feat(stack): replace Organizr with Tatlock UI, remove Netdata

Remove Organizr dashboard and Netdata monitoring:
- Delete stacks/organizr.yml and stacks/netdata.yml
- Delete organizr-widgets/ directory and npm forward-auth config
- Remove organizr database references from postgres-shared docs

Promote Tatlock UI as primary dashboard:
- Move from port 8092 to 9999 (Organizr's port)
- Enable external access at home.schweitz.net
- Update all documentation references

Update service counts: 26 containers across 20 stacks

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
2026-01-03 11:23:45 +01:00
co-authored by Claude Opus 4.5
parent d647a2e005
commit ba0aa5ef3d
13 changed files with 39 additions and 1000 deletions
+14 -89
View File
@@ -1,7 +1,7 @@
# Container Reference - tower-of-joy Infrastructure
> **Last Updated:** 2026-01-02
> **Total Services:** 28 containers across 22 stacks
> **Last Updated:** 2026-01-03
> **Total Services:** 26 containers across 20 stacks
> **System:** Intel i7-6700, RTX 2080 Ti (11GB VRAM), 64GB RAM, Zorin OS 16.3
---
@@ -17,8 +17,6 @@
| **Redis Shared** | 6379 | N/A (internal) | No | No | - | ✅ Running |
| **Ollama** | 11434 | http://192.168.86.149:11434 | LAN | Yes (RTX 2080 Ti) | - | ✅ Running |
| **Headscale** | 8085, 9090 | http://192.168.86.149:8085 | LAN | No | - | ✅ Running |
| **Netdata** | 19999 | http://192.168.86.149:19999 | LAN | No | - | ✅ Running |
| **Organizr** | 9999 | https://home.schweitz.net | Internet (SSO) | No | - | ✅ Running |
| **Watchtower** | None | N/A (background) | No | No | - | ✅ Running |
| **Open WebUI** | 82 | https://webui.schweitz.net | Internet (SSO) | No | - | ✅ Running |
| **Core API** | 8083 | http://192.168.86.149:8083 | LAN | No | - | ✅ Running (external) |
@@ -37,10 +35,10 @@
| **Paperless-ngx** | 8091 | https://documents.schweitz.net | Internet | No | 8 | ✅ Running |
| **ClamAV** | 3310 | N/A (host service) | No | No | - | ✅ Running |
| **AdGuard Home** | 53, 3053 | http://dns.schweitz.internal | LAN (DNS) | No | - | ✅ Running |
| **Tatlock UI** | 8092 | http://192.168.86.149:8092 | LAN (future: home.schweitz.net) | No | - | ✅ Running |
| **Tatlock UI** | 9999 | https://home.schweitz.net | Internet | No | - | ✅ Running |
### External Domains (SSL via Let's Encrypt)
- **home.schweitz.net** → Organizr (Protected by Authentik SSO)
- **home.schweitz.net** → Tatlock UI
- **media.schweitz.net** → Jellyfin
- **cloud.schweitz.net** → Nextcloud
- **git.schweitz.net** → Gitea
@@ -154,22 +152,13 @@ PostgreSQL Shared is a centralized PostgreSQL 17 database server providing isola
| **Resource Limits** | None |
| **GPU Required** | No |
| **Dependencies** | docker-dataplane network |
| **Databases** | `authentik` (Authentik SSO), `gitea` (Git hosting), `organizr` (Organizr dashboard), `paperless` (Document management), `system_settings` (Central Tatlock settings), `postgres` (default/admin) |
| **Database Users** | `authentik_user`, `gitea_user`, `organizr_user`, `paperless_user`, `settings` (system_settings RW), `postgres` (superuser) |
| **Databases** | `authentik` (Authentik SSO), `gitea` (Git hosting), `paperless` (Document management), `system_settings` (Central Tatlock settings), `postgres` (default/admin) |
| **Database Users** | `authentik_user`, `gitea_user`, `paperless_user`, `settings` (system_settings RW), `postgres` (superuser) |
| **Health Check** | `pg_isready -U postgres` (30s interval) |
| **Backup Strategy** | `/backups` volume for pg_dump exports |
**Initialization**: Databases and users for `authentik` and `gitea` are created by the `postgres-init.sh` script.
**Adding Organizr Database**:
1. **Generate a secure password** for the `organizr_user`.
