- HCL 79.5%
- Shell 15.6%
- Makefile 4.9%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
* Public: Digital Ocean live! Private: image updates, infra updates, ansible enabled --------- Co-authored-by: naliana <naliana@naliana.net> |
||
| infrastructure | ||
| scripts | ||
| services | ||
| .gitignore | ||
| Makefile | ||
| README.md | ||
About
Playground for microservices, infrastructure and backup scripts.
One Button deployments
#v3 - Logging & metrics services - clean up digital ocean images - we need to clean up how env vars are handled (github/postgress use different stypes) - automated updates for alpine - fetching new versions? - automated deployments for media
- Do a live & offline backup once mealie data is setup
- setup a script to pull volume into home
- Use ansible to change VM passwords so each vm has a different pw, different root per vm
- Forgejo syncing from github? Use Github actions or Forgejo actions?
###Bonus (v4+) - 1pass handles env secrets - ssh keys stored in 1pass? - manage proxmox nodes with ansible! - pve cluster backup - sqlite3 /var/lib/pve-cluster/config.db .dump > ~/config.dump.$(date --utc +%Z%Y%m%d%H%M%S).sql - https://forum.proxmox.com/threads/backup-cluster-config-pmxcfs-etc-pve.154569/ - xmr remote node for light systems - setup digital ocean forgeo instance for mirroring - packer builds on all 4 nodes the same image so I dont have to swap vars all the time >:| - forgeo/gha for deployments? - make a dual network node (redundancy for access) - make a special service for this with just the wg containers
encrypted folder in dropbox w/ gpg
- encrypt folder in dropbox with gpg
- should be portable across os
Internal DNS so we dont have to update IPS constantly
ON HOLD - Router sucks
- reverse proxy
- PIhole DNS
freenas permission
- user based access -- jelly, sonarr, ect
env secured
- 1pass autofill & inject env file secrets
- test on servers
Infrastructure
- UPS GRACEFUL shutdown
TP-Link switch
- external firewall
- internal firewall
- segmented network
- vlan for lab, guest, home iot, child
vlan cameras
- iot vlan
Services
Kwixi
- integrate into main
Syncthing
Nextcloud
Secondary Seed compose
- Binhex for fetch
- nzb grabber
Jitsi
- selfhostd jitsi meet server
- public digital ocean
Whole home ad-guard/pihole
- https://www.theobjectivedad.com/pub/20230410-homelab-4/index.html
- reverse proxy pointed at pihole/ad-guard
nextcloud on k8s as POC
- migrate services to k8s w/ helm
Services to try out
- https://keycloak.com
- https://owncloud.dev/ocis
- https://github.com/slskd/slskd
- https://www.authelia.com/
- https://github.com/k4lipso/gokill
- https://caddyserver.com/
- https://www.sniffnet.net/
- https://www.debontonline.com/2021/11/kubernetes-part-16-deploy-jellyfin.html
- https://jellyfin.org/docs/general/networking/caddy/
- https://www.pcloud.com/
- https://github.com/benphelps/homepage
- https://tandoor.dev/
- https://www.authelia.com/
- https://joplinapp.org/
- https://www.netdata.cloud/
- https://github.com/freifunkMUC/wg-access-server
- https://www.kiwix.org/en/cardshop-access/
- https://github.com/redhuntlabs/HTTPLoot
- https://github.com/0xInfection/TIDoS-Framework
- https://www.talos.dev/
- https://mopidy.com/
- https://www.cross-seed.org/docs/tutorials/injection