From 0a3fcc35f6572a5515d1ab37ffd0ad1f305443a3 Mon Sep 17 00:00:00 2001 From: homelab-runtime-publisher Date: Tue, 8 Sep 2026 16:03:52 +0000 Subject: [PATCH] runtime: publish NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31 --- ...STAGINGEDGE-PUBLICINGRESS-CORRELATE31.json | 38 ++++++++++++ ...-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.txt | 60 +++++++++++++++++++ runtime/latest.json | 28 ++++----- runtime/latest.txt | 60 ++++++++++++------- 4 files changed, 149 insertions(+), 37 deletions(-) create mode 100644 runtime/history/NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.json create mode 100644 runtime/history/NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.txt diff --git a/runtime/history/NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.json b/runtime/history/NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.json new file mode 100644 index 00000000..c66cf6e3 --- /dev/null +++ b/runtime/history/NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.json @@ -0,0 +1,38 @@ +{ + "schema_version": 1, + "channel": "homelab-runtime", + "command_id": "NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31", + "status": "OK", + "rc": 0, + "host": "pve01", + "mode": "read-only", + "component": "newfi-stagingedge-public-ingress-netbird-cluster-correlation-readonly", + "started_at_utc": "2026-09-08T16:03:40Z", + "finished_at_utc": "2026-09-08T16:03:51Z", + "reference_register_checked": true, + "reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66", + "error_register_checked": true, + "error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0", + "command_sha256": "bc3c9aec17da7c6e7ab8defad78a7e7504875ab0cf46d9f54b25230eeeba3ce0", + "duplicate_failed_command_blocked": false, + "block_reason": null, + "execution_started": true, + "change_declared": false, + "result_contract_valid": true, + "result_contract_status": null, + "result_contract_error": null, + "command_rc": 0, + "changes_made": false, + "rollback_started": false, + "rollback_restored": null, + "mutation_outcome": "NO_MUTATION", + "sanitized": true, + "secrets_included": false, + "private_addresses_included": false, + "raw_evidence_retained_locally": true, + "raw_evidence_sha256": "d0838ac2e5e7a4ce65b465ceb9e23ff6b931110766e654ff27fec8eaf8eccb95", + "sanitized_output_sha256": "d0838ac2e5e7a4ce65b465ceb9e23ff6b931110766e654ff27fec8eaf8eccb95", + "output_truncated_in_json": false, + "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", + "output": "CORRELATE31_BEGIN=true\nCOMMAND_ID=NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31\nMODE=read-only\nMUTATIONS_PERFORMED=NO\nERROR_REGISTER_CHECK=OK\nERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0\nREFERENCE_CHECK=OK\nREFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66\nRUNNER_SHA_MATCH=true\nPUBLIC_IP_SHA_MATCH=true\nPUBLIC_SSH_KEYSCAN_RC=0\nPUBLIC_SSH_ED25519_COUNT=1\nPUBLIC_SSH_ED25519_SHA256=8c930e3407a94a222d180662fd94ebde906024fec7b4098d23a82e4ddad1d1dd\nNETBIRD_STATUS_JSON_RC=0\nNETBIRD_JSON_PARSE_OK=true\nNETBIRD_STATUS_DETAIL_RC=0\nNETBIRD_PEER_IP_COUNT=15\nNETBIRD_PUBLIC_SSH_KEY_MATCH_COUNT=0\nNETBIRD_PUBLIC_SSH_KEY_MATCHES_JSON=[]\nCLUSTER_RESOURCES_RC=0\nCLUSTER_VM_COUNT=13\nCLUSTER_RELEVANT_VM_COUNT=4\nCLUSTER_RELEVANT_VMS_JSON=[{\"vmid\":\"150\",\"name\":\"snikket\",\"node\":\"pve01\",\"type\":\"qemu\",\"status\":\"running\"},{\"vmid\":\"160\",\"name\":\"forum-prod\",\"node\":\"pve02\",\"type\":\"qemu\",\"status\":\"running\"},{\"vmid\":\"9130\",\"name\":\"edge-cold-standby\",\"node\":\"pve02\",\"type\":\"qemu\",\"status\":\"stopped\"},{\"vmid\":\"130\",\"name\":\"edge-vm\",\"node\":\"pve03\",\"type\":\"qemu\",\"status\":\"running\"}]\nCLUSTER_QGA_CORRELATION_JSON=[{\"vmid\":\"150\",\"name\":\"snikket\",\"node\":\"pve01\",\"qga_rc\":0,\"ipv4_count\":2,\"ip_hashes\":[\"346840d5a3d9fe9b61ce99955bb98df3db872090732c96aa5df1d83cb1f3e85a\",\"4e29a2729bbc40663066bdae0c5a3d627070fba621f5c8c70639f4782afbc67d\"],\"matches_public_key_netbird_peer\":false},{\"vmid\":\"160\",\"name\":\"forum-prod\",\"node\":\"pve02\",\"qga_rc\":0,\"ipv4_count\":1,\"ip_hashes\":[\"bf059cb10a70745fde7a01faab601e85d2548ea031d4bdf79d70664cfb51e688\"],\"matches_public_key_netbird_peer\":false},{\"vmid\":\"130\",\"name\":\"edge-vm\",\"node\":\"pve03\",\"qga_rc\":0,\"ipv4_count\":12,\"ip_hashes\":[\"bc41ed840e46092321935dd48da46da10a932deab0005de91d17a509b9d42e2d\",\"d1d4b6abdd6b1971128522c259fade15c22be861a650e31fb34457339336a812\",\"0b7870e2230336f502277fa38348a4bd934ff816a05523581c97d4ce59589fa6\",\"5649415146501fa3dc7b2e08f469ef80b6b04e46b86079acd21229eb875e9440\",\"346840d5a3d9fe9b61ce99955bb98df3db872090732c96aa5df1d83cb1f3e85a\",\"fbd57f0145e15cc8436c042887ccaa6c122eb481613abb78201b3b2212fcc422\",\"f9bcbcb71ab0bfd4ae96928d23473c1d6728cd09d9b4c65058dbdfaa30fd1e45\",\"c138df8d3b53b19038a6a63dc7280bfac4a7e72ad4fbe7f359b49c55d1df3d4c\",\"93449cac351e054dbbd4e026e0e9ba9060e51c04961d9fca4281acac18dda1f9\",\"5db063f47c3859a031b1618455d7eefac6341c65feb96a90fd6a57a504ea4d84\",\"bc517b4af3298846906234d3d697d3820b0b652ade1880c937c9d71cd802c834\",\"885dfc9b72d2209e492b4631e0c538472ddf418cdf419aff8032c8d43704a63d\"],\"matches_public_key_netbird_peer\":false}]\nAUTHORITY_REFERENCE_COUNT=240\nAUTHORITY_REFERENCES_JSON=[{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":14,\"text\":\"- VM130 edge-vm | pve03 | running | KEEP\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":15,\"text\":\"- VM150 snikket | pve01 | running | KEEP\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":49,\"text\":\"- NPMplus retired proxy routes removed; KEEP routes verified.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":75,\"text\":\"NOTE edge-vm disk scsi1 backup=0 risk must be documented\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":106,\"text\":\"06_edge_npmplus_routes_safe.txt 17350 bytes\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":149,\"text\":\"- У VM130 edge-vm есть риск: дополнительный диск backup=0.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":166,\"text\":\"- VM130 edge-vm pve03 [PRIVATE_IP] Docker ingress/app host.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":167,\"text\":\"- VM150 Nextcloud pve01 [PRIVATE_IP] Nextcloud AIO.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":174,\"text\":\"- Nextcloud VM150 имеет Proxmox backup и restore-proof evidence.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":185,\"text\":\"- VM130 backup: closed, scsi1 backup=1, manual backup ZSTD_OK, exact offhost ZSTD_OK, old local backup removed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":187,\"text\":\"- Cloudflare token: [REDACTED] NPMplus token rotated, API verify OK, old exposed token externally confirmed revoked.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":312,\"text\":\"- [PRIVATE_IP] -> bc:24:11:e1:f3:3c NPMplus / edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":316,\"text\":\"- ISP tcp/80 -> bc:24:11:e1:f3:3c, NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":317,\"text\":\"- ISP tcp/443 -> bc:24:11:e1:f3:3c, NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":323,\"text\":\"- _WEBADMIN_Bridge0 permits Home-to-Proxmox access for DNS1/DNS2, AdGuard UI, NPMplus HTTP/HTTPS/UI, Nextcloud AIO/Talk TURN, Proxmox SSH/8006 and ICMP from admin PC.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":358,\"text\":\"## EXTERNAL_SERVICES_UPS_NETBIRD_MAIL_SCRIPTS_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":366,\"text\":\"- edge-vm: no UPS/NUT/APCUPSD integration discovered.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":370,\"text\":\"### NetBird\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":371,\"text\":\"- NetBird service is active on pve01, pve02, pve03 and edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":372,\"text\":\"- NetBird version observed: daemon 0.73.2, CLI 0.73.2.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":373,\"text\":\"- pve01: FQDN pve01.netbird.selfhosted, IPv4 [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":374,\"text\":\"- pve02: FQDN pve02.netbird.selfhosted, IPv4 [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":375,\"text\":\"- pve03: FQDN pve03.netbird.selfhosted, IPv4 [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":376,\"text\":\"- edge-vm: FQDN edge-vm.netbird.selfhosted, IPv4 [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":381,\"text\":\"- SSH Server through NetBird: Disabled.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":383,\"text\":\"- Inventory proof: 108_EXTERNAL_SERVICES_NETBIRD_MAIL_SCRIPTS_INVENTORY.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":394,\"text\":\"- Full script/unit inventory proof: 108_EXTERNAL_SERVICES_NETBIRD_MAIL_SCRIPTS_INVENTORY.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":395,\"text\":\"- edge-vm owns most application health, dashboard, ingress, backup, NetBox, NPMplus, certificate, Trivy and vulnerability jobs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":396,\"text\":\"- pve01 owns many backup/offhost/restore/health/security/NetBird VPS/rclone/sops/scrutiny jobs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":398,\"text\":\"- pve03 owns smartctl textfile, cluster internal IP, NetBird and staging/rclone helpers.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":455,\"text\":\"- edge-vm timers cover runtime dashboard, Paperless guard, external canary, health metrics, restore drill index, AdGuard rewrite sync, NPMplus cert expiry, NetBox backup/sync, retention, cluster daily status, vulnerability and Trivy scans, ingress hardening and NPMplus admin bind.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":456,\"text\":\"- pve01 timers cover VPN/NetBird health, health metrics, smartctl, disk space, MkDocs refresh, VPS identity audit, storage capacity, quality gate, evidence catalog, backup freshness, docker health, Filebrowser backup/offhost/restore, NPMplus/Kuma backup, NetBird VPS backup/offhost, Authentik/Gitea/Vaultwarden backup, SOPS secret coverage, mail cloud upload/restore, Immich/Memos/Paperless backup/offhost/restore, auto backup, edge-vm vzdump, secret sanity.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":459,\"text\":\"- Script hashes were captured for /usr/local/sbin and /usr/local/bin on edge-vm, pve01, pve02 and pve03.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":487,\"text\":\"- pve03 local-lvm is the most constrained active VM storage because VM130 has 96G OS disk plus 150G media disk.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":504,\"text\":\"- NetBird IP: [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":509,\"text\":\"- Main active workloads: CT110 dns1, CT112 unbound1, VM150 nextcloud.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":515,\"text\":\"- NetBird IP: [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":526,\"text\":\"- NetBird IP: [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":531,\"text\":\"- Main active workload: VM130 edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":597,\"text\":\"### VM130 edge-vm\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":600,\"text\":\"- Name: edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":614,\"text\":\"- Important note: VM130 has exact offhost backup proof after scsi1 backup=1.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":616,\"text\":\"### VM150 nextcloud\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":672,\"text\":\"- git.gram1.ru -> [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":683,\"text\":\"- Public WAN router forwards TCP/80 and TCP/443 to NPMplus on edge-vm, [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":686,\"text\":\"- NPMplus admin listener is bound to localhost on edge-vm, [PRIVATE_IP]:81; public disabled legacy host npm.gram1.ru exists but enabled=0.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":688,\"text\":\"### NPMplus runtime\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":689,\"text\":\"- Host: edge-vm, [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":690,\"text\":\"- Container: npmplus, image zoeyvid/npmplus:2026-06-17-b1, healthy at inventory time.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":692,\"text\":\"- Database: /opt/npmplus/npmplus/database.sqlite.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":694,\"text\":\"- Public listen ports on edge-vm: [PRIVATE_IP]:80 and [PRIVATE_IP]:443 by nginx/NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":695,\"text\":\"- NPMplus admin: [PRIVATE_IP]:81.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":696,\"text\":\"- Secret rule: Cloudflare DNS API token exists only inside NPMplus certificate metadata and must never be printed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":698,\"text\":\"### Public NPMplus proxy hosts\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":705,\"text\":\"- git.gram1.ru -> http://[PRIVATE_IP]:3002, cert=29, ssl_forced=1, enabled=1.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":713,\"text\":\"### VPN NPMplus proxy hosts\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":737,\"text\":\"- npmplus.vpn.gram1.ru -> https://[PRIVATE_IP]:81, cert=32.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":749,\"text\":\"### NPMplus certificates\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":754,\"text\":\"- cert=29: git.gram1.ru, expires 2026-09-13 17:36:55.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":762,\"text\":\"- NPMplus schema/listen inventory: 126_DNS_INGRESS_CERT_NPMPLUS_SAFE_INVENTORY.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":763,\"text\":\"- NPMplus exact proxy/cert rows: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":769,\"text\":\"- Host: edge-vm, IP [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":773,\"text\":\"- Additional compose roots: /opt/npmplus-compose, /opt/gotify-compose, /opt/uptime-kuma-compose, /opt/vaultwarden-compose, /opt/dockge-compose.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":774,\"text\":\"- Public ingress terminates through NPMplus on ports 80/443.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":775,\"text\":\"- Most app containers expose only [PRIVATE_IP] ports and are published through NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":776,\"text\":\"- NPMplus uses host networking.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":813,\"text\":\"- npmplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":826,\"text\":\"- Ingress/security: npmplus, socket-proxy, crowdsec.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":831,\"text\":\"- Admin/dashboard: homepage, dockge, netbox, dozzle, NPMplus VPN admin.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":863,\"text\":\"- NPMplus admin: [PRIVATE_IP]:81.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":864,\"text\":\"- NPMplus public ingress: [PRIVATE_IP]:80 and [PRIVATE_IP]:443.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":895,\"text\":\"- VM130 edge-vm: included in homelab-nightly-all, local backup on pve03.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":896,\"text\":\"- VM150 nextcloud: included in homelab-nightly-all, local backup on pve01.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":898,\"text\":\"- VM130 also has dedicated edge-vm-vzdump backup/offhost/restore health proofs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":900,\"text\":\"- VM130 scsi1 backup flag is enabled after correction: scsi1 backup=1.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":902,\"text\":\"### Edge VM / VM130 full-image protection\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":903,\"text\":\"- edge-vm-vzdump-backup: STATUS=OK, archive size about 28.2G, SHA256 recorded.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":904,\"text\":\"- edge-vm-vzdump-offhost: STATUS=OK, destination pve02 /mnt/staging/offhost/edge-vm-vzdump-from-pve03.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":905,\"text\":\"- edge-vm-vzdump-restore: STATUS=OK, zstd and vma verification OK.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":906,\"text\":\"- mail-cloud-edge-vm: STATUS=OK, recurring chunked upload, 53 parts, download verification enabled.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":907,\"text\":\"- Retention for edge-vm cloud upload: RETENTION_KEEP=4.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":918,\"text\":\"### NPMplus / Kuma / ingress config backups\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":919,\"text\":\"- npmplus-kuma-config-backup: STATUS=OK.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":920,\"text\":\"- Archive: /mnt/staging/npmplus-kuma-config-backups/snapshots/npmplus-kuma-config-*.tar.gz.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":921,\"text\":\"- NPMplus DB integrity: OK.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":926,\"text\":\"- npmplus-kuma-config-offhost: STATUS=OK to pve02.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":927,\"text\":\"- npmplus-kuma-config-restore: STATUS=OK with DB integrity checks.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":928,\"text\":\"- npmplus restore proof also exists from app backup quality checks.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":995,\"text\":\"- NetBird VPS backup: STATUS=OK, snapshot under /mnt/staging/netbird-vps-backups/snapshots.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":996,\"text\":\"- NetBird VPS offhost: STATUS=OK to pve02.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":997,\"text\":\"- NetBird VPS restore validation: STATUS=OK, archive SHA256 recorded.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1003,\"text\":\"- Disk retention policy: STATUS=OK, root used pct observed 70 on edge-vm, removed dirs 0, Docker volume prune NO.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1004,\"text\":\"- App backup retention dry-run timer exists on edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1027,\"text\":\"- Primary monitoring host: edge-vm, [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1039,\"text\":\"- Node exporter on edge-vm: node-exporter, local port [PRIVATE_IP]:9100.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1049,\"text\":\"- pve01 also runs private VPN host health, NetBird peer health, disk space health, MkDocs refresh, evidence catalog and quality gate timers.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1058,\"text\":\"- https://git.gram1.ru\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1084,\"text\":\"- HomelabP0WeeklyEdgeVmVzdumpHealthStale: weekly edge-vm vzdump health older than 8d.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1092,\"text\":\"- HomelabNpmplusCertExpiryHealthNotOkOrStale: NPMplus cert expiry health failed or older than 48h.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1103,\"text\":\"- Alloy relabels container, compose_project, compose_service and host=edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1114,\"text\":\"- external canary checks include nc.gram1.ru, git.gram1.ru, auth.gram1.ru, backup.gram1.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1122,\"text\":\"- npmplus-cert-expiry-health.txt is the standardized health alias for certificate expiry.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1123,\"text\":\"- npmplus-certificate-expiry.txt is the detailed cert expiry file.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1125,\"text\":\"- cluster-daily-status local extra check reports npmplus-cert-expiry status OK, problems=0, min_days=75.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1137,\"text\":\"- Main health dir on edge-vm: /var/lib/homelab-health.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1150,\"text\":\"- A previous compact check looked for npmplus-cert-expiry.txt; use npmplus-certificate-expiry.txt for detailed cert expiry and npmplus-cert-expiry-health.txt for standardized health.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1209,\"text\":\"- edge-vm is reached as debian@[PRIVATE_IP] with sudo.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1218,\"text\":\"- edge-vm root key observed: id_ed25519; debian authorized_keys observed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1226,\"text\":\"- NPMplus DB: /opt/npmplus/npmplus/database.sqlite, root-only mode observed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1237,\"text\":\"- edge-vm exposes public :80/:443 through NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1238,\"text\":\"- edge-vm NPMplus admin :81 and socket-proxy :2375 are bound to [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1239,\"text\":\"- edge-vm registry cache :5000 is bound to [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1240,\"text\":\"- edge-vm Home Assistant :8123 is intentionally LAN-exposed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1283,\"text\":\"- edge-vm runs Docker application stacks.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1284,\"text\":\"- Docker app data lives mainly under /opt/stacks, /opt/npmplus, /opt/gotify-compose, /opt/uptime-kuma-compose, /opt/vaultwarden-compose and /var/lib application paths.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1356,\"text\":\"- Public ingress HTTP/HTTPS: router forwards TCP 80/443 to edge-vm [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1357,\"text\":\"- Reverse proxy: NPMplus on edge-vm, container npmplus, host networking, admin bound to [PRIVATE_IP]:81.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1358,\"text\":\"- Edge runtime host: VM130 edge-vm, [PRIVATE_IP], Docker Compose projects count 43.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1359,\"text\":\"- NPMplus proxy routes count: 47.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1360,\"text\":\"- NPMplus certificates and proxy route source proof: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1365,\"text\":\"| nc.gram1.ru | http://[PRIVATE_IP]:11000 | VM150 Nextcloud AIO | VM150 vzdump, nextcloud restore proof, external canary |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1366,\"text\":\"| uptime.gram1.ru | http://[PRIVATE_IP]:3001 | edge-vm / uptime-kuma | npmplus-kuma backup/restore, Kuma health |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1367,\"text\":\"| gotify.gram1.ru | http://[PRIVATE_IP]:8082 | edge-vm / gotify | gotify health, alert-routing proof |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1368,\"text\":\"| vault.gram1.ru | http://[PRIVATE_IP]:8083 | edge-vm / vaultwarden | vaultwarden backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1369,\"text\":\"| dockge.gram1.ru | http://[PRIVATE_IP]:5001 | edge-vm / dockge | stack inventory |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1370,\"text\":\"| home.gram1.ru | http://[PRIVATE_IP]:3000 | edge-vm / homepage | homepage container, dashboard route |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1371,\"text\":\"| git.gram1.ru | http://[PRIVATE_IP]:3002 | edge-vm / gitea | gitea backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1372,\"text\":\"| dozzle.gram1.ru | http://[PRIVATE_IP]:9999 | edge-vm / dozzle | docker stack inventory |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1373,\"text\":\"| paper.gram1.ru | http://[PRIVATE_IP]:8010 | edge-vm / paperless | paperless backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1374,\"text\":\"| memos.gram1.ru | http://[PRIVATE_IP]:5230 | edge-vm / memos | memos backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1375,\"text\":\"| photos.gram1.ru | http://[PRIVATE_IP]:2283 | edge-vm / immich | immich media/full consistency proof |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1376,\"text\":\"| auth.gram1.ru | http://[PRIVATE_IP]:9000 | edge-vm / authentik | authentik backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1405,\"text\":\"| npmplus.vpn.gram1.ru | https://[PRIVATE_IP]:81 | NPMplus admin, localhost-bound on edge |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1418,\"text\":\"- npm.gram1.ru exists in NPMplus but was observed disabled.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1421,\"text\":\"- Router forwards TCP/UDP 51820 for WireGuard on the Home bridge, not to edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1424,\"text\":\"- If a public app is down, check in this order: DNS rewrite/upstream, NPMplus route/cert, upstream container/VM, app health file, backup/restore proof.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1425,\"text\":\"- If a VPN route is down, check NetBird first, then NPMplus wildcard cert, then local upstream.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1427,\"text\":\"- If NPMplus is broken, use backup/restore evidence from npmplus-kuma-config and NPMplus DB backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1428,\"text\":\"- If edge-vm is broken, VM130 full-image backup/offhost/restore proofs are authoritative.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1433,\"text\":\"- NPMplus route/cert rows: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1467,\"text\":\"- Check NPMplus route and certificate using NPMplus DB/proxy proof.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1479,\"text\":\"- Rewrites include public routes for git, dozzle, paper, memos, photos, auth and backup to edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1483,\"text\":\"### Ingress / NPMplus failure\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1484,\"text\":\"- Edge VM is VM130 at [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1485,\"text\":\"- NPMplus listens publicly on 80/443 and admin is bound to [PRIVATE_IP]:81.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1486,\"text\":\"- NPMplus DB is /opt/npmplus/npmplus/database.sqlite.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1489,\"text\":\"- Use npmplus-kuma-config backup/offhost/restore proofs for recovery.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1492,\"text\":\"- VM130 is the Docker runtime host.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1494,\"text\":\"- Then use VM130 full-image vzdump/offhost/restore proofs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1495,\"text\":\"- Current authoritative edge-vm backup/offhost/restore evidence is in backup catalog and VM130 proofs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1504,\"text\":\"- For VM130 and VM160, use their dedicated closure proofs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1507,\"text\":\"- Prometheus is on edge-vm at [PRIVATE_IP]:9090.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1568,\"text\":\"- DNS, ingress, NPMplus certificates and AdGuard/Unbound model.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1615,\"text\":\"## NEXTCLOUD_VM150_MAIL_CLOUD_BACKUP_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1616,\"text\":\"- VM150 Nextcloud Mail-cloud backup is installed on pve01.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1620,\"text\":\"- Proof: 192_NEXTCLOUD_VM150_MAIL_CLOUD_CHUNKED_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1636,\"text\":\"- P2 small-stack backup and restore dry-run is installed on edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1644,\"text\":\"- VM150 Nextcloud now has Mail-cloud chunked backup with download verification.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1670,\"text\":\"- VM150 Mail-cloud backup, router manual/recurring Mail-cloud backups, P2 small-stacks and 7 edge restore dry-runs are all confirmed OK.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1679,\"text\":\"- Covered checks include VM150 Mail-cloud, router startup/running config Mail-cloud, P2 small-stacks and seven restore dry-run health files.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1691,\"text\":\"- VM150 Nextcloud, router startup/running config, P0 critical and edge-vm backup directories are present on crypt remotes.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1693,\"text\":\"- Retention shape observed: P0 critical has 10 visible dirs with keep 14, edge-vm has 3 visible dirs with keep 4, new VM150/router jobs have initial dirs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1705,\"text\":\"- pve01 units checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1706,\"text\":\"- edge-vm units checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1707,\"text\":\"- Proof records LoadState, ActiveState, UnitFileState and failed-unit counts for pve01 and edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1712,\"text\":\"- Covered checks: VM150 Mail-cloud, router startup/running config, P2 small-stacks and seven restore dry-runs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1735,\"text\":\"- pve01 services checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1736,\"text\":\"- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1741,\"text\":\"- Corrected integrity proof was generated because one edge-vm executable required sudo for sha256sum.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1742,\"text\":\"- Corrected proof records hashes for pve01 and edge-vm unit fragments and executable scripts without printing script contents.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1753,\"text\":\"- pve01 timers checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1754,\"text\":\"- edge-vm timers checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1829,\"text\":\"- pve01 services checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1830,\"text\":\"- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1859,\"text\":\"## VM150_MAIL_CLOUD_JOURNAL_NOISE_CLASSIFICATION_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1860,\"text\":\"- VM150 Mail-cloud upload journal warnings/errors were classified after journal triage found non-zero counters.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1863,\"text\":\"- Proof: 278_VM150_MAIL_CLOUD_JOURNAL_NOISE_CLASSIFICATION_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1866,\"text\":\"- Audit manifest was regenerated after VM150 Mail-cloud journal-noise classification.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1870,\"text\":\"## SNAPSHOT_AFTER_VM150_JOURNAL_NOISE_CLASSIFICATION_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1871,\"text\":\"- Snapshot was created after VM150 Mail-cloud journal noise was classified as non-blocking historical noise.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1874,\"text\":\"- Proof: 282_SNAPSHOT_AFTER_VM150_JOURNAL_NOISE_CLASSIFICATION_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1877,\"text\":\"- Audit manifest was regenerated after snapshot following VM150 journal-noise classification.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1882,\"text\":\"- Post-backup-pass closure summary was generated after VM150 journal-noise classification.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1899,\"text\":\"- Verify P2 small-stacks, router running-config Mail-cloud and VM150 Nextcloud Mail-cloud first automatic runs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1921,\"text\":\"- Goal: make the portal show and open all web services, including external service cards such as NetBird and mail.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1931,\"text\":\"- Home portal gap analysis was collected for gethomepage/homepage behind npmplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1932,\"text\":\"- Proof records Homepage config hashes, redacted current cards/bookmarks, current URLs, npmplus route lines, local web-port probes and known service container candidates.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1941,\"text\":\"- Proof records current card URLs/titles, redacted widget config, redacted Homepage log errors, NPMPlus internal route files/routes and candidate public/VPN cards.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1950,\"text\":\"- Homepage services.yaml was backed up, duplicate VPN cards were removed where a non-VPN card existed, and missing web cards for NetBird, Mail and Webmail were added without VPN suffix in the card names.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1961,\"text\":\"- Corrected Homepage apply removed duplicate VPN cards where a non-VPN card existed and added NetBird, Mail and Webmail cards with non-VPN names.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1962,\"text\":\"- The added card URLs use currently reachable vpn.gram1.ru web endpoints because public netbird/mail/webmail hosts did not resolve/open during analysis.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2045,\"text\":\"## HOME_PORTAL_NPMPLUS_DEFAULT_ROUTE_ANALYSIS_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2046,\"text\":\"- Home portal NetBird/Mail/Webmail cards were investigated after user saw the NPMPlus default page from client [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2047,\"text\":\"- Analysis checks URL body fingerprints, NPMPlus route config matches, service container candidates and Homepage card lines.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2048,\"text\":\"- Proof: 356_HOME_PORTAL_NPMPLUS_DEFAULT_ROUTE_ANALYSIS_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2053,\"text\":\"- NetBird card points to https://nb.pvepro.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2065,\"text\":\"- NetBird: https://nb.pvepro.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2073,\"text\":\"- Excluded cards: Homepage, NPMplus, Router and Public Domain.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2101,\"text\":\"- Homepage External card/link for relay.pvepro.ru was removed because relay.pvepro.ru had DNS but no reachable HTTP/HTTPS endpoint from edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2113,\"text\":\"## HOME_EXTERNAL_NETBIRD_ALEXHOST_NORMALIZE_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2114,\"text\":\"- Homepage External NetBird and AlexHost Billing href/siteMonitor URLs normalized with trailing slash.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2116,\"text\":\"- Proof: 397_HOME_EXTERNAL_NETBIRD_ALEXHOST_NORMALIZE_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2120,\"text\":\"- Remaining blocker for Homepage green dot is HTTP/HTTPS 403 from router web service to edge-vm/Bridge1, not network reachability.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2126,\"text\":\"- Health endpoint service on edge-vm: homelab-router-moscow-health-http.service.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2139,\"text\":\"- Health endpoint service: homelab-router-moscow-health-http.service on edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2155,\"text\":\"- Do not publish Cloudflare/NPMplus routes for these forums until CodeVipe recipe is proven and final rebuild is complete.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2183,\"text\":\"- Edge NPMplus manual routes terminate TLS with real Let’s Encrypt certificates and proxy to forum-prod VM160 at [PRIVATE_IP]:80.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2188,\"text\":\"- Edge NPMplus forum publication backup created after public cutover.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2189,\"text\":\"- Backup location: /opt/npmplus/manual-backups/forum-public-ok-*.tar.gz on edge-vm [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2190,\"text\":\"- Includes manual proxy_host configs 200-204 and Let’s Encrypt forum certificates under /opt/npmplus/tls/forum-certs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2193,\"text\":\"- Edge certificate renewal configured on edge-vm [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2194,\"text\":\"- Token stored at /opt/npmplus/secure/forum_cf_token.env mode 600 root-only.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2195,\"text\":\"- Renewal script: /opt/npmplus/scripts/renew-forum-certs.sh.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2257,\"text\":\"- Mailcow and NetBird are reachable again: mail.pvepro.ru/admin and nb.pvepro.ru return HTTP 200.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2262,\"text\":\"- Proofs: 589_POST_UNBAN_MAILCOW_NETBIRD_VERIFY.txt on VPS, 590_FORUM_SMTP_FAILED_CONFIG_DISABLED_PROOF.txt, 591_POST_INCIDENT_PUBLIC_STATUS_PROOF.txt, 592_POST_INCIDENT_FINAL_STABLE_STATE_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2268,\"text\":\"- Mailcow and NetBird remained reachable after the test.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2274,\"text\":\"- Mailcow and NetBird remained reachable after the test.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2284,\"text\":\"- Mailcow and NetBird remained reachable after enabling persistent forum SMTP.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2291,\"text\":\"- Mailcow and NetBird remain reachable after enabling persistent forum SMTP.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2316,\"text\":\"- Mailcow admin and NetBird UI are reachable after persistent forum SMTP enablement.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2368,\"text\":\"- NPMplus on edge terminates TLS and proxies all five forums to VM160.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2408,\"text\":\"- NPMplus on edge terminates TLS and proxies to http://[PRIVATE_IP]:80.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2468,\"text\":\"- Local placeholder service on edge-vm: homelab-parked-domains-http.service, enabled/active, serves marker PARKED_PAGE_OK on http://[PRIVATE_IP]:18088.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2469,\"text\":\"- NPMplus manual managed route files: /data/nginx/proxy_host/998.conf for newfi.ru, 997.conf for hapusya.ru and 996.conf for kingofwolk.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2471,\"text\":\"- Certificates were issued by certbot DNS-01 using Cloudflare API hooks; HTTP-01 must not be retried for these parked domains without a new plan because earlier attempts hit NPMplus default redirect/include-order behavior.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2472,\"text\":\"- Cloudflare token value is not stored in the reference; token file path only: /opt/npmplus/secure/parked_cf_token, root-owned mode 600.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2473,\"text\":\"- Certificate names on edge-vm: parked-newfi.ru, parked-hapusya.ru and parked-kingofwolk.ru; observed expiry during setup: 2026-09-29.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2474,\"text\":\"- Certbot deploy hook installed: /etc/letsencrypt/renewal-hooks/deploy/parked-domains-npmplus-deploy.sh.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2476,\"text\":\"- Final route backup: /opt/npmplus/manual-backups/parked-stage16-route-only-20260701T155843Z.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2481,\"text\":\"- gram1.ru root and www.gram1.ru are routed to the existing parked placeholder page on edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2483,\"text\":\"- NPMplus managed route file: /data/nginx/proxy_host/995.conf.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2485,\"text\":\"- Certificate name on edge-vm: parked-gram1.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2486,\"text\":\"- Certificate issuance mode: certbot DNS-01 with dedicated gram1 Cloudflare token file /opt/npmplus/secure/gram1_cf_token.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2488,\"text\":\"- Certbot deploy hook: /etc/letsencrypt/renewal-hooks/deploy/gram1-root-npmplus-deploy.sh.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2497,\"text\":\"- NPMplus managed route file: /data/nginx/proxy_host/994.conf.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2498,\"text\":\"- Landing service on edge-vm: homelab-pvepro-landing-http.service on http://[PRIVATE_IP]:18089.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2500,\"text\":\"- Certificate name on edge-vm: landing-pvepro.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2501,\"text\":\"- Certificate issuance mode: certbot DNS-01 with dedicated pvepro Cloudflare token file /opt/npmplus/secure/pvepro_cf_token.