2. **In Portainer, navigate to the `postgres-shared` service.**
3. **Go to the "Env" tab and add a new environment variable:**
* **Name:** `ORGANIZR_DB_PASSWORD`
* **Value:** *Your generated password*
4. **Redeploy the `postgres-shared` service.** This will trigger the `postgres-init.sh` script to create the `organizr` database and user.
---
### Redis Shared
@@ -313,80 +302,20 @@ Headscale is a self-hosted control server for Tailscale's mesh VPN protocol, cre
---
## Monitoring Layer
### Netdata
Netdata provides comprehensive real-time system performance monitoring with per-second metric collection for CPU, RAM, disk I/O, network traffic, and Docker container resource usage, displaying everything through interactive web dashboards with zero configuration required. It collects thousands of metrics automatically with minimal overhead, offering drill-down capabilities from system-wide views to per-container and per-process analysis. The service maintains short-term metric history in RAM and can stream data to long-term storage backends for historical analysis.
| Property | Value |
|----------|-------|
| **Image** | `netdata/netdata:latest` |
| **Container Name** | `netdata` |
| **Access URL** | http://192.168.86.149:19999 |
| **External Access** | LAN only (metrics dashboard) |
| **Port Mapping** | 19999:19999 (Web UI) |
| **Network Mode** | Host (for full system visibility) |
| **Restart Policy** | `unless-stopped` |
| **Volume Mounts** | `/proc:/host/proc:ro`, `/sys:/host/sys:ro`, `/var/run/docker.sock:/var/run/docker.sock:ro` |
| **Capabilities** | `SYS_PTRACE`, `apparmor:unconfined` |
| **Resource Limits** | None (monitoring overhead ~1-3% CPU) |
| **GPU Required** | No |
| **Dependencies** | Docker socket (read-only) |
| **Metric Retention** | ~1 hour (RAM-based) |
---
### Organizr
Organizr serves as a comprehensive unified dashboard that consolidates all homelab services into a single tabbed interface with integrated homepage widgets showing real-time statistics from Jellyfin streams, Netdata metrics, and download client activity. It provides customizable authentication per-tab with support for SSO integration, user management with group-based access control, and a mobile-responsive interface for managing the entire infrastructure from anywhere. The service acts as a central hub replacing the need for multiple bookmarks or remembering service ports, offering both quick-access tabs and homepage cards with live data feeds from connected services.
| Property | Value |
|----------|-------|
| **Image** | `organizr/organizr:latest` |
| **Container Name** | `organizr` |
| **Access URL (LAN)** | http://192.168.86.149:9999 |
| **Access URL (Public)** | https://home.schweitz.net |
| **External Access** | Yes (via NPM reverse proxy with SSL) |
| **Port Mapping** | 9999:80 (HTTP), 443:443 (HTTPS) |
| **Network Mode** | Bridge |
| **Restart Policy** | `unless-stopped` |
| **Volume Mounts** | `~/docker-data/organizr:/config` |
| **Environment** | `DB_TYPE=pgsql`, `DB_HOST=postgres-shared`, `DB_PORT=5432`, `DB_NAME=organizr`, `DB_USER=organizr_user`, `DB_PASS=${ORGANIZR_DB_PASSWORD}` |
| **Resource Limits** | None |
| **GPU Required** | No |
| **Dependencies** | PostgreSQL Shared |
| **Database** | PostgreSQL on `postgres-shared` (database `organizr`) |
| **Database Size** | ~5-10MB (typical) |
| **Integrated Services** | Jellyfin, Netdata |
| **Authentication** | Internal (supports SSO, Plex OAuth, LDAP) |
**Configuration**:
1. **In Portainer, navigate to the `organizr` stack.**
2. **Go to the "Env" tab and ensure the following environment variables are set:**
* `DB_TYPE=pgsql`
* `DB_HOST=postgres-shared`
* `DB_PORT=5432`
* `DB_NAME=organizr`
* `DB_USER=organizr_user`
* `DB_PASS`: This should be a secret. Create a secret in Portainer named `ORGANIZR_DB_PASSWORD` and set its value to the password you generated for the `organizr_user`.
3. **Redeploy the `organizr` stack.**
---
## Dashboard Layer
### Tatlock UI
Tatlock UI is a modern Flutter-based home lab dashboard designed to replace Organizr, providing a responsive web interface for monitoring and accessing all infrastructure services. Built as a stateless static web application served via nginx, it offers fast load times and a clean, customizable interface for the tower-of-joy infrastructure. The Flutter web build is compiled and containerized via Gitea Actions, with automatic deployment through Watchtower.
