39 lines
16 KiB
JSON
39 lines
16 KiB
JSON
{
|
|
"schema_version": 1,
|
|
"channel": "homelab-runtime",
|
|
"command_id": "SUPPORT-260923-SPB-SNIKKET-HOME-TOPOLOGY-9212R1",
|
|
"status": "OK",
|
|
"rc": 0,
|
|
"host": "pve01",
|
|
"mode": "read-only",
|
|
"component": "spb-snikket-home-topology-preflight",
|
|
"started_at_utc": "2026-09-23T15:29:19Z",
|
|
"finished_at_utc": "2026-09-23T15:29:56Z",
|
|
"reference_register_checked": true,
|
|
"reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66",
|
|
"error_register_checked": true,
|
|
"error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0",
|
|
"command_sha256": "8b782274900f6bc9aa802887320595dc8daddda038b74f5bb47d7037e275cc95",
|
|
"duplicate_failed_command_blocked": false,
|
|
"block_reason": null,
|
|
"execution_started": true,
|
|
"change_declared": false,
|
|
"result_contract_valid": true,
|
|
"result_contract_status": null,
|
|
"result_contract_error": null,
|
|
"command_rc": 0,
|
|
"changes_made": false,
|
|
"rollback_started": false,
|
|
"rollback_restored": null,
|
|
"mutation_outcome": "NO_MUTATION",
|
|
"sanitized": true,
|
|
"secrets_included": false,
|
|
"private_addresses_included": false,
|
|
"raw_evidence_retained_locally": true,
|
|
"raw_evidence_sha256": "4647a1f838f614aee3bb390bbb1a36f357f9a8bf88e819fbd5f9d977f7cda299",
|
|
"sanitized_output_sha256": "4647a1f838f614aee3bb390bbb1a36f357f9a8bf88e819fbd5f9d977f7cda299",
|
|
"output_truncated_in_json": false,
|
|
"full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt",
|
|
"output": "SNIKKET9212_BEGIN=true\nMODE=READ_ONLY_TOPOLOGY_PREFLIGHT\nMUTATION_BOUNDARY=NONE;NO_SPB_WRITE;NO_HOME_WRITE;NO_DNS_WRITE;NO_SHUTDOWN\nLOCAL9209_BEGIN=true\nCID=SUPPORT-260923-SPB-SNIKKET-HOME-TOPOLOGY-9212R1\nPLINK_PRESENT=true\nSPB_CANDIDATE_COUNT=1\nSPB_CANDIDATE_SHA16=6d6149f42864ce03\nHOME_CANDIDATE_COUNT=1\nHOME_CANDIDATE_SHA16=bc517b4af3298846\nSPB_HASH_MATCH=true\nSPB_PINNED_PROBE_RC=0\nDPAPI_DECRYPTABLE_COUNT=1\nOLD9208_LOCAL_ERR_SHA16=5a00a4ad6f6ef637\nLOCAL_ACCESS_STATUS=PASS\nLOCAL9209_END=true\nSPB_PINNED_ACCESS=PASS\nSPB_SNIKKET_EXTRACT_RC=0\nSPB_SNIKKET_EXTRACT_STDERR_SHA16=01ba4719c80b6fe9\nHOME_TOPOLOGY_AUDIT_RC=0\nSPB_TO_HOME_PORT_PROBE_RC=0\nSPB_TO_HOME_PORT_PROBE_STDERR_SHA16=e3b0c44298fc1c14\nSPB_SNIKKET_RAW_SAFE={\"dnat_target_count\":1,\"dnat_target_sha16\":\"0b7870e2230336f5\",\"egress_exists\":true,\"egress_sha16\":\"6f95765c03a345c9\",\"egress_source_count\":1,\"egress_source_sha16\":\"4e29a2729bbc4066\",\"ingress_exists\":true,\"ingress_sha16\":\"a195c34384dd7b2c\",\"wg_exists\":true,\"wg_listen_port\":51820,\"wg_peer_count\":1,\"wg_sha16\":\"445cd0dd63bffe31\"}\nHOME_TOPOLOGY9212={\"classification\":{\"automatable_direct_edge\":true,\"home_public_owner