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2503,\"text\":\"- Certbot deploy hook: /etc/letsencrypt/renewal-hooks/deploy/pvepro-root-npmplus-deploy.sh.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2515,\"text\":\"- Recommended future path: establish VPN/NetBird/WireGuard or reverse-proxy/private management endpoint first; then issue DNS-01 certificate on a trusted node and deploy cert/key to the router only over that private path.\"}]\nCORRELATE31_DECISION=PUBLIC_INGRESS_NO_NETBIRD_KEY_CORRELATION\nCORRELATE31_END=true\n" +} diff --git a/runtime/history/NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.txt b/runtime/history/NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.txt new file mode 100644 index 00000000..5cd232db --- /dev/null +++ b/runtime/history/NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31.txt @@ -0,0 +1,60 @@ +CHAT_OUTPUT_BEGIN +COMMAND_ID=NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31 +STATUS=OK +RC=0 +HOST=pve01 +MODE=read-only +COMPONENT=newfi-stagingedge-public-ingress-netbird-cluster-correlation-readonly +REFERENCE_REGISTER_CHECK=OK +REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66 +ERROR_REGISTER_CHECK=OK +ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0 +COMMAND_SHA256=bc3c9aec17da7c6e7ab8defad78a7e7504875ab0cf46d9f54b25230eeeba3ce0 +DUPLICATE_FAILED_COMMAND_BLOCKED=false +EXECUTION_STARTED=true +CHANGE_DECLARED=false +RESULT_CONTRACT_VALID=true +RESULT_CONTRACT_STATUS=NOT_APPLICABLE +RESULT_CONTRACT_ERROR=NONE +COMMAND_RC=0 +CHANGES_MADE=false +ROLLBACK_STARTED=false +ROLLBACK_RESTORED=null +MUTATION_OUTCOME=NO_MUTATION +SANITIZED=yes +SECRETS_INCLUDED=no +PRIVATE_ADDRESSES_INCLUDED=no +RAW_EVIDENCE_SHA256=d0838ac2e5e7a4ce65b465ceb9e23ff6b931110766e654ff27fec8eaf8eccb95 +SANITIZED_OUTPUT_SHA256=d0838ac2e5e7a4ce65b465ceb9e23ff6b931110766e654ff27fec8eaf8eccb95 +OUTPUT_BEGIN +CORRELATE31_BEGIN=true +COMMAND_ID=NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31 +MODE=read-only +MUTATIONS_PERFORMED=NO +ERROR_REGISTER_CHECK=OK +ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0 +REFERENCE_CHECK=OK +REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66 +RUNNER_SHA_MATCH=true +PUBLIC_IP_SHA_MATCH=true +PUBLIC_SSH_KEYSCAN_RC=0 +PUBLIC_SSH_ED25519_COUNT=1 +PUBLIC_SSH_ED25519_SHA256=8c930e3407a94a222d180662fd94ebde906024fec7b4098d23a82e4ddad1d1dd +NETBIRD_STATUS_JSON_RC=0 +NETBIRD_JSON_PARSE_OK=true +NETBIRD_STATUS_DETAIL_RC=0 +NETBIRD_PEER_IP_COUNT=15 +NETBIRD_PUBLIC_SSH_KEY_MATCH_COUNT=0 +NETBIRD_PUBLIC_SSH_KEY_MATCHES_JSON=[] +CLUSTER_RESOURCES_RC=0 +CLUSTER_VM_COUNT=13 +CLUSTER_RELEVANT_VM_COUNT=4 +CLUSTER_RELEVANT_VMS_JSON=[{"vmid":"150","name":"snikket","node":"pve01","type":"qemu","status":"running"},{"vmid":"160","name":"forum-prod","node":"pve02","type":"qemu","status":"running"},{"vmid":"9130","name":"edge-cold-standby","node":"pve02","type":"qemu","status":"stopped"},{"vmid":"130","name":"edge-vm","node":"pve03","type":"qemu","status":"running"}] +CLUSTER_QGA_CORRELATION_JSON=[{"vmid":"150","name":"snikket","node":"pve01","qga_rc":0,"ipv4_count":2,"ip_hashes":["346840d5a3d9fe9b61ce99955bb98df3db872090732c96aa5df1d83cb1f3e85a","4e29a2729bbc40663066bdae0c5a3d627070fba621f5c8c70639f4782afbc67d"],"matches_public_key_netbird_peer":false},{"vmid":"160","name":"forum-prod","node":"pve02","qga_rc":0,"ipv4_count":1,"ip_hashes":["bf059cb10a70745fde7a01faab601e85d2548ea031d4bdf79d70664cfb51e688"],"matches_public_key_netbird_peer":false},{"vmid":"130","name":"edge-vm","node":"pve03","qga_rc":0,"ipv4_count":12,"ip_hashes":["bc41ed840e46092321935dd48da46da10a932deab0005de91d17a509b9d42e2d","d1d4b6abdd6b1971128522c259fade15c22be861a650e31fb34457339336a812","0b7870e2230336f502277fa38348a4bd934ff816a05523581c97d4ce59589fa6","5649415146501fa3dc7b2e08f469ef80b6b04e46b86079acd21229eb875e9440","346840d5a3d9fe9b61ce99955bb98df3db872090732c96aa5df1d83cb1f3e85a","fbd57f0145e15cc8436c042887ccaa6c122eb481613abb78201b3b2212fcc422","f9bcbcb71ab0bfd4ae96928d23473c1d6728cd09d9b4c65058dbdfaa30fd1e45","c138df8d3b53b19038a6a63dc7280bfac4a7e72ad4fbe7f359b49c55d1df3d4c","93449cac351e054dbbd4e026e0e9ba9060e51c04961d9fca4281acac18dda1f9","5db063f47c3859a031b1618455d7eefac6341c65feb96a90fd6a57a504ea4d84","bc517b4af3298846906234d3d697d3820b0b652ade1880c937c9d71cd802c834","885dfc9b72d2209e492b4631e0c538472ddf418cdf419aff8032c8d43704a63d"],"matches_public_key_netbird_peer":false}] +AUTHORITY_REFERENCE_COUNT=240 +AUTHORITY_REFERENCES_JSON=[{"file":"31_HOMELAB_REFERENCE.md","line":14,"text":"- VM130 edge-vm | pve03 | running | KEEP"},{"file":"31_HOMELAB_REFERENCE.md","line":15,"text":"- VM150 snikket | pve01 | running | KEEP"},{"file":"31_HOMELAB_REFERENCE.md","line":49,"text":"- NPMplus retired proxy routes removed; KEEP routes verified."},{"file":"31_HOMELAB_REFERENCE.md","line":75,"text":"NOTE edge-vm disk scsi1 backup=0 risk must be documented"},{"file":"31_HOMELAB_REFERENCE.md","line":106,"text":"06_edge_npmplus_routes_safe.txt 17350 bytes"},{"file":"31_HOMELAB_REFERENCE.md","line":149,"text":"- У VM130 edge-vm есть риск: дополнительный диск backup=0."},{"file":"31_HOMELAB_REFERENCE.md","line":166,"text":"- VM130 edge-vm pve03 [PRIVATE_IP] Docker ingress/app host."},{"file":"31_HOMELAB_REFERENCE.md","line":167,"text":"- VM150 Nextcloud pve01 [PRIVATE_IP] Nextcloud AIO."},{"file":"31_HOMELAB_REFERENCE.md","line":174,"text":"- Nextcloud VM150 имеет Proxmox backup и restore-proof evidence."},{"file":"31_HOMELAB_REFERENCE.md","line":185,"text":"- VM130 backup: closed, scsi1 backup=1, manual backup ZSTD_OK, exact offhost ZSTD_OK, old local backup removed."},{"file":"31_HOMELAB_REFERENCE.md","line":187,"text":"- Cloudflare token: [REDACTED] NPMplus token rotated, API verify OK, old exposed token externally confirmed revoked."},{"file":"31_HOMELAB_REFERENCE.md","line":312,"text":"- [PRIVATE_IP] -> bc:24:11:e1:f3:3c NPMplus / edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":316,"text":"- ISP tcp/80 -> bc:24:11:e1:f3:3c, NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":317,"text":"- ISP tcp/443 -> bc:24:11:e1:f3:3c, NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":323,"text":"- _WEBADMIN_Bridge0 permits Home-to-Proxmox access for DNS1/DNS2, AdGuard UI, NPMplus HTTP/HTTPS/UI, Nextcloud AIO/Talk TURN, Proxmox SSH/8006 and ICMP from admin PC."},{"file":"31_HOMELAB_REFERENCE.md","line":358,"text":"## EXTERNAL_SERVICES_UPS_NETBIRD_MAIL_SCRIPTS_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":366,"text":"- edge-vm: no UPS/NUT/APCUPSD integration discovered."},{"file":"31_HOMELAB_REFERENCE.md","line":370,"text":"### NetBird"},{"file":"31_HOMELAB_REFERENCE.md","line":371,"text":"- NetBird service is active on pve01, pve02, pve03 and edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":372,"text":"- NetBird version observed: daemon 0.73.2, CLI 0.73.2."},{"file":"31_HOMELAB_REFERENCE.md","line":373,"text":"- pve01: FQDN pve01.netbird.selfhosted, IPv4 [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":374,"text":"- pve02: FQDN pve02.netbird.selfhosted, IPv4 [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":375,"text":"- pve03: FQDN pve03.netbird.selfhosted, IPv4 [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":376,"text":"- edge-vm: FQDN edge-vm.netbird.selfhosted, IPv4 [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":381,"text":"- SSH Server through NetBird: Disabled."},{"file":"31_HOMELAB_REFERENCE.md","line":383,"text":"- Inventory proof: 108_EXTERNAL_SERVICES_NETBIRD_MAIL_SCRIPTS_INVENTORY.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":394,"text":"- Full script/unit inventory proof: 108_EXTERNAL_SERVICES_NETBIRD_MAIL_SCRIPTS_INVENTORY.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":395,"text":"- edge-vm owns most application health, dashboard, ingress, backup, NetBox, NPMplus, certificate, Trivy and vulnerability jobs."},{"file":"31_HOMELAB_REFERENCE.md","line":396,"text":"- pve01 owns many backup/offhost/restore/health/security/NetBird VPS/rclone/sops/scrutiny jobs."},{"file":"31_HOMELAB_REFERENCE.md","line":398,"text":"- pve03 owns smartctl textfile, cluster internal IP, NetBird and staging/rclone helpers."},{"file":"31_HOMELAB_REFERENCE.md","line":455,"text":"- edge-vm timers cover runtime dashboard, Paperless guard, external canary, health metrics, restore drill index, AdGuard rewrite sync, NPMplus cert expiry, NetBox backup/sync, retention, cluster daily status, vulnerability and Trivy scans, ingress hardening and NPMplus admin bind."},{"file":"31_HOMELAB_REFERENCE.md","line":456,"text":"- pve01 timers cover VPN/NetBird health, health metrics, smartctl, disk space, MkDocs refresh, VPS identity audit, storage capacity, quality gate, evidence catalog, backup freshness, docker health, Filebrowser backup/offhost/restore, NPMplus/Kuma backup, NetBird VPS backup/offhost, Authentik/Gitea/Vaultwarden backup, SOPS secret coverage, mail cloud upload/restore, Immich/Memos/Paperless backup/offhost/restore, auto backup, edge-vm vzdump, secret sanity."},{"file":"31_HOMELAB_REFERENCE.md","line":459,"text":"- Script hashes were captured for /usr/local/sbin and /usr/local/bin on edge-vm, pve01, pve02 and pve03."},{"file":"31_HOMELAB_REFERENCE.md","line":487,"text":"- pve03 local-lvm is the most constrained active VM storage because VM130 has 96G OS disk plus 150G media disk."},{"file":"31_HOMELAB_REFERENCE.md","line":504,"text":"- NetBird IP: [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":509,"text":"- Main active workloads: CT110 dns1, CT112 unbound1, VM150 nextcloud."},{"file":"31_HOMELAB_REFERENCE.md","line":515,"text":"- NetBird IP: [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":526,"text":"- NetBird IP: [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":531,"text":"- Main active workload: VM130 edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":597,"text":"### VM130 edge-vm"},{"file":"31_HOMELAB_REFERENCE.md","line":600,"text":"- Name: edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":614,"text":"- Important note: VM130 has exact offhost backup proof after scsi1 backup=1."},{"file":"31_HOMELAB_REFERENCE.md","line":616,"text":"### VM150 nextcloud"},{"file":"31_HOMELAB_REFERENCE.md","line":672,"text":"- git.gram1.ru -> [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":683,"text":"- Public WAN router forwards TCP/80 and TCP/443 to NPMplus on edge-vm, [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":686,"text":"- NPMplus admin listener is bound to localhost on edge-vm, [PRIVATE_IP]:81; public disabled legacy host npm.gram1.ru exists but enabled=0."},{"file":"31_HOMELAB_REFERENCE.md","line":688,"text":"### NPMplus runtime"},{"file":"31_HOMELAB_REFERENCE.md","line":689,"text":"- Host: edge-vm, [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":690,"text":"- Container: npmplus, image zoeyvid/npmplus:2026-06-17-b1, healthy at inventory time."},{"file":"31_HOMELAB_REFERENCE.md","line":692,"text":"- Database: /opt/npmplus/npmplus/database.sqlite."},{"file":"31_HOMELAB_REFERENCE.md","line":694,"text":"- Public listen ports on edge-vm: [PRIVATE_IP]:80 and [PRIVATE_IP]:443 by nginx/NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":695,"text":"- NPMplus admin: [PRIVATE_IP]:81."},{"file":"31_HOMELAB_REFERENCE.md","line":696,"text":"- Secret rule: Cloudflare DNS API token exists only inside NPMplus certificate metadata and must never be printed."},{"file":"31_HOMELAB_REFERENCE.md","line":698,"text":"### Public NPMplus proxy hosts"},{"file":"31_HOMELAB_REFERENCE.md","line":705,"text":"- git.gram1.ru -> http://[PRIVATE_IP]:3002, cert=29, ssl_forced=1, enabled=1."},{"file":"31_HOMELAB_REFERENCE.md","line":713,"text":"### VPN NPMplus proxy hosts"},{"file":"31_HOMELAB_REFERENCE.md","line":737,"text":"- npmplus.vpn.gram1.ru -> https://[PRIVATE_IP]:81, cert=32."},{"file":"31_HOMELAB_REFERENCE.md","line":749,"text":"### NPMplus certificates"},{"file":"31_HOMELAB_REFERENCE.md","line":754,"text":"- cert=29: git.gram1.ru, expires 2026-09-13 17:36:55."},{"file":"31_HOMELAB_REFERENCE.md","line":762,"text":"- NPMplus schema/listen inventory: 126_DNS_INGRESS_CERT_NPMPLUS_SAFE_INVENTORY.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":763,"text":"- NPMplus exact proxy/cert rows: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":769,"text":"- Host: edge-vm, IP [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":773,"text":"- Additional compose roots: /opt/npmplus-compose, /opt/gotify-compose, /opt/uptime-kuma-compose, /opt/vaultwarden-compose, /opt/dockge-compose."},{"file":"31_HOMELAB_REFERENCE.md","line":774,"text":"- Public ingress terminates through NPMplus on ports 80/443."},{"file":"31_HOMELAB_REFERENCE.md","line":775,"text":"- Most app containers expose only [PRIVATE_IP] ports and are published through NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":776,"text":"- NPMplus uses host networking."},{"file":"31_HOMELAB_REFERENCE.md","line":813,"text":"- npmplus."},{"file":"31_HOMELAB_REFERENCE.md","line":826,"text":"- Ingress/security: npmplus, socket-proxy, crowdsec."},{"file":"31_HOMELAB_REFERENCE.md","line":831,"text":"- Admin/dashboard: homepage, dockge, netbox, dozzle, NPMplus VPN admin."},{"file":"31_HOMELAB_REFERENCE.md","line":863,"text":"- NPMplus admin: [PRIVATE_IP]:81."},{"file":"31_HOMELAB_REFERENCE.md","line":864,"text":"- NPMplus public ingress: [PRIVATE_IP]:80 and [PRIVATE_IP]:443."},{"file":"31_HOMELAB_REFERENCE.md","line":895,"text":"- VM130 edge-vm: included in homelab-nightly-all, local backup on pve03."},{"file":"31_HOMELAB_REFERENCE.md","line":896,"text":"- VM150 nextcloud: included in homelab-nightly-all, local backup on pve01."},{"file":"31_HOMELAB_REFERENCE.md","line":898,"text":"- VM130 also has dedicated edge-vm-vzdump backup/offhost/restore health proofs."},{"file":"31_HOMELAB_REFERENCE.md","line":900,"text":"- VM130 scsi1 backup flag is enabled after correction: scsi1 backup=1."},{"file":"31_HOMELAB_REFERENCE.md","line":902,"text":"### Edge VM / VM130 full-image protection"},{"file":"31_HOMELAB_REFERENCE.md","line":903,"text":"- edge-vm-vzdump-backup: STATUS=OK, archive size about 28.2G, SHA256 recorded."},{"file":"31_HOMELAB_REFERENCE.md","line":904,"text":"- edge-vm-vzdump-offhost: STATUS=OK, destination pve02 /mnt/staging/offhost/edge-vm-vzdump-from-pve03."},{"file":"31_HOMELAB_REFERENCE.md","line":905,"text":"- edge-vm-vzdump-restore: STATUS=OK, zstd and vma verification OK."},{"file":"31_HOMELAB_REFERENCE.md","line":906,"text":"- mail-cloud-edge-vm: STATUS=OK, recurring chunked upload, 53 parts, download verification enabled."},{"file":"31_HOMELAB_REFERENCE.md","line":907,"text":"- Retention for edge-vm cloud upload: RETENTION_KEEP=4."},{"file":"31_HOMELAB_REFERENCE.md","line":918,"text":"### NPMplus / Kuma / ingress config backups"},{"file":"31_HOMELAB_REFERENCE.md","line":919,"text":"- npmplus-kuma-config-backup: STATUS=OK."},{"file":"31_HOMELAB_REFERENCE.md","line":920,"text":"- Archive: /mnt/staging/npmplus-kuma-config-backups/snapshots/npmplus-kuma-config-*.tar.gz."},{"file":"31_HOMELAB_REFERENCE.md","line":921,"text":"- NPMplus DB integrity: OK."},{"file":"31_HOMELAB_REFERENCE.md","line":926,"text":"- npmplus-kuma-config-offhost: STATUS=OK to pve02."},{"file":"31_HOMELAB_REFERENCE.md","line":927,"text":"- npmplus-kuma-config-restore: STATUS=OK with DB integrity checks."},{"file":"31_HOMELAB_REFERENCE.md","line":928,"text":"- npmplus restore proof also exists from app backup quality checks."},{"file":"31_HOMELAB_REFERENCE.md","line":995,"text":"- NetBird VPS backup: STATUS=OK, snapshot under /mnt/staging/netbird-vps-backups/snapshots."},{"file":"31_HOMELAB_REFERENCE.md","line":996,"text":"- NetBird VPS offhost: STATUS=OK to pve02."},{"file":"31_HOMELAB_REFERENCE.md","line":997,"text":"- NetBird VPS restore validation: STATUS=OK, archive SHA256 recorded."},{"file":"31_HOMELAB_REFERENCE.md","line":1003,"text":"- Disk retention policy: STATUS=OK, root used pct observed 70 on edge-vm, removed dirs 0, Docker volume prune NO."},{"file":"31_HOMELAB_REFERENCE.md","line":1004,"text":"- App backup retention dry-run timer exists on edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1027,"text":"- Primary monitoring host: edge-vm, [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1039,"text":"- Node exporter on edge-vm: node-exporter, local port [PRIVATE_IP]:9100."},{"file":"31_HOMELAB_REFERENCE.md","line":1049,"text":"- pve01 also runs private VPN host health, NetBird peer health, disk space health, MkDocs refresh, evidence catalog and quality gate timers."},{"file":"31_HOMELAB_REFERENCE.md","line":1058,"text":"- https://git.gram1.ru"},{"file":"31_HOMELAB_REFERENCE.md","line":1084,"text":"- HomelabP0WeeklyEdgeVmVzdumpHealthStale: weekly edge-vm vzdump health older than 8d."},{"file":"31_HOMELAB_REFERENCE.md","line":1092,"text":"- HomelabNpmplusCertExpiryHealthNotOkOrStale: NPMplus cert expiry health failed or older than 48h."},{"file":"31_HOMELAB_REFERENCE.md","line":1103,"text":"- Alloy relabels container, compose_project, compose_service and host=edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1114,"text":"- external canary checks include nc.gram1.ru, git.gram1.ru, auth.gram1.ru, backup.gram1.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":1122,"text":"- npmplus-cert-expiry-health.txt is the standardized health alias for certificate expiry."},{"file":"31_HOMELAB_REFERENCE.md","line":1123,"text":"- npmplus-certificate-expiry.txt is the detailed cert expiry file."},{"file":"31_HOMELAB_REFERENCE.md","line":1125,"text":"- cluster-daily-status local extra check reports npmplus-cert-expiry status OK, problems=0, min_days=75."},{"file":"31_HOMELAB_REFERENCE.md","line":1137,"text":"- Main health dir on edge-vm: /var/lib/homelab-health."},{"file":"31_HOMELAB_REFERENCE.md","line":1150,"text":"- A previous compact check looked for npmplus-cert-expiry.txt; use npmplus-certificate-expiry.txt for detailed cert expiry and npmplus-cert-expiry-health.txt for standardized health."},{"file":"31_HOMELAB_REFERENCE.md","line":1209,"text":"- edge-vm is reached as debian@[PRIVATE_IP] with sudo."},{"file":"31_HOMELAB_REFERENCE.md","line":1218,"text":"- edge-vm root key observed: id_ed25519; debian authorized_keys observed."},{"file":"31_HOMELAB_REFERENCE.md","line":1226,"text":"- NPMplus DB: /opt/npmplus/npmplus/database.sqlite, root-only mode observed."},{"file":"31_HOMELAB_REFERENCE.md","line":1237,"text":"- edge-vm exposes public :80/:443 through NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":1238,"text":"- edge-vm NPMplus admin :81 and socket-proxy :2375 are bound to [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1239,"text":"- edge-vm registry cache :5000 is bound to [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1240,"text":"- edge-vm Home Assistant :8123 is intentionally LAN-exposed."},{"file":"31_HOMELAB_REFERENCE.md","line":1283,"text":"- edge-vm runs Docker application stacks."},{"file":"31_HOMELAB_REFERENCE.md","line":1284,"text":"- Docker app data lives mainly under /opt/stacks, /opt/npmplus, /opt/gotify-compose, /opt/uptime-kuma-compose, /opt/vaultwarden-compose and /var/lib application paths."},{"file":"31_HOMELAB_REFERENCE.md","line":1356,"text":"- Public ingress HTTP/HTTPS: router forwards TCP 80/443 to edge-vm [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1357,"text":"- Reverse proxy: NPMplus on edge-vm, container npmplus, host networking, admin bound to [PRIVATE_IP]:81."},{"file":"31_HOMELAB_REFERENCE.md","line":1358,"text":"- Edge runtime host: VM130 edge-vm, [PRIVATE_IP], Docker Compose projects count 43."},{"file":"31_HOMELAB_REFERENCE.md","line":1359,"text":"- NPMplus proxy routes count: 47."