[main]: Update home-server
This commit is contained in:
7 files changed
+82
-15
No files matched your search
@@ -12,6 +12,8 @@ sources:
|
|||||||
reference: "Portainer state added to Backrest plan, 2026-10-06"
|
reference: "Portainer state added to Backrest plan, 2026-10-06"
|
||||||
- kind: owner-report
|
- kind: owner-report
|
||||||
reference: "All stack environment values/secrets managed in Portainer; GitHub access uses PAT, 2026-10-06"
|
reference: "All stack environment values/secrets managed in Portainer; GitHub access uses PAT, 2026-10-06"
|
||||||
|
- kind: owner-report
|
||||||
|
reference: "No independent credential recovery except restic key, 2026-10-06"
|
||||||
- kind: repository
|
- kind: repository
|
||||||
repository: jupiter-stacks
|
repository: jupiter-stacks
|
||||||
revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15
|
revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15
|
||||||
@@ -22,7 +24,6 @@ related: [home-server.reference, home-server.networking, home-server.portainer,
|
|||||||
update_triggers: [access-policy-change, authentication-change, secret-rotation, middleware-change]
|
update_triggers: [access-policy-change, authentication-change, secret-rotation, middleware-change]
|
||||||
unknowns:
|
unknowns:
|
||||||
- authelia-file-placeholder-expansion-mechanism
|
- authelia-file-placeholder-expansion-mechanism
|
||||||
- off-host-authelia-secret-and-user-database-recovery
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Authentication
|
# Authentication
|
||||||
@@ -75,5 +76,6 @@ unconfirmed.
|
|||||||
|
|
||||||
Authelia data remains outside the supplied backup plan.
|
Authelia data remains outside the supplied backup plan.
|
||||||
[Portainer state](portainer.md) is covered; secret recovery remains untested.
|
[Portainer state](portainer.md) is covered; secret recovery remains untested.
|
||||||
|
No independent recovery arrangement exists for stack secrets.
|
||||||
GitHub repository access uses a PAT; host SSH keys and tunnel credential files
|
GitHub repository access uses a PAT; host SSH keys and tunnel credential files
|
||||||
are separate from stack environment variables.
|
are separate from stack environment variables.
|
||||||
@@ -10,6 +10,8 @@ sources:
|
|||||||
reference: "Backrest plan JSON, destination, key custody and no restore test, 2026-10-06"
|
reference: "Backrest plan JSON, destination, key custody and no restore test, 2026-10-06"
|
||||||
- kind: owner-report
|
- kind: owner-report
|
||||||
reference: "Updated four-service Backrest plan and deployed Portainer bind mount/container name, 2026-10-06"
|
reference: "Updated four-service Backrest plan and deployed Portainer bind mount/container name, 2026-10-06"
|
||||||
|
- kind: owner-report
|
||||||
|
reference: "Only restic key has independent custody; no independent credential recovery or backup/restore evidence, 2026-10-06"
|
||||||
- kind: repository
|
- kind: repository
|
||||||
repository: jupiter-stacks
|
repository: jupiter-stacks
|
||||||
revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15
|
revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15
|
||||||
@@ -18,12 +20,11 @@ sources:
|
|||||||
- stacks/gitea/docker-compose.yml
|
- stacks/gitea/docker-compose.yml
|
||||||
- stacks/paperless-ngx/docker-compose.yml
|
- stacks/paperless-ngx/docker-compose.yml
|
||||||
- stacks/vaultwarden/docker-compose.yml
|
- stacks/vaultwarden/docker-compose.yml
|
||||||
related: [home-server.reference, home-server.storage, home-server.portainer, home-server.authentication]
|
related: [home-server.reference, home-server.storage, home-server.portainer, home-server.authentication, home-server.operations]
|
||||||
update_triggers: [backup-plan-change, destination-change, hook-change, credential-change, restore-test]
|