_count\":1,\"home_public_owners\":[{\"has_wg_home\":false,\"mentions_egress_source\":true,\"mentions_target\":true,\"name\":\"edge-vm\",\"node\":\"pve03\",\"owns_home_ip\":true,\"rc\":0,\"type\":\"qemu\",\"vmid\":130}],\"needs_router_specific_migration\":false,\"snikket_egress_source_owner_count\":2,\"snikket_egress_source_owners\":[{\"has_wg_home\":false,\"mentions_egress_source\":true,\"mentions_target\":true,\"name\":\"edge-vm\",\"node\":\"pve03\",\"owns_home_ip\":true,\"rc\":0,\"type\":\"qemu\",\"vmid\":130},{\"has_wg_home\":false,\"mentions_egress_source\":true,\"mentions_target\":false,\"name\":\"snikket\",\"node\":\"pve01\",\"owns_home_ip\":false,\"rc\":0,\"type\":\"qemu\",\"vmid\":150}],\"snikket_target_owner_count\":1,\"snikket_target_owners\":[{\"has_wg_home\":false,\"mentions_egress_source\":true,\"mentions_target\":true,\"name\":\"edge-vm\",\"node\":\"pve03\",\"owns_home_ip\":true,\"rc\":0,\"type\":\"qemu\",\"vmid\":130}],\"wg_home_owner_count\":0,\"wg_home_owners\":[]},\"config_hits\":[],\"guests\":[{\"has_wg_home\":false,\"mentions_egress_source\":true,\"mentions_target\":true,\"name\":\"edge-vm\",\"node\":\"pve03\",\"owns_home_ip\":true,\"rc\":0,\"type\":\"qemu\",\"vmid\":130},{\"has_wg_home\":false,\"mentions_egress_source\":true,\"mentions_target\":false,\"name\":\"snikket\",\"node\":\"pve01\",\"owns_home_ip\":false,\"rc\":0,\"type\":\"qemu\",\"vmid\":150}],\"hosts\":[{\"has_wg_home\":false,\"mentions_egress_source\":false,\"mentions_target\":false,\"node\":\"pve01\",\"owns_home_ip\":false,\"rc\":0},{\"has_wg_home\":false,\"mentions_egress_source\":false,\"mentions_target\":false,\"node\":\"pve02\",\"owns_home_ip\":false,\"rc\":0},{\"has_wg_home\":false,\"mentions_egress_source\":false,\"mentions_target\":false,\"node\":\"pve03\",\"owns_home_ip\":false,\"rc\":0}],\"reference_lines\":[{\"line\":14,\"text\":\"- VM130 edge-vm | pve03 | running | KEEP\"},{\"line\":15,\"text\":\"- VM150 snikket | pve01 | running | KEEP\"},{\"line\":20,\"text\":\"- VM9130 edge-cold-standby | pve02 | stopped | KEEP_DR\"},{\"line\":73,\"text\":\"NOTE exclude_from_reference_or_delete_later=05_edge_compose_safe.tgz\"},{\"line\":75,\"text\":\"NOTE edge-vm disk scsi1 backup=0 risk must be documented\"},{\"line\":77,\"text\":\"NOTE edge health WARN/ERROR items should be documented as known current states\"},{\"line\":101,\"text\":\"04_edge_vm_basic.txt 34506 bytes\"},{\"line\":102,\"text\":\"05_edge_compose_redacted.txt 24228 bytes\"},{\"line\":103,\"text\":\"05_edge_compose_safe.tgz.QUARANTINED.txt 354 bytes\"},{\"line\":104,\"text\":\"05_edge_compose_tar_errors.txt 166 bytes\"},{\"line\":106,\"text\":\"06_edge_npmplus_routes_safe.txt 17350 bytes\"},{\"line\":107,\"text\":\"07_edge_systemd_backup_audit.txt 20694 bytes\"},{\"line\":108,\"text\":\"08_edge_scripts_redacted.txt 198622 bytes\"},{\"line\":149,\"text\":\"- \\u0423 VM130 edge-vm \\u0435\\u0441\\u0442\\u044c \\u0440\\u0438\\u0441\\u043a: \\u0434\\u043e\\u043f\\u043e\\u043b\\u043d\\u0438\\u0442\\u0435\\u043b\\u044c\\u043d\\u044b\\u0439 \\u0434\\u0438\\u0441\\u043a backup=0.