makanilani.com — Infrastructure Wiki¶
Human-readable reference for the whole system: what runs where, how to reach it, how things connect, and what was learned the hard way. Last verified: 2026-09-30.
Ops tip: machine-readable snapshots + runbooks live in
vpn-vps/. This file is the map; the directories are the picture.
1. The Big Picture¶
Internet
│
┌──────▼───────┐
│ Cloudflare │ DNS for makanilani.com (+ wildcard *.p.m...)
└──────┬───────┘
│ (A records → VPS)
┌─────────▼───────────┐
│ VPS vpn.makanilani.com
│ 172.238.45.207 (RackNerd, Ubuntu 24.04)
│
│ ├─ Traefik :80/:443 (owns both ports, docker-proxy on gerbil netns)
│ ├─ Pangolin CE dashboard = pangolin.p.makanilani.com
│ ├─ Gerbil WireGuard hub :51820 (sites) + :21820 (client relay)
│ ├─ AdGuard Home DNS :53, admin :81, DoH via Traefik :443
│ └─ WireGuard wg0 personal VPN :57218/udp (10.66.66.0/24)
└─────────┬───────────┐
│ tunnels (WireGuard)
┌──────────────────┴──────────────────┐
│ │
┌───────▼─────────────────┐ ┌──────────▼──────────────┐
│ HAOS raspi │ │ Proxmox 192.168.0.131 │
│ homeassistant │ │ PVE 9.2.20 │
│ 192.168.0.129 │ │ │
│ │ │ LXC 100 hermesagent │
│ ├─ Newt connector │◄──────►│ LXC 101 neo4j │
│ │ (Pangolin site │ LAN │ LXC 102 elementsynapse │
│ │ "home") │ LXC 103 forgejo (git) │
│ ├─ AdGuard Home addon │ │ LXC 104 postgresql │
│ │ DNS :53 for LAN │ │ LXC 105 alpine-cinny │
│ ├─ Nginx Proxy Manager │ │ LXC 106 wekan │
│ │ :81 UI, :80/:443 │ │ │
│ ├─ HA UI :8123 │ └──────────────────────────┘
│ └─ more addons... │
└─────────────────────────┘
Home LAN is 192.168.0.0/24, gateway 192.168.0.1. The Haos raspi runs the LAN DNS (AdGuard) and the reverse proxy (NPM) for local-only access to services.
2. Host-by-host guide¶
2.1 VPS — vpn.makanilani.com (172.238.45.207)¶
Ubuntu 24.04 at RackNerd. Root: ssh -i ~/.ssh/vpn_pangolin root@vpn.makanilani.com.
| Service | Where | Access |
|---|---|---|
| Pangolin + Gerbil + Traefik | /opt/pangolin (docker compose) |
dashboard https://pangolin.p.makanilani.com |
| AdGuard Home | /opt/AdGuardHome — DNS :53, admin UI :81 |
UI also via https://vpn.makanilani.com (DoH) |
| Outbound WG VPN | /etc/wireguard/ wg0 |
port 57218/udp, peers on 10.66.66.x |
| CF DNS token | /opt/pangolin/config/traefik/.cf-env |
used for Let's Encrypt DNS-01 (never in git) |
Tunnel ports (critical): UDP 51820 and 21820 must BOTH be allowed on RackNerd's provider firewall (separate from host ufw!). This bit us once — Newt "bad gateway" until 21820 was opened at the provider edge.
Pangolin gives private access to home-LAN services using *.p.makanilani.com
resources (wildcard Let's Encrypt cert via Cloudflare DNS-01: p.makanilani.com).
Current private resources (site "home", Newt connector on HAOS):
| FQDN | Backend | Notes |
|---|---|---|
| vault.p.makanilani.com | 192.168.0.129:7277 | Vaultwarden on HAOS |
| options.p.makanilani.com | 192.168.0.132:8899 | LAN only, via client resource |
| git.p.makanilani.com | 192.168.0.134:3000 | Forgejo (also in NPM) |
| wekan.p.makanilani.com | 192.168.0.137:8081 | WeKan LXC (also in NPM for LAN) |
| wiki.p.makanilani.com | 192.168.0.132:8898 | mkdocs wiki on hermesagent (also in NPM). PUBLIC — unauthenticated, verified 2026-10-03 (policies: sso/password/whitelist all off, users/roles empty; 200 from VPS WAN vantage) |
| cinny.p.makanilani.com | 192.168.0.136:8080 | Cinny (matrix web client); resource deleted at some point, re-provisioned 2026-09-30 via Integration API; also NPM proxy host 12 |
Pangolin Integration API is enabled (self-host flag) and exposed at
https://api.p.makanilani.com/v1 via a custom Traefik router (int-api-router in
/opt/pangolin/config/traefik/dynamic_config.yml). Bearer token = PANGOLIN_API_KEY
in profile env. Swagger UI at https://api.p.makanilani.com/v1/docs.
Gotchas uncovered by real debugging:
- Pangolin Android client had a bad run in 0.7.x where hole punch traffic never
got sent (fosrl#3478, closed "not_planned"). Fix: reinstall app + verify with
docker exec gerbil wg show wg0 transferon VPS — client peer must move bytes. - Deleting a user client is only possible server-side:
docker exec pangolin pangctl delete-client --orgId <org> --niceId <niceId>(Dashboard only offers "Archive" for user clients). - "Public key mismatch" at re-register is normal. Repeated every connect means stale state — delete + re-enroll client.
