|
.agents
|
chore(agents): link Codex instructions and skills to Claude
|
2026-09-10 01:32:41 +03:00 |
|
.claude/skills
|
docs(problems): keycloak client secret race breaks fresh oauth2-proxy logins
|
2026-07-29 00:09:02 +03:00 |
|
.hermes/plans
|
docs: plan k3s state backups
|
2026-05-20 22:46:00 +00:00 |
|
apps
|
feat(omniroute): deploy AI gateway with native Keycloak login
|
2026-09-10 01:43:12 +03:00 |
|
argocd
|
feat(sso): retire authentik, keycloak is the sole IdP
|
2026-07-27 17:01:17 +03:00 |
|
argocd-crds
|
argocd: split CRDs into separate app with server-side apply
|
2026-05-09 23:45:18 +03:00 |
|
argocd-extras
|
feat(sso): retire authentik, keycloak is the sole IdP
|
2026-07-27 17:01:17 +03:00 |
|
bambuddy
|
feat(bambuddy): add Bambu Lab printer dashboard
|
2026-07-29 02:53:57 +03:00 |
|
bulwark
|
feat(storage): switch remaining enabled apps to local-path SC
|
2026-07-19 21:17:52 +03:00 |
|
ca
|
feat(cert-manager): distribute root CA configmap to all namespaces
|
2026-07-22 22:46:49 +03:00 |
|
calico
|
fix: drop k8s lan-router (moved to LXC), pin calico node IP autodetection to LAN CIDR
|
2026-07-15 00:03:11 +03:00 |
|
calico-crds
|
calico-crds: fix URL — use /raw/ format like external-secrets-crds
|
2026-05-10 00:09:08 +03:00 |
|
cert-manager
|
fix(cert-manager): verify DNS01 records through authoritative Knot
|
2026-09-07 02:54:10 +03:00 |
|
cert-manager-crds
|
cert-manager: split CRDs into separate app with server-side apply
|
2026-05-09 23:49:53 +03:00 |
|
cert-manager-extras
|
feat(secrets): kill ksops — all SOPS apps migrated to ESO/Bitwarden
|
2026-07-19 20:52:01 +03:00 |
|
certs
|
refactor(i-scheme): direct per-app LB + named private-ca certs, drop nginx path
|
2026-07-21 23:09:57 +03:00 |
|
cilium
|
refactor(mail): stalwart back to the CP node, drop the unused egress gateway
|
2026-07-27 01:59:53 +03:00 |
|
cnpg
|
fix(resources): reduce overprovisioned cpu requests
|
2026-05-22 16:56:48 +00:00 |
|
cnpg-crds
|
cnpg: split CRDs into separate app with server-side apply
|
2026-05-10 00:20:58 +03:00 |
|
cold-backups
|
cold-backups: add headscale backup
|
2026-07-14 22:14:31 +03:00 |
|
coredns
|
coredns: fix OOM loop — use .override instead of .server block
|
2026-05-11 16:37:24 +03:00 |
|
crossplane
|
fix(crossplane): skip dry-run for ProviderConfigs whose CRDs arrive with providers
|
2026-07-27 03:33:01 +03:00 |
|
crossplane-crds
|
crossplane-crds: use raw URLs — upstream dir lacks kustomization.yaml
|
2026-05-11 02:58:41 +03:00 |
|
decisions
|
docs: record DHCP LXC rollout and LAN verification
|
2026-09-08 18:28:45 +03:00 |
|
dhcp
|
docs: document DHCP interface and mDNS verification
|
2026-09-08 19:31:05 +03:00 |
|
docs/alerts
|
feat: route alerts to Hermes incidents
|
2026-05-21 11:47:32 +00:00 |
|
dtrade
|
feat(crawler): recreate hermes, dtrade, lan-router LXC as pct containers
|
2026-07-19 19:43:32 +03:00 |
|
element-web
|
synapse: SSO-only login, disable password auth
