Files

145 lines
8.6 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# openbureau Homelab — Dokumentation
> Stand: 2026-06-04 · Aktueller Ist-Zustand des fertig aufgebauten Homelabs.
> Der ursprüngliche Plan liegt unter [`plan/`](./plan/) (kann von der Realität abweichen).
---
## 1. Architektur in einem Bild
```
Internet
┌───────▼─────────┐ WireGuard-Reverse-Tunnel ┌──────────────────────────┐
│ VPS 46.225.70.71│◄════════════════════════════════════════│ Heim-Gateway CT101 │
│ (Caddy + Mail) │ VPS wählt NICHT an — das HEIM dialt │ 10.10.0.2 / wählt VPS an │
│ *.kgva.ch │ (Heim öffnet KEINE Ports) └────────────┬──────────────┘
│ Let's Encrypt │ │
└──────────────────┘ Heim-LAN 192.168.1.0/24
Proxmox "tanin" 192.168.1.2
(LXC-Container, ZFS)
```
- **Heim (Proxmox „tanin", 192.168.1.2):** Hypervisor. Ein Dienst = ein LXC-Container. ZFS: `rpool` (System, NVMe), `tank` (Daten, 2×4 TB Mirror).
- **VPS (46.225.70.71):** **Caddy** terminiert HTTPS für alle Domains (Let's-Encrypt-Wildcard `*.kgva.ch`) und proxyt via Tunnel ins Heim-LAN. Hostet zusätzlich den **Mailserver** (docker-mailserver).
- **WireGuard-Reverse-Tunnel:** Das Heim-Gateway (CT101) baut den Tunnel zum VPS auf → **das Heim muss KEINE Ports öffnen**. Der VPS routet `192.168.1.0/24` durch den Tunnel.
- **AdGuard (CT103):** netzweiter **DHCP** (.10.99) + **DNS** + Adblock.
- **Zugang von außen:**
- *Einzelne Dienste:* öffentliche Domain → VPS-Caddy → Heim. Kein VPN nötig.
- *Komplettes Heimnetz:* **WireGuard-Client** (Laptop/Handy-Config, nutzt AdGuard als DNS).
---
## 2. Dienst-Inventar
> **IP-Konvention:** `192.168.1.<CTID>` (außerhalb des DHCP-Bereichs). Ausnahmen: alte Instanzen behalten .177/.178.
| CT | IP | Dienst | Domain(s) | Zweck |
|----|------|--------|-----------|-------|
| 100 | .100 | **PBS** | — (intern :8007) | Proxmox Backup Server |
| 101 | .101 | **wg-gateway** | — | WireGuard-Reverse-Tunnel zum VPS |
| 102 | .102 | **fileserver** | — (Samba) | Samba-Shares `kgva` + `private` (in Nextcloud eingebunden) |
| 103 | .103 | **adguard** | — (:80) | DHCP + DNS + Adblock |
| 110 | .110 | **nextcloud** (neu) | cloud.kgva.ch | Hauptcloud (Rieger-Setup, shibui-Theme) |
| 111 | .111 | **immich** | immich.kgva.ch | Fotos/Videos |
| 112 | .112 | **vaultwarden** | vault.kgva.ch · vault.gabrielevarano.ch | Passwort-Tresor |
| 113 | .113 | **paperless** | — (:8000) | Dokumente + OCR |
| 114 | .114 | **dashboard** | — (:8080, intern/VPN) | Glance-Dashboard |
| 115 | .115 | **collabora** | collabora.kgva.ch (:9980) · whiteboard.kgva.ch (:3002) | Office + Whiteboard |
| 116 | .116 | **stirling** | pdf.kgva.ch | Stirling-PDF (PDF-Werkzeuge) |
| 120 | .120 | **gitea** | git.openbureau.ch · git.kgva.ch | Git (DIESES Repo) |
| 130 | .130 | **kgva-website** | karimgabrielevarano.xyz | Website |
| 132 | .132 | **rapport-website** | rapport.openbureau.ch | Website |
| 133 | .133 | **dossier-website** | dossier.openbureau.ch | Website |
| 134 | .134 | **openbureau-dev** | dev.openbureau.ch | Dev (Supabase-style :8000 / Web :8080) |
| 135 | .135 | **trattoriamarina.ch** | (Website) | Marinas Trattoria |
| 140 | .140 | **studio** | studio.kgva.ch (:8080) · api.studio.kgva.ch (:8000) | **Supabase** (Social-Media-Backend) — *von anderer Claude-Instanz betreut* |
| 800 | **.177** | **nextcloud-old** | cloud.gabrielevarano.ch | ALTE Nextcloud (Altdaten, 400 GB-Quota) |
| 802 | .14 (DHCP) | vaultwarden-old | — | alt, läuft sporadisch |
| 805/807/810/811/910/919/990 | — | *-old | — | alte Pre-Rebuild-Gäste (meist gestoppt) |
**VPS-Dienste (auf 46.225.70.71):**
| Domain | Dienst |
|--------|--------|
| mail.kgva.ch | docker-mailserver (Postfix/Dovecot/Rspamd, DKIM) |
| webmail.kgva.ch | SnappyMail |
| mailadmin.kgva.ch | DMS Admin-UI |
**Mail-Konten:** u. a. `karim@gabrielevarano.ch` (von hosttech migriert), kgva.ch-Adressen. MX → `mail.kgva.ch`, SPF/DKIM/DMARC gesetzt.
---
## 3. Backup
- **PBS (CT100)** · Datastore **`backup`** auf der **Seagate Expansion HDD** (USB, xfs, `/datastore-hdd`, bind in CT100).