update_triggers: [backup-plan-change, destination-change, hook-change, credential-change, restore-test]
|
||||||
unknowns:
|
unknowns:
|
||||||
- last-successful-backup-and-repository-check
|
- last-successful-backup-and-repository-check
|
||||||
- google-drive-repository-path-and-credential-recovery
|
- google-drive-repository-path
|
||||||
- off-host-backrest-config-recovery
|
|
||||||
- measured-rpo-and-rto
|
- measured-rpo-and-rto
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -36,6 +37,8 @@ unknowns:
|
|||||||
| Schedule | `0 3 * * *`; UTC; daily 03:00 |
|
| Schedule | `0 3 * * *`; UTC; daily 03:00 |
|
||||||
| Retention | `policyKeepLastN: 4`; last four snapshots, not four days |
|
| Retention | `policyKeepLastN: 4`; last four snapshots, not four days |
|
||||||
| Encryption key | iCloud password app; no key stored here |
|
| Encryption key | iCloud password app; no key stored here |
|
||||||
|
| Independent credential recovery | None beyond the restic encryption key |
|
||||||
|
| Backup / integrity evidence | None supplied |
|
||||||
| Restore test | Never performed |
|
| Restore test | Never performed |
|
||||||
|
|
||||||
## Coverage
|
## Coverage
|
||||||
@@ -92,4 +95,7 @@ Traefik, Backrest configuration, Docker named volumes, OS, or Mercury.
|
|||||||
|
|
||||||
Full-host recovery requires independently retrievable repository credentials,
|
Full-host recovery requires independently retrievable repository credentials,
|
||||||
configuration and restic key. Key custody alone does not establish recoverability.
|
configuration and restic key. Key custody alone does not establish recoverability.
|
||||||
|
No independent Google Drive/rclone credential recovery or Backrest-config
|
||||||
|
recovery arrangement exists. Recovering backed-up Portainer state is not a
|
||||||
|
substitute for first being able to retrieve the backup.
|
||||||
`/restore` is on the same RAID array; not an independent backup.
|
`/restore` is on the same RAID array; not an independent backup.
|
||||||
@@ -8,12 +8,13 @@ last_reviewed: "2026-10-06"
|
|||||||
sources:
|
sources:
|
||||||
- kind: owner-report
|
- kind: owner-report
|
||||||
reference: "Portainer GitHub/main/PAT configuration, environment management and manual pull/redeploy workflow, 2026-10-06"
|
reference: "Portainer GitHub/main/PAT configuration, environment management and manual pull/redeploy workflow, 2026-10-06"
|
||||||
related: [home-server.reference, home-server.host, home-server.portainer, home-server.authentication, home-server.backups]
|
- kind: owner-report
|
||||||
|
reference: "No independent credential recovery; operational rules not established, 2026-10-06"
|
||||||
|
related: [home-server.reference, home-server.host, home-server.portainer, home-server.authentication, home-server.backups, home-server.operations]
|
||||||
update_triggers: [deployment-workflow-change, repository-change, credential-rotation, rollback-policy-change]
|
update_triggers: [deployment-workflow-change, repository-change, credential-rotation, rollback-policy-change]
|
||||||
unknowns:
|
unknowns:
|
||||||
- github-pat-scopes-expiration-and-independent-recovery
|
- github-pat-scopes-and-expiration
|
||||||
- rollback-and-post-deployment-health-procedure
|
- post-deployment-health-criteria
|
||||||
- rules-for-portainer-ui-versus-repository-drift
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Deployment
|
# Deployment
|
||||||
@@ -39,5 +40,9 @@ repository credentials and stack environment values. [Portainer backups](backups
|
|||||||
exist; credential/state restoration is untested. Do not put secret values in
|
exist; credential/state restoration is untested. Do not put secret values in
|
||||||
this site or Git.
|
this site or Git.
|
||||||
|
|
||||||
|
No independent recovery arrangement exists for the PAT or stack secrets.