Tatlock UI is a modern Flutter-based home lab dashboard providing a responsive web interface for monitoring and accessing all infrastructure services. Built as a stateless static web application served via nginx, it offers fast load times and a clean, customizable interface for the tower-of-joy infrastructure. The Flutter web build is compiled and containerized via Gitea Actions, with automatic deployment through Watchtower.
| Property | Value |
|----------|-------|
| **Image** | `git.schweitz.net/jpmschweitzer/tatlock-ui:latest` |
| **Container Name** | `tatlock-ui` |
| **Access URL (LAN)** | http://192.168.86.149:8092 |
| **Access URL (Public)** | https://home.schweitz.net (future, replacing Organizr) |
| **External Access** | LAN only (future: via NPM reverse proxy with SSL) |
| **Port Mapping** | 8092:80 (HTTP) |
| **Access URL (LAN)** | http://192.168.86.149:9999 |
| **Access URL (Public)** | https://home.schweitz.net |
| **External Access** | Yes (via NPM reverse proxy with SSL) |
| **Port Mapping** | 9999:80 (HTTP) |
| **Network Mode** | Bridge (docker-dataplane) |
| **Restart Policy** | `unless-stopped` |
| **Volume Mounts** | None (stateless static web app) |
@@ -675,8 +604,6 @@ Gitea is a lightweight, self-hosted Git service providing repository hosting, is
| **Code-Server** | https://code.schweitz.net | Yes | Browser-based IDE |
| **Ollama** | http://192.168.86.149:11434 | No | ML model API |
| **Headscale** | http://192.168.86.149:8085 | No | VPN control server |
| **Netdata** | http://192.168.86.149:19999 | No | System metrics |
| **Organizr** | https://home.schweitz.net | Yes | Unified dashboard |
| **Open WebUI** | https://webui.schweitz.net | Yes (SSO) | LLM chat interface |
| **Tatlock** | https://tatlock.schweitz.net | Yes (SSO) | AI orchestration API |
| **Core API** | http://192.168.86.149:8083 | No | API functions & infrastructure mgmt |
@@ -685,7 +612,7 @@ Gitea is a lightweight, self-hosted Git service providing repository hosting, is
| **Gitea** | https://git.schweitz.net | Yes | Git repository hosting |
| **Samba** | \\\\192.168.86.149 | No | Network file shares |
| **Home Assistant** | https://housekeeping.schweitz.net | Yes | Smart home automation |
| **Tatlock UI** | http://192.168.86.149:8092 | No (future: Yes) | Home lab dashboard |
| **Tatlock UI** | https://home.schweitz.net | Yes | Home lab dashboard |
| **Watchtower** | N/A (background) | N/A | Auto-updates |
---
@@ -712,8 +639,6 @@ Gitea is a lightweight, self-hosted Git service providing repository hosting, is
| **Code-Server** | `~/.config/code-server/`, `~/docker-data/code-server/` | N/A | Config: ~5MB, Extensions: ~50-200MB, User data: ~50MB |
| **Ollama** | `~/docker-data/ollama/models/` | Alt: `/mnt/media/ollama/` | 2-15GB per model |
| **Headscale** | `~/docker-data/headscale/` | N/A | ~10MB |
| **Netdata** | RAM-based (ephemeral) | N/A | ~200MB RAM |
| **Organizr** | `~/docker-data/organizr/` | N/A | ~50MB |
| **Open WebUI** | `~/docker-data/open-webui/` | N/A | ~100MB |
| **Core API** | `~/docker-data/core-api/` | N/A | Logs: ~10MB |
| **Jellyfin** | `~/docker-data/jellyfin/` | `/mnt/media/jellyfin/` | Config: ~500MB, Media: ~2TB |
@@ -734,7 +659,7 @@ Gitea is a lightweight, self-hosted Git service providing repository hosting, is
| Network Name | Containers | Purpose |
|--------------|------------|---------|
| **docker-dataplane** | Ollama, Open WebUI, Core API, Qdrant, PostgreSQL Shared, Redis Shared, Headscale, Nextcloud, Gitea, Samba, Watchtower, Organizr, Netdata, Home Assistant | Unified service mesh for all containerized applications |
| **docker-dataplane** | Ollama, Open WebUI, Core API, Qdrant, PostgreSQL Shared, Redis Shared, Headscale, Nextcloud, Gitea, Samba, Watchtower, Tatlock UI, Home Assistant | Unified service mesh for all containerized applications |
| **host** | Portainer, NPM | Direct host port access for infrastructure management |
**Benefits of Consolidation**: