Commit graph

160 commits

Author SHA1 Message Date
73ff919b9f feat(forgejo): remove gitea-mirror, all repos now first-class
GitHub mirroring is no longer needed now that Forgejo is the primary
remote. Drops the gitea-mirror service, its volume, env vars, Caddy
site, and firewall rule; docs updated to match.
2026-07-19 13:21:05 +02:00
1549283f19 fix(forgejo): land on login instead of marketing homepage
REQUIRE_SIGNIN_VIEW doesn't affect the anonymous landing page; the actual
control is [server] LANDING_PAGE.
2026-07-18 22:56:07 +02:00
8732da91de feat(forgejo): disable password login, Zitadel OIDC only
ENABLE_INTERNAL_SIGNIN=false hides the password form; ENABLE_BASIC_AUTHENTICATION=false
blocks raw-password basic auth. PATs and SSH keys are unaffected.
2026-07-18 22:50:55 +02:00
0ba3d9c300 fix(forgejo): derive OIDC username from email local-part
Zitadel sends preferred_username == full email when no separate nickname
is set, which fails Forgejo's username validation and crashes before
ACCOUNT_LINKING=auto gets a chance to match the existing local account.
2026-07-18 22:47:13 +02:00
a261778b05 feat: add Forgejo stack with GitHub mirroring and Zitadel OIDC support
Self-hosted Git service (Postgres-backed) plus gitea-mirror for automatic
GitHub repo mirroring. Storage split follows the Paperless pattern: DB and
app config on local disk, git objects/LFS/attachments/avatars on the UNAS
forgejo_data share. Wired into the Makefile, root README, and UNAS NFS docs;
adds Caddy routes for git.<domain> and git-mirror.<domain>.
2026-07-18 22:39:57 +02:00
Hermes Agent
f3184edd2a chore(homeassistant): disable main bedroom plug schedule 2026-07-15 00:03:27 +02:00
Hermes Agent
67a296fa9c fix(homeassistant): stop resetting bulbs before off 2026-07-12 08:16:42 +02:00
Hermes Agent
de494c253c fix(homeassistant): keep Moirah lamp on overnight 2026-07-12 01:04:56 +02:00
Hermes Agent
4b5eabddc1 feat(homeassistant): schedule main bedroom plug 2026-07-11 19:59:01 +02:00
Hermes Agent
a062254731 fix(homeassistant): correct moirah schedule condition 2026-07-11 19:20:41 +02:00
Hermes Agent
862ac83ce8 fix(homeassistant): enforce moirah schedule 2026-07-11 19:08:14 +02:00
Hermes Agent
11355832f0 fix(homeassistant): rename kids lamp entity ids 2026-07-11 18:16:51 +02:00
44decc4b26 feat: remove Rackula stack 2026-07-11 16:42:28 +02:00
ffb141f1f0 feat: remove SnapOtter stack 2026-07-11 16:24:34 +02:00
Hermes Agent
571b036a7f fix(homeassistant): resync moirah lamp on reconnect 2026-07-09 18:27:31 +02:00
Hermes Agent
73f584dc57 fix(homeassistant): rename kids lamps and moirah lamp 2026-07-08 21:41:42 +02:00
Hermes Agent
c930aedfa6 fix(homeassistant): remove moirah lamp automations 2026-07-08 20:50:29 +02:00
Hermes Agent
6915a82268 feat(homeassistant): set moirah tuya 22 to 5 2026-07-08 20:30:59 +02:00
Hermes Agent
672e2fd7d4 feat(homeassistant): lower moirah 21:00 to 15 2026-07-07 22:52:43 +02:00
Hermes Agent
ad29c4302a feat(homeassistant): lower moirah lamp to 1 2026-07-07 22:49:21 +02:00
Hermes Agent
6005def31f feat(homeassistant): warm moirah lamp from 20:30 2026-07-07 22:38:23 +02:00
Hermes Agent
4d24978f32 feat(homeassistant): dim moirah lamp to 10 2026-07-07 22:25:41 +02:00
Hermes Agent
9de31abc02 feat(homeassistant): schedule moirah lamp 2026-07-07 17:26:09 +02:00
Hermes Agent
c480da26de feat(homeassistant): schedule brian lamp 2026-07-07 17:11:54 +02:00
Hermes Agent
269ee5106a fix(homeassistant): remove kids lamps group 2026-07-07 16:42:02 +02:00
Hermes Agent
1385194cc1 fix(homeassistant): reset lamps before turning off 2026-07-07 15:07:40 +02:00
Brian Pooe
3a314b16d6 feat: add Koffan, Rackula, and SnapOtter stacks; expose Hermes dashboard
- new compose templates + READMEs for the three LXC apps (110-112)
- Makefile deploy targets (rackula pre-owns its data dir for uid 1001)
- Caddy vhosts for all four, incl. Hermes /auth/login redirect workaround
- firewall docs: CADDY->TRUSTED rules for LXCs 110-113
2026-07-06 20:50:34 +02:00
Brian Pooe
110d17f59f fix(gramps-web): correct container paths in config template and gate OIDC
The official grampsweb image works under /app, not /opt/gramps-web —
media/index/cache paths pointed at unmounted directories. OIDC is now
opt-in via GRAMPS_OIDC_ENABLED and all optional placeholders have
defaults so rendering works without an OIDC/email config.