|
||||||
|
Rollback, health-check gates, approval rules and UI-versus-Git drift policy
|
||||||
|
are not established; do not assume permission to deploy, stop or delete services.
|
||||||
|
|
||||||
Host apt packages, fstab, RAID assembly, systemd units and Mercury nginx are
|
Host apt packages, fstab, RAID assembly, systemd units and Mercury nginx are
|
||||||
outside the Compose deployment workflow.
|
outside the Compose deployment workflow.
|
||||||
@@ -10,6 +10,8 @@ sources:
|
|||||||
reference: "Hardware, OS, bare-metal Docker and data-root confirmation, 2026-10-06"
|
reference: "Hardware, OS, bare-metal Docker and data-root confirmation, 2026-10-06"
|
||||||
- kind: owner-report
|
- kind: owner-report
|
||||||
reference: "hostnamectl, timedatectl, user/group records, Docker info/version and systemd units, 2026-10-06"
|
reference: "hostnamectl, timedatectl, user/group records, Docker info/version and systemd units, 2026-10-06"
|
||||||
|
- kind: owner-report
|
||||||
|
reference: "Owner does not recognize backup-puller account; no independent host-config archive, 2026-10-06"
|
||||||
related: [home-server.reference, home-server.storage, home-server.networking, home-server.deployment, home-server.operations]
|
related: [home-server.reference, home-server.storage, home-server.networking, home-server.deployment, home-server.operations]
|
||||||
update_triggers: [hardware-change, os-upgrade, kernel-upgrade, docker-reconfiguration, account-change, unit-change]
|
update_triggers: [hardware-change, os-upgrade, kernel-upgrade, docker-reconfiguration, account-change, unit-change]
|
||||||
unknowns:
|
unknowns:
|
||||||
@@ -63,7 +65,7 @@ Supplied Docker unit has no explicit `/data` mount dependency or ordering agains
|
|||||||
| Account / group | Identity |
|
| Account / group | Identity |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| `jay` | UID/GID `1000:1000`; `/home/jay`; bash; member of `sudo`, `docker`, `video`, `backups` |
|
| `jay` | UID/GID `1000:1000`; `/home/jay`; bash; member of `sudo`, `docker`, `video`, `backups` |
|
||||||
| `backup-puller` | UID/GID `1001:1001`; `/home/backup-puller`; bash; member of `backups`; purpose unconfirmed |
|
| `backup-puller` | UID/GID `1001:1001`; `/home/backup-puller`; bash; member of `backups`; origin/purpose not recognized by owner |
|
||||||
| `backups` | Shared group; GID `1002` |
|
| `backups` | Shared group; GID `1002` |
|
||||||
|
|
||||||
WireGuard and rclone: apt-managed. `wg-quick@wg0.service` is active in the supplied
|
WireGuard and rclone: apt-managed. `wg-quick@wg0.service` is active in the supplied
|
||||||
@@ -71,4 +73,8 @@ snapshot. No host-level nginx on Jupiter; nginx still exists in application
|
|||||||
containers. `unattended-upgrades.service` is enabled; effective update policy
|
containers. `unattended-upgrades.service` is enabled; effective update policy
|
||||||
not supplied.
|
not supplied.
|
||||||
|
|
||||||
|
No independent host-configuration archive is maintained. `backup-puller` must
|
||||||
|
not be assumed to perform backups; identify SSH/cron/service dependencies before
|
||||||
|
removing or repurposing it.
|
||||||
|
|
||||||
Hardware/versions are a dated snapshot, not live telemetry.
|
Hardware/versions are a dated snapshot, not live telemetry.
|
||||||
@@ -42,6 +42,7 @@ unknowns: []
|
|||||||
|
|
||||||
- `owner-report`: supplied host state/configuration; not independently inspected.
|
- `owner-report`: supplied host state/configuration; not independently inspected.
|
||||||
- `repository`: intended configuration at `revision`; not deployment proof.
