diff --git a/runtime/history/NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115.json b/runtime/history/NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115.json new file mode 100644 index 00000000..a876e8a5 --- /dev/null +++ b/runtime/history/NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115.json @@ -0,0 +1,38 @@ +{ + "schema_version": 1, + "channel": "homelab-runtime", + "command_id": "NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115", + "status": "OK", + "rc": 0, + "host": "pve01", + "mode": "change", + "component": "newfi-newfdom-articles206-pack2-water-safety-conformation", + "started_at_utc": "2026-09-18T22:24:43Z", + "finished_at_utc": "2026-09-18T22:25:06Z", + "reference_register_checked": true, + "reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66", + "error_register_checked": true, + "error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0", + "command_sha256": "f82579e91e7b6d0e6011dcdc787ef5f2fe5bbd45f7d1c6369cc4d8ffb870c33f", + "duplicate_failed_command_blocked": false, + "block_reason": null, + "execution_started": true, + "change_declared": true, + "result_contract_valid": true, + "result_contract_status": "OK", + "result_contract_error": null, + "command_rc": 0, + "changes_made": true, + "rollback_started": false, + "rollback_restored": null, + "mutation_outcome": "MUTATED", + "sanitized": true, + "secrets_included": false, + "private_addresses_included": false, + "raw_evidence_retained_locally": true, + "raw_evidence_sha256": "a3b2564df3df6d6ff6a75ac89eeaf0331dcad3d8ee727ab4c79c4ceed4d0a95a", + "sanitized_output_sha256": "a3b2564df3df6d6ff6a75ac89eeaf0331dcad3d8ee727ab4c79c4ceed4d0a95a", + "output_truncated_in_json": false, + "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", + "output": "NEWFI115_BEGIN\nCOMMAND_ID=NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115\nNEWFI115_PREMUTATION_CONTRACT={\"services\": [{\"category\": \"\\u0412\\u043e\\u0434\\u0430 \\u0438 \\u0431\\u0435\\u0437\\u043e\\u043f\\u0430\\u0441\\u043d\\u043e\\u0441\\u0442\\u044c\", \"class\": \"XFRM\\\\Service\\\\ResourceItem\\\\Create\", \"getResource\": true, \"getTagChanger\": false, \"save\": true, \"setContent\": true, \"versionProperty\": true}, {\"category\": \"\\u0412\\u044b\\u0441\\u0442\\u0430\\u0432\\u043a\\u0438 \\u0438 \\u0445\\u0435\\u043d\\u0434\\u043b\\u0438\\u043d\\u0433\", \"class\": \"XFRM\\\\Service\\\\ResourceItem\\\\Create\", \"getResource\": true, \"getTagChanger\": false, \"save\": true, \"setContent\": true, \"versionProperty\": true}]}\nNEWFI115_BACKUPS_2OF2=PASS\nNEWFI115_STAGING_REVIEW=PASS\nNEWFI115_STAGING_PUBLISH=PASS\nNEWFI115_STAGING_ROLLBACK=PASS\nNEWFI115_STAGING_REAPPLY=PASS\nNEWFI115_PRODUCTION=PASS\nNEWFI115_PUBLIC={\"conformation-start\": {\"body_bytes\": 64561, \"http\": 200, \"id\": 15, \"sha256\": \"bc6cdbbc0acf55a75937425329868563128be84c008f485282d474b591e527b1\", \"url\": \"https://newfi.ru/resources/15/\"}, \"water-safety\": {\"body_bytes\": 64062, \"http\": 200, \"id\": 14, \"sha256\": \"c95225f5b9f6f3016bcab189bbbf28cf8f23cc907e770a139bf34bb443a5b45d\", \"url\": \"https://newfi.ru/resources/14/\"}}\nNEWFI115_GIT_PROMOTION={\"old_head\": \"170be2c0729d69188b690dc2942f34e226b96212\", \"new_head\": \"f85c9474e2ce3689865fb342776c1faf6927f047\", \"remote_head\": \"f85c9474e2ce3689865fb342776c1faf6927f047\"}\nNEWFI115_DECISION=PASS_ARTICLES206_PACK2_GIT_LAST_PATCHED_INDEXNOW\nNEWFI115_NEXT_GATE=ARTICLES206_PACK3\nHOMELAB_RESULT_CONTRACT={\"version\": 1, \"command_id\": \"NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115\", \"status\": \"OK\", \"changes_made\": true, \"rollback_started\": false, \"rollback_restored\": null}\n" +} diff --git a/runtime/history/NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115.txt b/runtime/history/NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115.txt new file mode 100644 index 00000000..f5b0fbba --- /dev/null +++ b/runtime/history/NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115.txt @@ -0,0 +1,46 @@ +CHAT_OUTPUT_BEGIN +COMMAND_ID=NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115 +STATUS=OK +RC=0 +HOST=pve01 +MODE=change +COMPONENT=newfi-newfdom-articles206-pack2-water-safety-conformation +REFERENCE_REGISTER_CHECK=OK +REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66 +ERROR_REGISTER_CHECK=OK +ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0 +COMMAND_SHA256=f82579e91e7b6d0e6011dcdc787ef5f2fe5bbd45f7d1c6369cc4d8ffb870c33f +DUPLICATE_FAILED_COMMAND_BLOCKED=false +EXECUTION_STARTED=true +CHANGE_DECLARED=true +RESULT_CONTRACT_VALID=true +RESULT_CONTRACT_STATUS=OK +RESULT_CONTRACT_ERROR=NONE +COMMAND_RC=0 +CHANGES_MADE=true +ROLLBACK_STARTED=false +ROLLBACK_RESTORED=null +MUTATION_OUTCOME=MUTATED +SANITIZED=yes +SECRETS_INCLUDED=no +PRIVATE_ADDRESSES_INCLUDED=no +RAW_EVIDENCE_SHA256=a3b2564df3df6d6ff6a75ac89eeaf0331dcad3d8ee727ab4c79c4ceed4d0a95a +SANITIZED_OUTPUT_SHA256=a3b2564df3df6d6ff6a75ac89eeaf0331dcad3d8ee727ab4c79c4ceed4d0a95a +OUTPUT_BEGIN +NEWFI115_BEGIN +COMMAND_ID=NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115 +NEWFI115_PREMUTATION_CONTRACT={"services": [{"category": "\u0412\u043e\u0434\u0430 \u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c", "class": "XFRM\\Service\\ResourceItem\\Create", "getResource": true, "getTagChanger": false, "save": true, "setContent": true, "versionProperty": true}, {"category": "\u0412\u044b\u0441\u0442\u0430\u0432\u043a\u0438 \u0438 \u0445\u0435\u043d\u0434\u043b\u0438\u043d\u0433", "class": "XFRM\\Service\\ResourceItem\\Create", "getResource": true, "getTagChanger": false, "save": true, "setContent": true, "versionProperty": true}]} +NEWFI115_BACKUPS_2OF2=PASS +NEWFI115_STAGING_REVIEW=PASS +NEWFI115_STAGING_PUBLISH=PASS +NEWFI115_STAGING_ROLLBACK=PASS +NEWFI115_STAGING_REAPPLY=PASS +NEWFI115_PRODUCTION=PASS +NEWFI115_PUBLIC={"conformation-start": {"body_bytes": 64561, "http": 200, "id": 15, "sha256": "bc6cdbbc0acf55a75937425329868563128be84c008f485282d474b591e527b1", "url": "https://newfi.ru/resources/15/"}, "water-safety": {"body_bytes": 64062, "http": 200, "id": 14, "sha256": "c95225f5b9f6f3016bcab189bbbf28cf8f23cc907e770a139bf34bb443a5b45d", "url": "https://newfi.ru/resources/14/"}} +NEWFI115_GIT_PROMOTION={"old_head": "170be2c0729d69188b690dc2942f34e226b96212", "new_head": "f85c9474e2ce3689865fb342776c1faf6927f047", "remote_head": "f85c9474e2ce3689865fb342776c1faf6927f047"} +NEWFI115_DECISION=PASS_ARTICLES206_PACK2_GIT_LAST_PATCHED_INDEXNOW +NEWFI115_NEXT_GATE=ARTICLES206_PACK3 +HOMELAB_RESULT_CONTRACT={"version": 1, "command_id": "NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115", "status": "OK", "changes_made": true, "rollback_started": false, "rollback_restored": null} + +OUTPUT_END +CHAT_OUTPUT_END diff --git a/runtime/latest.json b/runtime/latest.json index 3cd8c356..a876e8a5 100644 --- a/runtime/latest.json +++ b/runtime/latest.json @@ -1,38 +1,38 @@ { "schema_version": 1, "channel": "homelab-runtime", - "command_id": "SUPPORT-260919-HOME-GRAM1-DISCOVERY-READONLY-567R1", + "command_id": "NEWFI-260919-NEWFDOM-ARTICLES206-PACK2-115", "status": "OK", "rc": 0, "host": "pve01", - "mode": "read-only", - "component": "home-gram1-discovery-readonly", - "started_at_utc": "2026-09-18T22:22:12Z", - "finished_at_utc": "2026-09-18T22:22:13Z", + "mode": "change", + "component": "newfi-newfdom-articles206-pack2-water-safety-conformation", + "started_at_utc": "2026-09-18T22:24:43Z", + "finished_at_utc": "2026-09-18T22:25:06Z", "reference_register_checked": true, "reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66", "error_register_checked": true, "error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0", - "command_sha256": "50e02bced33c549e5473026463c35e1de9e413b719a87fbbce99e44832b530ac", + "command_sha256": "f82579e91e7b6d0e6011dcdc787ef5f2fe5bbd45f7d1c6369cc4d8ffb870c33f", "duplicate_failed_command_blocked": false, "block_reason": null, "execution_started": true, - "change_declared": false, + "change_declared": true, "result_contract_valid": true, - "result_contract_status": null, + "result_contract_status": "OK", "result_contract_error": null, "command_rc": 0, - "changes_made": false, + "changes_made": true, "rollback_started": false, "rollback_restored": null, - "mutation_outcome": "NO_MUTATION", + "mutation_outcome": "MUTATED", "sanitized": true, "secrets_included": false, "private_addresses_included": false, "raw_evidence_retained_locally": true, - "raw_evidence_sha256": "50f1d3e3dcea8e65319a11fe2d0fece11ac11c4b4d31c4f246f93494e14ef553", - "sanitized_output_sha256": "a6dac104ea7d4cdbb25fcaf364a52d293dfded215899597298e94e11cbab79a8", + "raw_evidence_sha256": "a3b2564df3df6d6ff6a75ac89eeaf0331dcad3d8ee727ab4c79c4ceed4d0a95a", + "sanitized_output_sha256": "a3b2564df3df6d6ff6a75ac89eeaf0331dcad3d8ee727ab4c79c4ceed4d0a95a", "output_truncated_in_json": false, "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", - "output": "ERROR_REGISTER_CHECK=OK\nREFERENCE_CHECK=OK\nAUTHORITY_CHECK_SCOPE=READABILITY_ONLY_INCIDENTS_NOT_CLOSED\nREFERENCE_HOME_MATCH_COUNT=123\nREFERENCE_HOME_MATCH=50:- Homepage/Prometheus retired references absent; Uptime Kuma orphan extra_hosts removed.\nREFERENCE_HOME_MATCH=82:HEALTH_NOT_OK item=backup-restore-dashboard.txt line=STATUS=WARN TS=2026-06-29T18:10:09Z ITEMS=80 NOT_OK=13\nREFERENCE_HOME_MATCH=89:HEALTH_NOT_OK item=homepage-service-catalog-slo.txt line=STATUS=WARN\nREFERENCE_HOME_MATCH=153:- Проверить backup-restore-dashboard: STATUS=WARN, NOT_OK=13.\nREFERENCE_HOME_MATCH=192:## FINAL_DASHBOARD_RUNTIME_OK_20260630\nREFERENCE_HOME_MATCH=194:- Runtime dashboard: STATUS=OK, ITEMS=69, NOT_OK=0.\nREFERENCE_HOME_MATCH=196:- SLO/coverage WARN files: moved out of runtime dashboard into slo-coverage-backlog-index.txt.\nREFERENCE_HOME_MATCH=198:- Final proof: 103_FINAL_ALL_GREEN_DASHBOARD_PROOF.txt.\nREFERENCE_HOME_MATCH=395:- edge-vm owns most application health, dashboard, ingress, backup, NetBox, NPMplus, certificate, Trivy and vulnerability jobs.\nREFERENCE_HOME_MATCH=455:- edge-vm timers cover runtime dashboard, Paperless guard, external canary, health metrics, restore drill index, AdGuard rewrite sync, NPMplus cert expiry, NetBox backup/sync, retention, cluster daily status, vulnerability and Trivy scans, ingress hardening and NPMplus admin bind.\nREFERENCE_HOME_MATCH=704:- home.gram1.ru -> http://127.0.0.1:3000, cert=27, ssl_forced=1, enabled=1.\nREFERENCE_HOME_MATCH=715:- homepage.vpn.gram1.ru -> http://127.0.0.1:3000, cert=32.\nREFERENCE_HOME_MATCH=753:- cert=27: home.gram1.ru, expires 2026-09-13 16:43:44.\nREFERENCE_HOME_MATCH=799:- homepage.\nREFERENCE_HOME_MATCH=831:- Admin/dashboard: homepage, dockge, netbox, dozzle, NPMplus VPN admin.\nREFERENCE_HOME_MATCH=834:- Homepage: 127.0.0.1:3000.\nREFERENCE_HOME_MATCH=885:- Backup health dashboard: STATUS=OK, ITEMS=69, NOT_OK=0 at 2026-06-30T10:10:06Z.\nREFERENCE_HOME_MATCH=887:- SLO coverage is tracked separately from runtime dashboard. It had WARN backlog in backup-restore-coverage-slo with APP_TOTAL=43, GREEN=3, YELLOW=21, RED=19, MISSING_BACKUP_SIGNAL=31, MISSING_RESTORE_SIGNAL=28, MISSING_TIMER=31.\nREFERENCE_HOME_MATCH=1107:### Runtime dashboard semantics\nREFERENCE_HOME_MATCH=1108:- backup-restore-dashboard.txt is an authoritative runtime dashboard file.\nREFERENCE_HOME_MATCH=1109:- Current observed runtime dashboard: STATUS=OK, ITEMS=69, NOT_OK=0.\nREFERENCE_HOME_MATCH=1110:- backup-restore-dashboard.json confirmed not_ok=[].\nREFERENCE_HOME_MATCH=1118:- Uptime Kuma local endpoint returns HTTP 302 to /dashboard, which is expected for UI auth/redirect.\nREFERENCE_HOME_MATCH=1130:- Runtime dashboard OK does not mean SLO backlog is closed.\nREFERENCE_HOME_MATCH=1133:- Other observed WARN backlog files include container-image-lifecycle-slo, cron-job-monitoring-slo, direct-heartbeat-pilot-readiness, healthchecks-heartbeat-coverage, healthchecks-job-coverage, healthchecks-job-monitoring-slo, homepage-service-catalog-slo, ingress-dns-route-slo, observability-health-surface-slo and security-vulnerability-slo.\nREFERENCE_HOME_MATCH=1370:| home.gram1.ru | http://127.0.0.1:3000 | edge-vm / homepage | homepage container, dashboard route |\nREFERENCE_HOME_MATCH=1377:| backup.gram1.ru | http://[PRIVATE_IP]:9101 | pve01 / homelab-health-http | backup dashboard and health proofs |\nREFERENCE_HOME_MATCH=1383:| homepage.vpn.gram1.ru | http://127.0.0.1:3000 | homepage |\nREFERENCE_HOME_MATCH=1517:### Backup dashboard / SLO interpretation\nREFERENCE_HOME_MATCH=1518:- Runtime dashboard OK means current operational checks are green.\nREFERENCE_HOME_MATCH=1571:- Monitoring, alerting, health dashboard and Prometheus correction.\nREFERENCE_HOME_MATCH=1643:- Backup/cloud/restore improvement pass is closed with runtime dashboard STATUS=OK and NOT_OK=0.\nREFERENCE_HOME_MATCH=1668:- Runtime backup dashboard remains STATUS=OK with NOT_OK=0.\nREFERENCE_HOME_MATCH=1706:- edge-vm units checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\nREFERENCE_HOME_MATCH=1736:- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\nREFERENCE_HOME_MATCH=1754:- edge-vm timers checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\nREFERENCE_HOME_MATCH=1830:- edge-vm services checked: P2 small-stacks backup/restore, backup dashboard and restore drill index.\nREFERENCE_HOME_MATCH=1900:- Also verify service results, health status/age, Mail-cloud directories, dashboard, restore index, Prometheus firing alerts and Alertmanager readiness.\nREFERENCE_HOME_MATCH=1920:- Home portal discovery started for https://home.gram1.ru/.\nREFERENCE_HOME_MATCH=1922:- Discovery proof records DNS, HTTPS/TLS headers, reverse-proxy candidates, compose files, domain references and homepage config candidates without printing secrets.\nREFERENCE_HOME_MATCH=1926:- Home portal config and service inventory was collected for https://home.gram1.ru/.\nREFERENCE_HOME_MATCH=1931:- Home portal gap analysis was collected for gethomepage/homepage behind npmplus.\nREFERENCE_HOME_MATCH=1932:- Proof records Homepage config hashes, redacted current cards/bookmarks, current URLs, npmplus route lines, local web-port probes and known service container candidates.\nREFERENCE_HOME_MATCH=1940:- Home portal card/API-error analysis was collected before editing Homepage.\nREFERENCE_HOME_MATCH=1941:- Proof records current card URLs/titles, redacted widget config, redacted Homepage log errors, NPMPlus internal route files/routes and candidate public/VPN cards.\nREFERENCE_HOME_MATCH=1950:- Homepage services.yaml was backed up, duplicate VPN cards were removed where a non-VPN card existed, and missing web cards for NetBird, Mail and Webmail were added without VPN suffix in the card names.\nREFERENCE_HOME_MATCH=1952:- Homepage container was restarted and portal/card URLs were checked.\nREFERENCE_HOME_MATCH=1961:- Corrected Homepage apply removed duplicate VPN cards where a non-VPN card existed and added NetBird, Mail and Webmail cards with non-VPN names.