|
2026-05-09 03:51:23 +03:00 |
|
eveloot
|
eveloot: fix double /eve-where-to-sell-blue/ prefix on prebuilt asset URLs
|
2026-05-11 19:33:25 +03:00 |
|
exitnode
|
docs(exitnode): whole Vultr AS is shaped; working AnyConnect is RU-hosted
|
2026-09-01 20:10:42 +03:00 |
|
external-dns
|
Revert "feat(knot): zone on a PVC, served from the cluster via the edge proxy"
|
2026-07-26 20:27:51 +03:00 |
|
external-dns-secret
|
feat(secrets): kill ksops — all SOPS apps migrated to ESO/Bitwarden
|
2026-07-19 20:52:01 +03:00 |
|
external-secrets
|
fix(external-secrets): raise bitwarden sdk memory limit
|
2026-06-18 10:59:31 +00:00 |
|
external-secrets-crds
|
external-secrets: split CRDs into separate app (sync-wave -1)
|
2026-05-09 21:24:55 +03:00 |
|
external-secrets-extras
|
fix(eso): retire external-secrets-extras app — bootstrap token is manual by definition
|
2026-07-19 21:11:56 +03:00 |
|
firecrawl
|
fix(firecrawl): :80 redirect on proxy — API self-reports http URLs
|
2026-07-22 22:39:22 +03:00 |
|
fluent-bit
|
fix(monitoring): privileged PSS label for node-exporter and fluent-bit ns
|
2026-07-19 22:22:52 +03:00 |
|
forgejo
|
feat(sso): retire authentik, keycloak is the sole IdP
|
2026-07-27 17:01:17 +03:00 |
|
forgejo-extras
|
fix(forgejo): seed real admin username forgejo-admin from migrated DB
|
2026-07-19 20:58:09 +03:00 |
|
funkwhale
|
fix(funkwhale): ImplementationSpecific pathType for /.well-known
|
2026-07-28 23:53:55 +03:00 |
|
grafana
|
feat(grafana): LAN split-horizon access via public hostname
|
2026-07-27 23:00:06 +03:00 |
|
grafana-dashboards
|
grafana-dashboards: add kubernetes-mixin alerting rules
|
2026-05-10 02:41:32 +03:00 |
|
grafana-operator
|
fix(resources): reduce overprovisioned cpu requests
|
2026-05-22 16:56:48 +00:00 |
|
grafana-operator-crds
|
grafana-operator: add operator with CRDs split into separate Argo app
|
2026-04-28 16:28:00 +03:00 |
|
harbor
|
feat(storage): forgejo to zfs-ssd CSI; harbor registry to zfs-hdd-scratch, rest local-path
|
2026-07-21 19:36:39 +03:00 |
|
headscale
|
feat(sso): retire authentik, keycloak is the sole IdP
|
2026-07-27 17:01:17 +03:00 |
|
helium-services
|
fix(helium-services): ubo probe needs brotli in Accept-Encoding, not gzip
|
2026-07-15 03:17:00 +03:00 |
|
hermes
|
chore(hermes): add hermes_kimi_api_key to sops
|
2026-08-09 22:29:34 +03:00 |
|
hermes-operator
|
fix(hermes-operator): use shared in-cluster ClusterIssuer for webhook cert
|
2026-05-31 20:09:28 +03:00 |
|
home-assistant
|
chore(home-assistant): empty pruneEntries after auth_oidc migration
|
2026-08-10 01:05:33 +03:00 |
|
homebox
|
feat(sso): retire authentik, keycloak is the sole IdP
|
2026-07-27 17:01:17 +03:00 |
|
immich
|
feat(immich): bump to v3.0.3
|
2026-07-27 17:17:44 +03:00 |
|
incidents
|
incidents: record PodRestarted wsdd alert (self-resolving, fix was in repo)
|
2026-05-21 16:46:19 +00:00 |
|
ingress-edge
|