- **PVE-Storage:** `pbs` → Datastore `backup`.
- **Job:** täglich **02:30 + 14:30** (2×/Tag), alle Gäste, `mode snapshot`, **inkrementell + dedupliziert**.
- **Retention:** `keep-last=4, keep-daily=7, keep-weekly=4, keep-monthly=3`.
- **Kingston XS1000 SSD** wurde entfernt/freigeräumt (war der alte Pre-Wipe-Speicher).
- **Reboot-Fix:** `/etc/tmpfiles.d/zz-pbs-runtime.conf` in CT100 (sonst `/run/proxmox-backup`-EACCES nach Reboot).
- **Wiederherstellung:** PBS-WebUI (CT100:8007) oder `qmrestore`/`pct restore` aus dem `pbs`-Storage.
---
## 4. Netzwerk / DNS
- **DHCP-Bereich (AdGuard):** 192.168.1.**1099** → statische IPs immer ≥ .100 wählen.
- **Statische IP für eine CT:** PVE `net0` auf `ip=192.168.1.X/24,gw=192.168.1.1` **UND** intern `/etc/network/interfaces``iface eth0 inet static` (sonst zieht der Container trotzdem DHCP!).
- **AdGuard-DNS-Rewrites:** aktuell keine (immich.gabrielevarano.ch wurde entfernt → Immich nur noch über `immich.kgva.ch`).
- **Wildcard `*.kgva.ch`** → VPS. `gabrielevarano.ch` hat eine Wildcard, `openbureau.ch`/`karimgabrielevarano.xyz` eigene A-Records.
---
## 5. Zugang & Passwörter
- **SSH:** `~/.ssh/proxmox_homelab` → Host .2 · `~/.ssh/vps_kgva` → VPS.
- **Proxmox-UI:** https://192.168.1.2:8006 (root@pam). Subscription-Nag ist dauerhaft gepatcht (siehe How-Tos).
- **Glance-Dashboard:** http://192.168.1.114:8080 (nur intern/VPN).
- **Service-Logins:** sollen alle in **Vaultwarden** zentralisiert werden (Rotations-Skript: `/root/rotate-passwords.py` auf dem Host → erzeugt Bitwarden-Import-CSV).
- ⚠️ **Sicherheits-To-do:** Viele Dienste nutzen aktuell noch `Rationalism2025!`. **AdGuard:** `admin` / `Rationalism2026!`. → bei Gelegenheit rotieren.
---
## 6. How-Tos
### Neuen Dienst hinzufügen
1. CT anlegen (Debian-Template, unprivilegiert, `features nesting=1,keyctl=1`, static `ip=192.168.1.X/24,gw=…`).
2. `/etc/network/interfaces` intern auf **static** stellen.
3. Docker installieren (`curl -fsSL https://get.docker.com | sh`) + Dienst per compose.
4. Im **VPS-Caddyfile** (`/opt/dms-stack/caddy/Caddyfile`) Block ergänzen:
```
meinedienst.kgva.ch {
reverse_proxy 192.168.1.X:PORT
}
```
dann `docker restart dms-caddy` (Caddy holt das Cert automatisch, da `*.kgva.ch`-Wildcard).
5. Optional: ins Glance-Dashboard (Monitor + Bookmark) aufnehmen.
### Proxmox-Subscription-Nag (dauerhaft entfernt)
- Patch-Script: `/usr/local/bin/pve-no-nag.sh` (setzt `!== 'active'` → `=== 'active'` in `proxmoxlib.js`).
- apt-Hook `/etc/apt/apt.conf.d/no-nag-script` re-patcht nach **jedem** Update.
- Kommt der Nag mal wieder: nur Browser-Cache (Strg+Shift+R), der Server ist gepatcht.
### Glance-Dashboard
- CT114, Docker, Config in `/opt/glance/{config/glance.yml, assets/}`.
- **Wichtig:** Custom-CSS muss unter `server.assets-path` (`/app/assets`) liegen und als `/assets/custom.css` referenziert werden (aus `/app/config` liefert Glance es mit 404).
- Daten-API für die Widgets: Python-Dienst auf dem **Host** (`/opt/zfs-api/zfs_api.py`, systemd `zfs-api`, Port 9099) → `/pools /guests /errors /backup /sysinfo /adguard`. Plus **Glances** auf dem Host (systemd `glances`, Port 61208, `-w --disable-webui`).
### Whiteboard / Collabora (Nextcloud)
- Beide laufen in CT115. WOPI-Allowlist auf `0.0.0.0/0,::/0` (Tunnel-Routing macht IP-Härtung unpraktikabel).
- Whiteboard-Verify-Button meldet fälschlich „timeout" — die Echtzeit-Collaboration funktioniert trotzdem.
---
## 7. Offene Punkte / To-do
- [ ] **openbureau.ch (CT131)** — Caddy zeigt auf .131:80, Container existiert noch nicht → 502. openbureau-Suite bauen (Website/dev/app/rapport-server).
- [ ] **Passwörter rotieren** (`/root/rotate-passwords.py --apply`) + in Vaultwarden importieren.
- [ ] Master-Passwörter (Vaultwarden) + `Rationalism2025!` ablösen.
- [ ] Entscheiden: Flarum (CT810) / Obsidian-LiveSync (CT805) zurückbringen?
- [ ] Alte „-old"-Container aufräumen (NACH der Suite-Migration; CT800 mit Altdaten behalten).
---
*Diese Doku wird manuell gepflegt. Bei Änderungen am Setup hier nachziehen.*