\nREFERENCE_HOME_MATCH=1984:- Proof checks portal HTTP status, Homepage container state, required cards, duplicate VPN card pairs, current card URLs, redacted API-error logs and widget configuration.\nREFERENCE_HOME_MATCH=1993:- Homepage API error root-cause analysis was collected after the UI showed API errors.\nREFERENCE_HOME_MATCH=1994:- Current evidence points to the Open-Meteo/weather widget timing out from Homepage, separate from service cards.\nREFERENCE_HOME_MATCH=1995:- HTTP 200 for the portal is not sufficient for UI closure when Homepage logs still contain API errors.\nREFERENCE_HOME_MATCH=2004:- Open-Meteo/weather widget was disabled after root-cause analysis showed Homepage API errors from api.open-meteo.com timeouts.\nREFERENCE_HOME_MATCH=2006:- Portal closure now requires current Homepage API-error logs to be zero after restart/reload.\nREFERENCE_HOME_MATCH=2016:- Audit extracts current Homepage href URLs and checks whether each opens with an acceptable HTTP status.\nREFERENCE_HOME_MATCH=2026:- Explicit VPN duplicate cards were removed from Homepage with a short transparent perl edit: Homepage VPN, Authentik VPN, Gitea VPN and Uptime Kuma VPN.\nREFERENCE_HOME_MATCH=2031:- Remaining Homepage duplicate/VPN/router occurrences were inspected after corrected cleanup still reported REVIEW.\nREFERENCE_HOME_MATCH=2036:- Homepage duplicate cleanup was rechecked against active config files only, excluding logs and backup files.\nREFERENCE_HOME_MATCH=2041:- Active Homepage services/bookmarks files were cleaned from semantic VPN duplicate cards and old router URL references.\nREFERENCE_HOME_MATCH=2042:- Removed targets: Homepage VPN, Authentik VPN, Gitea VPN and Uptime Kuma VPN, plus matching vpn.gram1.ru duplicate URLs.\nREFERENCE_HOME_MATCH=2047:- Analysis checks URL body fingerprints, NPMPlus route config matches, service container candidates and Homepage card lines.\nREFERENCE_HOME_MATCH=2051:- Active Homepage URL: https://home.gram1.ru.\nREFERENCE_HOME_MATCH=2052:- Homepage container is running and portal HTTP check returned 200 after latest changes.\nREFERENCE_HOME_MATCH=2057:- Homepage services.yaml was updated via YAML-aware edit for siteMonitor fields.\nREFERENCE_HOME_MATCH=2059:- Latest validation before this reference update: YAML_ERRORS_LAST_5M=0, HOME_HTTP_CODE=200, HOMEPAGE_RUNNING=true.\nREFERENCE_HOME_MATCH=2064:- Direct Homepage link correction requested by operator.\nREFERENCE_HOME_MATCH=2073:- Excluded cards: Homepage, NPMplus, Router and Public Domain.\nREFERENCE_HOME_MATCH=2075:- Homepage restarted successfully and reported YAML_ERRORS=0.\nREFERENCE_HOME_MATCH=2080:- First next action: finish Homepage final validation.\nREFERENCE_HOME_MATCH=2082:## HOMEPAGE_BACKUP_GAP_CLASSIFICATION_20260630\nREFERENCE_HOME_MATCH=2083:- Homepage backup coverage gap classification file created at /etc/pve/HOMEPAGE_BACKUP_GAP_CLASSIFICATION.md.\nREFERENCE_HOME_MATCH=2084:- It defines closure requirements for the 13 remaining Homepage backup coverage gap/special-review rows.\nREFERENCE_HOME_MATCH=2087:## HOMEPAGE_EXISTING_BACKUP_EVIDENCE_CLOSURE_20260630\nREFERENCE_HOME_MATCH=2088:- Homepage backup coverage matrix started closing existing-evidence rows.\nREFERENCE_HOME_MATCH=2091:- Proof: 364_HOMEPAGE_EXISTING_BACKUP_EVIDENCE_CLOSURE_PROOF.txt.\nREFERENCE_HOME_MATCH=2094:- Homepage External group includes Cloudflare card: https://dash.cloudflare.com.\nREFERENCE_HOME_MATCH=2095:- Homepage External group includes AlexHost Billing card: https://bill.alexhost.com/.\nREFERENCE_HOME_MATCH=2097:- YAML validation passed, Homepage returned HTTP 200, container running, and no Homepage YAML errors were seen after restart.