5e614727be
NFS-Stabilisierung: site.yml aktualisieren
2026-08-14 06:47:53 +02:00
c8485ac04c
NFS-Stabilisierung: tests/test_nfs_stability_role.py hinzufügen
2026-08-14 06:47:53 +02:00
7a33a9628c
NFS-Stabilisierung: roles/nfs_stability/tasks/main.yml hinzufügen
2026-08-14 06:47:52 +02:00
a82f65dfb7
Merge pull request 'Unify streaming sysctl profile and add guck-vps' ( #4 ) from trulla/sysctl-streaming-20260813 into master
2026-08-13 17:25:01 +02:00
8e37300c92
Update pfannkuchen.ini for streaming path tuning
2026-08-13 17:24:59 +02:00
85e161f992
Update roles/sysctl/defaults/main.yml for streaming path tuning
2026-08-13 17:24:59 +02:00
ad1d2e2ffe
Merge pull request 'fix: verbleibende Sysctl-Doppeldefinitionen entfernen' ( #3 ) from fix/remove-remaining-sysctl-duplicates into master
2026-08-08 23:08:23 +02:00
11b6273f42
fix: verbleibende Sysctl-Doppeldefinitionen entfernen
2026-08-08 23:08:22 +02:00
184476e772
fix: verbleibende Sysctl-Doppeldefinitionen entfernen
2026-08-08 23:08:21 +02:00
1c7e0ec61f
fix: verbleibende Sysctl-Doppeldefinitionen entfernen
2026-08-08 23:08:20 +02:00
0a2171494c
Merge pull request 'fix: WireGuard-Medienpfad auf kanonisches sysctl-Profil bringen' ( #2 ) from fix/canonical-wireguard-sysctl into master
2026-08-08 22:43:22 +02:00
9fed3fe47a
fix: WireGuard-Medienpfad auf kanonisches sysctl-Profil bringen
2026-08-08 22:42:55 +02:00
a062d74bd0
fix: WireGuard-Medienpfad auf kanonisches sysctl-Profil bringen
2026-08-08 22:42:55 +02:00
88bbc3f0ce
fix: WireGuard-Medienpfad auf kanonisches sysctl-Profil bringen
2026-08-08 22:42:54 +02:00
1c8e2ac26c
fix: WireGuard-Medienpfad auf kanonisches sysctl-Profil bringen
2026-08-08 22:42:53 +02:00
8e057b0d4d
fix: WireGuard-Medienpfad auf kanonisches sysctl-Profil bringen
2026-08-08 22:42:53 +02:00
5fb6951583
fix: WireGuard-Medienpfad auf kanonisches sysctl-Profil bringen
2026-08-08 22:42:52 +02:00
0999abd10d
Merge pull request 'fix(borg): send real archive statistics to Backup Sentinel' ( #1 ) from fix/sentinel-backup-stats into master
2026-07-29 15:01:08 +02:00
f639c88952
fix(borg): update tests/fixtures/borgmatic-info-latest.json
2026-07-29 15:01:06 +02:00
1a87e5f35f
fix(borg): update tests/test_borg_sentinel_push.py
2026-07-29 15:01:06 +02:00
b6556cd18e
fix(borg): update roles/borg/tasks/main.yml
2026-07-29 15:01:05 +02:00
6ef859898c
fix(borg): update roles/borg/templates/borgmatic.yml.j2
2026-07-29 15:01:04 +02:00
baa3d2f908
fix(borg): update roles/borg/files/borg-sentinel-push.py
2026-07-29 15:01:04 +02:00
0c1fe5326e
backup: WireGuard und App-Config des Hetzner-VPS sichern
2026-07-29 13:51:23 +02:00
2c3a13beec
inventory: Host-Variablen für produktiven VPS versionieren
2026-07-29 13:51:22 +02:00
7554c78972
inventory: produktiven Hetzner-VPS aktualisieren
2026-07-29 13:50:47 +02:00
sascha
d4f86bf44c
wireguard-Rolle Pi-OS-tauglich + Spoke-Config für Pi 'butler'
...
- wireguard_manage_dns (default true): auf NetworkManager-Hosts (Pi OS) MUSS
false sein - resolvconf + 'DNS='-Zeile zerschiessen dort /etc/resolv.conf
- host_vars/butler/wireguard.yml: Tunnel-IP 10.200.200.9, Endpoint = echter Hub
netcup 194.13.80.132:51820 (NICHT tunnel.sascha-lutz.de = Hetzner/Caddy auf 443),
AllowedIPs nur 10.200.200.0/24 (kein Konflikt mit vm_net_routes), DNS-mgmt aus
- wireguard-butler.yml: gezieltes Playbook (butler ist nicht in [wireguard]-Node-Gruppe)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-25 21:58:57 +02:00
sascha
3ddbed1f9f
vm_net_routes-Rolle: statische Routen physischer Hosts in die VM-Netze
...
