-
c87fd3b1f2
deploy: one-shot boot without the bootloader's help (terra runs Limine)

darmanandClaude Opus 4.8
2026-07-24 02:35:33 +02:00
-
e538788907
deploy: make the local reinstall path actually work, and fail closed

darmanandClaude Opus 4.8
2026-07-24 02:25:14 +02:00
-
0ea90200b4
deploy: automate a full local reinstall, self-elevating and interactive-safe

darmanandClaude Sonnet 5
2026-07-24 01:53:45 +02:00
-
fd8328d7b3
installer-iso: clone the (now public) repo fresh at boot, not baked in

darmanandClaude Sonnet 5
2026-07-24 01:25:58 +02:00
-
2a27d2cf4b
terra: kexec-local hangs hard on real hardware, switch docs to USB installer

darmanandClaude Sonnet 5
2026-07-24 01:11:52 +02:00
-
5845c29a44
Set darman password for terra
darman
2026-07-24 00:40:08 +02:00
-
caab166af8
terra: package Tome, add vivaldi + dotnet dev tools

darmanandClaude Sonnet 5
2026-07-24 00:35:13 +02:00
-
106c67963e
terra: package rishot, a quickshell screenshot/annotation overlay

darmanandClaude Sonnet 5
2026-07-24 00:34:41 +02:00
-
eac20f5e0a
terra: add proton-pass-cli via flake input

darmanandClaude Sonnet 5
2026-07-24 00:34:12 +02:00
-
a793ac50f5
readme: document terra first-install steps (in-place kexec)

darmanandClaude Sonnet 5
2026-07-23 23:31:45 +02:00
-
3556a27c2b
Cleanup
darman
2026-07-23 23:27:38 +02:00
-
6e9d588f00
terra: migrate quickshell config into repo, add quickshell + opencode packages

darmanandClaude Sonnet 5
2026-07-23 23:22:03 +02:00
-
67b12cb96b
terra: add Ryzen 9 5900X desktop (Hyprland, tailnet, dev tools)
darman
2026-07-23 23:14:36 +02:00
-
c86e8a19c4
common: add zsh + oh-my-zsh + powerlevel10k for darman
darman
2026-07-23 23:14:24 +02:00
-
a4c7768625
immich: fix OIDC clientId, redirect logout to immich's own login page
darman
2026-07-23 23:14:11 +02:00
-
80c2b4fc7b
deploy: harden kexec-local, key vault items by config, add VM test

darmanandClaude Opus 4.8
2026-07-22 23:47:20 +02:00
-
7bcea764f6
Added immich VHOST to neptun
darman
2026-07-21 00:53:29 +02:00
-
6ce61ab519
immich: add the service and import the ZimaOS library
darman
2026-07-21 00:51:10 +02:00
-
3a6950779e
services: move cinephage and mediamanager to experimental/
darman
2026-07-21 00:50:43 +02:00
-
10416ed23d
deploy: auto-fill password prompts from Proton Pass
darman
2026-07-21 00:50:32 +02:00
-
0995a5fe2f
headscale: move the tailnet to orbit.sol, route all DNS through pihole

darmanandClaude Opus 4.8
2026-07-20 23:01:47 +02:00
-
6bf0eeab04
pihole: fix gravity writes, declare the blocklists

darmanandClaude Opus 4.8
2026-07-20 21:52:01 +02:00
-
4fb4297e12
README: refresh post-deploy steps after the DNS and OIDC changes

darmanandClaude Opus 4.8
2026-07-20 21:31:50 +02:00
-
564dfb16b8
headscale: add OIDC login, stop overriding clients' local DNS

darmanandClaude Opus 4.8
2026-07-20 21:12:31 +02:00
-
d70df14c8a
README: document the per-host post-deploy steps

darmanandClaude Opus 4.8
2026-07-20 19:45:36 +02:00
-
d9e6b6b697
headplane: point OIDC at the real Authentik app; rotate tailnet keys

darmanandClaude Opus 4.8
2026-07-20 19:41:40 +02:00
-
d9ea6a9ecc
mercury: join the tailnet

darmanandClaude Opus 4.8
2026-07-20 19:41:39 +02:00
-
8aa3dac4de
deploy: prompt for the sudo password on switch/boot/test

darmanandClaude Opus 4.8
2026-07-20 19:41:39 +02:00
-
82122a964d
neptun: record post-install hardware config, rotate darman's password