2026-07-03 19:02:17 +02:00
Brian Pooe
cc6cdebba2 fix(paperless-ngx): keep SQLite database and index on local disk
Only media/consume/export/trash stay on the UNAS share; SQLite over
NFS risks lock contention and corruption.
2026-07-03 18:38:50 +02:00
Brian Pooe
d20500c5be feat(beszel-hub): support SSO-only login via OIDC with PKCE
Add DISABLE_PASSWORD_AUTH and USER_CREATION env toggles and document
the Zitadel PKCE provider setup.
2026-07-03 18:31:11 +02:00
Brian Pooe
4eb6d6ee04 feat(paperless-ngx): store documents on the UNAS paperless_data share
Bind data/media/consume/export/trash from PAPERLESS_DATA_ROOT with
create_host_path: false so the stack refuses to start when the NFS
share is not mounted. Wire PAPERLESS_TRASH_DIR.
2026-07-03 18:11:49 +02:00
Brian Pooe
1815beadf4 refactor: restructure docs, sync stacks with Caddyfile, harden compose templates
- Add compose stacks for apps already proxied by Caddy: bento-pdf,
  it-tools, paperless-ngx, and beszel-hub (with Makefile targets)
- Remove the unused Vault stack and the drawio Caddyfile block
- Fix Caddyfile gramps upstream to port 80 to match the compose file
- Bring immich and gramps-web up to the shared template pattern
  (no-new-privileges, log rotation, memory limits, healthchecks)
- Single-quote vaultwarden SSO_AUDIENCE_TRUSTED so regex values like
  ^\d{18}$ render as valid YAML
- Move root docs into kebab-case topic folders, rebuild the docs index
  to cover every doc, and fix all broken links
2026-07-03 17:45:16 +02:00
Brian Pooe
f5a1c53713 chore: track .env.sample files for all stacks
Now that .gitignore allows docker-compose-files/**/.env.sample, add the
existing sample files that were previously untracked.
2026-07-02 22:28:44 +02:00
Brian Pooe
da5652aa10 feat(vaultwarden): add SSO/OIDC support with Zitadel documentation
- Add SSO environment variables to template.yaml (SSO_ENABLED, SSO_ONLY,
  SSO_AUTHORITY, SSO_CLIENT_ID, SSO_CLIENT_SECRET, SSO_SCOPES, SSO_PKCE,
  SSO_AUDIENCE_TRUSTED)
- Add SSO variables to .env.sample with Zitadel audience quirk explained
- Document full Zitadel setup in README: app creation, redirect URI, OIDC
  settings, and the audience fix (SSO_AUDIENCE_TRUSTED=^\d{18}$)
- Update .gitignore to track .env.sample files in docker-compose-files
2026-07-02 22:25:15 +02:00
Brian Pooe
206d83235d fix(caddy): restore vaultwarden hostname and Physical/static devices comment 2026-07-02 18:55:04 +02:00
Brian Pooe
2f2b3a6c6f feat(caddy,vaultwarden): add vaultwarden stack and reorganise Caddyfile by VLAN
- Add docker-compose-files/vaultwarden/ with template.yaml, .env.sample,
  and README (LXC assigned 10.0.10.16, port 8800)
- Reorganise Caddyfile site blocks into VLAN 1 / VLAN 10 / VLAN 30 sections
  matching the TRUSTED / IoT zone layout from docs/network/firewall-rules.md
- Sort VLAN 10 entries by IP; split into physical devices vs LXC Apps sub-sections
- Move zigbee from LAN section to VLAN 30 where it actually lives (10.0.30.5)
2026-07-02 18:53:25 +02:00
Brian Pooe
ab77ce7057 fix(homeassistant): target bulbs individually to fix hloni missing commands
Replaced light.kids_lambs group entity with explicit list of mpho_lamb
and hloni_lamb in sunset and 20:30 automations. Group multicast was
causing hloni to silently miss Zigbee commands; unicast to each bulb
individually ensures reliable delivery.
2026-06-30 21:45:55 +02:00
Brian Pooe
b123c57c4f feat(homeassistant): add 3-retry logic to all kids_lambs automations
Each automation now retries the command 3 times with a 1-minute gap to
handle transient Zigbee timeouts (e.g. hloni_lamb missing sunset trigger).