},{"file":"31_HOMELAB_REFERENCE.md","line":1360,"text":"- NPMplus certificates and proxy route source proof: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1365,"text":"| nc.gram1.ru | http://[PRIVATE_IP]:11000 | VM150 Nextcloud AIO | VM150 vzdump, nextcloud restore proof, external canary |"},{"file":"31_HOMELAB_REFERENCE.md","line":1366,"text":"| uptime.gram1.ru | http://[PRIVATE_IP]:3001 | edge-vm / uptime-kuma | npmplus-kuma backup/restore, Kuma health |"},{"file":"31_HOMELAB_REFERENCE.md","line":1367,"text":"| gotify.gram1.ru | http://[PRIVATE_IP]:8082 | edge-vm / gotify | gotify health, alert-routing proof |"},{"file":"31_HOMELAB_REFERENCE.md","line":1368,"text":"| vault.gram1.ru | http://[PRIVATE_IP]:8083 | edge-vm / vaultwarden | vaultwarden backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1369,"text":"| dockge.gram1.ru | http://[PRIVATE_IP]:5001 | edge-vm / dockge | stack inventory |"},{"file":"31_HOMELAB_REFERENCE.md","line":1370,"text":"| home.gram1.ru | http://[PRIVATE_IP]:3000 | edge-vm / homepage | homepage container, dashboard route |"},{"file":"31_HOMELAB_REFERENCE.md","line":1371,"text":"| git.gram1.ru | http://[PRIVATE_IP]:3002 | edge-vm / gitea | gitea backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1372,"text":"| dozzle.gram1.ru | http://[PRIVATE_IP]:9999 | edge-vm / dozzle | docker stack inventory |"},{"file":"31_HOMELAB_REFERENCE.md","line":1373,"text":"| paper.gram1.ru | http://[PRIVATE_IP]:8010 | edge-vm / paperless | paperless backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1374,"text":"| memos.gram1.ru | http://[PRIVATE_IP]:5230 | edge-vm / memos | memos backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1375,"text":"| photos.gram1.ru | http://[PRIVATE_IP]:2283 | edge-vm / immich | immich media/full consistency proof |"},{"file":"31_HOMELAB_REFERENCE.md","line":1376,"text":"| auth.gram1.ru | http://[PRIVATE_IP]:9000 | edge-vm / authentik | authentik backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1405,"text":"| npmplus.vpn.gram1.ru | https://[PRIVATE_IP]:81 | NPMplus admin, localhost-bound on edge |"},{"file":"31_HOMELAB_REFERENCE.md","line":1418,"text":"- npm.gram1.ru exists in NPMplus but was observed disabled."},{"file":"31_HOMELAB_REFERENCE.md","line":1421,"text":"- Router forwards TCP/UDP 51820 for WireGuard on the Home bridge, not to edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1424,"text":"- If a public app is down, check in this order: DNS rewrite/upstream, NPMplus route/cert, upstream container/VM, app health file, backup/restore proof."},{"file":"31_HOMELAB_REFERENCE.md","line":1425,"text":"- If a VPN route is down, check NetBird first, then NPMplus wildcard cert, then local upstream."},{"file":"31_HOMELAB_REFERENCE.md","line":1427,"text":"- If NPMplus is broken, use backup/restore evidence from npmplus-kuma-config and NPMplus DB backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1428,"text":"- If edge-vm is broken, VM130 full-image backup/offhost/restore proofs are authoritative."},{"file":"31_HOMELAB_REFERENCE.md","line":1433,"text":"- NPMplus route/cert rows: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1467,"text":"- Check NPMplus route and certificate using NPMplus DB/proxy proof."},{"file":"31_HOMELAB_REFERENCE.md","line":1479,"text":"- Rewrites include public routes for git, dozzle, paper, memos, photos, auth and backup to edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1483,"text":"### Ingress / NPMplus failure"},{"file":"31_HOMELAB_REFERENCE.md","line":1484,"text":"- Edge VM is VM130 at [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1485,"text":"- NPMplus listens publicly on 80/443 and admin is bound to [PRIVATE_IP]:81."},{"file":"31_HOMELAB_REFERENCE.md","line":1486,"text":"- NPMplus DB is /opt/npmplus/npmplus/database.sqlite."},{"file":"31_HOMELAB_REFERENCE.md","line":1489,"text":"- Use npmplus-kuma-config backup/offhost/restore proofs for recovery."},{"file":"31_HOMELAB_REFERENCE.md","line":1492,"text":"- VM130 is the Docker runtime host."},{"file":"31_HOMELAB_REFERENCE.md","line":1494,"text":"- Then use VM130 full-image vzdump/offhost/restore proofs."},{"file":"31_HOMELAB_REFERENCE.md","line":1495,"text":"- Current authoritative edge-vm backup/offhost/restore evidence is in backup catalog and VM130 proofs."},{"file":"31_HOMELAB_REFERENCE.md","line":1504,"text":"- For VM130 and VM160, use their dedicated closure proofs."},{"file":"31_HOMELAB_REFERENCE.md","line":1507,"text":"- Prometheus is on edge-vm at [PRIVATE_IP]:9090."},{"file":"31_HOMELAB_REFERENCE.md","line":1568,"text":"- DNS, ingress, NPMplus certificates and AdGuard/Unbound model."},{"file":"31_HOMELAB_REFERENCE.md","line":1615,"text":"## NEXTCLOUD_VM150_MAIL_CLOUD_BACKUP_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":1616,"text":"- VM150 Nextcloud Mail-cloud backup is installed on pve01."},{"file":"31_HOMELAB_REFERENCE.md","line":1620,"text":"- Proof: 192_NEXTCLOUD_VM150_MAIL_CLOUD_CHUNKED_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1636,"text":"- P2 small-stack backup and restore dry-run is installed on edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1644,"text":"- VM150 Nextcloud now has Mail-cloud chunked backup with download verification."},{"file":"31_HOMELAB_REFERENCE.md","line":1670,"text":"- VM150 Mail-cloud backup, router manual/recurring Mail-cloud backups, P2 small-stacks and 7 edge restore dry-runs are all confirmed OK."},{"file":"31_HOMELAB_REFERENCE.md","line":1679,"text":"- Covered checks include VM150 Mail-cloud, router startup/running config Mail-cloud, P2 small-stacks and seven restore dry-run health files."},{"file":"31_HOMELAB_REFERENCE.md","line":1691,"text":"- VM150 Nextcloud, router startup/running config, P0 critical and edge-vm backup directories are present on crypt remotes."},{"file":"31_HOMELAB_REFERENCE.md","line":1693,"text":"- Retention shape observed: P0 critical has 10 visible dirs with keep 14, edge-vm has 3 visible dirs with keep 4, new VM150/router jobs have initial dirs."},{"file":"31_HOMELAB_REFERENCE.md","line":1705,"text":"- pve01 units checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1706,"text":"- edge-vm units checked: P2 small-stacks backup/restore, backup dashboard and restore drill index."},{"file":"31_HOMELAB_REFERENCE.md","line":1707,"text":"- Proof records LoadState, ActiveState, UnitFileState and failed-unit counts for pve01 and edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1712,"text":"- Covered checks: VM150 Mail-cloud, router startup/running config, P2 small-stacks and seven restore dry-runs."},{"file":"31_HOMELAB_REFERENCE.md","line":1735,"text":"- pve01 services checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1736,"text":"- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index."},{"file":"31_HOMELAB_REFERENCE.md","line":1741,"text":"- Corrected integrity proof was generated because one edge-vm executable required sudo for sha256sum."},{"file":"31_HOMELAB_REFERENCE.md","line":1742,"text":"- Corrected proof records hashes for pve01 and edge-vm unit fragments and executable scripts without printing script contents."},{"file":"31_HOMELAB_REFERENCE.md","line":1753,"text":"- pve01 timers checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1754,"text":"- edge-vm timers checked: P2 small-stacks backup/restore, backup dashboard and restore drill index."},{"file":"31_HOMELAB_REFERENCE.md","line":1829,"text":"- pve01 services checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1830,"text":"- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index."},{"file":"31_HOMELAB_REFERENCE.md","line":1859,"text":"## VM150_MAIL_CLOUD_JOURNAL_NOISE_CLASSIFICATION_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":1860,"text":"- VM150 Mail-cloud upload journal warnings/errors were classified after journal triage found non-zero counters."},{"file":"31_HOMELAB_REFERENCE.md","line":1863,"text":"- Proof: 278_VM150_MAIL_CLOUD_JOURNAL_NOISE_CLASSIFICATION_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1866,"text":"- Audit manifest was regenerated after VM150 Mail-cloud journal-noise classification."},{"file":"31_HOMELAB_REFERENCE.md","line":1870,"text":"## SNAPSHOT_AFTER_VM150_JOURNAL_NOISE_CLASSIFICATION_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":1871,"text":"- Snapshot was created after VM150 Mail-cloud journal noise was classified as non-blocking historical noise."},{"file":"31_HOMELAB_REFERENCE.md","line":1874,"text":"- Proof: 282_SNAPSHOT_AFTER_VM150_JOURNAL_NOISE_CLASSIFICATION_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1877,"text":"- Audit manifest was regenerated after snapshot following VM150 journal-noise classification."},{"file":"31_HOMELAB_REFERENCE.md","line":1882,"text":"- Post-backup-pass closure summary was generated after VM150 journal-noise classification."},{"file":"31_HOMELAB_REFERENCE.md","line":1899,"text":"- Verify P2 small-stacks, router running-config Mail-cloud and VM150 Nextcloud Mail-cloud first automatic runs."},{"file":"31_HOMELAB_REFERENCE.md","line":1921,"text":"- Goal: make the portal show and open all web services, including external service cards such as NetBird and mail."},{"file":"31_HOMELAB_REFERENCE.md","line":1931,"text":"- Home portal gap analysis was collected for gethomepage/homepage behind npmplus."},{"file":"31_HOMELAB_REFERENCE.md","line":1932,"text":"- Proof records Homepage config hashes, redacted current cards/bookmarks, current URLs, npmplus route lines, local web-port probes and known service container candidates."},{"file":"31_HOMELAB_REFERENCE.md","line":1941,"text":"- Proof records current card URLs/titles, redacted widget config, redacted Homepage log errors, NPMPlus internal route files/routes and candidate public/VPN cards."},{"file":"31_HOMELAB_REFERENCE.md","line":1950,"text":"- Homepage services.yaml was backed up, duplicate VPN cards were removed where a non-VPN card existed, and missing web cards for NetBird, Mail and Webmail were added without VPN suffix in the card names."},{"file":"31_HOMELAB_REFERENCE.md","line":1961,"text":"- Corrected Homepage apply removed duplicate VPN cards where a non-VPN card existed and added NetBird, Mail and Webmail cards with non-VPN names."},{"file":"31_HOMELAB_REFERENCE.md","line":1962,"text":"- The added card URLs use currently reachable vpn.gram1.ru web endpoints because public netbird/mail/webmail hosts did not resolve/open during analysis."},{"file":"31_HOMELAB_REFERENCE.md","line":2045,"text":"## HOME_PORTAL_NPMPLUS_DEFAULT_ROUTE_ANALYSIS_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":2046,"text":"- Home portal NetBird/Mail/Webmail cards were investigated after user saw the NPMPlus default page from client [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":2047,"text":"- Analysis checks URL body fingerprints, NPMPlus route config matches, service container candidates and Homepage card lines."},{"file":"31_HOMELAB_REFERENCE.md","line":2048,"text":"- Proof: 356_HOME_PORTAL_NPMPLUS_DEFAULT_ROUTE_ANALYSIS_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":2053,"text":"- NetBird card points to https://nb.pvepro.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2065,"text":"- NetBird: https://nb.pvepro.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2073,"text":"- Excluded cards: Homepage, NPMplus, Router and Public Domain."},{"file":"31_HOMELAB_REFERENCE.md","line":2101,"text":"- Homepage External card/link for relay.pvepro.ru was removed because relay.pvepro.ru had DNS but no reachable HTTP/HTTPS endpoint from edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":2113,"text":"## HOME_EXTERNAL_NETBIRD_ALEXHOST_NORMALIZE_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":2114,"text":"- Homepage External NetBird and AlexHost Billing href/siteMonitor URLs normalized with trailing slash."},{"file":"31_HOMELAB_REFERENCE.md","line":2116,"text":"- Proof: 397_HOME_EXTERNAL_NETBIRD_ALEXHOST_NORMALIZE_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":2120,"text":"- Remaining blocker for Homepage green dot is HTTP/HTTPS 403 from router web service to edge-vm/Bridge1, not network reachability."},{"file":"31_HOMELAB_REFERENCE.md","line":2126,"text":"- Health endpoint service on edge-vm: homelab-router-moscow-health-http.service."},{"file":"31_HOMELAB_REFERENCE.md","line":2139,"text":"- Health endpoint service: homelab-router-moscow-health-http.service on edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":2155,"text":"- Do not publish Cloudflare/NPMplus routes for these forums until CodeVipe recipe is proven and final rebuild is complete."},{"file":"31_HOMELAB_REFERENCE.md","line":2183,"text":"- Edge NPMplus manual routes terminate TLS with real Let’s Encrypt certificates and proxy to forum-prod VM160 at [PRIVATE_IP]:80."},{"file":"31_HOMELAB_REFERENCE.md","line":2188,"text":"- Edge NPMplus forum publication backup created after public cutover."},{"file":"31_HOMELAB_REFERENCE.md","line":2189,"text":"- Backup location: /opt/npmplus/manual-backups/forum-public-ok-*.tar.gz on edge-vm [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":2190,"text":"- Includes manual proxy_host configs 200-204 and Let’s Encrypt forum certificates under /opt/npmplus/tls/forum-certs."},{"file":"31_HOMELAB_REFERENCE.md","line":2193,"text":"- Edge certificate renewal configured on edge-vm [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":2194,"text":"- Token stored at /opt/npmplus/secure/forum_cf_token.env mode 600 root-only."},{"file":"31_HOMELAB_REFERENCE.md","line":2195,"text":"- Renewal script: /opt/npmplus/scripts/renew-forum-certs.sh."},{"file":"31_HOMELAB_REFERENCE.md","line":2257,"text":"- Mailcow and NetBird are reachable again: mail.pvepro.ru/admin and nb.pvepro.ru return HTTP 200."},{"file":"31_HOMELAB_REFERENCE.md","line":2262,"text":"- Proofs: 589_POST_UNBAN_MAILCOW_NETBIRD_VERIFY.txt on VPS, 590_FORUM_SMTP_FAILED_CONFIG_DISABLED_PROOF.txt, 591_POST_INCIDENT_PUBLIC_STATUS_PROOF.txt, 592_POST_INCIDENT_FINAL_STABLE_STATE_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":2268,"text":"- Mailcow and NetBird remained reachable after the test."},{"file":"31_HOMELAB_REFERENCE.md","line":2274,"text":"- Mailcow and NetBird remained reachable after the test."},{"file":"31_HOMELAB_REFERENCE.md","line":2284,"text":"- Mailcow and NetBird remained reachable after enabling persistent forum SMTP."},{"file":"31_HOMELAB_REFERENCE.md","line":2291,"text":"- Mailcow and NetBird remain reachable after enabling persistent forum SMTP."},{"file":"31_HOMELAB_REFERENCE.md","line":2316,"text":"- Mailcow admin and NetBird UI are reachable after persistent forum SMTP enablement."},{"file":"31_HOMELAB_REFERENCE.md","line":2368,"text":"- NPMplus on edge terminates TLS and proxies all five forums to VM160."},{"file":"31_HOMELAB_REFERENCE.md","line":2408,"text":"- NPMplus on edge terminates TLS and proxies to http://[PRIVATE_IP]:80."},{"file":"31_HOMELAB_REFERENCE.md","line":2468,"text":"- Local placeholder service on edge-vm: homelab-parked-domains-http.service, enabled/active, serves marker PARKED_PAGE_OK on http://[PRIVATE_IP]:18088."},{"file":"31_HOMELAB_REFERENCE.md","line":2469,"text":"- NPMplus manual managed route files: /data/nginx/proxy_host/998.conf for newfi.ru, 997.conf for hapusya.ru and 996.conf for kingofwolk.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2471,"text":"- Certificates were issued by certbot DNS-01 using Cloudflare API hooks; HTTP-01 must not be retried for these parked domains without a new plan because earlier attempts hit NPMplus default redirect/include-order behavior."},{"file":"31_HOMELAB_REFERENCE.md","line":2472,"text":"- Cloudflare token value is not stored in the reference; token file path only: /opt/npmplus/secure/parked_cf_token, root-owned mode 600."},{"file":"31_HOMELAB_REFERENCE.md","line":2473,"text":"- Certificate names on edge-vm: parked-newfi.ru, parked-hapusya.ru and parked-kingofwolk.ru; observed expiry during setup: 2026-09-29."},{"file":"31_HOMELAB_REFERENCE.md","line":2474,"text":"- Certbot deploy hook installed: /etc/letsencrypt/renewal-hooks/deploy/parked-domains-npmplus-deploy.sh."},{"file":"31_HOMELAB_REFERENCE.md","line":2476,"text":"- Final route backup: /opt/npmplus/manual-backups/parked-stage16-route-only-20260701T155843Z."},{"file":"31_HOMELAB_REFERENCE.md","line":2481,"text":"- gram1.ru root and www.gram1.ru are routed to the existing parked placeholder page on edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":2483,"text":"- NPMplus managed route file: /data/nginx/proxy_host/995.conf."},{"file":"31_HOMELAB_REFERENCE.md","line":2485,"text":"- Certificate name on edge-vm: parked-gram1.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2486,"text":"- Certificate issuance mode: certbot DNS-01 with dedicated gram1 Cloudflare token file /opt/npmplus/secure/gram1_cf_token."},{"file":"31_HOMELAB_REFERENCE.md","line":2488,"text":"- Certbot deploy hook: /etc/letsencrypt/renewal-hooks/deploy/gram1-root-npmplus-deploy.sh."},{"file":"31_HOMELAB_REFERENCE.md","line":2497,"text":"- NPMplus managed route file: /data/nginx/proxy_host/994.conf."},{"file":"31_HOMELAB_REFERENCE.md","line":2498,"text":"- Landing service on edge-vm: homelab-pvepro-landing-http.service on http://[PRIVATE_IP]:18089."},{"file":"31_HOMELAB_REFERENCE.md","line":2500,"text":"- Certificate name on edge-vm: landing-pvepro.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2501,"text":"- Certificate issuance mode: certbot DNS-01 with dedicated pvepro Cloudflare token file /opt/npmplus/secure/pvepro_cf_token."},{"file":"31_HOMELAB_REFERENCE.md","line":2503,"text":"- Certbot deploy hook: /etc/letsencrypt/renewal-hooks/deploy/pvepro-root-npmplus-deploy.sh."},{"file":"31_HOMELAB_REFERENCE.md","line":2515,"text":"- Recommended future path: establish VPN/NetBird/WireGuard or reverse-proxy/private management endpoint first; then issue DNS-01 certificate on a trusted node and deploy cert/key to the router only over that private path."