75 lines
2.9 KiB
Markdown
75 lines
2.9 KiB
Markdown
---
|
|
schema_version: 1
|
|
id: home-server.host
|
|
type: reference
|
|
scope: [jupiter, hardware, operating-system, docker]
|
|
sensitivity: private-infrastructure
|
|
last_reviewed: "2026-10-06"
|
|
sources:
|
|
- kind: owner-report
|
|
reference: "Hardware, OS, bare-metal Docker and data-root confirmation, 2026-10-06"
|
|
- kind: owner-report
|
|
reference: "hostnamectl, timedatectl, user/group records, Docker info/version and systemd units, 2026-10-06"
|
|
related: [home-server.reference, home-server.storage, home-server.networking, home-server.deployment, home-server.operations]
|
|
update_triggers: [hardware-change, os-upgrade, kernel-upgrade, docker-reconfiguration, account-change, unit-change]
|
|
unknowns:
|
|
- exact-gpu-model
|
|
- jupiter-firewall-policy
|
|
- docker-package-installation-source
|
|
- backup-puller-account-purpose
|
|
---
|
|
|
|
# Host
|
|
|
|
| Component | Configuration |
|
|
| --- | --- |
|
|
| Host | Jupiter; bare metal |
|
|
| OS | Debian GNU/Linux 13 (trixie); x86_64 |
|
|
| Kernel | `6.12.94+deb13-amd64` |
|
|
| CPU | AMD Ryzen 5 5600X; 6 cores / 12 threads; reported 4.65 GHz |
|
|
| RAM | 1 x 16 GB Corsair Vengeance LPX |
|
|
| GPU | AMD Radeon HD 5000/6000/7350/8350 Series; discrete; exact model unresolved |
|
|
| Motherboard | Gigabyte B550M DS3H |
|
|
| Firmware | `FB`; dated `2023-06-08` |
|
|
| PSU | Corsair CV550 |
|
|
| SSD | Samsung 860 EVO; 1 TB; OS and SSD-backed caches |
|
|
| HDD | 2 x Seagate BarraCuda; 2 TB each; RAID 0 |
|
|
| Docker | Native host engine; data root `/var/lib/docker` |
|
|
| LAN | `192.168.1.56` |
|
|
| WireGuard | `10.0.0.2/24`; Mercury peer/server `10.0.0.1/24` |
|
|
| Time | `Europe/London`; RTC UTC; NTP active; clock synchronized at review |
|
|
|
|
## Docker runtime
|
|
|
|
| Setting | Observed value |
|
|
| --- | --- |
|
|
| Engine / API | Docker CE `29.8.2` / `1.56` |
|
|
| Compose CLI plugin | `v5.6.0`; not proof of Portainer's Compose implementation |
|
|
| containerd / runc | `v2.3.6` / `1.5.1` |
|
|
| Storage | `overlayfs`; containerd snapshotter |
|
|
| Cgroups | `systemd`; v2 |
|
|
| Logging | `json-file`; default |
|
|
| Firewall backend | `iptables` |
|
|
| Runtime security | AppArmor, seccomp, cgroup namespaces |
|
|
| Swarm / live restore | Inactive / disabled |
|
|
|
|
Docker/containerd services and `docker.socket` are enabled.
|
|
Docker starts `/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock`.
|
|
Supplied Docker unit has no explicit `/data` mount dependency or ordering against
|
|
`rclone-seedbox.service`.
|
|
|
|
## Host administration
|
|
|
|
| Account / group | Identity |
|
|
| --- | --- |
|
|
| `jay` | UID/GID `1000:1000`; `/home/jay`; bash; member of `sudo`, `docker`, `video`, `backups` |
|
|
| `backup-puller` | UID/GID `1001:1001`; `/home/backup-puller`; bash; member of `backups`; purpose unconfirmed |
|
|
| `backups` | Shared group; GID `1002` |
|
|
|
|
WireGuard and rclone: apt-managed. `wg-quick@wg0.service` is active in the supplied
|
|
snapshot. No host-level nginx on Jupiter; nginx still exists in application
|
|
containers. `unattended-upgrades.service` is enabled; effective update policy
|
|
not supplied.
|
|
|
|
Hardware/versions are a dated snapshot, not live telemetry.
|