Revert "feat(knot): zone on a PVC, served from the cluster via the edge proxy"
|
2026-07-26 20:27:51 +03:00 |
|
keycloak
|
feat(keycloak): add OmniRoute OIDC client
|
2026-09-10 01:38:56 +03:00 |
|
knot
|
feat(dns): resend domain verification records
|
2026-07-27 01:41:41 +03:00 |
|
kube-state-metrics
|
metrics: add VictoriaMetrics + vmagent, node-exporter, kube-state-metrics with Grafana dashboards
|
2026-04-28 21:08:06 +03:00 |
|
kubeconfig
|
fix(kubeconfig): switch cert to letsencrypt — zerossl ACME returns 405
|
2026-07-26 02:55:51 +03:00 |
|
kvm
|
feat(kvm): nanokvm console tooling and docs
|
2026-07-17 03:22:01 +03:00 |
|
lan-router
|
feat(network): drop pod/LB routes everywhere, L2 path is now authoritative
|
2026-07-21 22:55:21 +03:00 |
|
lb
|
fix(dns): enable AXFR for external-dns — sync policy was blind
|
2026-07-21 23:31:17 +03:00 |
|
lldap
|
feat(odysseus): replace authentik outpost with oauth2-proxy gate on keycloak
|
2026-07-27 05:44:11 +03:00 |
|
local-path
|
feat(local-path): local-path-provisioner as default SC for talos k8s cluster
|
2026-07-17 03:54:48 +03:00 |
|
mail
|
docs(mail): document LLDAP directory switch
|
2026-07-27 04:31:56 +03:00 |
|
mosquitto
|
fix(mosquitto): terminate base password file before adding users
|
2026-09-10 04:09:21 +03:00 |
|
navidrome
|
feat(navidrome): put web UI behind Keycloak via oauth2-proxy forward-auth
|
2026-07-28 22:09:46 +03:00 |
|
network
|
docs: record DHCP LXC rollout and LAN verification
|
2026-09-08 18:28:45 +03:00 |
|
node
|
docs: document DHCP interface and mDNS verification
|
2026-09-08 19:31:05 +03:00 |
|
node-exporter
|
fix(monitoring): privileged PSS label for node-exporter and fluent-bit ns
|
2026-07-19 22:22:52 +03:00 |
|
odysseus
|
docs(odysseus): upstream transfer verification note
|
2026-08-09 23:10:52 +03:00 |
|
omniroute
|
fix(omniroute): comply with restricted pod security
|
2026-09-10 01:49:41 +03:00 |
|
openebs
|
docs(node): detach dead gravepair toshiba, pool now single hitachi
|
2026-07-17 03:33:45 +03:00 |
|
portfolio
|
ghpages: route farwydi.dev + eveloot.farwydi.dev via nginx-ingress
|
2026-05-11 18:45:36 +03:00 |
|
postgres
|
feat(bambuddy): add Bambu Lab printer dashboard
|
2026-07-29 02:53:57 +03:00 |
|
printbuddy
|
feat(printbuddy): add Klipper-capable Bambuddy fork for QIDI Q1 Pro
|
2026-07-29 03:34:20 +03:00 |
|
problems
|
docs(mosquitto): record password file newline regression
|
2026-09-10 04:13:26 +03:00 |
|
proxmox-csi
|
feat(ingress-edge): revive edge nginx on the talos edge node
|
2026-07-26 01:23:40 +03:00 |
|
redis
|
fix(redis): refreshPolicy OnChange on redis-acl ES
|
2026-07-28 23:44:42 +03:00 |
|
redis-operator
|
fix(resources): reduce overprovisioned cpu requests
|
2026-05-22 16:56:48 +00:00 |
|
redis-operator-crds
|
redis-operator: split CRDs into separate app with server-side apply
|
2026-05-10 00:25:47 +03:00 |
|
reflector
|
reflector/certs: share *.cluster.farwydi.dev wildcard cross-ns
