Commit Graph
149 Commits
Author SHA1 Message Date
jpmschweitzerandClaude Opus 4.6 4520f627ba ops(scheduler): add GCS credentials mount for offsite backups
Mount secrets directory and GCS_CREDENTIALS_FILE env var to support
the new gcs_backup_executor in scheduler v1.2.0.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-31 09:28:54 +02:00
jpmschweitzerandClaude Opus 4.6 73b70629bf docs(containers): remove obsolete Shell In A Box, update counts
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:39:18 +01:00
jpmschweitzerandClaude Opus 4.6 b7cca51d7a docs(stacks): update README for models stack and Matter Server
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:39:00 +01:00
jpmschweitzerandClaude Opus 4.6 a4379fe373 feat(stack): consolidate Ollama, Stable Audio, and TRELLIS into models stack
Merge three individual GPU service stacks into a unified models.yml.
All services share the RTX 2080 Ti and docker-dataplane network.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:38:52 +01:00
jpmschweitzerandClaude Opus 4.6 cfb6cea452 docs: add project handover notes
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:35:09 +01:00
jpmschweitzerandClaude Opus 4.6 d0f06918ea docs(containers): add Stable Audio and TRELLIS, update service counts
- Add full profiles for Stable Audio and TRELLIS services
- Update quick reference table, GPU services, and storage distribution
- Add new stacks to README port allocation and GPU section
- Update total services to 37 across 23 stacks

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:34:49 +01:00
jpmschweitzerandClaude Opus 4.6 bc1574b36e feat(stack): add Stable Audio and TRELLIS GPU service stacks
- Stable Audio Open: AI audio generation on port 11500 (~6GB VRAM)
- TRELLIS: 3D model generation on port 11510 (~6-8GB VRAM, low-VRAM fork)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:34:34 +01:00
jpmschweitzerandClaude Opus 4.6 827dffe164 fix(penpot): update assets storage config for Penpot 2.11+
Rename PENPOT_ASSETS_STORAGE_* to PENPOT_OBJECTS_STORAGE_* per upstream changes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:34:27 +01:00
jpmschweitzerandClaude Opus 4.6 71cd913d05 fix(core-api): use IP address for Home Assistant URL
Container name resolution doesn't work for host-networked services.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:34:19 +01:00
jpmschweitzerandClaude Opus 4.6 aa54af8a87 config(agents): add Anthropic API config for Tatlock and Webber
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:34:14 +01:00
jpmschweitzerandClaude Opus 4.6 dd141099e1 config(ollama): reduce VRAM usage for GPU sharing with other services
Change keep-alive from infinite to 5m and max loaded models from 2 to 1,
freeing VRAM for Stable Audio, TRELLIS, and other GPU services.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:34:09 +01:00
jpmschweitzerandClaude Opus 4.6 ec8c3f5925 feat(home-assistant): switch to host networking and add Matter Server
- Switch HA from bridge to host networking for better device discovery
- Add python-matter-server container for Matter protocol support
- Both services share host network for mDNS/IPv6 multicast
- Update NPM forward hostname to use IP address
- Add Matter Server setup instructions

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:33:49 +01:00
jpmschweitzerandClaude Opus 4.6 24a70d9527 fix(agents): correct RAM spec from 16GB to 64GB
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:33:42 +01:00
jpmschweitzerandClaude Opus 4.6 9ac817bb6e chore(gitignore): ignore local Claude settings and Jupyter checkpoints
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:33:35 +01:00
jpmschweitzerandClaude Opus 4.5 cd3cdad11c docs(containers): add Shell In A Box host service
Add shellinabox web-based terminal emulator running on port 4200,
accessible via https://shell.schweitz.net through NPM reverse proxy.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-12 17:55:10 +01:00
jpmschweitzerandClaude Opus 4.5 27e7d9aff0 docs(home-assistant): add MCP server setup guide for Claude integration
Documents the configuration steps for connecting Claude.ai and Claude Desktop
to Home Assistant via the Model Context Protocol (MCP) server endpoint.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-06 09:12:35 +01:00
jpmschweitzerandClaude Opus 4.5 653cd2771e docs(penpot): update status and correct port/healthcheck info
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-31 12:43:23 +01:00
jpmschweitzerandClaude Opus 4.5 f54b6cff08 fix(penpot): correct port mappings, healthchecks, and feature flags
- Fix frontend port mapping (8080, not 80)
- Fix healthcheck endpoints to use /readyz
- Add secret key to exporter service
- Disable email verification (no SMTP configured)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-31 12:40:19 +01:00
jpmschweitzerandClaude Opus 4.5 7d61fab2b7 feat(stack): add Penpot design platform deployment
Add self-hosted Penpot (Figma alternative) with:
- Docker stack using shared PostgreSQL and Redis infrastructure
- Authentik SSO integration (OIDC, password login disabled)
- Three services: frontend, backend, exporter
- Port 9001 for web UI, external via penpot.schweitz.net

