Commit graph

213 commits

Author SHA1 Message Date
Brian Pooe
7628ddac36 Update DNS host deployment details 2026-06-15 11:19:21 +02:00
Brian Pooe
708f260cfc Standardize stack deployment guides 2026-06-15 10:53:29 +02:00
Brian Pooe
40cd9f6788 Simplify Technitium deployment guide 2026-06-15 10:39:59 +02:00
Brian Pooe
50ed8305d5 Simplify Caddy deployment guide 2026-06-15 10:32:52 +02:00
Brian Pooe
027027a3bb Clarify UniFi step five workflow 2026-06-14 14:25:18 +02:00
Brian Pooe
80c1a3c4da Add worked UniFi policy example 2026-06-14 14:21:11 +02:00
Brian Pooe
933af8bdd6 Document exact UniFi address policies 2026-06-14 14:12:02 +02:00
Brian Pooe
b114487ede Clarify UniFi 10.4 policy address matching 2026-06-14 14:05:56 +02:00
Brian Pooe
02f061f238 Feature-slice Caddy configuration 2026-06-13 17:47:19 +02:00
Brian Pooe
a2fe91b125 feat: caddy setup 2026-06-13 17:41:31 +02:00
Brian Pooe
6b343a593c Add Raspberry Pi Caddy deployment 2026-06-13 17:25:27 +02:00
Brian Pooe
71f4b838fd Document phased UDM Pro SE zone migration 2026-06-13 17:09:02 +02:00
Brian Pooe
5148bbe47f Update Technitium deployment documentation 2026-06-13 16:15:32 +02:00
Brian Pooe
d99d21263a fix: documentation alignment to new hardware 2026-06-12 18:14:16 +02:00
Brian Pooe
ea6afc20ee docs: add Proxmox LXC arr deployment walkthrough 2026-06-11 21:21:08 +02:00
Brian Pooe
ad260360dc feat: adapt arr storage for Proxmox LXC 2026-06-11 21:20:58 +02:00
c80f1e3588
Merge pull request #22 from brianpooe/claude/gallant-mendel-k5nzkm
Document rsync uid/gid configuration for Docker appdata migration
2026-06-10 19:07:11 +02:00
Claude
b370e47639
docs: recommend uid=root for root-owned Docker appdata rsync modules
Modules covering /volume1/docker or any path with container-owned files
need uid=root/gid=root to avoid Permission denied errors. Added a second
example block, explained why it is safe alongside read only=yes and
hosts allow, and updated the troubleshooting table accordingly.