|
2026-05-20 01:26:25 +03:00 |
|
registry
|
revert(postgres): drop pg_cron rig from shared pg — nuq has its own instance
|
2026-07-22 22:28:35 +03:00 |
|
s3
|
feat(sso): retire authentik, keycloak is the sole IdP
|
2026-07-27 17:01:17 +03:00 |
|
samba
|
fix(samba): manage qbittorrent v5 config keys via ansible
|
2026-08-07 21:54:14 +03:00 |
|
sky-locator
|
refactor(sky-locator): deploy the canonical GitHub source
|
2026-09-07 02:51:12 +03:00 |
|
sops
|
docs: drop manual helm/kubectl-apply, document GitOps-only flow
|
2026-04-27 00:28:52 +03:00 |
|
synapse
|
feat(sso): retire authentik, keycloak is the sole IdP
|
2026-07-27 17:01:17 +03:00 |
|
synapse-extras
|
feat(secrets): kill ksops — all SOPS apps migrated to ESO/Bitwarden
|
2026-07-19 20:52:01 +03:00 |
|
teleport
|
docs: record teleport leg subnet in IPAM, refresh README
|
2026-09-01 22:35:51 +03:00 |
|
velero
|
fix(resources): reduce overprovisioned cpu requests
|
2026-05-22 16:56:48 +00:00 |
|
victoria-logs
|
fix(i-scheme): HTTPS everywhere — .dev is HSTS-preloaded, plain HTTP is dead
|
2026-07-21 23:53:07 +03:00 |
|
victoria-metrics
|
fix(i-scheme): HTTPS everywhere — .dev is HSTS-preloaded, plain HTTP is dead
|
2026-07-21 23:53:07 +03:00 |
|
victoria-metrics-operator
|
fix(resources): reduce overprovisioned cpu requests
|
2026-05-22 16:56:48 +00:00 |
|
vm
|
feat(exitnode): ocserv VPN server + teleport VM client; docs: IPAM, outage postmortem
|
2026-09-01 20:02:45 +03:00 |
|
volsync
|
volsync: add Volsync operator with CRDs split
|
2026-05-03 18:24:57 +03:00 |
|
volsync-crds
|
volsync: add Volsync operator with CRDs split
|
2026-05-03 18:24:57 +03:00 |
|
woodpecker
|
feat(sso): retire authentik, keycloak is the sole IdP
|
2026-07-27 17:01:17 +03:00 |
|
workflow
|
docs(mosquitto): verify CO2 sensor onboarding
|
2026-09-10 04:36:03 +03:00 |
|
.gitignore
|
feat(exitnode): ocserv VPN server + teleport VM client; docs: IPAM, outage postmortem
|
2026-09-01 20:02:45 +03:00 |
|
.sops.yaml
|
refactor(talos): edge patch plain in git, wg key alone in sops
|
2026-07-26 02:06:14 +03:00 |
|
AGENTS.md
|
chore(agents): link Codex instructions and skills to Claude
|
2026-09-10 01:32:41 +03:00 |
|
CLAUDE.md
|
docs: document DHCP interface and mDNS verification
|
2026-09-08 19:31:05 +03:00 |
|
DNS.md
|
fix(i-scheme): HTTPS everywhere — .dev is HSTS-preloaded, plain HTTP is dead
|
2026-07-21 23:53:07 +03:00 |
|
IPAM.md
|
docs: document DHCP interface and mDNS verification
|
2026-09-08 19:31:05 +03:00 |
|
NETWORK.md
|
docs: record DHCP LXC rollout and LAN verification
|
2026-09-08 18:28:45 +03:00 |
|
NODE.md
|
docs: document DHCP interface and mDNS verification
|
2026-09-08 19:31:05 +03:00 |
|
root.yaml
|
migrate git
|
2026-05-09 02:39:41 +03:00 |
|
ROUTER.md
|
docs: record DHCP LXC rollout and LAN verification
|
2026-09-08 18:28:45 +03:00 |
|
SOUL.md
|
feat: add Blightkeeper Hermes profile to repo
|
2026-05-21 13:00:03 +00:00 |