\"},{\"line\":157,\"text\":\"- Edge VM: ssh debian@<IP:bc517b4af3298846>, \\u0438\\u0441\\u043f\\u043e\\u043b\\u044c\\u0437\\u043e\\u0432\\u0430\\u0442\\u044c sudo, root-login \\u043d\\u0435 \\u0438\\u0441\\u043f\\u043e\\u043b\\u044c\\u0437\\u043e\\u0432\\u0430\\u0442\\u044c.\"},{\"line\":166,\"text\":\"- VM130 edge-vm pve03 <IP:bc517b4af3298846> Docker ingress/app host.\"},{\"line\":173,\"text\":\"- Edge VM \\u0438\\u043c\\u0435\\u0435\\u0442 vzdump/offhost/restore evidence; \\u0440\\u0438\\u0441\\u043a backup=0 \\u043f\\u043e \\u0434\\u043e\\u043f\\u043e\\u043b\\u043d\\u0438\\u0442\\u0435\\u043b\\u044c\\u043d\\u043e\\u043c\\u0443 \\u0434\\u0438\\u0441\\u043a\\u0443 \\u043e\\u0441\\u0442\\u0430\\u0451\\u0442\\u0441\\u044f.\"},{\"line\":199,\"text\":\"## ROUTER_NETCRAZE_ULTRA_NC1812_20260630\"},{\"line\":226,\"text\":\"### WAN \\u0438 \\u0440\\u0435\\u0437\\u0435\\u0440\\u0432\\u043d\\u044b\\u0439 \\u0438\\u043d\\u0442\\u0435\\u0440\\u043d\\u0435\\u0442\"},{\"line\":227,\"text\":\"- Main WAN: GigabitEthernet1, renamed ISP, description \\u0420\\u043e\\u0441\\u0442\\u0435\\u043b.\"},{\"line\":228,\"text\":\"- WAN security-level: public.\"},{\"line\":229,\"text\":\"- WAN addressing: DHCP.\"},{\"line\":230,\"text\":\"- WAN MTU: 1500.\"},{\"line\":231,\"text\":\"- WAN global priority: 700.\"},{\"line\":232,\"text\":\"- WAN ping-check profile: default.\"},{\"line\":234,\"text\":\"- WAN DHCP observed in router log: <IP:18d462ba98aa4550>, gateway <IP:29948130c37b10e3>.\"},{\"line\":235,\"text\":\"- ISP DNS observed in router log: <IP:009e7a91182f3b0b>, <IP:0c2f3683ba1d821a>.\"},{\"line\":236,\"text\":\"- Backup/mobile WAN: CdcEthernet0, description SIM.\"},{\"line\":238,\"text\":\"- CdcEthernet0 security-level: public.\"},{\"line\":282,\"text\":\"- Default router: <IP:c5eb5a4cc76a5cdb>.\"},{\"line\":311,\"text\":\"- <IP:6e3573c5557733db> -> bc:24:11:f4:c5:d8 WireGuard.\"},{\"line\":312,\"text\":\"- <IP:bc517b4af3298846> -> bc:24:11:e1:f3:3c NPMplus / edge-vm.\"},{\"line\":315,\"text\":\"### NAT / port forwarding\"},{\"line\":318,\"text\":\"- ISP tcpudp/3478 -> bc:24:11:e1:9a:25, Nextcloud Talk TURN.\"},{\"line\":319,\"text\":\"- Home tcp/51820 -> bc:24:11:f4:c5:d8, WireGuard vpn1.\"},{\"line\":327,\"text\":\"### Router management\"},{\"line\":333,\"text\":\"- Telnet port configured: 2323, security-level private; router log shows Telnet disabled later on 2026-06-26.