https://claude.ai/code/session_017P1M5Gava6kdP4VemtJpqU
2026-06-10 17:06:12 +00:00
cfa0a51f68 fix Synology migration exclusions 2026-06-06 16:29:38 +02:00
fc9c6b48e1 docs: revise Synology to UNAS migration guide 2026-06-06 15:45:39 +02:00
f2efda425a Fix Synology→UNAS migration: add metadata exclusions and CIFS permission flags
Adds --exclude flags for Synology-specific dirs (@eaDir, #recycle, @tmp,
@sharebin, .SynologyWorkingDirectory) to prevent polluting the UNAS share
with thumbnail caches and recycle bin data. Adds --no-perms --no-owner
--no-group to avoid silent CIFS permission errors stalling the transfer.
Applies exclusions to pilot, full run, and verification dry-run commands.
Adds UniFi Drive 4.3.5 manual re-index note to troubleshooting table.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-06 13:06:06 +02:00
02f3243d36
Merge pull request #21 from brianpooe/claude/cool-bell-zh2OI 2026-05-26 22:42:16 +02:00
Claude
f38e3d2424
Add host runtime decisions: Technitium bare-metal, Caddy Docker, Netbird host
New section §10 documents the runtime split:
- Technitium on bare metal (official install.sh) — critical infra, avoids
  Docker-needs-DNS bootstrap, minimum failure surface
- Caddy in Docker via caddy:builder with the Cloudflare DNS plugin baked
  in at build time, reusing this repo's existing Caddyfile_template and
  substitute_env.sh workflow. Adds template Dockerfile + compose.
- Netbird agent via official pkgs.netbird.io install script as a host
  systemd service, keeping tunnel state outside the Caddy container.
2026-05-26 17:58:30 +00:00
Claude
592f46f7cf
Revise UDM Pro zones doc: 6 VLANs/5 zones, Netbird ingress, DNAT DNS
Folds in design review feedback:
- Split Caddy into its own DMZ zone (VLAN 15) on a dedicated host
- Public ingress via Netbird VPS + agent on Caddy host (no WAN port-forward)
- Replace brittle ':53 block' with DNAT redirect for FAMILY/MEDIA/IOT/GUEST,
  silently capturing hardcoded resolvers without source-IP mismatch breakage
- Document UniFi 9.x intra-zone default-allow as the rationale for keeping
  FAMILY/MEDIA and IOT/GUEST as separate zones
- Add Technitium Allowed Networks ACL prerequisite for cross-subnet queries
- Caddy host hardening: SSH source-lock, wt0 firewall, no Docker socket,
  cap_drop ALL, Netbird as host service
2026-05-26 16:29:39 +00:00
Claude
4d0243a739
Add UDM Pro zone-based firewall migration doc
Captures the pfSense → UDM Pro cutover with 5 custom zones replacing
7 per-interface rule sets. Consolidates LAN/Office/AdBlock into
TRUSTED so Proxmox-hosted Caddy and apps share one VLAN, while
keeping MEDIA and FAMILY as their own firewalled zones restricted to
Caddy + DNS + internet (no UDM admin, no NAS, no workstations).
2026-05-26 12:39:32 +00:00
5821a3ce21
Merge pull request #20 from brianpooe/claude/rename-to-homelab-blueprint
docs: update repo references to homelab-blueprint
2026-05-24 00:02:46 +02:00
Claude
ce580591f3
docs: update repo references to homelab-blueprint
Repo is being renamed from synology-docker-services to
homelab-blueprint to reflect the actual scope (compose stacks,
network/rack docs, DNS recipes, Caddy config) and the Synology
retirement called out in the migration guide.
2026-05-23 22:01:31 +00:00
5bde07c305
Merge pull request #19 from brianpooe/claude/tender-planck-TxJPY
Clarify CRS309 uplink to use RJ45 directly, remove SFP module
2026-05-23 23:54:01 +02:00
Claude
1c3e96cb9a
docs(network): drop redundant "no SFP module" call-outs
Per review on PR #19: the link description, §7.3, and the BoM
already state the link is RJ45-to-RJ45; explicitly noting the
absence of an SFP module is noise.
2026-05-23 21:52:55 +00:00
Claude
928de859a4
docs(network): drop SFP-to-RJ45 module from Lite-8 ↔ CRS309 link
The CRS309's GbE RJ45 port is a full switchport that also accepts
802.3at PoE-in, so a single Cat6 from a Lite-8 PoE+ port to the
CRS309 GbE port carries both the 1G trunk and the power. §7.4
already described this; §7.3, the link table, the topology
mermaid, the migration sequence, the PoE budget, and the BoM
contradicted it by assuming a 1G SFP-to-RJ45 module on a CRS309
SFP+ cage (physically impossible to also pass PoE).

Aligned all of the above with the RJ45-to-RJ45 design and removed
the UACC-CM-RJ45-1G line from the shopping list.
2026-05-23 21:49:13 +00:00
649325e0fb
Merge pull request #18 from brianpooe/claude/wizardly-faraday-1ISDi
docs: add Synology DS920+ to UNAS Pro migration guide
2026-05-22 21:26:09 +02:00
Claude
542c1395b3
docs: add Synology DS920+ to UNAS Pro migration guide 2026-05-22 19:25:35 +00:00
ce0e013473
Merge pull request #17 from brianpooe/claude/update-homelab-network-docs-wx1pG
Stack ASCII rack diagrams vertically and use plain ASCII
2026-05-10 17:36:30 +02:00
Claude
1429e6cafc
Restore side-by-side ASCII rack diagrams with equal-width columns
Each box is 36 chars wide, every U gets a single line (no inner row
separators), and multi-U devices are marked with '}' on each occupied
line. Verified all 17 diagram lines render at exactly 74 chars so the
two columns stay aligned in any monospace renderer.
2026-05-10 15:32:53 +00:00
Claude
2bf5ab77a5
Stack ASCII rack diagrams vertically and use plain ASCII
The side-by-side layout broke alignment because Unicode box-drawing
glyphs (▣, ░) and nested box characters render at different widths
across fonts. Stacking the two diagrams vertically and switching to
plain ASCII (+, -, |) makes them legible in any monospace font.
2026-05-10 15:13:35 +00:00
f6efe7ed62
Merge pull request #16 from brianpooe/claude/update-homelab-network-docs-wx1pG
Add §11 (2.5GbE future upgrade) and §12 (rack layout & cable management)
2026-05-10 17:07:28 +02:00
Claude
27d0e3d451
Add ASCII + Mermaid rack diagrams (before/after) and standalone reference
§12.6 ASCII rack diagram side-by-side, §12.7 Mermaid equivalent for
GitHub-rendered viewing. Standalone copy at docs/network/rack-layout.md
so the visual is reachable without scrolling through the full migration
guide.
2026-05-10 14:59:53 +00:00
Claude
34286aebdf
Add §11 (2.5GbE future upgrade) and §12 (rack layout & cable management)
§11 documents the explicit decision to defer 2.5GbE at the desk, the
constraints that block a quick fix (NUC 1G NIC, Lite-8 1G ports, CRS309
has no 2.5G RJ45), and two upgrade paths for when it's revisited.

