Commit Graph

16 Commits

Author SHA1 Message Date
danlin a3d7803819 rclone-backup: exclude live SQLite sidecar files
The nightly sync failed every night with 'corrupted on transfer: md5
hashes differ' on gitea.db-journal: rclone copies the volatile SQLite
journal while Gitea rewrites/removes it. That IO error also made rclone
skip the delete phase, so the backup drifted out of sync. Exclude the
transient *.db-journal/-wal/-shm files.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-26 09:31:44 +02:00
danlin 2fb046a880 rclone-backup: raise throughput now that we have our own Drive quota
With the dedicated client_id the shared-project rate limits are gone, so
lift the pacing: tpslimit 10->25 and drive-pacer-min-sleep 100ms->10ms
(the old 100ms capped requests at ~10/s and would have throttled the
higher tpslimit anyway).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-25 19:34:20 +02:00
danlin 70febee487 Reap orphaned Gitea Actions job containers
When the runner is stopped mid-job (reboot, autoUpgrade, gitea restart),
its job container keeps running its `sleep 10800` entrypoint and is never
cleaned up, and unused images pile up. Add a 15-min timer that removes a
GITEA-ACTIONS-TASK-N container only when Gitea's DB reports that task as
finished (status 1/2/3/4); running/unknown tasks are left untouched. Also
prune unused actions networks/volumes and dangling images.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-25 17:35:26 +02:00
danlin 82ff0dc817 rclone-backup: throttle API calls to survive Drive rate limits
The nightly sync has failed since Jul 18 with RATE_LIMIT_EXCEEDED,
transferring 0 B. Limit transactions and pace Drive requests, and retry
a few times before giving up. This mitigates rather than fixes the cause
(the remote still uses rclone's shared default client_id).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 07:58:39 +02:00
danlin 0f2ec2db3b filebrowser: seed config.yaml that the bind mount would otherwise hide
The image ships /home/filebrowser/data/config.yaml, but mounting the host
directory there hides it and the app refuses to start. Seed it with
tmpfiles 'C' (create-if-missing) so it stays editable afterwards.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 07:51:18 +02:00
danlin b782b4b8aa Fix filebrowser: persist database and allow port 80 bind
The image switched to the FILEBROWSER_* env scheme and now runs as
non-root (uid 1000), which broke two things:

- It binds :80 inside the container, which a non-root user may not do
  ("bind: permission denied" since the Jul 19 reboot). Allow it via
  net.ipv4.ip_unprivileged_port_start=0 instead of running as root.
- It stores DB/config under /home/filebrowser/data, not /config, so the
  old FB_DATABASE + /config mount were ignored and the database lived
  inside the container (lost on every restart). Mount the host dir there
  and give it to uid 1000.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 07:49:43 +02:00
danlin 2e78934b3a Use Podman (not Docker) as the gitea-actions-runner backend
The default docker package is marked insecure; the runner module already
supports Podman natively (DOCKER_HOST -> /run/podman/podman.sock, group
podman), and the socket + group are already present on the host.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 21:37:09 +02:00
danlin ac80d261b8 Add Gitea Actions runner (Docker executor)
- Enable Gitea Actions in the container (GITEA__actions__ENABLED)
- Run dockerd alongside podman for job containers
- services.gitea-actions-runner: instance-wide runner "fileserver",
  Docker labels, registered against the internal LAN URL; reads the
  registration token from /data/secrets/gitea-runner-token

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 21:14:41 +02:00
danlin 7f1767345a Remove dj-beets project
No longer in use. Drops the beets containers (cli/web), build +
autoimport services and timer, the beet CLI wrapper, /opt/dj-beets
tmpfiles entry, firewall port 8337, the Makefile copy step, and the
src/dj-beets tree (which contained a Beatport token) so the repo can
be made public safely.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 19:50:03 +02:00
danlin a0658b3a97 Merge branch 'claude/stoic-edison-841399'
* Remove k8s-server host
* Clean up duplicate sections in README
* Track latest gitea release
* Add konnektor + api/auth/mailpit reverse proxies
* Point konnektor.home at konnektor-web

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 00:58:42 +02:00
danlin cb0c3c791b Persist filebrowser config to /data/filebrowser
Mount /data/filebrowser as /config and point FB_DATABASE at
/config/filebrowser.db so the user/share database survives
container recreations.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 00:58:29 +02:00
danlin c8ccc76173 Track latest gitea release instead of pinning to 1.25
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 21:50:03 +02:00
danlin c4938a6c05 Remove plaintext secrets, update SSH key, and upgrade to NixOS 25.11
Replace initialPassword with hashedPassword for danlin user, move
FileBrowser admin password to external environmentFile with restricted
secrets directory, update SSH authorized key, and bump nixpkgs to 25.11.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-19 17:44:03 +01:00
danlin cdf71a5ded Add Gitea container configuration and update firewall rules for access 2025-12-15 09:46:14 +01:00
danlin b92ccc8360 Update WSDD service configuration for improved network handling and stability 2025-12-09 16:57:48 +01:00
danlin dbc64845f4 Add initial pyproject.toml for dj-beets project with dependencies and metadata 2025-12-08 10:40:52 +01:00