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-31 11:33:03 +01:00
jpmschweitzerandClaude Opus 4.5 39b604a0bd config(authentik): increase outpost memory limit to 1G
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-22 19:03:25 +01:00
jpmschweitzerandClaude Opus 4.5 bcae6055af config(agents): fix ALLOWED_PATHS array syntax in Webber
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-22 19:01:38 +01:00
jpmschweitzerandClaude Opus 4.5 fad6325b80 docs(amp): document AMP containerization migration
- AMP ADS controller now runs in Docker container (standalone, not Portainer stack)
- Uses host network mode for game server container communication
- Custom entrypoint wrapper handles Docker socket permissions
- Storage split: SSD (~/docker-data/amp/) for config, HDD (/mnt/media/amp/instances/) for game data
- Updated quick reference, service access matrix, storage distribution, and network architecture tables

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-22 18:59:15 +01:00
jpmschweitzerandClaude Opus 4.5 e8021307da feat(stack): create unified agents stack with Tatlock and Webber
Consolidate Tatlock API into new agents stack and add Webber LLM agent
orchestration service. Webber provides autonomous agent execution with
tool use, authenticating via Tatlock API.

Changes:
- Add stacks/agents.yml with Tatlock (port 8000) and Webber (port 8086)
- Remove stacks/tatlock.yml (merged into agents stack)
- Document Webber service in CONTAINERS.md (Redis DB 9)
- Add full Tatlock API documentation to CONTAINERS.md

Config updates (pre-existing):
- core-api: Enable OIDC, add host stats access, simplify model config
- gitea: Migrate from dedicated DB to postgres-shared
- media: Remove GPU reservation from Jellyfin

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-09 19:27:44 +01:00
jpmschweitzerandClaude Opus 4.5 3df367ff85 config(media): add SABnzbd host whitelist for web access
Adds HOST_WHITELIST env var to allow access from container name,
localhost, LAN IP, and hostname.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-06 18:42:46 +01:00
jpmschweitzerandClaude Opus 4.5 d3400fb622 config(authentik): optimize DB connections and worker scaling
- Replace USE_PGBOUNCER with CONN_MAX_AGE=0 and CONN_HEALTH_CHECKS
- Reduce web workers to 1 with 2 threads (homelab scale)
- Update worker config: CONCURRENCY=1, THREADS=2
- Remove redundant Redis config from worker service

Reduces overall PostgreSQL connection count.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-06 12:42:04 +01:00
jpmschweitzerandClaude Opus 4.5 6052f81ec1 feat(stack): add unified media stack with Sonarr, Radarr, Prowlarr, SABnzbd
Consolidates Jellyfin into a new media stack with full *arr automation:
- Sonarr (8989) - TV show management
- Radarr (7878) - Movie management
- Prowlarr (9696) - Indexer management
- SABnzbd (8880) - Usenet download client
- Jellyfin (8096) - Media streaming with GPU transcoding

Database: All *arr apps use PostgreSQL (postgres-shared) with media_user.
Databases created: sonarr, radarr, prowlarr

