Skip to content

changelog

every publish of this site, newest first. times are pacific.

publishes

when publish kind what changed
2026-10-02 18:23 #39 docs + features + fixes
  • added doc: a UPS section: truenas1, the proxmox cluster and PeaNUT
  • added feature: NUT on truenas1 and on all three proxmox nodes, reading both UPSes over their network cards, so each shuts down what it feeds before the battery runs out
  • added feature: the proxmox cluster shuts down together in a power cut: Ceph flags set, guests stopped, a hold so no node leaves Ceph early, and the flags cleared on the next boot
  • changed feature: the proxmox HA shutdown policy is freeze
  • added feature: PeaNUT on truenas1, a dashboard for both UPSes
  • added doc: unpoller: UniFi metrics for prometheus, with the queries i use
  • added feature: UnPoller on truenas1, scraped by prometheus, with a gatus check on what prometheus has from it
  • added doc: victorialogs: the log store on truenas1, with UniFi's events arriving by syslog and the queries i use
  • added feature: VictoriaLogs on truenas1, UniFi's SIEM target, with a gatus check on its health
  • added feature: capped truenas1's GPU at 350 W, set again at every boot, to stay inside the UPS's power budget, see hardware
  • changed feature: raised wordpress's apache header limit to 32 KB, so a browser signed in to oauth2-proxy isn't refused with a 400
  • fix: verify-restore restores to the container's disk, not its tmpfs /tmp, where a large directory got the restore killed for memory, and counts the backup's entries, which it counted as 0
  • changed doc: wordpress: how to put the whole site back from one backup's files and dump, and why the dump has to be copied out first
  • added feature: pbs-restore, a file-level restore portal for the VM and container backups, lan only, with proxmox's own sign-in, in the access table
  • added feature: traefik can refuse requests another site started, per name, except to listed paths (cross_site_paths)
2026-09-28 13:32 #38 docs
  • changed doc: wordpress: open the network admin in a browser window that maps the root site's name to traefik, with the commands for chrome and edge, instead of a hosts file
2026-09-28 11:50 #37 docs + features
  • removed feature: the last names traefik passed through to nginx proxy manager, which served nothing once it stopped
2026-09-28 11:14 #36 docs + features
  • changed feature: made wordpress's root site lan-only: outside, every path redirects to www.
  • changed feature: set up wordpress's site on another domain on traefik again, with a certificate of its own. cloudflare checks that certificate (full, strict) and uses post-quantum key agreement to traefik
  • changed feature: set up gatus to check the certificate of a name outside my domain, by name but still on the lan
2026-09-28 10:12 #35 docs + features
  • changed feature: moved the config from git sidecars to ssh over port 443, after port 22 to github stopped answering
  • added feature: replaced nginx proxy manager with traefik
  • added doc: traefik
  • added feature: set up oauth with entra ID on traefik, through oauth2-proxy, for the names with no login of their own
  • changed doc: rewrote oauth2-proxy for how it runs now, with its app registration in entra
  • added doc: auth: how people sign in to every app, on the lan and from outside, and the MFA on each way in
  • added doc: entra ID: every app registration, and the password logins for when entra is down
  • changed doc: traefik: the diagram is two, one for requests and one for config
  • changed doc: placeholders the site hid are shown on entra ID auth, let's encrypt via cloudflare and installing debian as VM. on the entra page, the rest of the list showed as a link
  • changed doc: nginx proxy manager is stopped, replaced by traefik
  • removed doc: the old traefik template
  • changed feature: set up wordpress on traefik. the root site's front page redirects to www.
  • added doc: signing in to portainer with entra ID
  • added doc: webauthn keys on every node of the proxmox cluster
  • changed feature: set up gatus to check every traefik route, and traefik itself over a private network
  • changed feature: set adguard's minimum cache TTL to 0
  • changed feature: encrypted the PBS copy in azure with rclone crypt, see backups
  • added feature: set up a nightly backup of truenas1's fast/configs to PBS, and from there to azure, see tasks and scripts
  • changed feature: set the PBS datastore's record size to 1M, see proxmox backup server
2026-09-26 10:15 #34 docs + features
  • added feature: added a bbolt check of portainer's database to every hourly cephfs backup
  • changed doc: databases: portainer is restored from the checked copy in the cephfs backup
  • added feature: replicated truenas1's fast/configs to the rust pool after every hourly snapshot, see storage and snapshots
  • added feature: set up a nightly copy of the catalogue apps' settings into fast/configs, see tasks and scripts
2026-09-26 08:35 #33 docs + features
  • added doc: databases: every database, how each is copied, and how to restore it
  • added feature: portainer's S3 backups keep 14 nights, and always the newest 14. a cron job on truenas deletes older ones, see portainer to S3
  • removed feature: two anonymous accounts on nginx proxy manager's database, which nothing used
  • changed doc: backups: portainer's database has no scheduled consistent copy, and truenas1's app databases have no copy off their pool
2026-09-26 07:28 #32 docs
  • changed doc: changelog: publishes first, each change labelled, and the newest publish's time filled in when it goes live
2026-09-25 23:27 #31 docs
  • added doc: changelog: every publish, and the pace by week
2026-09-25 23:06 #30 docs + features
  • added feature: hourly consistent dumps of the wordpress and nginx proxy manager databases, for the cephfs backup
  • added feature: gatus copies its database every hour, through the fork
  • changed feature: wordpress keeps two days of binary logs, down from thirty
  • changed doc: cephfs backups: what runs for each database, and how to restore each copy
  • changed doc: stack conventions: the adguards are the one swarm service with a healthcheck, and why
2026-09-25 18:50 #29 docs + features + fixes
  • fix: re-plugging a docker VM's network card removed adguard's macvlan address. a healthcheck on that address now gets the container replaced
  • fix: the macvlan shim is built by eth0's stanza, so it comes back with the card
  • changed feature: the two adguards keep off each other's node
2026-09-25 17:28 #28 docs + features
  • added feature: cephfs backups run in a container on the proxmox cluster that any node can run: hourly snapshots, the backup to PBS, and a restore check
  • added doc: building and rebuilding pbs1, from the truenas container api to its certificate
  • changed feature: pbs1 has one static address
  • changed doc: proxmox backup server links to the build
2026-09-25 13:07 #27 docs + features
2026-09-25 08:02 #26 docs + features + fixes
2026-09-22 23:33 #25 docs + features
  • added doc: IPv6 on the docker hosts: the addressing plan, the interface and daemon config, and how a stack turns it on
  • added feature: the docker hosts route IPv6 to containers, with no NAT66
  • added feature: a macvlan shim on every docker host, so a node reaches the adguard running on it
  • added feature: a cold copy of portainer before each upgrade, on portainer to S3
  • changed doc: portainer: each environment is added by its agent's address on port 9001
2026-09-22 12:36 #24 docs
  • changed doc: stacks in git: why portainer's force redeployment stays off, and a current screenshot of the deploy ruleset
2026-09-22 09:55 #23 docs + features
2026-09-20 08:54 #22 docs + features
2026-09-19 16:36 #21 docs
2026-09-19 16:04 #20 docs
2026-09-16 12:37 #19 docs
  • changed doc: numbered steps that restarted at 1 now count through, on eight proxmox pages
2026-09-16 11:53 #18 docs + features
  • added doc: omni-tools and bentopdf
  • added feature: omni-tools and bentopdf on the swarm
  • changed doc: stacks in git: which git reference to pick when adding a stack
2026-09-15 21:34 #12 docs
  • changed doc: the site's theme, mkdocs-material 9.5.44 to 9.7.7
2026-09-15 21:25 #17 docs
  • changed doc: stacks in git: what a standalone docker host shares with the swarm
2026-09-15 21:08 #16 docs
  • changed doc: thread: clipboard and state commands that run on each platform
2026-09-15 19:15 #15 docs
  • changed doc: thread: which ESP-IDF tree windows uses, and naming each board after its MAC as a normal step
2026-09-15 18:24 #14 docs
  • changed doc: thread starts from an unflashed ESP board: parts, ESP-IDF on each OS, flashing, and joining from home assistant
  • added doc: an optional firmware patch that names each ESP board after its MAC
  • changed doc: raspberry pi: the stacks portainer deploys there from git
  • changed doc: 34 lists that rendered as paragraphs now render as lists, and numbered steps no longer restart at 1 in 19 places
2026-09-15 16:58 #13 docs + features
2026-08-26 11:05 a937c79 docs
  • changed doc: the swarm install steps render as a numbered list
2026-08-24 12:03 #11 docs + features
2026-08-23 19:05 7e36498 docs
  • added doc: comments on the ten busiest pages, through github discussions
2026-08-23 18:53 765b1e5 docs
  • added doc: a list of the 16 gists not yet moved to the site
2026-08-23 18:43 100397a docs
  • added doc: the site: my proxmox and docker swarm gists, brought together in mkdocs

pace

  • 33 publishes in 41 days, from 2026-08-23 18:43 to 2026-10-02 18:23. the busiest day was 2026-09-15, with six publishes
  • 287 pull requests merged in the private repo since the first publish: 106 to the docs, 181 to stacks, tools and CI. the busiest day was 2026-09-24, with 50
week starting publishes docs changes stack, tool and CI changes
2026-09-28 5 13 16
2026-09-21 12 60 80
2026-09-14 11 27 51
2026-09-07 0 0 0
2026-08-31 0 0 0
2026-08-24 2 4 24
2026-08-17 3 2 10