| 2026-10-02 18:23 |
#39 |
docs + features + fixes |
- added doc: a UPS section: truenas1, the proxmox cluster and PeaNUT
- added feature: NUT on truenas1 and on all three proxmox nodes, reading both UPSes over their network cards, so each shuts down what it feeds before the battery runs out
- added feature: the proxmox cluster shuts down together in a power cut: Ceph flags set, guests stopped, a hold so no node leaves Ceph early, and the flags cleared on the next boot
- changed feature: the proxmox HA shutdown policy is
freeze - added feature: PeaNUT on truenas1, a dashboard for both UPSes
- added doc: unpoller: UniFi metrics for prometheus, with the queries i use
- added feature: UnPoller on truenas1, scraped by prometheus, with a gatus check on what prometheus has from it
- added doc: victorialogs: the log store on truenas1, with UniFi's events arriving by syslog and the queries i use
- added feature: VictoriaLogs on truenas1, UniFi's SIEM target, with a gatus check on its health
- added feature: capped truenas1's GPU at 350 W, set again at every boot, to stay inside the UPS's power budget, see hardware
- changed feature: raised wordpress's apache header limit to 32 KB, so a browser signed in to oauth2-proxy isn't refused with a 400
- fix: verify-restore restores to the container's disk, not its tmpfs
/tmp, where a large directory got the restore killed for memory, and counts the backup's entries, which it counted as 0 - changed doc: wordpress: how to put the whole site back from one backup's files and dump, and why the dump has to be copied out first
- added feature:
pbs-restore, a file-level restore portal for the VM and container backups, lan only, with proxmox's own sign-in, in the access table - added feature: traefik can refuse requests another site started, per name, except to listed paths (
cross_site_paths)
|
| 2026-09-28 13:32 |
#38 |
docs |
- changed doc: wordpress: open the network admin in a browser window that maps the root site's name to traefik, with the commands for chrome and edge, instead of a hosts file
|
| 2026-09-28 11:50 |
#37 |
docs + features |
- removed feature: the last names traefik passed through to nginx proxy manager, which served nothing once it stopped
|
| 2026-09-28 11:14 |
#36 |
docs + features |
- changed feature: made wordpress's root site lan-only: outside, every path redirects to
www. - changed feature: set up wordpress's site on another domain on traefik again, with a certificate of its own. cloudflare checks that certificate (full, strict) and uses post-quantum key agreement to traefik
- changed feature: set up gatus to check the certificate of a name outside my domain, by name but still on the lan
|
| 2026-09-28 10:12 |
#35 |
docs + features |
- changed feature: moved the config from git sidecars to ssh over port 443, after port 22 to github stopped answering
- added feature: replaced nginx proxy manager with traefik
- added doc: traefik
- added feature: set up oauth with entra ID on traefik, through oauth2-proxy, for the names with no login of their own
- changed doc: rewrote oauth2-proxy for how it runs now, with its app registration in entra
- added doc: auth: how people sign in to every app, on the lan and from outside, and the MFA on each way in
- added doc: entra ID: every app registration, and the password logins for when entra is down
- changed doc: traefik: the diagram is two, one for requests and one for config
- changed doc: placeholders the site hid are shown on entra ID auth, let's encrypt via cloudflare and installing debian as VM. on the entra page, the rest of the list showed as a link
- changed doc: nginx proxy manager is stopped, replaced by traefik
- removed doc: the old traefik template
- changed feature: set up wordpress on traefik. the root site's front page redirects to
www. - added doc: signing in to portainer with entra ID
- added doc: webauthn keys on every node of the proxmox cluster
- changed feature: set up gatus to check every traefik route, and traefik itself over a private network
- changed feature: set adguard's minimum cache TTL to 0
- changed feature: encrypted the PBS copy in azure with rclone crypt, see backups
- added feature: set up a nightly backup of truenas1's
fast/configs to PBS, and from there to azure, see tasks and scripts - changed feature: set the PBS datastore's record size to 1M, see proxmox backup server
|
| 2026-09-26 10:15 |
#34 |
docs + features |
- added feature: added a
bbolt check of portainer's database to every hourly cephfs backup - changed doc: databases: portainer is restored from the checked copy in the cephfs backup
- added feature: replicated truenas1's
fast/configs to the rust pool after every hourly snapshot, see storage and snapshots - added feature: set up a nightly copy of the catalogue apps' settings into
fast/configs, see tasks and scripts
|
| 2026-09-26 08:35 |
#33 |
docs + features |
- added doc: databases: every database, how each is copied, and how to restore it
- added feature: portainer's S3 backups keep 14 nights, and always the newest 14. a cron job on truenas deletes older ones, see portainer to S3
- removed feature: two anonymous accounts on nginx proxy manager's database, which nothing used
- changed doc: backups: portainer's database has no scheduled consistent copy, and truenas1's app databases have no copy off their pool
|
| 2026-09-26 07:28 |
#32 |
docs |