}] +CORRELATE31_DECISION=PUBLIC_INGRESS_NO_NETBIRD_KEY_CORRELATION +CORRELATE31_END=true + +OUTPUT_END +CHAT_OUTPUT_END diff --git a/runtime/latest.json b/runtime/latest.json index b494f7ff..c66cf6e3 100644 --- a/runtime/latest.json +++ b/runtime/latest.json @@ -1,27 +1,27 @@ { "schema_version": 1, "channel": "homelab-runtime", - "command_id": "SIGNALBOT-260908-SEALED-ACTIVATION-043ACT5", - "status": "FAIL", - "rc": 3, + "command_id": "NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31", + "status": "OK", + "rc": 0, "host": "pve01", - "mode": "change", - "component": "signalbot-cr0116-sealed-activation-v5", - "started_at_utc": "2026-09-08T16:02:52Z", - "finished_at_utc": "2026-09-08T16:02:55Z", + "mode": "read-only", + "component": "newfi-stagingedge-public-ingress-netbird-cluster-correlation-readonly", + "started_at_utc": "2026-09-08T16:03:40Z", + "finished_at_utc": "2026-09-08T16:03:51Z", "reference_register_checked": true, "reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66", "error_register_checked": true, "error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0", - "command_sha256": "aef71b5a657deb6b67829d8f20e637bb59775e96487b8b69599a3f15e69a0e93", + "command_sha256": "bc3c9aec17da7c6e7ab8defad78a7e7504875ab0cf46d9f54b25230eeeba3ce0", "duplicate_failed_command_blocked": false, "block_reason": null, "execution_started": true, - "change_declared": true, + "change_declared": false, "result_contract_valid": true, - "result_contract_status": "FAIL", + "result_contract_status": null, "result_contract_error": null, - "command_rc": 3, + "command_rc": 0, "changes_made": false, "rollback_started": false, "rollback_restored": null, @@ -30,9 +30,9 @@ "secrets_included": false, "private_addresses_included": false, "raw_evidence_retained_locally": true, - "raw_evidence_sha256": "a35440d46ac9951060a7c8945c5455fd10da259f04d695508ddb47c6fab8acd7", - "sanitized_output_sha256": "a35440d46ac9951060a7c8945c5455fd10da259f04d695508ddb47c6fab8acd7", + "raw_evidence_sha256": "d0838ac2e5e7a4ce65b465ceb9e23ff6b931110766e654ff27fec8eaf8eccb95", + "sanitized_output_sha256": "d0838ac2e5e7a4ce65b465ceb9e23ff6b931110766e654ff27fec8eaf8eccb95", "output_truncated_in_json": false, "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", - "output": "ERROR_REGISTER_CHECK=OK\nREFERENCE_CHECK=OK\nAUTHORITY_CHECK_SCOPE=READABILITY_ONLY_INCIDENTS_NOT_CLOSED\nSB043A5_RUNNER_SHA256=b248a4c32c9cc64e5747e7dce6c7fc0a23f5124a77c71ce72e27a81aceae9d2d\nSB043A5_RUNNER_ROLLBACK_RULES=OK\nSB043A5_QGA_BYTES={\"activation\":23309,\"limit\":921600,\"probe\":1507}\nSB043A5_VM170_CLUSTER={\"name\":\"core-apps\",\"node\":\"pve01\",\"status\":\"running\",\"type\":\"qemu\"}\nSB043A5_ERROR=AttributeError:'str' object has no attribute 'tzinfo'\nSB043A5_GUEST_DECISION=PREMUTATION_HOLD\nSB043A5_ACTIVATION_QGA={\"rc\":3,\"stderr_present\":false}\nSB043A5_INDEPENDENT_POSTSTATE={\"activation_dir_exists\":false,\"env\":{\"APP_IMAGE\":\"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70\",\"CODE_IDENTITY\":\"e32760c69a4311728db9066ee8bf2bf66b1e5a70\",\"COLLECTION_START_AT\":\"2026-09-07T00:00:00+00:00\",\"EXPERIMENT_ID\":\"ec477ea41ecbd5cfdef5afc259595aab20674a7d933f41a389329ff05098b338\",\"RUNTIME_MANIFEST_ID\":\"58d3b59200bdc0eb8d448612679d667b194263586cb3198dfc08597935053a1a\"},\"result\":null,\"services\":[{\"image\":\"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70\",\"image_id\":\"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736\",\"restart_count\":0,\"running\":true,\"service\":\"worker\",\"started_at\":\"2026-09-06T18:48:20.586788319Z\"},{\"image\":\"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70\",\"image_id\":\"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736\",\"restart_count\":0,\"running\":true,\"service\":\"relay\",\"started_at\":\"2026-09-06T18:48:20.603414848Z\"},{\"image\":\"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70\",\"image_id\":\"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736\",\"restart_count\":19,\"running\":true,\"service\":\"collector\",\"started_at\":\"2026-09-08T13:42:51.284969517Z\"},{\"image\":\"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70\",\"image_id\":\"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736\",\"restart_count\":0,\"running\":true,\"service\":\"shadow\",\"started_at\":\"2026-09-06T18:48:20.768190553Z\"}]}\nSB043A5_HOLDS=[\"PREMUTATION_HOLD\"]\nSB043A5_DECISION=HOLD_NO_TARGET_MUTATION\nHOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"SIGNALBOT-260908-SEALED-ACTIVATION-043ACT5\",\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"FAIL\",\"version\":1}\n" + "output": "CORRELATE31_BEGIN=true\nCOMMAND_ID=NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31\nMODE=read-only\nMUTATIONS_PERFORMED=NO\nERROR_REGISTER_CHECK=OK\nERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0\nREFERENCE_CHECK=OK\nREFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66\nRUNNER_SHA_MATCH=true\nPUBLIC_IP_SHA_MATCH=true\nPUBLIC_SSH_KEYSCAN_RC=0\nPUBLIC_SSH_ED25519_COUNT=1\nPUBLIC_SSH_ED25519_SHA256=8c930e3407a94a222d180662fd94ebde906024fec7b4098d23a82e4ddad1d1dd\nNETBIRD_STATUS_JSON_RC=0\nNETBIRD_JSON_PARSE_OK=true\nNETBIRD_STATUS_DETAIL_RC=0\nNETBIRD_PEER_IP_COUNT=15\nNETBIRD_PUBLIC_SSH_KEY_MATCH_COUNT=0\nNETBIRD_PUBLIC_SSH_KEY_MATCHES_JSON=[]\nCLUSTER_RESOURCES_RC=0\nCLUSTER_VM_COUNT=13\nCLUSTER_RELEVANT_VM_COUNT=4\nCLUSTER_RELEVANT_VMS_JSON=[{\"vmid\":\"150\",\"name\":\"snikket\",\"node\":\"pve01\",\"type\":\"qemu\",\"status\":\"running\"},{\"vmid\":\"160\",\"name\":\"forum-prod\",\"node\":\"pve02\",\"type\":\"qemu\",\"status\":\"running\"},{\"vmid\":\"9130\",\"name\":\"edge-cold-standby\",\"node\":\"pve02\",\"type\":\"qemu\",\"status\":\"stopped\"},{\"vmid\":\"130\",\"name\":\"edge-vm\",\"node\":\"pve03\",\"type\":\"qemu\",\"status\":\"running\"}]\nCLUSTER_QGA_CORRELATION_JSON=[{\"vmid\":\"150\",\"name\":\"snikket\",\"node\":\"pve01\",\"qga_rc\":0,\"ipv4_count\":2,\"ip_hashes\":[\"346840d5a3d9fe9b61ce99955bb98df3db872090732c96aa5df1d83cb1f3e85a\",\"4e29a2729bbc40663066bdae0c5a3d627070fba621f5c8c70639f4782afbc67d\"],\"matches_public_key_netbird_peer\":false},{\"vmid\":\"160\",\"name\":\"forum-prod\",\"node\":\"pve02\",\"qga_rc\":0,\"ipv4_count\":1,\"ip_hashes\":[\"bf059cb10a70745fde7a01faab601e85d2548ea031d4bdf79d70664cfb51e688\"],\"matches_public_key_netbird_peer\":false},{\"vmid\":\"130\",\"name\":\"edge-vm\",\"node\":\"pve03\",\"qga_rc\":0,\"ipv4_count\":12,\"ip_hashes\":[\"bc41ed840e46092321935dd48da46da10a932deab0005de91d17a509b9d42e2d\",\"d1d4b6abdd6b1971128522c259fade15c22be861a650e31fb34457339336a812\",\"0b7870e2230336f502277fa38348a4bd934ff816a05523581c97d4ce59589fa6\",\"5649415146501fa3dc7b2e08f469ef80b6b04e46b86079acd21229eb875e9440\",\"346840d5a3d9fe9b61ce99955bb98df3db872090732c96aa5df1d83cb1f3e85a\",\"fbd57f0145e15cc8436c042887ccaa6c122eb481613abb78201b3b2212fcc422\",\"f9bcbcb71ab0bfd4ae96928d23473c1d6728cd09d9b4c65058dbdfaa30fd1e45\",\"c138df8d3b53b19038a6a63dc7280bfac4a7e72ad4fbe7f359b49c55d1df3d4c\",\"93449cac351e054dbbd4e026e0e9ba9060e51c04961d9fca4281acac18dda1f9\",\"5db063f47c3859a031b1618455d7eefac6341c65feb96a90fd6a57a504ea4d84\",\"bc517b4af3298846906234d3d697d3820b0b652ade1880c937c9d71cd802c834\",\"885dfc9b72d2209e492b4631e0c538472ddf418cdf419aff8032c8d43704a63d\"],\"matches_public_key_netbird_peer\":false}]\nAUTHORITY_REFERENCE_COUNT=240\nAUTHORITY_REFERENCES_JSON=[{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":14,\"text\":\"- VM130 edge-vm | pve03 | running | KEEP\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":15,\"text\":\"- VM150 snikket | pve01 | running | KEEP\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":49,\"text\":\"- NPMplus retired proxy routes removed; KEEP routes verified.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":75,\"text\":\"NOTE edge-vm disk scsi1 backup=0 risk must be documented\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":106,\"text\":\"06_edge_npmplus_routes_safe.txt 17350 bytes\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":149,\"text\":\"- У VM130 edge-vm есть риск: дополнительный диск backup=0.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":166,\"text\":\"- VM130 edge-vm pve03 [PRIVATE_IP] Docker ingress/app host.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":167,\"text\":\"- VM150 Nextcloud pve01 [PRIVATE_IP] Nextcloud AIO.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":174,\"text\":\"- Nextcloud VM150 имеет Proxmox backup и restore-proof evidence.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":185,\"text\":\"- VM130 backup: closed, scsi1 backup=1, manual backup ZSTD_OK, exact offhost ZSTD_OK, old local backup removed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":187,\"text\":\"- Cloudflare token: [REDACTED] NPMplus token rotated, API verify OK, old exposed token externally confirmed revoked.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":312,\"text\":\"- [PRIVATE_IP] -> bc:24:11:e1:f3:3c NPMplus / edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":316,\"text\":\"- ISP tcp/80 -> bc:24:11:e1:f3:3c, NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":317,\"text\":\"- ISP tcp/443 -> bc:24:11:e1:f3:3c, NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":323,\"text\":\"- _WEBADMIN_Bridge0 permits Home-to-Proxmox access for DNS1/DNS2, AdGuard UI, NPMplus HTTP/HTTPS/UI, Nextcloud AIO/Talk TURN, Proxmox SSH/8006 and ICMP from admin PC.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":358,\"text\":\"## EXTERNAL_SERVICES_UPS_NETBIRD_MAIL_SCRIPTS_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":366,\"text\":\"- edge-vm: no UPS/NUT/APCUPSD integration discovered.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":370,\"text\":\"### NetBird\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":371,\"text\":\"- NetBird service is active on pve01, pve02, pve03 and edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":372,\"text\":\"- NetBird version observed: daemon 0.73.2, CLI 0.73.2.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":373,\"text\":\"- pve01: FQDN pve01.netbird.selfhosted, IPv4 [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":374,\"text\":\"- pve02: FQDN pve02.netbird.selfhosted, IPv4 [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":375,\"text\":\"- pve03: FQDN pve03.netbird.selfhosted, IPv4 [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":376,\"text\":\"- edge-vm: FQDN edge-vm.netbird.selfhosted, IPv4 [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":381,\"text\":\"- SSH Server through NetBird: Disabled.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":383,\"text\":\"- Inventory proof: 108_EXTERNAL_SERVICES_NETBIRD_MAIL_SCRIPTS_INVENTORY.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":394,\"text\":\"- Full script/unit inventory proof: 108_EXTERNAL_SERVICES_NETBIRD_MAIL_SCRIPTS_INVENTORY.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":395,\"text\":\"- edge-vm owns most application health, dashboard, ingress, backup, NetBox, NPMplus, certificate, Trivy and vulnerability jobs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":396,\"text\":\"- pve01 owns many backup/offhost/restore/health/security/NetBird VPS/rclone/sops/scrutiny jobs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":398,\"text\":\"- pve03 owns smartctl textfile, cluster internal IP, NetBird and staging/rclone helpers.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":455,\"text\":\"- edge-vm timers cover runtime dashboard, Paperless guard, external canary, health metrics, restore drill index, AdGuard rewrite sync, NPMplus cert expiry, NetBox backup/sync, retention, cluster daily status, vulnerability and Trivy scans, ingress hardening and NPMplus admin bind.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":456,\"text\":\"- pve01 timers cover VPN/NetBird health, health metrics, smartctl, disk space, MkDocs refresh, VPS identity audit, storage capacity, quality gate, evidence catalog, backup freshness, docker health, Filebrowser backup/offhost/restore, NPMplus/Kuma backup, NetBird VPS backup/offhost, Authentik/Gitea/Vaultwarden backup, SOPS secret coverage, mail cloud upload/restore, Immich/Memos/Paperless backup/offhost/restore, auto backup, edge-vm vzdump, secret sanity.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":459,\"text\":\"- Script hashes were captured for /usr/local/sbin and /usr/local/bin on edge-vm, pve01, pve02 and pve03.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":487,\"text\":\"- pve03 local-lvm is the most constrained active VM storage because VM130 has 96G OS disk plus 150G media disk.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":504,\"text\":\"- NetBird IP: [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":509,\"text\":\"- Main active workloads: CT110 dns1, CT112 unbound1, VM150 nextcloud.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":515,\"text\":\"- NetBird IP: [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":526,\"text\":\"- NetBird IP: [PRIVATE_IP]/16.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":531,\"text\":\"- Main active workload: VM130 edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":597,\"text\":\"### VM130 edge-vm\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":600,\"text\":\"- Name: edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":614,\"text\":\"- Important note: VM130 has exact offhost backup proof after scsi1 backup=1.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":616,\"text\":\"### VM150 nextcloud\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":672,\"text\":\"- git.gram1.ru -> [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":683,\"text\":\"- Public WAN router forwards TCP/80 and TCP/443 to NPMplus on edge-vm, [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":686,\"text\":\"- NPMplus admin listener is bound to localhost on edge-vm, [PRIVATE_IP]:81; public disabled legacy host npm.gram1.ru exists but enabled=0.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":688,\"text\":\"### NPMplus runtime\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":689,\"text\":\"- Host: edge-vm, [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":690,\"text\":\"- Container: npmplus, image zoeyvid/npmplus:2026-06-17-b1, healthy at inventory time.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":692,\"text\":\"- Database: /opt/npmplus/npmplus/database.sqlite.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":694,\"text\":\"- Public listen ports on edge-vm: [PRIVATE_IP]:80 and [PRIVATE_IP]:443 by nginx/NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":695,\"text\":\"- NPMplus admin: [PRIVATE_IP]:81.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":696,\"text\":\"- Secret rule: Cloudflare DNS API token exists only inside NPMplus certificate metadata and must never be printed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":698,\"text\":\"### Public NPMplus proxy hosts\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":705,\"text\":\"- git.gram1.ru -> http://[PRIVATE_IP]:3002, cert=29, ssl_forced=1, enabled=1.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":713,\"text\":\"### VPN NPMplus proxy hosts\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":737,\"text\":\"- npmplus.vpn.gram1.ru -> https://[PRIVATE_IP]:81, cert=32.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":749,\"text\":\"### NPMplus certificates\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":754,\"text\":\"- cert=29: git.gram1.ru, expires 2026-09-13 17:36:55.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":762,\"text\":\"- NPMplus schema/listen inventory: 126_DNS_INGRESS_CERT_NPMPLUS_SAFE_INVENTORY.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":763,\"text\":\"- NPMplus exact proxy/cert rows: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":769,\"text\":\"- Host: edge-vm, IP [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":773,\"text\":\"- Additional compose roots: /opt/npmplus-compose, /opt/gotify-compose, /opt/uptime-kuma-compose, /opt/vaultwarden-compose, /opt/dockge-compose.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":774,\"text\":\"- Public ingress terminates through NPMplus on ports 80/443.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":775,\"text\":\"- Most app containers expose only [PRIVATE_IP] ports and are published through NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":776,\"text\":\"- NPMplus uses host networking.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":813,\"text\":\"- npmplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":826,\"text\":\"- Ingress/security: npmplus, socket-proxy, crowdsec.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":831,\"text\":\"- Admin/dashboard: homepage, dockge, netbox, dozzle, NPMplus VPN admin.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":863,\"text\":\"- NPMplus admin: [PRIVATE_IP]:81.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":864,\"text\":\"- NPMplus public ingress: [PRIVATE_IP]:80 and [PRIVATE_IP]:443.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":895,\"text\":\"- VM130 edge-vm: included in homelab-nightly-all, local backup on pve03.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":896,\"text\":\"- VM150 nextcloud: included in homelab-nightly-all, local backup on pve01.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":898,\"text\":\"- VM130 also has dedicated edge-vm-vzdump backup/offhost/restore health proofs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":900,\"text\":\"- VM130 scsi1 backup flag is enabled after correction: scsi1 backup=1.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":902,\"text\":\"### Edge VM / VM130 full-image protection\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":903,\"text\":\"- edge-vm-vzdump-backup: STATUS=OK, archive size about 28.2G, SHA256 recorded.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":904,\"text\":\"- edge-vm-vzdump-offhost: STATUS=OK, destination pve02 /mnt/staging/offhost/edge-vm-vzdump-from-pve03.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":905,\"text\":\"- edge-vm-vzdump-restore: STATUS=OK, zstd and vma verification OK.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":906,\"text\":\"- mail-cloud-edge-vm: STATUS=OK, recurring chunked upload, 53 parts, download verification enabled.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":907,\"text\":\"- Retention for edge-vm cloud upload: RETENTION_KEEP=4.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":918,\"text\":\"### NPMplus / Kuma / ingress config backups\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":919,\"text\":\"- npmplus-kuma-config-backup: STATUS=OK.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":920,\"text\":\"- Archive: /mnt/staging/npmplus-kuma-config-backups/snapshots/npmplus-kuma-config-*.tar.gz.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":921,\"text\":\"- NPMplus DB integrity: OK.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":926,\"text\":\"- npmplus-kuma-config-offhost: STATUS=OK to pve02.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":927,\"text\":\"- npmplus-kuma-config-restore: STATUS=OK with DB integrity checks.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":928,\"text\":\"- npmplus restore proof also exists from app backup quality checks.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":995,\"text\":\"- NetBird VPS backup: STATUS=OK, snapshot under /mnt/staging/netbird-vps-backups/snapshots.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":996,\"text\":\"- NetBird VPS offhost: STATUS=OK to pve02.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":997,\"text\":\"- NetBird VPS restore validation: STATUS=OK, archive SHA256 recorded.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1003,\"text\":\"- Disk retention policy: STATUS=OK, root used pct observed 70 on edge-vm, removed dirs 0, Docker volume prune NO.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1004,\"text\":\"- App backup retention dry-run timer exists on edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1027,\"text\":\"- Primary monitoring host: edge-vm, [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1039,\"text\":\"- Node exporter on edge-vm: node-exporter, local port [PRIVATE_IP]:9100.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1049,\"text\":\"- pve01 also runs private VPN host health, NetBird peer health, disk space health, MkDocs refresh, evidence catalog and quality gate timers.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1058,\"text\":\"- https://git.gram1.ru\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1084,\"text\":\"- HomelabP0WeeklyEdgeVmVzdumpHealthStale: weekly edge-vm vzdump health older than 8d.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1092,\"text\":\"- HomelabNpmplusCertExpiryHealthNotOkOrStale: NPMplus cert expiry health failed or older than 48h.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1103,\"text\":\"- Alloy relabels container, compose_project, compose_service and host=edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1114,\"text\":\"- external canary checks include nc.gram1.ru, git.gram1.ru, auth.gram1.ru, backup.gram1.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1122,\"text\":\"- npmplus-cert-expiry-health.txt is the standardized health alias for certificate expiry.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1123,\"text\":\"- npmplus-certificate-expiry.txt is the detailed cert expiry file.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1125,\"text\":\"- cluster-daily-status local extra check reports npmplus-cert-expiry status OK, problems=0, min_days=75.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1137,\"text\":\"- Main health dir on edge-vm: /var/lib/homelab-health.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1150,\"text\":\"- A previous compact check looked for npmplus-cert-expiry.txt; use npmplus-certificate-expiry.txt for detailed cert expiry and npmplus-cert-expiry-health.txt for standardized health.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1209,\"text\":\"- edge-vm is reached as debian@[PRIVATE_IP] with sudo.