\nREFERENCE_HOME_MATCH=2101:- Homepage External card/link for relay.pvepro.ru was removed because relay.pvepro.ru had DNS but no reachable HTTP/HTTPS endpoint from edge-vm.\nREFERENCE_HOME_MATCH=2106:- Homepage Moscow Router red-dot fix requires router ACL/Web UI/admin-level change, not routerbackup.\nREFERENCE_HOME_MATCH=2114:- Homepage External NetBird and AlexHost Billing href/siteMonitor URLs normalized with trailing slash.\nREFERENCE_HOME_MATCH=2115:- Homepage container node checks returned HTTP 200 for both URLs.\nREFERENCE_HOME_MATCH=2120:- Remaining blocker for Homepage green dot is HTTP/HTTPS 403 from router web service to edge-vm/Bridge1, not network reachability.\nREFERENCE_HOME_MATCH=2124:- Moscow Router Homepage card href: http://[PRIVATE_IP]:5080.\nREFERENCE_HOME_MATCH=2125:- Moscow Router Homepage siteMonitor: http://[PRIVATE_IP]:18083/router-moscow.\nREFERENCE_HOME_MATCH=2131:- Moscow Router Homepage card target after fixed apply: href http://[PRIVATE_IP]:5080, siteMonitor http://[PRIVATE_IP]:18083/router-moscow.\nREFERENCE_HOME_MATCH=2132:- Fixed updater handles Homepage service-name-key YAML shape and property-style YAML shape.\nREFERENCE_HOME_MATCH=2136:- Moscow Router Homepage card exact active YAML shape was service-key style.\nREFERENCE_HOME_MATCH=2567:## HOMEPAGE_EXTERNAL_SMARTAPE_AND_SITES_OK_20260702\nREFERENCE_HOME_MATCH=2568:- Homepage services.yaml repaired with YAML-aware edit after bad indentation issue.\nREFERENCE_HOME_MATCH=2572:- Proof: /root/evidence/671_HOMEPAGE_EXTERNAL_SMARTAPE_AND_SITES_OK_20260702_PROOF.txt\nREFERENCE_HOME_MATCH=2589:- Removed obsolete NPMplus route aliases without Homepage cards: auth.vpn.gram1.ru, gitea.vpn.gram1.ru, homepage.vpn.gram1.ru, kuma.vpn.gram1.ru.\nREFERENCE_HOME_MATCH=2593:## HOMELAB_HOMEPAGE_AND_TAFTAUTO_FINAL_OK_20260702\nREFERENCE_HOME_MATCH=2594:- Homepage final layout/category state confirmed: YAML validates, categories use row/columns layout, logs show no YAMLException.\nREFERENCE_HOME_MATCH=2599:- Proof: /root/evidence/677_HOMELAB_HOMEPAGE_AND_TAFTAUTO_FINAL_OK_20260702_PROOF.txt\nREFERENCE_HOME_MATCH=2614:- 677 is current final Homepage/TaftAuto authority; 678 is current Cloudflare token audit authority.\nREFERENCE_HOME_MATCH=2617:## HOMEPAGE_LOCAL_HEALTH_MONITORS_OK_20260702\nREFERENCE_HOME_MATCH=2618:- Local edge health endpoint is used for Homepage monitoring of Роутер Москва and NPMplus.\nREFERENCE_HOME_MATCH=2621:- Homepage YAML validates and logs show no YAMLException.\nREFERENCE_HOME_MATCH=2622:- Proof: /root/evidence/681_HOMEPAGE_LOCAL_HEALTH_MONITORS_OK_20260702_PROOF.txt\nREFERENCE_HOME_MATCH=2624:## HOMEPAGE_SELF_CARD_REMOVED_FROM_CORE_20260702\nREFERENCE_HOME_MATCH=2625:- Removed Homepage self-referential card from Core.\nREFERENCE_HOME_MATCH=2626:- Homepage YAML validates and logs show no YAMLException.\nREFERENCE_HOME_MATCH=2627:- Proof: /root/evidence/682_HOMEPAGE_SELF_CARD_REMOVED_FROM_CORE_20260702_PROOF.txt\nREFERENCE_HOME_MATCH=2664:- TaftAuto, Homepage, Cloudflare tokens, evidence map, cert hooks, deploy guards, public HTTPS, route/cert mapping, and secret scan are documented.\nREFERENCE_HOME_MATCH=2679:## HOMEPAGE_RU_LAYOUT_MONITORING_PROPOSALS_20260702\nREFERENCE_HOME_MATCH=2680:- Homepage live config is on core-apps VM [PRIVATE_IP] under /opt/stacks/homepage/config.\nREFERENCE_HOME_MATCH=2685:- Red badges after migration were primarily caused by Homepage container resolving *.vpn.gram1.ru to edge NetBird IP and timing out; fixed by mapping vpn hostnames to edge LAN [PRIVATE_IP] in Homepage compose extra_hosts.\nREFERENCE_HOME_MATCH=2688:- Missing-card proposal report: /var/lib/homelab-health/homepage-missing-card-proposals-final.txt.