\"},{\"line\":339,\"text\":\"### Router services\"},{\"line\":354,\"text\":\"### Router automation warning\"},{\"line\":357,\"text\":\"- Automation must use router CLI syntax, not bash syntax.\"},{\"line\":366,\"text\":\"- edge-vm: no UPS/NUT/APCUPSD integration discovered.\"},{\"line\":371,\"text\":\"- NetBird service is active on pve01, pve02, pve03 and edge-vm.\"},{\"line\":376,\"text\":\"- edge-vm: FQDN edge-vm.netbird.selfhosted, IPv4 <IP:8ffeea43651fd0fa>.\"},{\"line\":378,\"text\":\"- WireGuard port: 51820.\"},{\"line\":395,\"text\":\"- edge-vm owns most application health, dashboard, ingress, backup, NetBox, NPMplus, certificate, Trivy and vulnerability jobs.\"},{\"line\":455,\"text\":\"- edge-vm timers cover runtime dashboard, Paperless guard, external canary, health metrics, restore drill index, AdGuard rewrite sync, NPMplus cert expiry, NetBox backup/sync, retention, cluster daily status, vulnerability and Trivy scans, ingress hardening and NPMplus admin bind.\"},{\"line\":456,\"text\":\"- pve01 timers cover VPN/NetBird health, health metrics, smartctl, disk space, MkDocs refresh, VPS identity audit, storage capacity, quality gate, evidence catalog, backup freshness, docker health, Filebrowser backup/offhost/restore, NPMplus/Kuma backup, NetBird VPS backup/offhost, Authentik/Gitea/Vaultwarden backup, SOPS secret coverage, mail cloud upload/restore, Immich/Memos/Paperless backup/offhost/restore, auto backup, edge-vm vzdump, secret sanity.\"},{\"line\":459,\"text\":\"- Script hashes were captured for /usr/local/sbin and /usr/local/bin on edge-vm, pve01, pve02 and pve03.\"},{\"line\":531,\"text\":\"- Main active workload: VM130 edge-vm.\"},{\"line\":545,\"text\":\"- Network: vmbr0, gateway <IP:4f9da1283166a1e9>.\"},{\"line\":560,\"text\":\"- Network: vmbr0, gateway <IP:4f9da1283166a1e9>.\"},{\"line\":575,\"text\":\"- Network: vmbr0, gateway <IP:4f9da1283166a1e9>.\"},{\"line\":590,\"text\":\"- Network: vmbr0, gateway <IP:4f9da1283166a1e9>.\"},{\"line\":597,\"text\":\"### VM130 edge-vm\"},{\"line\":600,\"text\":\"- Name: edge-vm.\"},{\"line\":604,\"text\":\"- Role: edge application host / reverse proxy / monitoring / backup automation host.\"},{\"line\":608,\"text\":\"- Network: vmbr0, gateway <IP:4f9da1283166a1e9>.\"},{\"line\":626,\"text\":\"- Network: vmbr0, gateway <IP:4f9da1283166a1e9>.\"},{\"line\":643,\"text\":\"- Network: vmbr0, gateway <IP:4f9da1283166a1e9>.\"},{\"line\":682,\"text\":\"### Router ingress\"},{\"line\":683,\"text\":\"- Public WAN router forwards TCP/80 and TCP/443 to NPMplus on edge-vm, <IP:bc517b4af3298846>.\"},{\"line\":684,\"text\":\"- Router forwards TCP/UDP 3478 to Nextcloud Talk TURN on <IP:4e29a2729bbc4066>.