2026-06-29 18:59:39 +02:00
Brian Pooe
9287b93e90 feat(homeassistant): reduce mpho night light from 10% to 5% at 02:00 2026-06-28 18:18:53 +02:00
Brian Pooe
1164a79d46 fix(homeassistant): replace color_temp mireds with color_temp_kelvin
HA 2026 rejects color_temp (mireds) via the service API with 400 Bad
Request, silently breaking automation actions. Switch all color
parameters to color_temp_kelvin: 6500 (cool white) and 2200 (warm white).
2026-06-28 18:14:52 +02:00
Brian Pooe
5b347f8fbb feat(homeassistant): drive kids_lambs on purely by sunset
Removes the fixed 18:00 fallback trigger — lights now come on at actual
sunset year-round via the sun platform.
2026-06-28 18:05:46 +02:00
Brian Pooe
6a2af1c91e feat(homeassistant): add mpho night-light dim and switch to sunrise off
Dims mpho_lamb to 10% warm at 02:00 as a night light, and replaces the
fixed 06:00 off trigger with a sun sunrise event so the light goes off
at actual daybreak year-round.
2026-06-28 18:02:57 +02:00
Brian Pooe
8081e0c753 feat(homeassistant): add kids_lambs light group and daily automations
Creates a light group combining mpho_lamb and hloni_lamb, and sets up
four daily automations: on at sunset/18:00 (full cool white), warm dim
at 20:30, hloni off at 22:00, mpho off at 06:00 — all with fade transitions.
setup-homeassistant.sh now deploys automations.yaml alongside configuration.yaml.
2026-06-28 17:59:26 +02:00
Brian Pooe
e2f62deb2d Document Youtarr SMB storage mount 2026-06-28 13:40:08 +02:00
Brian Pooe
cdd4874bf1 Document and proxy Youtarr deployment 2026-06-28 11:59:59 +02:00
Brian Pooe
0fca695aa4 Add Youtarr stack and document PhotoSync storage 2026-06-28 11:47:24 +02:00
Brian Pooe
d59814c8fe fix(homeassistant): harden blueprint for fresh installs and public repo safety
- Add SLZB06_HOST and CADDY_HOST_IP stubs to root .env.sample so cp -n covers all required vars
- Remove dead :-10.0.15.5 default from ha_configuration.yaml (CADDY_HOST_IP is required; default was unreachable)
- Genericise CADDY_HOST_IP comment in ha_configuration.yaml (removed hardcoded personal IP)
- Default zigbee2mqtt pan_id and network_key to GENERATE (remove personal network credentials from public blueprint)
- Remove hardcoded device list from zigbee2mqtt_configuration.yaml (Z2M builds this on pairing)
- Clarify README installation steps: root .env path, missing-var behaviour for SLZB06_HOST and CADDY_HOST_IP
2026-06-27 17:38:04 +02:00
Brian Pooe
86cfe2aecc docs(immich): add phone-to-NAS mobile sync guide and wire mobile_photos share
Documents the FolderSync/PhotoSync → UNAS Pro → Immich external library
pattern as the workaround for immich-app/immich#4282 (deleted photos
re-uploading on next mobile sync). Includes all steps: UNAS share creation,
Proxmox NFS mount, LXC bind mount, docker-compose volume, Immich library
import path update, and per-app config for Android (FolderSync) and iOS
(PhotoSync).

- Adds docs/immich/mobile-sync.md with full step-by-step guide
- Adds mobile_photos to share map in docs/unas/nfs-mounts.md
- Adds IMMICH_MOBILE_SYNC_DIR volume (/mnt/mobile:ro) to template.yaml
- Documents IMMICH_MOBILE_SYNC_DIR in README.md and .env.sample
2026-06-27 15:31:08 +02:00
Brian Pooe
eb3c0a0f00 feat(immich): switch to NVENC for transcoding and CUDA for ML inference
- immich-server: add runtime: nvidia + NVIDIA_DRIVER_CAPABILITIES=video,
  compute,utility to enable NVENC hardware H.264 transcoding
- immich-machine-learning: change image tag to :release-cuda so
  CUDAExecutionProvider is selected over CPUExecutionProvider for CLIP,
  face detection, and OCR
- Update GPU Verification section in README with verification commands
  and note on resetting QSV → NVENC in the admin UI
2026-06-27 12:31:30 +02:00
Brian Pooe
11935bd02a docs(immich): document OIDC-only login, external library setup, and firewall rule
- Adds OIDC disable-password-login workflow to README (enforce SSO after
  confirming Zitadel PKCE works; clarifies client secret is not needed)
- Expands external library section with user UUID lookup and warning about
  Immich blocking paths under the upload volume
- Adds Allow Caddy to Immich rule (10.0.15.5 → 10.0.10.15:2283) to
  firewall-rules.md
2026-06-27 12:18:12 +02:00