§12 captures the current 15U Linkbasic rack contents, a recommended
target layout that puts the patch panel between Lite-8 and CRS309 for
short patches, uses rear-routed DACs through a brush panel so MS-A2 and
UNAS Pro don't have to sit adjacent to the CRS309, and pairs MS-A2 with
the Wyse 5070 on a shared 2U vented shelf. Also includes a physical
migration order, cable-management discipline, and a power-draw delta.

Shopping list renumbered §11 → §13.
2026-05-10 14:53:02 +00:00
8ffcce7d96
Merge pull request #15 from brianpooe/claude/update-homelab-network-docs-wx1pG
Shorten UNAS Pro label in target diagram to prevent overlap
2026-05-09 22:23:59 +02:00
Claude
6a454a83d7
Collapse UNAS Pro node to single-line label 2026-05-09 20:23:06 +00:00
Claude
8f5dd95a0e
Shorten UNAS Pro label in target diagram to prevent overlap 2026-05-09 20:21:27 +00:00
b18a10458f
Merge pull request #14 from brianpooe/claude/update-homelab-network-docs-wx1pG
Retire TL-SG1016DE and Node-RED, document current+target topology
2026-05-09 22:16:41 +02:00
Claude
897c32bc4e
Retire TL-SG1016DE and Node-RED, document current+target topology
- Add §2 "Current Topology" with Lite-8 port map and mermaid diagram so
  readers can see what's changing, not just the destination.
- Retire the TP-Link TL-SG1016DE office switch; office devices fold back
  onto Lite-8 ports 6/7/8 (U3425we monitor, Wyse 5070, optional NUC drop).
- Pin Wyse 5070 as the dedicated Home Assistant host (HA + Mosquitto +
  Z2M stay on it; only the uplink moves).
- Remove Node-RED from the service map — being decommissioned.
- Add §6 "Service Placement" mapping every Docker stack from the repo to
  its target host, plus UNAS Pro NFS share layout.
- New gotchas: Lite-8 port budget, Z2M-over-TCP, Emby VAAPI on MS-A2,
  Beszel host networking, KVM pass-through caveat.
2026-05-09 20:15:22 +00:00
c2bbb5f4d4
Merge pull request #13 from brianpooe/claude/update-homelab-network-docs-wx1pG
Retire DS920+, swap Mac mini for NUC, add SLZB-06U to PoE budget
2026-05-09 19:09:40 +02:00
Claude
4680476ef7
Retire DS920+, swap Mac mini for NUC, add SLZB-06U to PoE budget
DS920+ is fully retired (no backup role). Intel NUC repurposed as
desktop replacing Mac mini. SMLIGHT SLZB-06U Zigbee coordinator is
PoE-powered from the Lite-8, so it's added to the PoE budget table —
new total ~30-35 W of 52 W, but all 4 PoE+ ports are now used.

https://claude.ai/code/session_011ttbGhvdo5k2GTn69kceA2
2026-05-09 17:06:53 +00:00
dea4961672
Merge pull request #12 from brianpooe/claude/update-homelab-network-docs-wx1pG
Redesign homelab network: MikroTik core + pfSense VM + UniFi NAS
2026-05-09 18:55:53 +02:00
Claude
79f4efc675
Update homelab migration doc for revised hardware
Replace UDM Pro / USW-Aggregation / UGREEN DXP8800 Plus / Intel NUC
build with MS-A2 (Proxmox + pfSense VM), MikroTik CRS309-1G-8S+IN,
and UniFi NAS Pro 2U. Power CRS309 via PoE-in from Lite-8, keep
1G SFP-to-RJ45 for Lite-8 uplink (thermal), and host the UniFi
Network Application on the NAS Pro. Mermaid diagram switched to
vertical layout.

https://claude.ai/code/session_011ttbGhvdo5k2GTn69kceA2
2026-05-09 16:52:37 +00:00
Brian Pooe
2381b139a9 docs: correct gambling blocklist domain count to ~203k 2026-04-20 20:40:36 +02:00
Brian Pooe
a56b040ecc docs: add recommended HaGeZi blocklists section to Technitium guide 2026-04-20 13:47:31 +02:00
Brian Pooe
567403f88c fix: use tail -1 in get_env_value so appended secrets are read correctly
head -1 always returned the first (empty) match when a key existed with
an empty value in .env, causing auto-generated secrets like
NODE_RED_CREDENTIAL_SECRET to be ignored during substitution.
2026-04-05 16:30:27 +02:00