\nREFERENCE_HOME_MATCH=2697:- Recommended next monitors are P0 only after operator approval: Router Moscow Health, Backup/Restore Dashboard, Restore Drill Index, NetBird Peers, CrowdSec CAPI, Paperless Restore.\nREFERENCE_HOME_MATCH=2707:- Approved Uptime Kuma monitor batch installed after Homepage/Kuma analysis.\nREFERENCE_HOME_MATCH=2715: - Backup Restore Dashboard -> http://[PRIVATE_IP]:9101/backup-restore-dashboard.txt\nREFERENCE_HOME_MATCH=2725: - backup-restore-dashboard.txt\nREFERENCE_HOME_MATCH=2766:- Per-service done criteria: URL, TLS, admin, SSO decision, volumes, backup, restore test, Kuma, Homepage, docs.\nREFERENCE_HOME_MATCH=2984:Homepage canonical=https://kingofwolk.ru/\nREFERENCE_HOME_MATCH=2986:Legacy homepage forum links with index.php? absent.\nREFERENCE_HOME_MATCH=2989:robots.txt intentionally absent; XenForo returns HTTP 404 and page indexing is not blocked. Homepage has no noindex meta/X-Robots-Tag.\nREFERENCE_HOME_MATCH=3045:Style2 extra.less hides only the homepage forum_list H1 via body[data-template=\"forum_list\"] .p-title-value { display:none; }.\nREFERENCE_HOME_MATCH=3058:Header wordmark centered through style2 extra.less. Duplicate homepage H1 hidden only for body[data-template=\"forum_list\"]; forum_view H1 remains visible.\nREFERENCE_HOME_MATCH=3059:Public no-cookie homepage and forum HTTP 200 with style s=2; sitemap HTTP 200 with 11 loc entries; private 192.168.50.x leak absent.\nREFERENCE_HOME_MATCH=3082:Public homepage HTTP 200 verifies both xenforo.info attribution and the KingOfWolk line, with KingOfWolk appearing after the localization entry.\nREFERENCE_HOME_MATCH=3093:Public PNG returns HTTP 200 with image/png and exact expected SHA256. Public homepage remains HTTP 200 with no 192.168.50.x leak.\nREFERENCE_HOME_MATCH=3168:## KINGOFWOLK_ADMIN_DASHBOARD_WARNINGS_CLEARED_20260903\nERRORREG_HOME_MATCH_COUNT=40\nERRORREG_HOME_MATCH=109:Команда 138 пересобрала dashboard, но диагностический Python-блок упал с NameError из-за кавычек.\nERRORREG_HOME_MATCH=110:Не использовать heredoc Python внутри вложенного ssh; для dashboard verification использовать cat/grep JSON или простые команды.\nERRORREG_HOME_MATCH=194:- Rule: home portal closure requires current Homepage API-error logs to be zero after restart/reload, not only HTTP 200.\nERRORREG_HOME_MATCH=195:- If Homepage UI shows API error or logs contain current httpProxy/API timeout errors, the portal is REVIEW until the widget/API cause is disabled or fixed.\nERRORREG_HOME_MATCH=204:- Rule: Homepage cleanup validation must check active config files only, not logs or backup files.\nERRORREG_HOME_MATCH=205:- Active files are services.yaml, bookmarks.yaml, widgets.yaml, settings.yaml and docker.yaml under /opt/stacks/homepage/config.\nERRORREG_HOME_MATCH=209:- Rule: Homepage link validation must not treat HTTP 200 as success if the body is the NPMPlus default “Congratulations” / host-not-set-up page.\nERRORREG_HOME_MATCH=214:- Context: attempted Netcraze router ACL apply through SSH stdin/multiline for Homepage Moscow Router monitor fix.\nERRORREG_HOME_MATCH=242:- Context: proof 400 tested Moscow router HTTPS monitor from Homepage container with custom Node lookup callback.\nERRORREG_HOME_MATCH=248:- Context: Moscow Router Homepage monitor after ACL fix.\nERRORREG_HOME_MATCH=251:- Impact: Homepage siteMonitor cannot be made green via direct router HTTP URL until router web service allows the Bridge1/Proxmox/protected segment or an explicit safe monitor endpoint is used.\nERRORREG_HOME_MATCH=262:- Context: Moscow Router Homepage siteMonitor attempt using http://[PRIVATE_IP]:5080.\nERRORREG_HOME_MATCH=263:- Evidence: proof 405 showed route to [PRIVATE_IP] via Docker bridge and Homepage container ECONNRESET.