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1218,\"text\":\"- edge-vm root key observed: id_ed25519; debian authorized_keys observed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1226,\"text\":\"- NPMplus DB: /opt/npmplus/npmplus/database.sqlite, root-only mode observed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1237,\"text\":\"- edge-vm exposes public :80/:443 through NPMplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1238,\"text\":\"- edge-vm NPMplus admin :81 and socket-proxy :2375 are bound to [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1239,\"text\":\"- edge-vm registry cache :5000 is bound to [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1240,\"text\":\"- edge-vm Home Assistant :8123 is intentionally LAN-exposed.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1283,\"text\":\"- edge-vm runs Docker application stacks.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1284,\"text\":\"- Docker app data lives mainly under /opt/stacks, /opt/npmplus, /opt/gotify-compose, /opt/uptime-kuma-compose, /opt/vaultwarden-compose and /var/lib application paths.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1356,\"text\":\"- Public ingress HTTP/HTTPS: router forwards TCP 80/443 to edge-vm [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1357,\"text\":\"- Reverse proxy: NPMplus on edge-vm, container npmplus, host networking, admin bound to [PRIVATE_IP]:81.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1358,\"text\":\"- Edge runtime host: VM130 edge-vm, [PRIVATE_IP], Docker Compose projects count 43.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1359,\"text\":\"- NPMplus proxy routes count: 47.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1360,\"text\":\"- NPMplus certificates and proxy route source proof: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1365,\"text\":\"| nc.gram1.ru | http://[PRIVATE_IP]:11000 | VM150 Nextcloud AIO | VM150 vzdump, nextcloud restore proof, external canary |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1366,\"text\":\"| uptime.gram1.ru | http://[PRIVATE_IP]:3001 | edge-vm / uptime-kuma | npmplus-kuma backup/restore, Kuma health |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1367,\"text\":\"| gotify.gram1.ru | http://[PRIVATE_IP]:8082 | edge-vm / gotify | gotify health, alert-routing proof |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1368,\"text\":\"| vault.gram1.ru | http://[PRIVATE_IP]:8083 | edge-vm / vaultwarden | vaultwarden backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1369,\"text\":\"| dockge.gram1.ru | http://[PRIVATE_IP]:5001 | edge-vm / dockge | stack inventory |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1370,\"text\":\"| home.gram1.ru | http://[PRIVATE_IP]:3000 | edge-vm / homepage | homepage container, dashboard route |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1371,\"text\":\"| git.gram1.ru | http://[PRIVATE_IP]:3002 | edge-vm / gitea | gitea backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1372,\"text\":\"| dozzle.gram1.ru | http://[PRIVATE_IP]:9999 | edge-vm / dozzle | docker stack inventory |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1373,\"text\":\"| paper.gram1.ru | http://[PRIVATE_IP]:8010 | edge-vm / paperless | paperless backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1374,\"text\":\"| memos.gram1.ru | http://[PRIVATE_IP]:5230 | edge-vm / memos | memos backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1375,\"text\":\"| photos.gram1.ru | http://[PRIVATE_IP]:2283 | edge-vm / immich | immich media/full consistency proof |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1376,\"text\":\"| auth.gram1.ru | http://[PRIVATE_IP]:9000 | edge-vm / authentik | authentik backup/offhost/restore |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1405,\"text\":\"| npmplus.vpn.gram1.ru | https://[PRIVATE_IP]:81 | NPMplus admin, localhost-bound on edge |\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1418,\"text\":\"- npm.gram1.ru exists in NPMplus but was observed disabled.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1421,\"text\":\"- Router forwards TCP/UDP 51820 for WireGuard on the Home bridge, not to edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1424,\"text\":\"- If a public app is down, check in this order: DNS rewrite/upstream, NPMplus route/cert, upstream container/VM, app health file, backup/restore proof.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1425,\"text\":\"- If a VPN route is down, check NetBird first, then NPMplus wildcard cert, then local upstream.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1427,\"text\":\"- If NPMplus is broken, use backup/restore evidence from npmplus-kuma-config and NPMplus DB backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1428,\"text\":\"- If edge-vm is broken, VM130 full-image backup/offhost/restore proofs are authoritative.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1433,\"text\":\"- NPMplus route/cert rows: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1467,\"text\":\"- Check NPMplus route and certificate using NPMplus DB/proxy proof.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1479,\"text\":\"- Rewrites include public routes for git, dozzle, paper, memos, photos, auth and backup to edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1483,\"text\":\"### Ingress / NPMplus failure\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1484,\"text\":\"- Edge VM is VM130 at [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1485,\"text\":\"- NPMplus listens publicly on 80/443 and admin is bound to [PRIVATE_IP]:81.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1486,\"text\":\"- NPMplus DB is /opt/npmplus/npmplus/database.sqlite.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1489,\"text\":\"- Use npmplus-kuma-config backup/offhost/restore proofs for recovery.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1492,\"text\":\"- VM130 is the Docker runtime host.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1494,\"text\":\"- Then use VM130 full-image vzdump/offhost/restore proofs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1495,\"text\":\"- Current authoritative edge-vm backup/offhost/restore evidence is in backup catalog and VM130 proofs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1504,\"text\":\"- For VM130 and VM160, use their dedicated closure proofs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1507,\"text\":\"- Prometheus is on edge-vm at [PRIVATE_IP]:9090.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1568,\"text\":\"- DNS, ingress, NPMplus certificates and AdGuard/Unbound model.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1615,\"text\":\"## NEXTCLOUD_VM150_MAIL_CLOUD_BACKUP_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1616,\"text\":\"- VM150 Nextcloud Mail-cloud backup is installed on pve01.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1620,\"text\":\"- Proof: 192_NEXTCLOUD_VM150_MAIL_CLOUD_CHUNKED_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1636,\"text\":\"- P2 small-stack backup and restore dry-run is installed on edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1644,\"text\":\"- VM150 Nextcloud now has Mail-cloud chunked backup with download verification.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1670,\"text\":\"- VM150 Mail-cloud backup, router manual/recurring Mail-cloud backups, P2 small-stacks and 7 edge restore dry-runs are all confirmed OK.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1679,\"text\":\"- Covered checks include VM150 Mail-cloud, router startup/running config Mail-cloud, P2 small-stacks and seven restore dry-run health files.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1691,\"text\":\"- VM150 Nextcloud, router startup/running config, P0 critical and edge-vm backup directories are present on crypt remotes.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1693,\"text\":\"- Retention shape observed: P0 critical has 10 visible dirs with keep 14, edge-vm has 3 visible dirs with keep 4, new VM150/router jobs have initial dirs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1705,\"text\":\"- pve01 units checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1706,\"text\":\"- edge-vm units checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1707,\"text\":\"- Proof records LoadState, ActiveState, UnitFileState and failed-unit counts for pve01 and edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1712,\"text\":\"- Covered checks: VM150 Mail-cloud, router startup/running config, P2 small-stacks and seven restore dry-runs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1735,\"text\":\"- pve01 services checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1736,\"text\":\"- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1741,\"text\":\"- Corrected integrity proof was generated because one edge-vm executable required sudo for sha256sum.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1742,\"text\":\"- Corrected proof records hashes for pve01 and edge-vm unit fragments and executable scripts without printing script contents.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1753,\"text\":\"- pve01 timers checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1754,\"text\":\"- edge-vm timers checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1829,\"text\":\"- pve01 services checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1830,\"text\":\"- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1859,\"text\":\"## VM150_MAIL_CLOUD_JOURNAL_NOISE_CLASSIFICATION_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1860,\"text\":\"- VM150 Mail-cloud upload journal warnings/errors were classified after journal triage found non-zero counters.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1863,\"text\":\"- Proof: 278_VM150_MAIL_CLOUD_JOURNAL_NOISE_CLASSIFICATION_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1866,\"text\":\"- Audit manifest was regenerated after VM150 Mail-cloud journal-noise classification.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1870,\"text\":\"## SNAPSHOT_AFTER_VM150_JOURNAL_NOISE_CLASSIFICATION_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1871,\"text\":\"- Snapshot was created after VM150 Mail-cloud journal noise was classified as non-blocking historical noise.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1874,\"text\":\"- Proof: 282_SNAPSHOT_AFTER_VM150_JOURNAL_NOISE_CLASSIFICATION_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1877,\"text\":\"- Audit manifest was regenerated after snapshot following VM150 journal-noise classification.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1882,\"text\":\"- Post-backup-pass closure summary was generated after VM150 journal-noise classification.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1899,\"text\":\"- Verify P2 small-stacks, router running-config Mail-cloud and VM150 Nextcloud Mail-cloud first automatic runs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1921,\"text\":\"- Goal: make the portal show and open all web services, including external service cards such as NetBird and mail.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1931,\"text\":\"- Home portal gap analysis was collected for gethomepage/homepage behind npmplus.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1932,\"text\":\"- Proof records Homepage config hashes, redacted current cards/bookmarks, current URLs, npmplus route lines, local web-port probes and known service container candidates.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1941,\"text\":\"- Proof records current card URLs/titles, redacted widget config, redacted Homepage log errors, NPMPlus internal route files/routes and candidate public/VPN cards.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1950,\"text\":\"- Homepage services.yaml was backed up, duplicate VPN cards were removed where a non-VPN card existed, and missing web cards for NetBird, Mail and Webmail were added without VPN suffix in the card names.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1961,\"text\":\"- Corrected Homepage apply removed duplicate VPN cards where a non-VPN card existed and added NetBird, Mail and Webmail cards with non-VPN names.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":1962,\"text\":\"- The added card URLs use currently reachable vpn.gram1.ru web endpoints because public netbird/mail/webmail hosts did not resolve/open during analysis.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2045,\"text\":\"## HOME_PORTAL_NPMPLUS_DEFAULT_ROUTE_ANALYSIS_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2046,\"text\":\"- Home portal NetBird/Mail/Webmail cards were investigated after user saw the NPMPlus default page from client [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2047,\"text\":\"- Analysis checks URL body fingerprints, NPMPlus route config matches, service container candidates and Homepage card lines.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2048,\"text\":\"- Proof: 356_HOME_PORTAL_NPMPLUS_DEFAULT_ROUTE_ANALYSIS_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2053,\"text\":\"- NetBird card points to https://nb.pvepro.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2065,\"text\":\"- NetBird: https://nb.pvepro.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2073,\"text\":\"- Excluded cards: Homepage, NPMplus, Router and Public Domain.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2101,\"text\":\"- Homepage External card/link for relay.pvepro.ru was removed because relay.pvepro.ru had DNS but no reachable HTTP/HTTPS endpoint from edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2113,\"text\":\"## HOME_EXTERNAL_NETBIRD_ALEXHOST_NORMALIZE_20260630\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2114,\"text\":\"- Homepage External NetBird and AlexHost Billing href/siteMonitor URLs normalized with trailing slash.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2116,\"text\":\"- Proof: 397_HOME_EXTERNAL_NETBIRD_ALEXHOST_NORMALIZE_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2120,\"text\":\"- Remaining blocker for Homepage green dot is HTTP/HTTPS 403 from router web service to edge-vm/Bridge1, not network reachability.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2126,\"text\":\"- Health endpoint service on edge-vm: homelab-router-moscow-health-http.service.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2139,\"text\":\"- Health endpoint service: homelab-router-moscow-health-http.service on edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2155,\"text\":\"- Do not publish Cloudflare/NPMplus routes for these forums until CodeVipe recipe is proven and final rebuild is complete.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2183,\"text\":\"- Edge NPMplus manual routes terminate TLS with real Let’s Encrypt certificates and proxy to forum-prod VM160 at [PRIVATE_IP]:80.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2188,\"text\":\"- Edge NPMplus forum publication backup created after public cutover.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2189,\"text\":\"- Backup location: /opt/npmplus/manual-backups/forum-public-ok-*.tar.gz on edge-vm [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2190,\"text\":\"- Includes manual proxy_host configs 200-204 and Let’s Encrypt forum certificates under /opt/npmplus/tls/forum-certs.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2193,\"text\":\"- Edge certificate renewal configured on edge-vm [PRIVATE_IP].\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2194,\"text\":\"- Token stored at /opt/npmplus/secure/forum_cf_token.env mode 600 root-only.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2195,\"text\":\"- Renewal script: /opt/npmplus/scripts/renew-forum-certs.sh.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2257,\"text\":\"- Mailcow and NetBird are reachable again: mail.pvepro.ru/admin and nb.pvepro.ru return HTTP 200.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2262,\"text\":\"- Proofs: 589_POST_UNBAN_MAILCOW_NETBIRD_VERIFY.txt on VPS, 590_FORUM_SMTP_FAILED_CONFIG_DISABLED_PROOF.txt, 591_POST_INCIDENT_PUBLIC_STATUS_PROOF.txt, 592_POST_INCIDENT_FINAL_STABLE_STATE_PROOF.txt.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2268,\"text\":\"- Mailcow and NetBird remained reachable after the test.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2274,\"text\":\"- Mailcow and NetBird remained reachable after the test.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2284,\"text\":\"- Mailcow and NetBird remained reachable after enabling persistent forum SMTP.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2291,\"text\":\"- Mailcow and NetBird remain reachable after enabling persistent forum SMTP.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2316,\"text\":\"- Mailcow admin and NetBird UI are reachable after persistent forum SMTP enablement.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2368,\"text\":\"- NPMplus on edge terminates TLS and proxies all five forums to VM160.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2408,\"text\":\"- NPMplus on edge terminates TLS and proxies to http://[PRIVATE_IP]:80.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2468,\"text\":\"- Local placeholder service on edge-vm: homelab-parked-domains-http.service, enabled/active, serves marker PARKED_PAGE_OK on http://[PRIVATE_IP]:18088.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2469,\"text\":\"- NPMplus manual managed route files: /data/nginx/proxy_host/998.conf for newfi.ru, 997.conf for hapusya.ru and 996.conf for kingofwolk.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2471,\"text\":\"- Certificates were issued by certbot DNS-01 using Cloudflare API hooks; HTTP-01 must not be retried for these parked domains without a new plan because earlier attempts hit NPMplus default redirect/include-order behavior.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2472,\"text\":\"- Cloudflare token value is not stored in the reference; token file path only: /opt/npmplus/secure/parked_cf_token, root-owned mode 600.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2473,\"text\":\"- Certificate names on edge-vm: parked-newfi.ru, parked-hapusya.ru and parked-kingofwolk.ru; observed expiry during setup: 2026-09-29.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2474,\"text\":\"- Certbot deploy hook installed: /etc/letsencrypt/renewal-hooks/deploy/parked-domains-npmplus-deploy.sh.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2476,\"text\":\"- Final route backup: /opt/npmplus/manual-backups/parked-stage16-route-only-20260701T155843Z.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2481,\"text\":\"- gram1.ru root and www.gram1.ru are routed to the existing parked placeholder page on edge-vm.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2483,\"text\":\"- NPMplus managed route file: /data/nginx/proxy_host/995.conf.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2485,\"text\":\"- Certificate name on edge-vm: parked-gram1.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2486,\"text\":\"- Certificate issuance mode: certbot DNS-01 with dedicated gram1 Cloudflare token file /opt/npmplus/secure/gram1_cf_token.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2488,\"text\":\"- Certbot deploy hook: /etc/letsencrypt/renewal-hooks/deploy/gram1-root-npmplus-deploy.sh.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2497,\"text\":\"- NPMplus managed route file: /data/nginx/proxy_host/994.conf.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2498,\"text\":\"- Landing service on edge-vm: homelab-pvepro-landing-http.service on http://[PRIVATE_IP]:18089.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2500,\"text\":\"- Certificate name on edge-vm: landing-pvepro.ru.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2501,\"text\":\"- Certificate issuance mode: certbot DNS-01 with dedicated pvepro Cloudflare token file /opt/npmplus/secure/pvepro_cf_token.