
40cd9f6788 Simplify Technitium deployment guide 2026-06-15 10:39:59 +02:00
Brian Pooe
50ed8305d5 Simplify Caddy deployment guide 2026-06-15 10:32:52 +02:00
Brian Pooe
02f061f238 Feature-slice Caddy configuration 2026-06-13 17:47:19 +02:00
Brian Pooe
a2fe91b125 feat: caddy setup 2026-06-13 17:41:31 +02:00
Brian Pooe
6b343a593c Add Raspberry Pi Caddy deployment 2026-06-13 17:25:27 +02:00
Brian Pooe
71f4b838fd Document phased UDM Pro SE zone migration 2026-06-13 17:09:02 +02:00
Brian Pooe
5148bbe47f Update Technitium deployment documentation 2026-06-13 16:15:32 +02:00
Brian Pooe
d99d21263a fix: documentation alignment to new hardware 2026-06-12 18:14:16 +02:00