darmanandClaude Opus 4.8
2026-07-20 09:45:29 +02:00
-
3671841eca
headscale: run our own DERP relay instead of Tailscale's

darmanandClaude Opus 4.8
2026-07-20 09:45:29 +02:00
-
4fedc80bb4
neptun: serve the vhosts that are actually in production

darmanandClaude Opus 4.8
2026-07-20 08:24:35 +02:00
-
ac42f231f5
neptun: replace Zitadel with Authentik as the OIDC provider

darmanandClaude Opus 4.8
2026-07-20 07:50:39 +02:00
-
d7a66f3e3b
Reorganize services/ into category subfolders

darmanandClaude Sonnet 5
2026-07-20 06:08:43 +02:00
-
4679afa505
Trim comments across configs and services

darmanandClaude Sonnet 5
2026-07-20 06:04:27 +02:00
-
c4702b577c
neptun: serve Headplane at vpn.mgaction.town/admin, auth via Zitadel OIDC

darmanandClaude Sonnet 5
2026-07-19 22:42:03 +02:00
-
5507dfac0a
neptun: add Headscale + Headplane

darmanandClaude Sonnet 5
2026-07-19 22:36:40 +02:00
-
ced2b56764
neptun: add Zitadel (identity/OIDC provider)

darmanandClaude Sonnet 5
2026-07-19 22:30:11 +02:00
-
84da4bacc5
neptun: forward :2222 to jupiter's gitea SSH server

darmanandClaude Sonnet 5
2026-07-19 22:22:39 +02:00
-
69a63dc615
Add *arr media stack + Gitea to jupiter

darmanandClaude Sonnet 5
2026-07-19 21:27:50 +02:00
-
fe5b363b73
Added Jellyfin service to jupiter
darman
2026-07-17 23:12:04 +02:00
-
ac05d948b6
refactor: rename vps host -> neptun (solar-system theme)
erik
2026-07-14 13:32:44 +02:00
-
19c65e1921
feat(pihole): wildcard *.jupiter.sol -> jupiter (VM-verified)
erik
2026-07-14 13:24:22 +02:00
-
9feecd8daa
docs: add CLAUDE.md (layout, deploy commands, secrets model, gotchas)
erik
2026-07-14 13:19:35 +02:00
-
a6e6f0d5d4
feat(mercury): static IPv6 (fd18:df17:9078:0::10) for IPv6 DNS
erik
2026-07-14 13:07:37 +02:00
-
20a16fda99
fix(pihole): pin image to 2026.07.2 (sed failed in prior commit)
erik
2026-07-14 00:11:08 +02:00
-
fd3ccf5f07
feat(mercury): pihole via container (native FTL segfaults on aarch64)
erik
2026-07-14 00:10:43 +02:00
-
c2ac7e3af4
fix(pihole): local DNS records for mercury.sol + jupiter.sol (dns.hosts)
erik
2026-07-13 22:58:41 +02:00
-
b0ad211a92
fix(mercury): sops age key on root fs (/var/lib/sops-nix/age.txt)
erik
2026-07-13 22:53:43 +02:00
-
dd6e093ca4
chore: set mercury secrets
darman
2026-07-13 22:42:20 +02:00
-
22a3eee85b
feat(mercury): pihole web password from sops via FTLCONF env override
erik
2026-07-13 22:40:12 +02:00
-
750821f43a
test: add mercury-vm (x86 qemu) to validate pihole+unbound before SD flash
erik
2026-07-13 22:02:34 +02:00
-
70a851c71d
feat(mercury): switch to pihole-ftl (declarative static leases)
erik
2026-07-13 21:56:08 +02:00
-
2f89a5c5e7
feat(deploy flash): auto-install sops age key onto the SD boot partition
erik
2026-07-13 21:02:34 +02:00
-
1937d59b2c
feat: per-host darman passwords via sops; mercury sops; AdGuard pw via UI
erik
2026-07-13 20:52:06 +02:00
-
b989490333
fix(deploy flash): validate device before building the image
erik
2026-07-13 20:44:38 +02:00
-
bcd2e6ebf2
feat(deploy): add image (build SD) + flash (build+dd to device) subcommands
erik
2026-07-13 20:44:04 +02:00
-
5a23638f75
feat(mercury): AdGuard Home DNS adblock + DHCP, forwards to unbound
erik
2026-07-13 20:13:01 +02:00
-
587fcbfa3d
feat(mercury): set real IP 10.0.0.10; add services/unbound.nix recursive resolver
erik
2026-07-13 20:01:55 +02:00
-
894f88c71e
feat: scaffold mercury (rpi 3b+ aarch64 SD image) for DNS/DHCP
erik
2026-07-13 19:49:45 +02:00
-
b6c393ff98
refactor: move host configs under hosts/{jupiter,vps}
erik
2026-07-13 19:34:27 +02:00
-
fb782cb9fe
refactor: split services into reusable services/ modules
erik
2026-07-13 19:13:11 +02:00
-
2b170af346
chore(scripts): move deploy+edit_secrets to scripts/, resolve repo root via git
erik
2026-07-13 18:58:25 +02:00
-
ec309c8fe1
refactor(deploy): generalize to any config, all params mandatory (no defaults)
erik
2026-07-13 01:05:28 +02:00
-
946c44f1d3
feat: scaffold netcup vps host (disko/vda, static net, tailscale, caddy)
erik
2026-07-13 01:01:53 +02:00
-
25c6982cea
feat(audiobookshelf): bind 0.0.0.0 so it's reachable over tailscale (VPS proxy)
erik
2026-07-13 00:26:16 +02:00
-
5dddc9d2fb
feat: tailscale via headscale (vpn.mgaction.town) + fix audiobookshelf extraGroups syntax
erik
2026-07-13 00:17:41 +02:00
-
101bb948ce
feat: add audiobookshelf (native service + caddy vhost)
erik
2026-07-13 00:05:54 +02:00
-
d83de7e37c
fix(boot): reboot=pci — warm reset hangs at firmware on this board
erik
2026-07-12 23:54:01 +02:00
-
1f5728b7ee
fix(nix): trust @wheel so remote deploy can push unsigned closures
erik
2026-07-12 23:17:21 +02:00
-
9db059df5a
feat: USB recovery installer ISO (ssh key baked in) for headless reinstall
erik
2026-07-12 22:42:29 +02:00
-
d105aa5908
fix(boot): pin eMMC initrd modules in configuration.nix (survive hw-config regen)
erik
2026-07-12 22:40:59 +02:00
-
7200ab5836
fix(deploy kexec): ship static cpio+gzip (ZimaOS lacks them); single-password multiplex
erik
2026-07-12 22:25:58 +02:00
-
f581203b57
feat: custom kexec installer for headless install on read-only-root (ZimaOS)

