Commit Graph

11 Commits

Author SHA1 Message Date
danlin b782b4b8aa Fix filebrowser: persist database and allow port 80 bind
The image switched to the FILEBROWSER_* env scheme and now runs as
non-root (uid 1000), which broke two things:

- It binds :80 inside the container, which a non-root user may not do
  ("bind: permission denied" since the Jul 19 reboot). Allow it via
  net.ipv4.ip_unprivileged_port_start=0 instead of running as root.
- It stores DB/config under /home/filebrowser/data, not /config, so the
  old FB_DATABASE + /config mount were ignored and the database lived
  inside the container (lost on every restart). Mount the host dir there
  and give it to uid 1000.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 07:49:43 +02:00
danlin 2e78934b3a Use Podman (not Docker) as the gitea-actions-runner backend
The default docker package is marked insecure; the runner module already
supports Podman natively (DOCKER_HOST -> /run/podman/podman.sock, group
podman), and the socket + group are already present on the host.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 21:37:09 +02:00
danlin ac80d261b8 Add Gitea Actions runner (Docker executor)
- Enable Gitea Actions in the container (GITEA__actions__ENABLED)
- Run dockerd alongside podman for job containers
- services.gitea-actions-runner: instance-wide runner "fileserver",
  Docker labels, registered against the internal LAN URL; reads the
  registration token from /data/secrets/gitea-runner-token

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 21:14:41 +02:00
danlin 7f1767345a Remove dj-beets project
No longer in use. Drops the beets containers (cli/web), build +
autoimport services and timer, the beet CLI wrapper, /opt/dj-beets
tmpfiles entry, firewall port 8337, the Makefile copy step, and the
src/dj-beets tree (which contained a Beatport token) so the repo can
be made public safely.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 19:50:03 +02:00
danlin a0658b3a97 Merge branch 'claude/stoic-edison-841399'
* Remove k8s-server host
* Clean up duplicate sections in README
* Track latest gitea release
* Add konnektor + api/auth/mailpit reverse proxies
* Point konnektor.home at konnektor-web

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 00:58:42 +02:00
danlin cb0c3c791b Persist filebrowser config to /data/filebrowser
Mount /data/filebrowser as /config and point FB_DATABASE at
/config/filebrowser.db so the user/share database survives
container recreations.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 00:58:29 +02:00
danlin c8ccc76173 Track latest gitea release instead of pinning to 1.25
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-23 21:50:03 +02:00
danlin c4938a6c05 Remove plaintext secrets, update SSH key, and upgrade to NixOS 25.11
Replace initialPassword with hashedPassword for danlin user, move
FileBrowser admin password to external environmentFile with restricted
secrets directory, update SSH authorized key, and bump nixpkgs to 25.11.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-19 17:44:03 +01:00
danlin cdf71a5ded Add Gitea container configuration and update firewall rules for access 2025-12-15 09:46:14 +01:00
danlin b92ccc8360 Update WSDD service configuration for improved network handling and stability 2025-12-09 16:57:48 +01:00
danlin dbc64845f4 Add initial pyproject.toml for dj-beets project with dependencies and metadata 2025-12-08 10:40:52 +01:00