Physische Hosts (10.5.85.x) erreichen die VM-internen Netze 10.X.1.0/24 nicht -
die liegen auf vmbr0 der Nodes ohne physische NIC-Bindung. Routen via jeweiligem
Node (10.1.1->node1 ... 10.7.1->node7) persistent ueber NetworkManager gesetzt.
Pi 'butler' erreicht damit den Butler-Dienst (10.4.1.116:8888) - /vm/list verifiziert.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-25 11:02:32 +02:00
sascha
94c58a80ce
Pi5 'butler' (arm64) als AI-Orchestrator-Host aufnehmen
...
- pfannkuchen.ini: neue Gruppe [ai] mit butler (10.5.85.2), child in all/backup/hawser
- docker-Rolle: arch dynamisch via 'dpkg --print-architecture' statt hardcoded amd64
(check_mode:false, damit --check auf ARM nicht leeres arch erzeugt) -> arm64-tauglich
- base-Rolle: Raspberry Pi OS erkennen (raspi.sources) -> sources.list-Ueberschreibung
und qemu-guest-agent auf Pi ueberspringen, damit Pi-Kernel/Firmware-Repos intakt bleiben
Erster Bare-Metal-ARM-Host der Flotte. base+docker+borg+hawser+sysctl erfolgreich
ausgerollt, Docker 29.6.0 arm64 + Hawser aktiv, raspi-Repos unberuehrt.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-25 10:29:39 +02:00
bc765668a6
sync: Inventory-Realabgleich + neue host_vars/roles/playbooks
...
Nachgezogener Arbeitsstand des Homelabs:
- neue host_vars (k3s-*, gluster-*, docmost, paperless, kometa, thelounge, satisfactory, wolfstack-vm)
- neue Rollen/Playbooks (net_watchdog, patchmon-agent, tc_ratelimit, sops-age, rotate-ssh-key, dns-doh, remove-postfix, checkrr-deploy)
- diverse Rollen-Updates (base, borg, dns_resolver, frp_client, hawser, nvidia)
Ausgeklammert (bleiben uncommittet): host_vars/docmost/vars.yml (Klartext-Token -> sollte vault-konform via vault_* referenziert werden).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:27:23 +02:00
d857b72cf8
netcup VPS: Inventory-Eintrag + sysctl-Override (BBR/fq, ohne VM-Werte)
...
- [vps]-Gruppe mit netcup (194.13.80.132) ins Inventory, in [all:children]
- sysctl-Rolle: Loop auf Variable sysctl_params umgestellt (defaults/main.yml)
- group_vars/vps: VPS-Override (fq ergaenzt, swappiness/dirty_ratio weggelassen)
- .gitignore: id_ed25519 (privater Key!) + iso-builder/output ergaenzt
Entspricht dem live gesetzten /etc/sysctl.d/99-net-tuning.conf (15.06.2026).
Dry-run gegen netcup: changed=0 (idempotent), andere Hosts unveraendert.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:27:23 +02:00
e8a521da09
add vault-password for semaphore
2026-04-18 18:59:43 +02:00
sascha
73281a3ac6
ansible: add xray_client role + playbook + [xray] inventory group
...
- New role: xray_client (deploys Xray VLESS+Reality client container)
- New playbook: xray-client.yml
- New inventory group: [xray] (emby-sascha, emby-chris)
- pfannkuchen.sh: new command 'xray'
- Prepared for migration from FRP to Xray tunnel
2026-04-10 22:13:58 +02:00
Kiro
2650391432
fix: disable tcpMux to avoid head-of-line blocking on CGNAT
2026-04-07 22:02:47 +02:00
Kiro
39d83172d3
fix: FRP tuning - disable compression, poolCount 10/20, remove QUIC defaults
2026-04-07 21:51:19 +02:00
feldjaeger
7e87097555
chore: automation VM auskommentiert (deprecated, kann abgeschaltet werden)
2026-04-03 20:32:29 +02:00
feldjaeger
e597839407
chore: pihole entfernt (nicht mehr im Betrieb)
2026-04-03 20:28:06 +02:00
sascha
1509daad4c
dns_resolver role, update-dns script, dns-deploy playbook, inventory updates
2026-04-03 19:42:50 +02:00
feldjaeger
152edb8345
feat: add backup-status push hook to borgmatic template
2026-04-02 11:49:49 +02:00
sascha
eab92ac29f
remove tmp/ from tracking, add to gitignore
2026-03-30 15:56:51 +02:00
sascha
4d305fa19f
initial pfannkuchen
2026-03-30 15:19:20 +02:00
b6dafc7a73
inital
2026-03-03 21:45:41 +01:00