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2503,\"text\":\"- Certbot deploy hook: /etc/letsencrypt/renewal-hooks/deploy/pvepro-root-npmplus-deploy.sh.\"},{\"file\":\"31_HOMELAB_REFERENCE.md\",\"line\":2515,\"text\":\"- Recommended future path: establish VPN/NetBird/WireGuard or reverse-proxy/private management endpoint first; then issue DNS-01 certificate on a trusted node and deploy cert/key to the router only over that private path.\"}]\nCORRELATE31_DECISION=PUBLIC_INGRESS_NO_NETBIRD_KEY_CORRELATION\nCORRELATE31_END=true\n" } diff --git a/runtime/latest.txt b/runtime/latest.txt index 6438a949..5cd232db 100644 --- a/runtime/latest.txt +++ b/runtime/latest.txt @@ -1,22 +1,22 @@ CHAT_OUTPUT_BEGIN -COMMAND_ID=SIGNALBOT-260908-SEALED-ACTIVATION-043ACT5 -STATUS=FAIL -RC=3 +COMMAND_ID=NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31 +STATUS=OK +RC=0 HOST=pve01 -MODE=change -COMPONENT=signalbot-cr0116-sealed-activation-v5 +MODE=read-only +COMPONENT=newfi-stagingedge-public-ingress-netbird-cluster-correlation-readonly REFERENCE_REGISTER_CHECK=OK REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66 ERROR_REGISTER_CHECK=OK ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0 -COMMAND_SHA256=aef71b5a657deb6b67829d8f20e637bb59775e96487b8b69599a3f15e69a0e93 +COMMAND_SHA256=bc3c9aec17da7c6e7ab8defad78a7e7504875ab0cf46d9f54b25230eeeba3ce0 DUPLICATE_FAILED_COMMAND_BLOCKED=false EXECUTION_STARTED=true -CHANGE_DECLARED=true +CHANGE_DECLARED=false RESULT_CONTRACT_VALID=true -RESULT_CONTRACT_STATUS=FAIL +RESULT_CONTRACT_STATUS=NOT_APPLICABLE RESULT_CONTRACT_ERROR=NONE -COMMAND_RC=3 +COMMAND_RC=0 CHANGES_MADE=false ROLLBACK_STARTED=false ROLLBACK_RESTORED=null @@ -24,23 +24,37 @@ MUTATION_OUTCOME=NO_MUTATION SANITIZED=yes SECRETS_INCLUDED=no PRIVATE_ADDRESSES_INCLUDED=no -RAW_EVIDENCE_SHA256=a35440d46ac9951060a7c8945c5455fd10da259f04d695508ddb47c6fab8acd7 -SANITIZED_OUTPUT_SHA256=a35440d46ac9951060a7c8945c5455fd10da259f04d695508ddb47c6fab8acd7 +RAW_EVIDENCE_SHA256=d0838ac2e5e7a4ce65b465ceb9e23ff6b931110766e654ff27fec8eaf8eccb95 +SANITIZED_OUTPUT_SHA256=d0838ac2e5e7a4ce65b465ceb9e23ff6b931110766e654ff27fec8eaf8eccb95 OUTPUT_BEGIN +CORRELATE31_BEGIN=true +COMMAND_ID=NEWFI-260908-A-STAGINGEDGE-PUBLICINGRESS-CORRELATE31 +MODE=read-only +MUTATIONS_PERFORMED=NO ERROR_REGISTER_CHECK=OK +ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0 REFERENCE_CHECK=OK -AUTHORITY_CHECK_SCOPE=READABILITY_ONLY_INCIDENTS_NOT_CLOSED -SB043A5_RUNNER_SHA256=b248a4c32c9cc64e5747e7dce6c7fc0a23f5124a77c71ce72e27a81aceae9d2d -SB043A5_RUNNER_ROLLBACK_RULES=OK -SB043A5_QGA_BYTES={"activation":23309,"limit":921600,"probe":1507} -SB043A5_VM170_CLUSTER={"name":"core-apps","node":"pve01","status":"running","type":"qemu"} -SB043A5_ERROR=AttributeError:'str' object has no attribute 'tzinfo' -SB043A5_GUEST_DECISION=PREMUTATION_HOLD -SB043A5_ACTIVATION_QGA={"rc":3,"stderr_present":false} -SB043A5_INDEPENDENT_POSTSTATE={"activation_dir_exists":false,"env":{"APP_IMAGE":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","CODE_IDENTITY":"e32760c69a4311728db9066ee8bf2bf66b1e5a70","COLLECTION_START_AT":"2026-09-07T00:00:00+00:00","EXPERIMENT_ID":"ec477ea41ecbd5cfdef5afc259595aab20674a7d933f41a389329ff05098b338","RUNTIME_MANIFEST_ID":"58d3b59200bdc0eb8d448612679d667b194263586cb3198dfc08597935053a1a"},"result":null,"services":[{"image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"worker","started_at":"2026-09-06T18:48:20.586788319Z"},{"image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"relay","started_at":"2026-09-06T18:48:20.603414848Z"},{"image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":19,"running":true,"service":"collector","started_at":"2026-09-08T13:42:51.284969517Z"},{"image":"8020-demonov-shadow:e32760c69a4311728db9066ee8bf2bf66b1e5a70","image_id":"sha256:403c4266282a56cb210bed95cd58295692296502913e7440e2133d7b5664c736","restart_count":0,"running":true,"service":"shadow","started_at":"2026-09-06T18:48:20.768190553Z"}]} -SB043A5_HOLDS=["PREMUTATION_HOLD"] -SB043A5_DECISION=HOLD_NO_TARGET_MUTATION -HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"SIGNALBOT-260908-SEALED-ACTIVATION-043ACT5","rollback_restored":null,"rollback_started":false,"status":"FAIL","version":1} +REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66 +RUNNER_SHA_MATCH=true +PUBLIC_IP_SHA_MATCH=true +PUBLIC_SSH_KEYSCAN_RC=0 +PUBLIC_SSH_ED25519_COUNT=1 +PUBLIC_SSH_ED25519_SHA256=8c930e3407a94a222d180662fd94ebde906024fec7b4098d23a82e4ddad1d1dd +NETBIRD_STATUS_JSON_RC=0 +NETBIRD_JSON_PARSE_OK=true +NETBIRD_STATUS_DETAIL_RC=0 +NETBIRD_PEER_IP_COUNT=15 +NETBIRD_PUBLIC_SSH_KEY_MATCH_COUNT=0 +NETBIRD_PUBLIC_SSH_KEY_MATCHES_JSON=[] +CLUSTER_RESOURCES_RC=0 +CLUSTER_VM_COUNT=13 +CLUSTER_RELEVANT_VM_COUNT=4 +CLUSTER_RELEVANT_VMS_JSON=[{"vmid":"150","name":"snikket","node":"pve01","type":"qemu","status":"running"},{"vmid":"160","name":"forum-prod","node":"pve02","type":"qemu","status":"running"},{"vmid":"9130","name":"edge-cold-standby","node":"pve02","type":"qemu","status":"stopped"},{"vmid":"130","name":"edge-vm","node":"pve03","type":"qemu","status":"running"}] +CLUSTER_QGA_CORRELATION_JSON=[{"vmid":"150","name":"snikket","node":"pve01","qga_rc":0,"ipv4_count":2,"ip_hashes":["346840d5a3d9fe9b61ce99955bb98df3db872090732c96aa5df1d83cb1f3e85a","4e29a2729bbc40663066bdae0c5a3d627070fba621f5c8c70639f4782afbc67d"],"matches_public_key_netbird_peer":false},{"vmid":"160","name":"forum-prod","node":"pve02","qga_rc":0,"ipv4_count":1,"ip_hashes":["bf059cb10a70745fde7a01faab601e85d2548ea031d4bdf79d70664cfb51e688"],"matches_public_key_netbird_peer":false},{"vmid":"130","name":"edge-vm","node":"pve03","qga_rc":0,"ipv4_count":12,"ip_hashes":["bc41ed840e46092321935dd48da46da10a932deab0005de91d17a509b9d42e2d","d1d4b6abdd6b1971128522c259fade15c22be861a650e31fb34457339336a812","0b7870e2230336f502277fa38348a4bd934ff816a05523581c97d4ce59589fa6","5649415146501fa3dc7b2e08f469ef80b6b04e46b86079acd21229eb875e9440","346840d5a3d9fe9b61ce99955bb98df3db872090732c96aa5df1d83cb1f3e85a","fbd57f0145e15cc8436c042887ccaa6c122eb481613abb78201b3b2212fcc422","f9bcbcb71ab0bfd4ae96928d23473c1d6728cd09d9b4c65058dbdfaa30fd1e45","c138df8d3b53b19038a6a63dc7280bfac4a7e72ad4fbe7f359b49c55d1df3d4c","93449cac351e054dbbd4e026e0e9ba9060e51c04961d9fca4281acac18dda1f9","5db063f47c3859a031b1618455d7eefac6341c65feb96a90fd6a57a504ea4d84","bc517b4af3298846906234d3d697d3820b0b652ade1880c937c9d71cd802c834","885dfc9b72d2209e492b4631e0c538472ddf418cdf419aff8032c8d43704a63d"],"matches_public_key_netbird_peer":false}] +AUTHORITY_REFERENCE_COUNT=240 +AUTHORITY_REFERENCES_JSON=[{"file":"31_HOMELAB_REFERENCE.md","line":14,"text":"- VM130 edge-vm | pve03 | running | KEEP"},{"file":"31_HOMELAB_REFERENCE.md","line":15,"text":"- VM150 snikket | pve01 | running | KEEP"},{"file":"31_HOMELAB_REFERENCE.md","line":49,"text":"- NPMplus retired proxy routes removed; KEEP routes verified."},{"file":"31_HOMELAB_REFERENCE.md","line":75,"text":"NOTE edge-vm disk scsi1 backup=0 risk must be documented"},{"file":"31_HOMELAB_REFERENCE.md","line":106,"text":"06_edge_npmplus_routes_safe.txt 17350 bytes"},{"file":"31_HOMELAB_REFERENCE.md","line":149,"text":"- У VM130 edge-vm есть риск: дополнительный диск backup=0."},{"file":"31_HOMELAB_REFERENCE.md","line":166,"text":"- VM130 edge-vm pve03 [PRIVATE_IP] Docker ingress/app host."},{"file":"31_HOMELAB_REFERENCE.md","line":167,"text":"- VM150 Nextcloud pve01 [PRIVATE_IP] Nextcloud AIO."},{"file":"31_HOMELAB_REFERENCE.md","line":174,"text":"- Nextcloud VM150 имеет Proxmox backup и restore-proof evidence."},{"file":"31_HOMELAB_REFERENCE.md","line":185,"text":"- VM130 backup: closed, scsi1 backup=1, manual backup ZSTD_OK, exact offhost ZSTD_OK, old local backup removed."},{"file":"31_HOMELAB_REFERENCE.md","line":187,"text":"- Cloudflare token: [REDACTED] NPMplus token rotated, API verify OK, old exposed token externally confirmed revoked."},{"file":"31_HOMELAB_REFERENCE.md","line":312,"text":"- [PRIVATE_IP] -> bc:24:11:e1:f3:3c NPMplus / edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":316,"text":"- ISP tcp/80 -> bc:24:11:e1:f3:3c, NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":317,"text":"- ISP tcp/443 -> bc:24:11:e1:f3:3c, NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":323,"text":"- _WEBADMIN_Bridge0 permits Home-to-Proxmox access for DNS1/DNS2, AdGuard UI, NPMplus HTTP/HTTPS/UI, Nextcloud AIO/Talk TURN, Proxmox SSH/8006 and ICMP from admin PC."},{"file":"31_HOMELAB_REFERENCE.md","line":358,"text":"## EXTERNAL_SERVICES_UPS_NETBIRD_MAIL_SCRIPTS_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":366,"text":"- edge-vm: no UPS/NUT/APCUPSD integration discovered."},{"file":"31_HOMELAB_REFERENCE.md","line":370,"text":"### NetBird"},{"file":"31_HOMELAB_REFERENCE.md","line":371,"text":"- NetBird service is active on pve01, pve02, pve03 and edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":372,"text":"- NetBird version observed: daemon 0.73.2, CLI 0.73.2."},{"file":"31_HOMELAB_REFERENCE.md","line":373,"text":"- pve01: FQDN pve01.netbird.selfhosted, IPv4 [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":374,"text":"- pve02: FQDN pve02.netbird.selfhosted, IPv4 [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":375,"text":"- pve03: FQDN pve03.netbird.selfhosted, IPv4 [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":376,"text":"- edge-vm: FQDN edge-vm.netbird.selfhosted, IPv4 [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":381,"text":"- SSH Server through NetBird: Disabled."},{"file":"31_HOMELAB_REFERENCE.md","line":383,"text":"- Inventory proof: 108_EXTERNAL_SERVICES_NETBIRD_MAIL_SCRIPTS_INVENTORY.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":394,"text":"- Full script/unit inventory proof: 108_EXTERNAL_SERVICES_NETBIRD_MAIL_SCRIPTS_INVENTORY.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":395,"text":"- edge-vm owns most application health, dashboard, ingress, backup, NetBox, NPMplus, certificate, Trivy and vulnerability jobs."},{"file":"31_HOMELAB_REFERENCE.md","line":396,"text":"- pve01 owns many backup/offhost/restore/health/security/NetBird VPS/rclone/sops/scrutiny jobs."},{"file":"31_HOMELAB_REFERENCE.md","line":398,"text":"- pve03 owns smartctl textfile, cluster internal IP, NetBird and staging/rclone helpers."},{"file":"31_HOMELAB_REFERENCE.md","line":455,"text":"- edge-vm timers cover runtime dashboard, Paperless guard, external canary, health metrics, restore drill index, AdGuard rewrite sync, NPMplus cert expiry, NetBox backup/sync, retention, cluster daily status, vulnerability and Trivy scans, ingress hardening and NPMplus admin bind."},{"file":"31_HOMELAB_REFERENCE.md","line":456,"text":"- pve01 timers cover VPN/NetBird health, health metrics, smartctl, disk space, MkDocs refresh, VPS identity audit, storage capacity, quality gate, evidence catalog, backup freshness, docker health, Filebrowser backup/offhost/restore, NPMplus/Kuma backup, NetBird VPS backup/offhost, Authentik/Gitea/Vaultwarden backup, SOPS secret coverage, mail cloud upload/restore, Immich/Memos/Paperless backup/offhost/restore, auto backup, edge-vm vzdump, secret sanity."},{"file":"31_HOMELAB_REFERENCE.md","line":459,"text":"- Script hashes were captured for /usr/local/sbin and /usr/local/bin on edge-vm, pve01, pve02 and pve03."},{"file":"31_HOMELAB_REFERENCE.md","line":487,"text":"- pve03 local-lvm is the most constrained active VM storage because VM130 has 96G OS disk plus 150G media disk."},{"file":"31_HOMELAB_REFERENCE.md","line":504,"text":"- NetBird IP: [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":509,"text":"- Main active workloads: CT110 dns1, CT112 unbound1, VM150 nextcloud."},{"file":"31_HOMELAB_REFERENCE.md","line":515,"text":"- NetBird IP: [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":526,"text":"- NetBird IP: [PRIVATE_IP]/16."},{"file":"31_HOMELAB_REFERENCE.md","line":531,"text":"- Main active workload: VM130 edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":597,"text":"### VM130 edge-vm"},{"file":"31_HOMELAB_REFERENCE.md","line":600,"text":"- Name: edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":614,"text":"- Important note: VM130 has exact offhost backup proof after scsi1 backup=1."},{"file":"31_HOMELAB_REFERENCE.md","line":616,"text":"### VM150 nextcloud"},{"file":"31_HOMELAB_REFERENCE.md","line":672,"text":"- git.gram1.ru -> [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":683,"text":"- Public WAN router forwards TCP/80 and TCP/443 to NPMplus on edge-vm, [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":686,"text":"- NPMplus admin listener is bound to localhost on edge-vm, [PRIVATE_IP]:81; public disabled legacy host npm.gram1.ru exists but enabled=0."},{"file":"31_HOMELAB_REFERENCE.md","line":688,"text":"### NPMplus runtime"},{"file":"31_HOMELAB_REFERENCE.md","line":689,"text":"- Host: edge-vm, [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":690,"text":"- Container: npmplus, image zoeyvid/npmplus:2026-06-17-b1, healthy at inventory time."},{"file":"31_HOMELAB_REFERENCE.md","line":692,"text":"- Database: /opt/npmplus/npmplus/database.sqlite."},{"file":"31_HOMELAB_REFERENCE.md","line":694,"text":"- Public listen ports on edge-vm: [PRIVATE_IP]:80 and [PRIVATE_IP]:443 by nginx/NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":695,"text":"- NPMplus admin: [PRIVATE_IP]:81."},{"file":"31_HOMELAB_REFERENCE.md","line":696,"text":"- Secret rule: Cloudflare DNS API token exists only inside NPMplus certificate metadata and must never be printed."},{"file":"31_HOMELAB_REFERENCE.md","line":698,"text":"### Public NPMplus proxy hosts"},{"file":"31_HOMELAB_REFERENCE.md","line":705,"text":"- git.gram1.ru -> http://[PRIVATE_IP]:3002, cert=29, ssl_forced=1, enabled=1."},{"file":"31_HOMELAB_REFERENCE.md","line":713,"text":"### VPN NPMplus proxy hosts"},{"file":"31_HOMELAB_REFERENCE.md","line":737,"text":"- npmplus.vpn.gram1.ru -> https://[PRIVATE_IP]:81, cert=32."},{"file":"31_HOMELAB_REFERENCE.md","line":749,"text":"### NPMplus certificates"},{"file":"31_HOMELAB_REFERENCE.md","line":754,"text":"- cert=29: git.gram1.ru, expires 2026-09-13 17:36:55."},{"file":"31_HOMELAB_REFERENCE.md","line":762,"text":"- NPMplus schema/listen inventory: 126_DNS_INGRESS_CERT_NPMPLUS_SAFE_INVENTORY.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":763,"text":"- NPMplus exact proxy/cert rows: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":769,"text":"- Host: edge-vm, IP [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":773,"text":"- Additional compose roots: /opt/npmplus-compose, /opt/gotify-compose, /opt/uptime-kuma-compose, /opt/vaultwarden-compose, /opt/dockge-compose."},{"file":"31_HOMELAB_REFERENCE.md","line":774,"text":"- Public ingress terminates through NPMplus on ports 80/443."},{"file":"31_HOMELAB_REFERENCE.md","line":775,"text":"- Most app containers expose only [PRIVATE_IP] ports and are published through NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":776,"text":"- NPMplus uses host networking."},{"file":"31_HOMELAB_REFERENCE.md","line":813,"text":"- npmplus."},{"file":"31_HOMELAB_REFERENCE.md","line":826,"text":"- Ingress/security: npmplus, socket-proxy, crowdsec."},{"file":"31_HOMELAB_REFERENCE.md","line":831,"text":"- Admin/dashboard: homepage, dockge, netbox, dozzle, NPMplus VPN admin."},{"file":"31_HOMELAB_REFERENCE.md","line":863,"text":"- NPMplus admin: [PRIVATE_IP]:81."},{"file":"31_HOMELAB_REFERENCE.md","line":864,"text":"- NPMplus public ingress: [PRIVATE_IP]:80 and [PRIVATE_IP]:443."},{"file":"31_HOMELAB_REFERENCE.md","line":895,"text":"- VM130 edge-vm: included in homelab-nightly-all, local backup on pve03."},{"file":"31_HOMELAB_REFERENCE.md","line":896,"text":"- VM150 nextcloud: included in homelab-nightly-all, local backup on pve01."},{"file":"31_HOMELAB_REFERENCE.md","line":898,"text":"- VM130 also has dedicated edge-vm-vzdump backup/offhost/restore health proofs."},{"file":"31_HOMELAB_REFERENCE.md","line":900,"text":"- VM130 scsi1 backup flag is enabled after correction: scsi1 backup=1."},{"file":"31_HOMELAB_REFERENCE.md","line":902,"text":"### Edge VM / VM130 full-image protection"},{"file":"31_HOMELAB_REFERENCE.md","line":903,"text":"- edge-vm-vzdump-backup: STATUS=OK, archive size about 28.2G, SHA256 recorded."},{"file":"31_HOMELAB_REFERENCE.md","line":904,"text":"- edge-vm-vzdump-offhost: STATUS=OK, destination pve02 /mnt/staging/offhost/edge-vm-vzdump-from-pve03."},{"file":"31_HOMELAB_REFERENCE.md","line":905,"text":"- edge-vm-vzdump-restore: STATUS=OK, zstd and vma verification OK."},{"file":"31_HOMELAB_REFERENCE.md","line":906,"text":"- mail-cloud-edge-vm: STATUS=OK, recurring chunked upload, 53 parts, download verification enabled."},{"file":"31_HOMELAB_REFERENCE.md","line":907,"text":"- Retention for edge-vm cloud upload: RETENTION_KEEP=4."},{"file":"31_HOMELAB_REFERENCE.md","line":918,"text":"### NPMplus / Kuma / ingress config backups"},{"file":"31_HOMELAB_REFERENCE.md","line":919,"text":"- npmplus-kuma-config-backup: STATUS=OK."},{"file":"31_HOMELAB_REFERENCE.md","line":920,"text":"- Archive: /mnt/staging/npmplus-kuma-config-backups/snapshots/npmplus-kuma-config-*.tar.gz."},{"file":"31_HOMELAB_REFERENCE.md","line":921,"text":"- NPMplus DB integrity: OK."},{"file":"31_HOMELAB_REFERENCE.md","line":926,"text":"- npmplus-kuma-config-offhost: STATUS=OK to pve02."},{"file":"31_HOMELAB_REFERENCE.md","line":927,"text":"- npmplus-kuma-config-restore: STATUS=OK with DB integrity checks."},{"file":"31_HOMELAB_REFERENCE.md","line":928,"text":"- npmplus restore proof also exists from app backup quality checks."},{"file":"31_HOMELAB_REFERENCE.md","line":995,"text":"- NetBird VPS backup: STATUS=OK, snapshot under /mnt/staging/netbird-vps-backups/snapshots."},{"file":"31_HOMELAB_REFERENCE.md","line":996,"text":"- NetBird VPS offhost: STATUS=OK to pve02."},{"file":"31_HOMELAB_REFERENCE.md","line":997,"text":"- NetBird VPS restore validation: STATUS=OK, archive SHA256 recorded."},{"file":"31_HOMELAB_REFERENCE.md","line":1003,"text":"- Disk retention policy: STATUS=OK, root used pct observed 70 on edge-vm, removed dirs 0, Docker volume prune NO."},{"file":"31_HOMELAB_REFERENCE.md","line":1004,"text":"- App backup retention dry-run timer exists on edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1027,"text":"- Primary monitoring host: edge-vm, [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1039,"text":"- Node exporter on edge-vm: node-exporter, local port [PRIVATE_IP]:9100."},{"file":"31_HOMELAB_REFERENCE.md","line":1049,"text":"- pve01 also runs private VPN host health, NetBird peer health, disk space health, MkDocs refresh, evidence catalog and quality gate timers."},{"file":"31_HOMELAB_REFERENCE.md","line":1058,"text":"- https://git.gram1.ru"},{"file":"31_HOMELAB_REFERENCE.md","line":1084,"text":"- HomelabP0WeeklyEdgeVmVzdumpHealthStale: weekly edge-vm vzdump health older than 8d."},{"file":"31_HOMELAB_REFERENCE.md","line":1092,"text":"- HomelabNpmplusCertExpiryHealthNotOkOrStale: NPMplus cert expiry health failed or older than 48h."},{"file":"31_HOMELAB_REFERENCE.md","line":1103,"text":"- Alloy relabels container, compose_project, compose_service and host=edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1114,"text":"- external canary checks include nc.gram1.ru, git.gram1.ru, auth.gram1.ru, backup.gram1.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":1122,"text":"- npmplus-cert-expiry-health.txt is the standardized health alias for certificate expiry."},{"file":"31_HOMELAB_REFERENCE.md","line":1123,"text":"- npmplus-certificate-expiry.txt is the detailed cert expiry file."},{"file":"31_HOMELAB_REFERENCE.md","line":1125,"text":"- cluster-daily-status local extra check reports npmplus-cert-expiry status OK, problems=0, min_days=75."},{"file":"31_HOMELAB_REFERENCE.md","line":1137,"text":"- Main health dir on edge-vm: /var/lib/homelab-health."},{"file":"31_HOMELAB_REFERENCE.md","line":1150,"text":"- A previous compact check looked for npmplus-cert-expiry.txt; use npmplus-certificate-expiry.txt for detailed cert expiry and npmplus-cert-expiry-health.txt for standardized health."