|
- `repository`: intended configuration at `revision`; not deployment proof.
|
||||||
|
- `documentation`: upstream behaviour; not proof of deployed settings.
|
||||||
- `revision: working-tree`: uncommitted source; `base_revision`: base commit.
|
- `revision: working-tree`: uncommitted source; `base_revision`: base commit.
|
||||||
- `unknowns`: unresolved facts; never infer defaults as deployed state.
|
- `unknowns`: unresolved facts; never infer defaults as deployed state.
|
||||||
- `related`: stable document IDs; `update_triggers`: re-review conditions.
|
- `related`: stable document IDs; `update_triggers`: re-review conditions.
|
||||||
|
|||||||
@@ -8,10 +8,12 @@ last_reviewed: "2026-10-06"
|
|||||||
sources:
|
sources:
|
||||||
- kind: owner-report
|
- kind: owner-report
|
||||||
reference: "RAID/media tradeoff, CGNAT/public IPv4 rationale, no alerting and running monitoring/log containers, 2026-10-06"
|
reference: "RAID/media tradeoff, CGNAT/public IPv4 rationale, no alerting and running monitoring/log containers, 2026-10-06"
|
||||||
|
- kind: owner-report
|
||||||
|
reference: "Outages over one day catastrophic; no independent credentials except restic key, recovery evidence, host-config archive or operational rules, 2026-10-06"
|
||||||
related: [home-server.reference, home-server.host, home-server.mercury, home-server.networking, home-server.storage, home-server.backups, home-server.deployment]
|
related: [home-server.reference, home-server.host, home-server.mercury, home-server.networking, home-server.storage, home-server.backups, home-server.deployment]
|
||||||
update_triggers: [data-priority-change, architecture-change, alerting-change, recovery-test]
|
update_triggers: [data-priority-change, architecture-change, alerting-change, recovery-test]
|
||||||
unknowns:
|
unknowns:
|
||||||
- acceptable-downtime-and-data-loss-by-service
|
- acceptable-data-loss-and-recovery-order-by-service
|
||||||
- data-criticality-outside-the-four-backed-up-directories
|
- data-criticality-outside-the-four-backed-up-directories
|
||||||
- tested-full-host-recovery-order
|
- tested-full-host-recovery-order
|
||||||
- monitoring-review-frequency
|
- monitoring-review-frequency
|
||||||
@@ -45,7 +47,28 @@ stopped services and storage failures require manual detection.
|
|||||||
|
|
||||||
## Recovery status
|
## Recovery status
|
||||||
|
|
||||||
No restore test performed. Backup scope is documented in [Backups](backups.md);
|
| Item | Current status |
|
||||||
OS, host configuration and named-volume coverage must not be inferred from
|
| --- | --- |
|
||||||
the four-directory plan. Recovery priorities, RPO/RTO and validated bootstrap
|
| Jupiter outage tolerance | At most 24 hours; longer is catastrophic to the owner |
|
||||||
instructions remain unconfirmed.
|
| Recovery time | Not measured; 24-hour objective is not demonstrated |
|
||||||
|
| Acceptable data loss / RPO | Not defined |
|
||||||
|
| Independent recovery secrets | Restic encryption key only |
|
||||||
|
| Backup/integrity evidence | None supplied |
|
||||||
|
| Restore exercise | Never performed |
|
||||||
|
| Independent host-config archive | Not maintained |
|
||||||
|
| Operational rules / rollback policy | Not established |
|
||||||
|
|
||||||
|
Backup scope is documented in [Backups](backups.md). The four-directory plan
|
||||||
|
does not establish OS, host-configuration or named-volume recovery.
|
||||||
|
|
||||||
|
## Proposed recovery storage
|
||||||
|
|
||||||
|
Not implemented:
|
||||||
|
|
||||||
|
- Private Git repository: sanitized host configuration and bootstrap instructions.
|
||||||
|
- Encrypted off-host/offline archive: required credentials and secret-bearing configuration.