\"},{\"line\":685,\"text\":\"- Router forwards Home TCP/51820 to WireGuard host <IP:6e3573c5557733db>.\"},{\"line\":686,\"text\":\"- NPMplus admin listener is bound to localhost on edge-vm, <IP:12ca17b49af22894>:81; public disabled legacy host npm.gram1.ru exists but enabled=0.\"},{\"line\":689,\"text\":\"- Host: edge-vm, <IP:bc517b4af3298846>.\"},{\"line\":694,\"text\":\"- Public listen ports on edge-vm: <IP:19e36255972107d4>:80 and <IP:19e36255972107d4>:443 by nginx/NPMplus.\"},{\"line\":698,\"text\":\"### Public NPMplus proxy hosts\"},{\"line\":766,\"text\":\"## EDGE_DOCKER_STACKS_REFERENCE_20260630\"},{\"line\":769,\"text\":\"- Host: edge-vm, IP <IP:bc517b4af3298846>.\"},{\"line\":774,\"text\":\"- Public ingress terminates through NPMplus on ports 80/443.\"},{\"line\":864,\"text\":\"- NPMplus public ingress: <IP:19e36255972107d4>:80 and <IP:19e36255972107d4>:443.\"},{\"line\":869,\"text\":\"- Full path inventory is in 133_EDGE_DOCKER_STACKS_SAFE_INVENTORY.txt.\"},{\"line\":870,\"text\":\"- Normalized runtime map is in 134_EDGE_DOCKER_CONTAINER_NORMALIZED_MAP.txt.\"},{\"line\":873,\"text\":\"- Raw Docker/stacks inventory: 133_EDGE_DOCKER_STACKS_SAFE_INVENTORY.txt.\"},{\"line\":874,\"text\":\"- Normalized container map: 134_EDGE_DOCKER_CONTAINER_NORMALIZED_MAP.txt.\"},{\"line\":895,\"text\":\"- VM130 edge-vm: included in homelab-nightly-all, local backup on pve03.\"},{\"line\":898,\"text\":\"- VM130 also has dedicated edge-vm-vzdump backup/offhost/restore health proofs.\"},{\"line\":902,\"text\":\"### Edge VM / VM130 full-image protection\"},{\"line\":903,\"text\":\"- edge-vm-vzdump-backup: STATUS=OK, archive size about 28.2G, SHA256 recorded.\"},{\"line\":904,\"text\":\"- edge-vm-vzdump-offhost: STATUS=OK, destination pve02 /mnt/staging/offhost/edge-vm-vzdump-from-pve03.\"},{\"line\":905,\"text\":\"- edge-vm-vzdump-restore: STATUS=OK, zstd and vma verification OK.\"},{\"line\":906,\"text\":\"- mail-cloud-edge-vm: STATUS=OK, recurring chunked upload, 53 parts, download verification enabled.\"},{\"line\":907,\"text\":\"- Retention for edge-vm cloud upload: RETENTION_KEEP=4.\"},{\"line\":908,\"text\":\"- Edge restore proof offhost: STATUS=OK, ITEMS=14, OK=14.\"},{\"line\":915,\"text\":\"- mail-cloud-restore-drill: STATUS=OK, CRITICAL_OK=2, EDGE_OK=1.\"},{\"line\":934,\"text\":\"- Router self-test config is stored as uploaded/generated reference evidence, not yet automated as recurring router backup.\"},{\"line\":999,\"text\":\"- XenForo SMTP rotation has DB backup proof from earlier rotation work; production forum application-level backup catalog should be expanded separately with CodeVipe-specific DB/files/cron/public cutover details.\"},{\"line\":1003,\"text\":\"- Disk retention policy: STATUS=OK, root used pct observed 70 on edge-vm, removed dirs 0, Docker volume prune NO.