},{"file":"31_HOMELAB_REFERENCE.md","line":1209,"text":"- edge-vm is reached as debian@[PRIVATE_IP] with sudo."},{"file":"31_HOMELAB_REFERENCE.md","line":1218,"text":"- edge-vm root key observed: id_ed25519; debian authorized_keys observed."},{"file":"31_HOMELAB_REFERENCE.md","line":1226,"text":"- NPMplus DB: /opt/npmplus/npmplus/database.sqlite, root-only mode observed."},{"file":"31_HOMELAB_REFERENCE.md","line":1237,"text":"- edge-vm exposes public :80/:443 through NPMplus."},{"file":"31_HOMELAB_REFERENCE.md","line":1238,"text":"- edge-vm NPMplus admin :81 and socket-proxy :2375 are bound to [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1239,"text":"- edge-vm registry cache :5000 is bound to [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1240,"text":"- edge-vm Home Assistant :8123 is intentionally LAN-exposed."},{"file":"31_HOMELAB_REFERENCE.md","line":1283,"text":"- edge-vm runs Docker application stacks."},{"file":"31_HOMELAB_REFERENCE.md","line":1284,"text":"- Docker app data lives mainly under /opt/stacks, /opt/npmplus, /opt/gotify-compose, /opt/uptime-kuma-compose, /opt/vaultwarden-compose and /var/lib application paths."},{"file":"31_HOMELAB_REFERENCE.md","line":1356,"text":"- Public ingress HTTP/HTTPS: router forwards TCP 80/443 to edge-vm [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1357,"text":"- Reverse proxy: NPMplus on edge-vm, container npmplus, host networking, admin bound to [PRIVATE_IP]:81."},{"file":"31_HOMELAB_REFERENCE.md","line":1358,"text":"- Edge runtime host: VM130 edge-vm, [PRIVATE_IP], Docker Compose projects count 43."},{"file":"31_HOMELAB_REFERENCE.md","line":1359,"text":"- NPMplus proxy routes count: 47."},{"file":"31_HOMELAB_REFERENCE.md","line":1360,"text":"- NPMplus certificates and proxy route source proof: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1365,"text":"| nc.gram1.ru | http://[PRIVATE_IP]:11000 | VM150 Nextcloud AIO | VM150 vzdump, nextcloud restore proof, external canary |"},{"file":"31_HOMELAB_REFERENCE.md","line":1366,"text":"| uptime.gram1.ru | http://[PRIVATE_IP]:3001 | edge-vm / uptime-kuma | npmplus-kuma backup/restore, Kuma health |"},{"file":"31_HOMELAB_REFERENCE.md","line":1367,"text":"| gotify.gram1.ru | http://[PRIVATE_IP]:8082 | edge-vm / gotify | gotify health, alert-routing proof |"},{"file":"31_HOMELAB_REFERENCE.md","line":1368,"text":"| vault.gram1.ru | http://[PRIVATE_IP]:8083 | edge-vm / vaultwarden | vaultwarden backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1369,"text":"| dockge.gram1.ru | http://[PRIVATE_IP]:5001 | edge-vm / dockge | stack inventory |"},{"file":"31_HOMELAB_REFERENCE.md","line":1370,"text":"| home.gram1.ru | http://[PRIVATE_IP]:3000 | edge-vm / homepage | homepage container, dashboard route |"},{"file":"31_HOMELAB_REFERENCE.md","line":1371,"text":"| git.gram1.ru | http://[PRIVATE_IP]:3002 | edge-vm / gitea | gitea backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1372,"text":"| dozzle.gram1.ru | http://[PRIVATE_IP]:9999 | edge-vm / dozzle | docker stack inventory |"},{"file":"31_HOMELAB_REFERENCE.md","line":1373,"text":"| paper.gram1.ru | http://[PRIVATE_IP]:8010 | edge-vm / paperless | paperless backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1374,"text":"| memos.gram1.ru | http://[PRIVATE_IP]:5230 | edge-vm / memos | memos backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1375,"text":"| photos.gram1.ru | http://[PRIVATE_IP]:2283 | edge-vm / immich | immich media/full consistency proof |"},{"file":"31_HOMELAB_REFERENCE.md","line":1376,"text":"| auth.gram1.ru | http://[PRIVATE_IP]:9000 | edge-vm / authentik | authentik backup/offhost/restore |"},{"file":"31_HOMELAB_REFERENCE.md","line":1405,"text":"| npmplus.vpn.gram1.ru | https://[PRIVATE_IP]:81 | NPMplus admin, localhost-bound on edge |"},{"file":"31_HOMELAB_REFERENCE.md","line":1418,"text":"- npm.gram1.ru exists in NPMplus but was observed disabled."},{"file":"31_HOMELAB_REFERENCE.md","line":1421,"text":"- Router forwards TCP/UDP 51820 for WireGuard on the Home bridge, not to edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1424,"text":"- If a public app is down, check in this order: DNS rewrite/upstream, NPMplus route/cert, upstream container/VM, app health file, backup/restore proof."},{"file":"31_HOMELAB_REFERENCE.md","line":1425,"text":"- If a VPN route is down, check NetBird first, then NPMplus wildcard cert, then local upstream."},{"file":"31_HOMELAB_REFERENCE.md","line":1427,"text":"- If NPMplus is broken, use backup/restore evidence from npmplus-kuma-config and NPMplus DB backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1428,"text":"- If edge-vm is broken, VM130 full-image backup/offhost/restore proofs are authoritative."},{"file":"31_HOMELAB_REFERENCE.md","line":1433,"text":"- NPMplus route/cert rows: 129_NPMPLUS_PROXY_CERT_STREAM_ROWS_SAFE.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1467,"text":"- Check NPMplus route and certificate using NPMplus DB/proxy proof."},{"file":"31_HOMELAB_REFERENCE.md","line":1479,"text":"- Rewrites include public routes for git, dozzle, paper, memos, photos, auth and backup to edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1483,"text":"### Ingress / NPMplus failure"},{"file":"31_HOMELAB_REFERENCE.md","line":1484,"text":"- Edge VM is VM130 at [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":1485,"text":"- NPMplus listens publicly on 80/443 and admin is bound to [PRIVATE_IP]:81."},{"file":"31_HOMELAB_REFERENCE.md","line":1486,"text":"- NPMplus DB is /opt/npmplus/npmplus/database.sqlite."},{"file":"31_HOMELAB_REFERENCE.md","line":1489,"text":"- Use npmplus-kuma-config backup/offhost/restore proofs for recovery."},{"file":"31_HOMELAB_REFERENCE.md","line":1492,"text":"- VM130 is the Docker runtime host."},{"file":"31_HOMELAB_REFERENCE.md","line":1494,"text":"- Then use VM130 full-image vzdump/offhost/restore proofs."},{"file":"31_HOMELAB_REFERENCE.md","line":1495,"text":"- Current authoritative edge-vm backup/offhost/restore evidence is in backup catalog and VM130 proofs."},{"file":"31_HOMELAB_REFERENCE.md","line":1504,"text":"- For VM130 and VM160, use their dedicated closure proofs."},{"file":"31_HOMELAB_REFERENCE.md","line":1507,"text":"- Prometheus is on edge-vm at [PRIVATE_IP]:9090."},{"file":"31_HOMELAB_REFERENCE.md","line":1568,"text":"- DNS, ingress, NPMplus certificates and AdGuard/Unbound model."},{"file":"31_HOMELAB_REFERENCE.md","line":1615,"text":"## NEXTCLOUD_VM150_MAIL_CLOUD_BACKUP_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":1616,"text":"- VM150 Nextcloud Mail-cloud backup is installed on pve01."},{"file":"31_HOMELAB_REFERENCE.md","line":1620,"text":"- Proof: 192_NEXTCLOUD_VM150_MAIL_CLOUD_CHUNKED_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1636,"text":"- P2 small-stack backup and restore dry-run is installed on edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1644,"text":"- VM150 Nextcloud now has Mail-cloud chunked backup with download verification."},{"file":"31_HOMELAB_REFERENCE.md","line":1670,"text":"- VM150 Mail-cloud backup, router manual/recurring Mail-cloud backups, P2 small-stacks and 7 edge restore dry-runs are all confirmed OK."},{"file":"31_HOMELAB_REFERENCE.md","line":1679,"text":"- Covered checks include VM150 Mail-cloud, router startup/running config Mail-cloud, P2 small-stacks and seven restore dry-run health files."},{"file":"31_HOMELAB_REFERENCE.md","line":1691,"text":"- VM150 Nextcloud, router startup/running config, P0 critical and edge-vm backup directories are present on crypt remotes."},{"file":"31_HOMELAB_REFERENCE.md","line":1693,"text":"- Retention shape observed: P0 critical has 10 visible dirs with keep 14, edge-vm has 3 visible dirs with keep 4, new VM150/router jobs have initial dirs."},{"file":"31_HOMELAB_REFERENCE.md","line":1705,"text":"- pve01 units checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1706,"text":"- edge-vm units checked: P2 small-stacks backup/restore, backup dashboard and restore drill index."},{"file":"31_HOMELAB_REFERENCE.md","line":1707,"text":"- Proof records LoadState, ActiveState, UnitFileState and failed-unit counts for pve01 and edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":1712,"text":"- Covered checks: VM150 Mail-cloud, router startup/running config, P2 small-stacks and seven restore dry-runs."},{"file":"31_HOMELAB_REFERENCE.md","line":1735,"text":"- pve01 services checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1736,"text":"- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index."},{"file":"31_HOMELAB_REFERENCE.md","line":1741,"text":"- Corrected integrity proof was generated because one edge-vm executable required sudo for sha256sum."},{"file":"31_HOMELAB_REFERENCE.md","line":1742,"text":"- Corrected proof records hashes for pve01 and edge-vm unit fragments and executable scripts without printing script contents."},{"file":"31_HOMELAB_REFERENCE.md","line":1753,"text":"- pve01 timers checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1754,"text":"- edge-vm timers checked: P2 small-stacks backup/restore, backup dashboard and restore drill index."},{"file":"31_HOMELAB_REFERENCE.md","line":1829,"text":"- pve01 services checked: VM150 Mail-cloud upload and router running-config Mail-cloud backup."},{"file":"31_HOMELAB_REFERENCE.md","line":1830,"text":"- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index."},{"file":"31_HOMELAB_REFERENCE.md","line":1859,"text":"## VM150_MAIL_CLOUD_JOURNAL_NOISE_CLASSIFICATION_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":1860,"text":"- VM150 Mail-cloud upload journal warnings/errors were classified after journal triage found non-zero counters."},{"file":"31_HOMELAB_REFERENCE.md","line":1863,"text":"- Proof: 278_VM150_MAIL_CLOUD_JOURNAL_NOISE_CLASSIFICATION_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1866,"text":"- Audit manifest was regenerated after VM150 Mail-cloud journal-noise classification."},{"file":"31_HOMELAB_REFERENCE.md","line":1870,"text":"## SNAPSHOT_AFTER_VM150_JOURNAL_NOISE_CLASSIFICATION_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":1871,"text":"- Snapshot was created after VM150 Mail-cloud journal noise was classified as non-blocking historical noise."},{"file":"31_HOMELAB_REFERENCE.md","line":1874,"text":"- Proof: 282_SNAPSHOT_AFTER_VM150_JOURNAL_NOISE_CLASSIFICATION_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":1877,"text":"- Audit manifest was regenerated after snapshot following VM150 journal-noise classification."},{"file":"31_HOMELAB_REFERENCE.md","line":1882,"text":"- Post-backup-pass closure summary was generated after VM150 journal-noise classification."},{"file":"31_HOMELAB_REFERENCE.md","line":1899,"text":"- Verify P2 small-stacks, router running-config Mail-cloud and VM150 Nextcloud Mail-cloud first automatic runs."},{"file":"31_HOMELAB_REFERENCE.md","line":1921,"text":"- Goal: make the portal show and open all web services, including external service cards such as NetBird and mail."},{"file":"31_HOMELAB_REFERENCE.md","line":1931,"text":"- Home portal gap analysis was collected for gethomepage/homepage behind npmplus."},{"file":"31_HOMELAB_REFERENCE.md","line":1932,"text":"- Proof records Homepage config hashes, redacted current cards/bookmarks, current URLs, npmplus route lines, local web-port probes and known service container candidates."},{"file":"31_HOMELAB_REFERENCE.md","line":1941,"text":"- Proof records current card URLs/titles, redacted widget config, redacted Homepage log errors, NPMPlus internal route files/routes and candidate public/VPN cards."},{"file":"31_HOMELAB_REFERENCE.md","line":1950,"text":"- Homepage services.yaml was backed up, duplicate VPN cards were removed where a non-VPN card existed, and missing web cards for NetBird, Mail and Webmail were added without VPN suffix in the card names."},{"file":"31_HOMELAB_REFERENCE.md","line":1961,"text":"- Corrected Homepage apply removed duplicate VPN cards where a non-VPN card existed and added NetBird, Mail and Webmail cards with non-VPN names."},{"file":"31_HOMELAB_REFERENCE.md","line":1962,"text":"- The added card URLs use currently reachable vpn.gram1.ru web endpoints because public netbird/mail/webmail hosts did not resolve/open during analysis."},{"file":"31_HOMELAB_REFERENCE.md","line":2045,"text":"## HOME_PORTAL_NPMPLUS_DEFAULT_ROUTE_ANALYSIS_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":2046,"text":"- Home portal NetBird/Mail/Webmail cards were investigated after user saw the NPMPlus default page from client [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":2047,"text":"- Analysis checks URL body fingerprints, NPMPlus route config matches, service container candidates and Homepage card lines."},{"file":"31_HOMELAB_REFERENCE.md","line":2048,"text":"- Proof: 356_HOME_PORTAL_NPMPLUS_DEFAULT_ROUTE_ANALYSIS_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":2053,"text":"- NetBird card points to https://nb.pvepro.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2065,"text":"- NetBird: https://nb.pvepro.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2073,"text":"- Excluded cards: Homepage, NPMplus, Router and Public Domain."},{"file":"31_HOMELAB_REFERENCE.md","line":2101,"text":"- Homepage External card/link for relay.pvepro.ru was removed because relay.pvepro.ru had DNS but no reachable HTTP/HTTPS endpoint from edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":2113,"text":"## HOME_EXTERNAL_NETBIRD_ALEXHOST_NORMALIZE_20260630"},{"file":"31_HOMELAB_REFERENCE.md","line":2114,"text":"- Homepage External NetBird and AlexHost Billing href/siteMonitor URLs normalized with trailing slash."},{"file":"31_HOMELAB_REFERENCE.md","line":2116,"text":"- Proof: 397_HOME_EXTERNAL_NETBIRD_ALEXHOST_NORMALIZE_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":2120,"text":"- Remaining blocker for Homepage green dot is HTTP/HTTPS 403 from router web service to edge-vm/Bridge1, not network reachability."},{"file":"31_HOMELAB_REFERENCE.md","line":2126,"text":"- Health endpoint service on edge-vm: homelab-router-moscow-health-http.service."},{"file":"31_HOMELAB_REFERENCE.md","line":2139,"text":"- Health endpoint service: homelab-router-moscow-health-http.service on edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":2155,"text":"- Do not publish Cloudflare/NPMplus routes for these forums until CodeVipe recipe is proven and final rebuild is complete."},{"file":"31_HOMELAB_REFERENCE.md","line":2183,"text":"- Edge NPMplus manual routes terminate TLS with real Let’s Encrypt certificates and proxy to forum-prod VM160 at [PRIVATE_IP]:80."},{"file":"31_HOMELAB_REFERENCE.md","line":2188,"text":"- Edge NPMplus forum publication backup created after public cutover."},{"file":"31_HOMELAB_REFERENCE.md","line":2189,"text":"- Backup location: /opt/npmplus/manual-backups/forum-public-ok-*.tar.gz on edge-vm [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":2190,"text":"- Includes manual proxy_host configs 200-204 and Let’s Encrypt forum certificates under /opt/npmplus/tls/forum-certs."},{"file":"31_HOMELAB_REFERENCE.md","line":2193,"text":"- Edge certificate renewal configured on edge-vm [PRIVATE_IP]."},{"file":"31_HOMELAB_REFERENCE.md","line":2194,"text":"- Token stored at /opt/npmplus/secure/forum_cf_token.env mode 600 root-only."},{"file":"31_HOMELAB_REFERENCE.md","line":2195,"text":"- Renewal script: /opt/npmplus/scripts/renew-forum-certs.sh."},{"file":"31_HOMELAB_REFERENCE.md","line":2257,"text":"- Mailcow and NetBird are reachable again: mail.pvepro.ru/admin and nb.pvepro.ru return HTTP 200."},{"file":"31_HOMELAB_REFERENCE.md","line":2262,"text":"- Proofs: 589_POST_UNBAN_MAILCOW_NETBIRD_VERIFY.txt on VPS, 590_FORUM_SMTP_FAILED_CONFIG_DISABLED_PROOF.txt, 591_POST_INCIDENT_PUBLIC_STATUS_PROOF.txt, 592_POST_INCIDENT_FINAL_STABLE_STATE_PROOF.txt."},{"file":"31_HOMELAB_REFERENCE.md","line":2268,"text":"- Mailcow and NetBird remained reachable after the test."},{"file":"31_HOMELAB_REFERENCE.md","line":2274,"text":"- Mailcow and NetBird remained reachable after the test."},{"file":"31_HOMELAB_REFERENCE.md","line":2284,"text":"- Mailcow and NetBird remained reachable after enabling persistent forum SMTP."},{"file":"31_HOMELAB_REFERENCE.md","line":2291,"text":"- Mailcow and NetBird remain reachable after enabling persistent forum SMTP."},{"file":"31_HOMELAB_REFERENCE.md","line":2316,"text":"- Mailcow admin and NetBird UI are reachable after persistent forum SMTP enablement."},{"file":"31_HOMELAB_REFERENCE.md","line":2368,"text":"- NPMplus on edge terminates TLS and proxies all five forums to VM160."},{"file":"31_HOMELAB_REFERENCE.md","line":2408,"text":"- NPMplus on edge terminates TLS and proxies to http://[PRIVATE_IP]:80."},{"file":"31_HOMELAB_REFERENCE.md","line":2468,"text":"- Local placeholder service on edge-vm: homelab-parked-domains-http.service, enabled/active, serves marker PARKED_PAGE_OK on http://[PRIVATE_IP]:18088."},{"file":"31_HOMELAB_REFERENCE.md","line":2469,"text":"- NPMplus manual managed route files: /data/nginx/proxy_host/998.conf for newfi.ru, 997.conf for hapusya.ru and 996.conf for kingofwolk.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2471,"text":"- Certificates were issued by certbot DNS-01 using Cloudflare API hooks; HTTP-01 must not be retried for these parked domains without a new plan because earlier attempts hit NPMplus default redirect/include-order behavior."},{"file":"31_HOMELAB_REFERENCE.md","line":2472,"text":"- Cloudflare token value is not stored in the reference; token file path only: /opt/npmplus/secure/parked_cf_token, root-owned mode 600."},{"file":"31_HOMELAB_REFERENCE.md","line":2473,"text":"- Certificate names on edge-vm: parked-newfi.ru, parked-hapusya.ru and parked-kingofwolk.ru; observed expiry during setup: 2026-09-29."},{"file":"31_HOMELAB_REFERENCE.md","line":2474,"text":"- Certbot deploy hook installed: /etc/letsencrypt/renewal-hooks/deploy/parked-domains-npmplus-deploy.sh."},{"file":"31_HOMELAB_REFERENCE.md","line":2476,"text":"- Final route backup: /opt/npmplus/manual-backups/parked-stage16-route-only-20260701T155843Z."},{"file":"31_HOMELAB_REFERENCE.md","line":2481,"text":"- gram1.ru root and www.gram1.ru are routed to the existing parked placeholder page on edge-vm."},{"file":"31_HOMELAB_REFERENCE.md","line":2483,"text":"- NPMplus managed route file: /data/nginx/proxy_host/995.conf."},{"file":"31_HOMELAB_REFERENCE.md","line":2485,"text":"- Certificate name on edge-vm: parked-gram1.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2486,"text":"- Certificate issuance mode: certbot DNS-01 with dedicated gram1 Cloudflare token file /opt/npmplus/secure/gram1_cf_token."},{"file":"31_HOMELAB_REFERENCE.md","line":2488,"text":"- Certbot deploy hook: /etc/letsencrypt/renewal-hooks/deploy/gram1-root-npmplus-deploy.sh."},{"file":"31_HOMELAB_REFERENCE.md","line":2497,"text":"- NPMplus managed route file: /data/nginx/proxy_host/994.conf."},{"file":"31_HOMELAB_REFERENCE.md","line":2498,"text":"- Landing service on edge-vm: homelab-pvepro-landing-http.service on http://[PRIVATE_IP]:18089."},{"file":"31_HOMELAB_REFERENCE.md","line":2500,"text":"- Certificate name on edge-vm: landing-pvepro.ru."},{"file":"31_HOMELAB_REFERENCE.md","line":2501,"text":"- Certificate issuance mode: certbot DNS-01 with dedicated pvepro Cloudflare token file /opt/npmplus/secure/pvepro_cf_token."},{"file":"31_HOMELAB_REFERENCE.md","line":2503,"text":"- Certbot deploy hook: /etc/letsencrypt/renewal-hooks/deploy/pvepro-root-npmplus-deploy.sh."},{"file":"31_HOMELAB_REFERENCE.md","line":2515,"text":"- Recommended future path: establish VPN/NetBird/WireGuard or reverse-proxy/private management endpoint first; then issue DNS-01 certificate on a trusted node and deploy cert/key to the router only over that private path."}] +CORRELATE31_DECISION=PUBLIC_INGRESS_NO_NETBIRD_KEY_CORRELATION +CORRELATE31_END=true OUTPUT_END CHAT_OUTPUT_END