erikandClaude Opus 4.8
2026-07-12 22:14:35 +02:00
-
95e945fa6f
feat: authorize erik ssh key + add deploy script (install/switch)
erik
2026-07-12 21:45:14 +02:00
-
ba31568efc
fix(hardware): add eMMC (sdhci/mmc) initrd modules so root mounts on ZimaBlade
erik
2026-07-12 21:37:55 +02:00
-
5239f1ce71
chore: set real samba + darman secrets; edit_secrets zeditor support
erik
2026-07-12 21:35:58 +02:00
-
98c6390ede
fix(edit_secrets): guarantee a working editor (bundle nano, --wait for GUI)
erik
2026-07-12 21:32:12 +02:00
-
dd6c4829ad
feat: darman login password via sops (hashedPasswordFile)

erikandClaude Opus 4.8
2026-07-12 21:22:00 +02:00
-
7a97abeb25
chore: add edit_secrets helper for sops
erik
2026-07-12 21:10:56 +02:00
-
94b1460bc7
feat: wire ZimaBlade real disks (eMMC OS + md0 RAID0 data)

erikandClaude Opus 4.8
2026-07-12 20:59:25 +02:00
-
f9358375b5
feat: sops decrypts via pre-generated SSH host key (works on boot #1)

erikandClaude Opus 4.8
2026-07-12 20:48:33 +02:00
-
10387fdbee
feat: sops-nix for samba password secret

erikandClaude Opus 4.8
2026-07-12 20:16:17 +02:00
-
9fb32fd454
feat: disko OS-disk layout + nixos-anywhere install flow

erikandClaude Opus 4.8
2026-07-12 17:44:05 +02:00
-
27e9aaf787
chore: drop build-ova.sh (Docker build path, superseded by native nix build)

erikandClaude Opus 4.8
2026-07-12 15:41:56 +02:00
-
062a631edf
feat: samba password provisioning + caddy reverse proxy; rename user to darman

erikandClaude Opus 4.8
2026-07-11 19:01:34 +02:00
-
bb4823efe9
feat: flake NixOS config for jupiter + VirtualBox test image

erikandClaude Opus 4.8
2026-07-11 16:09:32 +02:00