Commit Graph

  • c87fd3b1f2 deploy: one-shot boot without the bootloader's help (terra runs Limine) darmanandClaude Opus 4.8 2026-07-24 02:35:33 +02:00
  • e538788907 deploy: make the local reinstall path actually work, and fail closed darmanandClaude Opus 4.8 2026-07-24 02:25:14 +02:00
  • 0ea90200b4 deploy: automate a full local reinstall, self-elevating and interactive-safe darmanandClaude Sonnet 5 2026-07-24 01:53:45 +02:00
  • fd8328d7b3 installer-iso: clone the (now public) repo fresh at boot, not baked in darmanandClaude Sonnet 5 2026-07-24 01:25:58 +02:00
  • 2a27d2cf4b terra: kexec-local hangs hard on real hardware, switch docs to USB installer darmanandClaude Sonnet 5 2026-07-24 01:11:52 +02:00
  • 5845c29a44 Set darman password for terra darman 2026-07-24 00:40:08 +02:00
  • caab166af8 terra: package Tome, add vivaldi + dotnet dev tools darmanandClaude Sonnet 5 2026-07-24 00:35:13 +02:00
  • 106c67963e terra: package rishot, a quickshell screenshot/annotation overlay darmanandClaude Sonnet 5 2026-07-24 00:34:41 +02:00
  • eac20f5e0a terra: add proton-pass-cli via flake input darmanandClaude Sonnet 5 2026-07-24 00:34:12 +02:00
  • a793ac50f5 readme: document terra first-install steps (in-place kexec) darmanandClaude Sonnet 5 2026-07-23 23:31:45 +02:00
  • 3556a27c2b Cleanup darman 2026-07-23 23:27:38 +02:00
  • 6e9d588f00 terra: migrate quickshell config into repo, add quickshell + opencode packages darmanandClaude Sonnet 5 2026-07-23 23:22:03 +02:00
  • 67b12cb96b terra: add Ryzen 9 5900X desktop (Hyprland, tailnet, dev tools) darman 2026-07-23 23:14:36 +02:00
  • c86e8a19c4 common: add zsh + oh-my-zsh + powerlevel10k for darman darman 2026-07-23 23:14:24 +02:00
  • a4c7768625 immich: fix OIDC clientId, redirect logout to immich's own login page darman 2026-07-23 23:14:11 +02:00
  • 80c2b4fc7b deploy: harden kexec-local, key vault items by config, add VM test darmanandClaude Opus 4.8 2026-07-22 23:47:20 +02:00
  • 7bcea764f6 Added immich VHOST to neptun darman 2026-07-21 00:53:29 +02:00
  • 6ce61ab519 immich: add the service and import the ZimaOS library darman 2026-07-21 00:51:10 +02:00
  • 3a6950779e services: move cinephage and mediamanager to experimental/ darman 2026-07-21 00:50:43 +02:00
  • 10416ed23d deploy: auto-fill password prompts from Proton Pass darman 2026-07-21 00:50:32 +02:00
  • 0995a5fe2f headscale: move the tailnet to orbit.sol, route all DNS through pihole darmanandClaude Opus 4.8 2026-07-20 23:01:47 +02:00
  • 6bf0eeab04 pihole: fix gravity writes, declare the blocklists darmanandClaude Opus 4.8 2026-07-20 21:52:01 +02:00
  • 4fb4297e12 README: refresh post-deploy steps after the DNS and OIDC changes darmanandClaude Opus 4.8 2026-07-20 21:31:50 +02:00
  • 564dfb16b8 headscale: add OIDC login, stop overriding clients' local DNS darmanandClaude Opus 4.8 2026-07-20 21:12:31 +02:00
  • d70df14c8a README: document the per-host post-deploy steps darmanandClaude Opus 4.8 2026-07-20 19:45:36 +02:00
  • d9e6b6b697 headplane: point OIDC at the real Authentik app; rotate tailnet keys darmanandClaude Opus 4.8 2026-07-20 19:41:40 +02:00
  • d9ea6a9ecc mercury: join the tailnet darmanandClaude Opus 4.8 2026-07-20 19:41:39 +02:00
  • 8aa3dac4de deploy: prompt for the sudo password on switch/boot/test darmanandClaude Opus 4.8 2026-07-20 19:41:39 +02:00