- changed doc: changelog: publishes first, each change labelled, and the newest publish's time filled in when it goes live
|
| 2026-09-25 23:27 |
#31 |
docs |
- added doc: changelog: every publish, and the pace by week
|
| 2026-09-25 23:06 |
#30 |
docs + features |
- added feature: hourly consistent dumps of the wordpress and nginx proxy manager databases, for the cephfs backup
- added feature: gatus copies its database every hour, through the fork
- changed feature: wordpress keeps two days of binary logs, down from thirty
- changed doc: cephfs backups: what runs for each database, and how to restore each copy
- changed doc: stack conventions: the adguards are the one swarm service with a healthcheck, and why
|
| 2026-09-25 18:50 |
#29 |
docs + features + fixes |
- fix: re-plugging a docker VM's network card removed adguard's macvlan address. a healthcheck on that address now gets the container replaced
- fix: the macvlan shim is built by
eth0's stanza, so it comes back with the card - changed feature: the two adguards keep off each other's node
|
| 2026-09-25 17:28 |
#28 |
docs + features |
- added feature: cephfs backups run in a container on the proxmox cluster that any node can run: hourly snapshots, the backup to PBS, and a restore check
- added doc: building and rebuilding pbs1, from the truenas container api to its certificate
- changed feature: pbs1 has one static address
- changed doc: proxmox backup server links to the build
|
| 2026-09-25 13:07 |
#27 |
docs + features |
|
| 2026-09-25 08:02 |
#26 |
docs + features + fixes |
|
| 2026-09-22 23:33 |
#25 |
docs + features |
- added doc: IPv6 on the docker hosts: the addressing plan, the interface and daemon config, and how a stack turns it on
- added feature: the docker hosts route IPv6 to containers, with no NAT66
- added feature: a macvlan shim on every docker host, so a node reaches the adguard running on it
- added feature: a cold copy of portainer before each upgrade, on portainer to S3
- changed doc: portainer: each environment is added by its agent's address on port 9001
|
| 2026-09-22 12:36 |
#24 |
docs |
- changed doc: stacks in git: why portainer's force redeployment stays off, and a current screenshot of the deploy ruleset
|
| 2026-09-22 09:55 |
#23 |
docs + features |
- added doc: three sections replace docker swarm: docker, apps and monitoring. the 29 pages that moved redirect
- added doc: standalone docker hosts, stack conventions, portainer, truenas tasks and scripts, wordpress and the arr stack
- added doc: the raspberry pi page split into stacks, thread radio, GPS time and PoE HAT OLED
- added feature: a homepage dashboard that finds its tiles on the swarm
- added feature: gatus health checks, with their config in git
- added feature: dozzle and glances on every host
- added feature: the arr stack deployed from git on truenas1
- changed feature: every container on pacific time
- removed feature: uptime kuma, replaced by gatus
- removed doc: the unifi poller page, which now redirects to apps
|
| 2026-09-20 08:54 |
#22 |
docs + features |
- added doc: a truenas section: hardware and base install, system extensions, storage, apps, containers, boot environments and frigate
- added doc: a secrets section, moved out of docker swarm, with guides to add, rotate, retire and recover
- added feature: an encrypted secret store, sops and age, run from a key-manager container
- added feature: acme.sh renews the certificates on the BMC and the synology
- added feature: frigate deployed from git on truenas1, off the app catalogue
|
| 2026-09-19 16:36 |
#21 |
docs |
|
| 2026-09-19 16:04 |
#20 |
docs |
|
| 2026-09-16 12:37 |
#19 |
docs |
- changed doc: numbered steps that restarted at 1 now count through, on eight proxmox pages
|
| 2026-09-16 11:53 |
#18 |
docs + features |
- added doc: omni-tools and bentopdf
- added feature: omni-tools and bentopdf on the swarm
- changed doc: stacks in git: which git reference to pick when adding a stack
|
| 2026-09-15 21:34 |
#12 |
docs |
- changed doc: the site's theme, mkdocs-material 9.5.44 to 9.7.7
|
| 2026-09-15 21:25 |
#17 |
docs |
- changed doc: stacks in git: what a standalone docker host shares with the swarm
|
| 2026-09-15 21:08 |
#16 |
docs |
- changed doc: thread: clipboard and state commands that run on each platform
|
| 2026-09-15 19:15 |
#15 |
docs |
- changed doc: thread: which ESP-IDF tree windows uses, and naming each board after its MAC as a normal step
|
| 2026-09-15 18:24 |
#14 |
docs |
- changed doc: thread starts from an unflashed ESP board: parts, ESP-IDF on each OS, flashing, and joining from home assistant
- added doc: an optional firmware patch that names each ESP board after its MAC
- changed doc: raspberry pi: the stacks portainer deploys there from git
- changed doc: 34 lists that rendered as paragraphs now render as lists, and numbered steps no longer restart at 1 in 19 places
|
| 2026-09-15 16:58 |
#13 |
docs + features |
|
| 2026-08-26 11:05 |
a937c79 |
docs |
- changed doc: the swarm install steps render as a numbered list
|
| 2026-08-24 12:03 |
#11 |
docs + features |
|
| 2026-08-23 19:05 |
7e36498 |
docs |
- added doc: comments on the ten busiest pages, through github discussions
|
| 2026-08-23 18:53 |
765b1e5 |
docs |
- added doc: a list of the 16 gists not yet moved to the site
|
| 2026-08-23 18:43 |
100397a |
docs |
- added doc: the site: my proxmox and docker swarm gists, brought together in mkdocs
|