\"},{\"line\":1004,\"text\":\"- App backup retention dry-run timer exists on edge-vm.\"},{\"line\":1017,\"text\":\"- Router config backup is currently reference/self-test based, not confirmed as recurring automated backup.\"},{\"line\":1027,\"text\":\"- Primary monitoring host: edge-vm, <IP:bc517b4af3298846>.\"},{\"line\":1033,\"text\":\"- Uptime Kuma container: uptime-kuma, local port <IP:12ca17b49af22894>:3001, public route uptime.gram1.ru and VPN route kuma.vpn.gram1.ru.\"},{\"line\":1034,\"text\":\"- Gotify container: gotify, local port <IP:12ca17b49af22894>:8082, public route gotify.gram1.ru.\"},{\"line\":1039,\"text\":\"- Node exporter on edge-vm: node-exporter, local port <IP:12ca17b49af22894>:9100.\"},{\"line\":1062,\"text\":\"- Edge node exporter scrape target: node-exporter:9100.\"},{\"line\":1084,\"text\":\"- HomelabP0WeeklyEdgeVmVzdumpHealthStale: weekly edge-vm vzdump health older than 8d.\"},{\"line\":1103,\"text\":\"- Alloy relabels container, compose_project, compose_service and host=edge-vm.\"},{\"line\":1137,\"text\":\"- Main health dir on edge-vm: /var/lib/homelab-health.\"},{\"line\":1209,\"text\":\"- edge-vm is reached as debian@<IP:bc517b4af3298846> with sudo.\"},{\"line\":1215,\"text\":\"- pve01 root keys observed: id_rsa, id_ed25519 and public keys.\"}],\"spb_safe\":{\"dnat_target_count\":1,\"dnat_target_sha16\":\"0b7870e2230336f5\",\"egress_exists\":true,\"egress_sha16\":\"6f95765c03a345c9\",\"egress_source_count\":1,\"egress_source_sha16\":\"4e29a2729bbc4066\",\"ingress_exists\":true,\"ingress_sha16\":\"a195c34384dd7b2c\",\"wg_exists\":true,\"wg_listen_port\":51820,\"wg_peer_count\":1,\"wg_sha16\":\"445cd0dd63bffe31\"}}\nSPB_TO_HOME_PORT_PROBE={\"tcp\":{\"3478\":\"TIMEOUT\",\"3479\":\"TIMEOUT\",\"5000\":\"TIMEOUT\",\"5222\":\"TIMEOUT\",\"5349\":\"TIMEOUT\",\"5350\":\"TIMEOUT\"},\"udp_stun\":{\"3478\":{\"ok\":false,\"result\":\"TIMEOUT\"},\"3479\":{\"ok\":false,\"result\":\"TIMEOUT\"}}}\nHOME_PUBLIC_OWNER_COUNT=1\nSNIKKET_TARGET_OWNER_COUNT=1\nSNIKKET_EGRESS_SOURCE_OWNER_COUNT=2\nWG_HOME_OWNER_COUNT=0\nMIGRATION_AUTOMATABLE_ON_KNOWN_HOME_HOST=true\nNEEDS_ROUTER_SPECIFIC_MIGRATION=false\nDIRECT_HOME_TCP_OPEN_COUNT=0\nDIRECT_HOME_STUN_OK_COUNT=0\nDIRECT_SNIKKET_INGRESS_APPEARS_READY=false\nNEXT_ACTION=APPLY_GUARDED_HOME_NFT_MIGRATION\nTASK_COMPLETE=true\nTASK_RESULT=PASS_SPB_SNIKKET_HOME_TOPOLOGY_PREFLIGHT\nDECISION=READ_EXACT_9212_AND_APPLY_ONLY_PROVEN_HOME_EDGE_PATH\nNEXT_GATE=EXACT_9212_HOME_EDGE_TOPOLOGY\nHOMELAB_RESULT_CONTRACT={\"version\":1,\"command_id\":\"SUPPORT-260923-SPB-SNIKKET-HOME-TOPOLOGY-9212R1\",\"status\":\"OK\",\"changes_made\":false,\"rollback_started\":false,\"rollback_restored\":null}\n"
|
|
}
|