  • 82122a964d neptun: record post-install hardware config, rotate darman's password darmanandClaude Opus 4.8 2026-07-20 09:45:29 +02:00
  • 3671841eca headscale: run our own DERP relay instead of Tailscale's darmanandClaude Opus 4.8 2026-07-20 09:45:29 +02:00
  • 4fedc80bb4 neptun: serve the vhosts that are actually in production darmanandClaude Opus 4.8 2026-07-20 08:24:35 +02:00
  • ac42f231f5 neptun: replace Zitadel with Authentik as the OIDC provider darmanandClaude Opus 4.8 2026-07-20 07:50:39 +02:00
  • d7a66f3e3b Reorganize services/ into category subfolders darmanandClaude Sonnet 5 2026-07-20 06:08:43 +02:00
  • 4679afa505 Trim comments across configs and services darmanandClaude Sonnet 5 2026-07-20 06:04:27 +02:00
  • c4702b577c neptun: serve Headplane at vpn.mgaction.town/admin, auth via Zitadel OIDC darmanandClaude Sonnet 5 2026-07-19 22:42:03 +02:00
  • 5507dfac0a neptun: add Headscale + Headplane darmanandClaude Sonnet 5 2026-07-19 22:36:40 +02:00
  • ced2b56764 neptun: add Zitadel (identity/OIDC provider) darmanandClaude Sonnet 5 2026-07-19 22:30:11 +02:00
  • 84da4bacc5 neptun: forward :2222 to jupiter's gitea SSH server darmanandClaude Sonnet 5 2026-07-19 22:22:39 +02:00
  • 69a63dc615 Add *arr media stack + Gitea to jupiter darmanandClaude Sonnet 5 2026-07-19 21:27:50 +02:00
  • fe5b363b73 Added Jellyfin service to jupiter darman 2026-07-17 23:12:04 +02:00
  • ac05d948b6 refactor: rename vps host -> neptun (solar-system theme) erik 2026-07-14 13:32:44 +02:00
  • 19c65e1921 feat(pihole): wildcard *.jupiter.sol -> jupiter (VM-verified) erik 2026-07-14 13:24:22 +02:00
  • 9feecd8daa docs: add CLAUDE.md (layout, deploy commands, secrets model, gotchas) erik 2026-07-14 13:19:35 +02:00
  • a6e6f0d5d4 feat(mercury): static IPv6 (fd18:df17:9078:0::10) for IPv6 DNS erik 2026-07-14 13:07:37 +02:00
  • 20a16fda99 fix(pihole): pin image to 2026.07.2 (sed failed in prior commit) erik 2026-07-14 00:11:08 +02:00
  • fd3ccf5f07 feat(mercury): pihole via container (native FTL segfaults on aarch64) erik 2026-07-14 00:10:43 +02:00
  • c2ac7e3af4 fix(pihole): local DNS records for mercury.sol + jupiter.sol (dns.hosts) erik 2026-07-13 22:58:41 +02:00
  • b0ad211a92 fix(mercury): sops age key on root fs (/var/lib/sops-nix/age.txt) erik 2026-07-13 22:53:43 +02:00
  • dd6e093ca4 chore: set mercury secrets darman 2026-07-13 22:42:20 +02:00
  • 22a3eee85b feat(mercury): pihole web password from sops via FTLCONF env override erik 2026-07-13 22:40:12 +02:00
  • 750821f43a test: add mercury-vm (x86 qemu) to validate pihole+unbound before SD flash erik 2026-07-13 22:02:34 +02:00
  • 70a851c71d feat(mercury): switch to pihole-ftl (declarative static leases) erik 2026-07-13 21:56:08 +02:00
  • 2f89a5c5e7 feat(deploy flash): auto-install sops age key onto the SD boot partition erik 2026-07-13 21:02:34 +02:00
  • 1937d59b2c feat: per-host darman passwords via sops; mercury sops; AdGuard pw via UI erik 2026-07-13 20:52:06 +02:00
  • b989490333 fix(deploy flash): validate device before building the image erik 2026-07-13 20:44:38 +02:00
  • bcd2e6ebf2 feat(deploy): add image (build SD) + flash (build+dd to device) subcommands erik 2026-07-13 20:44:04 +02:00
  • 5a23638f75 feat(mercury): AdGuard Home DNS adblock + DHCP, forwards to unbound erik 2026-07-13 20:13:01 +02:00
  • 587fcbfa3d feat(mercury): set real IP 10.0.0.10; add services/unbound.nix recursive resolver erik 2026-07-13 20:01:55 +02:00