|
||||||
|
- Independent access instructions: account recovery, archive location and decryption.
|
||||||
|
|
||||||
|
Access/decryption must work without Jupiter or Portainer. A private Git
|
||||||
|
repository is not a substitute for protecting secret values. Restic key custody
|
||||||
|
alone does not provide Google Drive access.
|
||||||
@@ -10,6 +10,12 @@ sources:
|
|||||||
reference: "Ultra.cc plan, remaining capacity, rclone remote/process and enabled systemd unit, 2026-10-06"
|
reference: "Ultra.cc plan, remaining capacity, rclone remote/process and enabled systemd unit, 2026-10-06"
|
||||||
- kind: owner-report
|
- kind: owner-report
|
||||||
reference: "apt-managed rclone, active FUSE mount and Radarr/Sonarr bind-mount inspection, 2026-10-06"
|
reference: "apt-managed rclone, active FUSE mount and Radarr/Sonarr bind-mount inspection, 2026-10-06"
|
||||||
|
- kind: owner-report
|
||||||
|
reference: "Import-then-delete intent, Remove Completed enabled, sample ratio about 0.01 and global seeding ratio limit 1, 2026-10-06"
|
||||||
|
- kind: documentation
|
||||||
|
reference: "https://wiki.servarr.com/radarr/settings#remove-completed-downloads"
|
||||||
|
- kind: documentation
|
||||||
|
reference: "https://wiki.servarr.com/sonarr/settings#remove-completed-downloads"
|
||||||
- kind: repository
|
- kind: repository
|
||||||
repository: jupiter-stacks
|
repository: jupiter-stacks
|
||||||
revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15
|
revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15
|
||||||
@@ -22,7 +28,9 @@ unknowns:
|
|||||||
- total-traffic-allowance-and-reset-period
|
- total-traffic-allowance-and-reset-period
|
||||||
- renewal-behaviour
|
- renewal-behaviour
|
||||||
- rclone-cache-location-and-size-limit
|
- rclone-cache-location-and-size-limit
|
||||||
- import-copy-move-and-remote-deletion-policy
|
- import-copy-move-settings
|
||||||
|
- qbittorrent-seeding-limit-action-and-per-torrent-overrides
|
||||||
|
- download-client-categories-and-api-removal-outcome
|
||||||
- mount-startup-ordering-relative-to-docker-containers
|
- mount-startup-ordering-relative-to-docker-containers
|
||||||
- seedbox-backup-policy
|
- seedbox-backup-policy
|
||||||
---
|
---
|
||||||
@@ -90,3 +98,19 @@ propagated into existing containers.
|
|||||||
|
|
||||||
The FUSE-reported capacity is not evidence of the account quota; use the
|
The FUSE-reported capacity is not evidence of the account quota; use the
|
||||||
provider allocation above.
|
provider allocation above.
|
||||||
|
|
||||||
|
## Import / removal
|
||||||
|
|
||||||
|
Intent: Radarr/Sonarr import required media, then remove completed downloads.
|
||||||
|
Owner reports `Completed Download Handling / Remove Completed` enabled.
|
||||||
|
qBittorrent global seeding ratio limit: `1.0`.
|
||||||
|
|
||||||
|
Reported undeleted example: share ratio approximately `0.01`; seeded less
|
||||||
|
than one minute. That ratio does not meet the configured global limit.
|
||||||
|
`Completed` download status alone does not establish completed seeding.
|
||||||
|
|
||||||
|
Upstream requirements: successful import, supported seeding goal reached,
|
||||||
|
client reports seeding complete, paused/stopped torrent, expected category.
|
||||||
|
Removal is requested through qBittorrent's API, not by deleting through rclone.
|
||||||
|
Limit action, torrent overrides and removal after reaching the goal remain
|
||||||
|
unconfirmed; no configuration change or successful-removal evidence recorded.
|
||||||
Reference in new issue
Block a user