Also adds pg-connections.sh utility script for monitoring PostgreSQL connections.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-06 12:39:27 +01:00
jpmschweitzer dc1fb868fd host system stats access 2026-01-04 11:47:29 +01:00
jpmschweitzerandClaude Opus 4.5 47ceb31a18 config(authentik): upgrade to 2025.10.3, remove Redis dependency
Authentik 2025.10 no longer uses Redis for caching/sessions (now uses
Postgres). Updated stack to remove Redis config and renamed deprecated
WORKER__CONCURRENCY to WORKER__THREADS. Redis DB 0 now available.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-04 11:02:28 +01:00
jpmschweitzerandClaude Opus 4.5 ba0aa5ef3d feat(stack): replace Organizr with Tatlock UI, remove Netdata
Remove Organizr dashboard and Netdata monitoring:
- Delete stacks/organizr.yml and stacks/netdata.yml
- Delete organizr-widgets/ directory and npm forward-auth config
- Remove organizr database references from postgres-shared docs

Promote Tatlock UI as primary dashboard:
- Move from port 8092 to 9999 (Organizr's port)
- Enable external access at home.schweitz.net
- Update all documentation references

Update service counts: 26 containers across 20 stacks

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-03 11:23:45 +01:00
jpmschweitzerandClaude Opus 4.5 d647a2e005 config(core-api): reorganize environment and add service integrations
- Disable debug mode for production
- Add Portainer, NPM, Postgres, Authentik API configurations
- Add SearXNG URL for search integration
- Use container name for Home Assistant URL
- Simplify healthcheck to /health endpoint
- Group environment variables by service

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-02 13:58:57 +01:00
jpmschweitzerandClaude Opus 4.5 4dc72b2128 feat(stack): add Tatlock UI home lab dashboard
Add Flutter-based dashboard to replace Organizr:
- Port 8092, stateless static web app via nginx
- Resource limits (128M/32M), wget-based healthcheck
- Documented in CONTAINERS.md with full service profile

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-02 13:58:26 +01:00
jpmschweitzerandClaude Opus 4.5 7b729aa285 docs: remove completed Paperless-ngx planning document
The NEW_CONTAINERS.md planning document for Paperless-ngx and ClamAV
has served its purpose - all information was already integrated into
CONTAINERS.md.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-01 20:52:10 +01:00
jpmschweitzerandClaude Opus 4.5 566afe0de5 config(library-desk): add system settings database and scheduler integration
Add environment variables for:
- Central settings database (postgres-shared/system_settings)
- Scheduler service URL for task coordination

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-31 00:22:17 +01:00
jpmschweitzerandClaude Opus 4.5 f3d29089d6 config(npm): reorganize tatlock and webui domain mappings
Fix naming conflict where tatlock.schweitz.net incorrectly pointed to
Open WebUI. Now correctly maps:
- tatlock.schweitz.net → Tatlock API (port 8000) with Authentik SSO
- webui.schweitz.net → Open WebUI (port 82) with Authentik SSO
- Corresponding .schweitz.internal domains for programmatic access

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-31 00:03:55 +01:00
jpmschweitzerandClaude Opus 4.5 facdd6a2ec feat(stack): add AdGuard Home DNS ad-blocking
Deploy AdGuard Home as network-wide DNS ad blocker with:
- Quad9 DoH upstream for encrypted, security-focused DNS
- Web UI on port 3053, DNS on 192.168.86.149:53
- Internal domain: dns.schweitz.internal

Includes setup guide (ADGUARD_SETUP.md) for completing wizard.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-25 14:09:38 +01:00
jpmschweitzerandClaude Opus 4.5 7f9e73a849 feat(npm): add internal domain aliases for all external hosts
Add *.schweitz.internal domains as HTTP-only alternatives to *.schweitz.net
domains for programmatic access without SSL or Authentik authentication.