  • 894f88c71e feat: scaffold mercury (rpi 3b+ aarch64 SD image) for DNS/DHCP erik 2026-07-13 19:49:45 +02:00
  • b6c393ff98 refactor: move host configs under hosts/{jupiter,vps} erik 2026-07-13 19:34:27 +02:00
  • fb782cb9fe refactor: split services into reusable services/ modules erik 2026-07-13 19:13:11 +02:00
  • 2b170af346 chore(scripts): move deploy+edit_secrets to scripts/, resolve repo root via git erik 2026-07-13 18:58:25 +02:00
  • ec309c8fe1 refactor(deploy): generalize to any config, all params mandatory (no defaults) erik 2026-07-13 01:05:28 +02:00
  • 946c44f1d3 feat: scaffold netcup vps host (disko/vda, static net, tailscale, caddy) erik 2026-07-13 01:01:53 +02:00
  • 25c6982cea feat(audiobookshelf): bind 0.0.0.0 so it's reachable over tailscale (VPS proxy) erik 2026-07-13 00:26:16 +02:00
  • 5dddc9d2fb feat: tailscale via headscale (vpn.mgaction.town) + fix audiobookshelf extraGroups syntax erik 2026-07-13 00:17:41 +02:00
  • 101bb948ce feat: add audiobookshelf (native service + caddy vhost) erik 2026-07-13 00:05:54 +02:00
  • d83de7e37c fix(boot): reboot=pci — warm reset hangs at firmware on this board erik 2026-07-12 23:54:01 +02:00
  • 1f5728b7ee fix(nix): trust @wheel so remote deploy can push unsigned closures erik 2026-07-12 23:17:21 +02:00
  • 9db059df5a feat: USB recovery installer ISO (ssh key baked in) for headless reinstall erik 2026-07-12 22:42:29 +02:00
  • d105aa5908 fix(boot): pin eMMC initrd modules in configuration.nix (survive hw-config regen) erik 2026-07-12 22:40:59 +02:00
  • 7200ab5836 fix(deploy kexec): ship static cpio+gzip (ZimaOS lacks them); single-password multiplex erik 2026-07-12 22:25:58 +02:00
  • f581203b57 feat: custom kexec installer for headless install on read-only-root (ZimaOS) erikandClaude Opus 4.8 2026-07-12 22:14:35 +02:00
  • 95e945fa6f feat: authorize erik ssh key + add deploy script (install/switch) erik 2026-07-12 21:45:14 +02:00
  • ba31568efc fix(hardware): add eMMC (sdhci/mmc) initrd modules so root mounts on ZimaBlade erik 2026-07-12 21:37:55 +02:00
  • 5239f1ce71 chore: set real samba + darman secrets; edit_secrets zeditor support erik 2026-07-12 21:35:58 +02:00
  • 98c6390ede fix(edit_secrets): guarantee a working editor (bundle nano, --wait for GUI) erik 2026-07-12 21:32:12 +02:00
  • dd6c4829ad feat: darman login password via sops (hashedPasswordFile) erikandClaude Opus 4.8 2026-07-12 21:22:00 +02:00
  • 7a97abeb25 chore: add edit_secrets helper for sops erik 2026-07-12 21:10:56 +02:00
  • 94b1460bc7 feat: wire ZimaBlade real disks (eMMC OS + md0 RAID0 data) erikandClaude Opus 4.8 2026-07-12 20:59:25 +02:00
  • f9358375b5 feat: sops decrypts via pre-generated SSH host key (works on boot #1) erikandClaude Opus 4.8 2026-07-12 20:48:33 +02:00
  • 10387fdbee feat: sops-nix for samba password secret erikandClaude Opus 4.8 2026-07-12 20:16:17 +02:00
  • 9fb32fd454 feat: disko OS-disk layout + nixos-anywhere install flow erikandClaude Opus 4.8 2026-07-12 17:44:05 +02:00
  • 27e9aaf787 chore: drop build-ova.sh (Docker build path, superseded by native nix build) erikandClaude Opus 4.8 2026-07-12 15:41:56 +02:00
  • 062a631edf feat: samba password provisioning + caddy reverse proxy; rename user to darman erikandClaude Opus 4.8 2026-07-11 19:01:34 +02:00
  • bb4823efe9 feat: flake NixOS config for jupiter + VirtualBox test image erikandClaude Opus 4.8 2026-07-11 16:09:32 +02:00