\nERRORREG_HOME_MATCH=264:- Impact: do not use [PRIVATE_IP] directly as Homepage siteMonitor from edge-vm.\nERRORREG_HOME_MATCH=265:- Mitigation: use dedicated edge-vm health endpoint that checks router TCP [PRIVATE_IP]:5080 and returns HTTP 200/503 for Homepage.\nERRORREG_HOME_MATCH=267:## HOMEPAGE_ROUTER_MOSCOW_YAML_TITLE_SHAPE_MISMATCH_20260701\nERRORREG_HOME_MATCH=268:- Context: applying Moscow Router Homepage siteMonitor health endpoint.\nERRORREG_HOME_MATCH=269:- Mistake: assistant apply script matched only property-style cards with `title`, but active Homepage YAML can use service-name-key style like `- Service Name:`.\nERRORREG_HOME_MATCH=273:## HOMEPAGE_ROUTER_MOSCOW_APPLY_SCRIPT_SYNTAX_ERROR_20260701\nERRORREG_HOME_MATCH=274:- Context: applying Moscow Router Homepage health endpoint.\nERRORREG_HOME_MATCH=276:- Evidence: proof 408 showed SyntaxError in /tmp/homepage-router-moscow-apply-fixed.py.\nERRORREG_HOME_MATCH=277:- Actual impact: YAML was not changed, so Homepage green dot could not appear.\nERRORREG_HOME_MATCH=624:## HOMEPAGE_SERVICES_YAML_BAD_INDENT_20260702\nERRORREG_HOME_MATCH=625:- Assistant inserted Homepage services.yaml entries with wrong indentation; YAMLException bad indentation at line 227.\nERRORREG_HOME_MATCH=628:## HOMEPAGE_SERVICES_YAML_BAD_INDENT_REPAIR_20260702\nERRORREG_HOME_MATCH=643:## HOMEPAGE_XENFORO_INFO_INLINE_PYTHON_SYNTAX_ERROR_20260702\nERRORREG_HOME_MATCH=644:- Assistant used invalid inline Python syntax with def after semicolon while adding XenForo.info to Homepage External.\nERRORREG_HOME_MATCH=647:## HOMEPAGE_USEFUL_ROUTER_NAME_MISMATCH_20260702\nERRORREG_HOME_MATCH=648:- Previous apply looked for Russian Router card name, but active Homepage Useful group contains Router and Public Domain.\nERRORREG_HOME_MATCH=651:## HOMEPAGE_USEFUL_ROUTER_CARD_NOT_FOUND_20260702\nERRORREG_HOME_MATCH=653:- Need verify active Homepage config path, docker mount, and any alternate services.yaml before next apply.\nERRORREG_HOME_MATCH=668:## LESSON_20260702_HOMEPAGE_MONITORS_REPAIR_NOT_DELETE\nERRORREG_HOME_MATCH=669:- Do not delete or disable Homepage siteMonitor fields to hide red badges.\nERRORREG_HOME_MATCH=671:- Do not touch Cloudflare Homepage card when operator says it is green and opens correctly.\nERRORREG_HOME_MATCH=672:- Before changing Homepage, identify the live config host; in this state live Homepage is on core-apps [PRIVATE_IP], not edge-vm.\nERRORREG_HOME_MATCH=2544:## KOW_ADMIN_DASHBOARD_WARNINGS_POST_FINAL_20260903\nERRORREG_HOME_MATCH=2546:Scope: KingOfWolk XenForo admin dashboard after technical-final checkpoint.\nERRORREG_HOME_MATCH=2547:Observed: admin dashboard reports potentially outdated templates and existing server error-log entries.\nERRORREG_HOME_MATCH=2575:## KOW_ADMIN_DASHBOARD_WARNINGS_POST_FINAL_20260903_CLOSURE\nERRORREG_HOME_MATCH=2577:Current xf_error_log is empty, so the server-error dashboard warning has no live entries.\nDNS_GETENT_RC=0\nDNS_GETENT_BEGIN\n[PRIVATE_IP] STREAM home.gram1.ru\n[PRIVATE_IP] DGRAM \n[PRIVATE_IP] RAW \nDNS_GETENT_END\nDNS_DIG_A_RC=0\nDNS_DIG_A_BEGIN\n[PRIVATE_IP]\nDNS_DIG_A_END\nDNS_DIG_CNAME_RC=0\nHTTPS_HEADERS_RC=0\nHTTPS_HEADERS_BEGIN\nHTTP/2 200 \ndate: Fri, 18 Sep 2026 22:22:12 GMT\ncontent-type: text/html; charset=utf-8\ncontent-length: 70393\nvary: Accept-Encoding\ncache-control: s-maxage=31536000\netag: \"6etjfbh43j1bgc\"\nvary: Accept-Encoding\norigin-agent-cluster: ?1\nx-dns-prefetch-control: off\nx-content-type-options: nosniff\nx-permitted-cross-domain-policies: none\nreferrer-policy: strict-origin-when-cross-origin\nx-frame-options: SAMEORIGIN\n\nHTTPS_HEADERS_END\nHTTPS_STATUS_RC=0\nHTTPS_STATUS_BEGIN\nHTTP=200 IP=[PRIVATE_IP] TLS=20 REDIR=\nHTTPS_STATUS_END\nHTTPS_BODY_RC=0\nHTTPS_BODY_SAMPLE_BEGIN\n