- Configure 11 internal domain proxy hosts in NPM
- Document internal domain setup process in setup-new-host.md
- Add internal domains reference table to CONTAINERS.md
- Update external domains list with library and tatlock mappings

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-25 11:51:13 +01:00
jpmschweitzerandClaude Opus 4.5 765818b4e9 feat(stack): add Paperless-ngx document management system
- Add paperless.yml stack (port 8091, documents.schweitz.net)
- Uses shared postgres (DB: paperless) and redis (DB 8)
- ClamAV installed on host for virus scanning (port 3310)
- Add Paperless integration to library-desk stack
- Update CONTAINERS.md with Paperless and ClamAV profiles
- Add Portainer and NPM API documentation to setup-new-host.md
- Update redis-shared.yml and postgres-shared.yml with Paperless refs

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-25 00:36:15 +01:00
jpmschweitzer 7e06c915ad remove old webscraper code and add new home assistant settings to env for core-api.yaml 2025-12-24 19:38:51 +01:00
jpmschweitzerandClaude Opus 4.5 6a9000569a feat(stack): add Home Assistant smart home platform
- Add home-assistant.yml stack (port 8123, privileged mode for USB)
- External access via https://housekeeping.schweitz.net
- Health check using /manifest.json endpoint
- Update CONTAINERS.md with service profile
- Update stacks/README.md with port allocation

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-14 22:32:13 +01:00
jpmschweitzer b3a30a5694 add qdrant env vars to tatlock 2025-12-14 15:49:57 +01:00
jpmschweitzerandClaude Opus 4.5 64ffeda928 feat: add Redis DB tracking and resolve DB conflicts
- Add Redis DB column to All Services table in CONTAINERS.md
- Move Nextcloud from DB 3 to DB 7 to resolve conflict with Scheduler
- Split Tatlock Redis usage: DB 1 (memory), DB 6 (benchmarks)
- Add missing services to table: Wiki.js, Tatlock, Library Desk

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-14 14:46:21 +01:00
jpmschweitzerandClaude Opus 4.5 5d0c0fbad9 chore: remove hardcoded APP_VERSION from stack files
🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-14 13:36:03 +01:00
jpmschweitzerandClaude Opus 4.5 bde4386b90 feat: enable Watchtower HTTP API and use internal registry
- Add HTTP API to Watchtower for CI/CD triggered updates
- Update custom container images to use git.schweitz.internal
- Add GITEA_TOKEN env var to scheduler for release cleanup task

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-14 13:26:51 +01:00
jpmschweitzerandClaude Opus 4.5 9b2b32323c docs: add setup guide for SSL + Authentik protected hosts
Step-by-step instructions for adding new subdomains with:
- Let's Encrypt SSL via NPM
- Authentik forward authentication
- Troubleshooting common issues

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-14 12:06:05 +01:00
jpmschweitzerandClaude Opus 4.5 75c3950dd8 feat: add Docker healthchecks, remove Uptime Kuma
- Add healthcheck configurations to 13 stacks for Portainer status monitoring
- Remove Uptime Kuma service (replaced by Docker healthchecks)
- Clean up stale Heimdall references
- Update documentation and service counts

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-14 12:05:05 +01:00
jpmschweitzer 8793ff1779 update with library desk api ENV vars 2025-12-11 19:20:40 +01:00
jpmschweitzerandClaude Opus 4.5 7c62577377 fix: use JSON array format for CORS_ORIGINS env var
Pydantic settings expects list[str] fields as JSON arrays, not plain strings.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-11 18:46:42 +01:00
jpmschweitzerandClaude Opus 4.5 235b694356 feat: add tatlock stack for homelab butler API
- OpenAI-compatible API server with LLM agent orchestration
- Port 8000, connects to docker-dataplane network
- Integrates with ollama, searxng, redis-shared services
- Watchtower auto-update enabled

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-11 18:28:04 +01:00
jpmschweitzerandClaude Opus 4.5 6581a743ac refactor: extract library-desk to standalone repository
- Move library-desk service to git.schweitz.net/jpmschweitzer/library-desk
- Update stacks/library-desk.yml to use container image
- Add library-desk to External Repositories in CONTAINERS.md
- Remove source code (now in external repo)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-11 17:46:48 +01:00
jpmschweitzer 98c92a1211 cleanup of docs 2025-12-11 16:32:37 +01:00