- Pangolin reads your Proxmox token from
~/.hermes/profiles/sysadmin/.env.
2.2 HAOS raspi — homeassistant (192.168.0.129)¶
Raspberry Pi 5, HAOS 18.3, Supervisor 1.14.0. ~28 GB disk (used ~18 GB).
SSH root: ssh -i ~/.ssh/forgejo_hermes root@192.168.0.129 → lands in
"Advanced SSH & Web Terminal" addon container (a0d7b954-ssh), with the
full ha CLI available. Must use root — homeassistant@ is rejected.
HA REST API: see HASS_URL / HASS_TOKEN in the sysadmin profile env.
HA long-lived tokens do not work over websocket (auth_invalid on
/api/websocket) — they only work on REST (/api/…). Use REST + ha over SSH.
Key addon slugs:
| Addon | Slug | Port / notes |
|---|---|---|
| Advanced SSH & Web Terminal | a0d7b954_ssh |
:22, keys in addon config tab, restart after edit |
| Nginx Proxy Manager | a0d7b954_nginxproxymanager |
UI :81, proxy :80/:443 — yes, NPM owns LAN :80/:443 too! Best used for LAN routes (git.lan etc.) |
| AdGuard Home | a0d7b954_adguard |
DNS :53 for LAN. Default UI via HA Ingress only; direct API on :3000 (HA basic auth) |
| Newt (Pangolin connector) | 96282436_newt |
connects this box's resources to VPS tunnels |
| Vaultwarden | a0d7b954_bitwarden |
:7277 |
| Portainer | db21ed7f_portainer |
manages HAOS docker |
| WireGuard | a0d7b954_wireguard |
personal VPN |
| Monica | db21ed7f_monica |
:8181 |
| Joplin Server | db21ed7f_joplin |
:22300 |
| Postgres 17 / pgAdmin4 | db21ed7f_postgres_latest / 77b2833f_pgadmin4 |
|
| Matter Server | core_matter_server |
|
| File editor | core_configurator |
|
| ESPHome | 5c53de3b_esphome |
|
| Duck DNS | core_duckdns |
AdGuard Home LAN (the one your devices actually use!) runs here, not on the VPS.
- UI: via HA sidebar → AdGuard Home (Ingress). Direct API on port 3000 is disabled by default and only unlocked by setting a Network → port override then restarting the addon. Currently 3000 is open with HA basic auth.
- Basic auth gotcha: NGINX in front (from the addon) validates against your Home Assistant login (not the AdGuard admin). Successful basic-auth = HA creds, which then talk to AdGuard's API itself (only if AdGuard has no users configured — which is our case).
- API endpoints (mounted under
/control, e.g.http://192.168.0.129:3000/control/…): GET /control/statusGET /control/rewrite/listPOST /control/rewrite/addor/control/rewrite/deletewith JSON{"domain":"x.example.com","answer":"192.168.0.x"}- Current rewrites include (as of 2026‑09‑27): matrix, git, vault, joplin, ma pointing to HAOS (192.168.0.129); git.lan → .134, hermes.lan → .132, proxmox.lan → .131, cinny.lan → .136, matrix.lan → .133.
- WeKan rewrites were just added:
wekan.p.makanilani.comandwekan.lan→ 192.168.0.129 (a different direction — they go through NPM, see below).
Note also: personal VPN WireGuard on wg0 (VPS) has each peer's /32 and uses
10.66.66.x. AdGuard (this one) is the LAN's resolver, different from the
VPS's /opt/AdGuardHome on the VPS itself. They're separate installs.
2.3 Proxmox — 192.168.0.131 (node "proxmox")¶
PVE 9.2.20, single node, ~31 GB RAM, local-lvm 94 GB free.
API/token (recommended for automation, password never on disk):
root@pam!hermes — token secret stored in sysadmin .env as PROXMOX_API_TOKEN
(the "full" string you'd need at login is root@pam!hermes=SECRET;
stored value includes that left-hand prefix).
Reachability:
- HTTPS API (turned on for the hermesagent token): https://192.168.0.131:8006/api2/json/version
- SSH: ssh -i ~/.ssh/forgejo_hermes root@192.168.0.131 (root key auth works).
Existing guests (as of 2026-09):
| VMID | Name | Type | Notes |
|---|---|---|---|
| 100 | hermesagent | LXC | this agent itself — Debian with hermes running |
| 101 | neo4j | LXC | |
| 102 | elementsynapse | LXC | Matrix Synapse |
| 103 | forgejo | LXC | Forgejo git server |
| 104 | postgresql | LXC | |
| 105 | alpine-cinny | LXC | Cinny web client (Alpine, minimal) |
| 106 | wekan | LXC | WeKan + MongoDB 8 (unprivileged, nesting, DHCP) |
| 107 | forex | LXC | CT 107 — live paper loop on /opt/forex; deploy via home-proxmox/ct107-forex-deploy.md + scripts/ct107-forex-deploy.sh |
| 110 | hindsight | LXC | Hindsight agent-memory (shared for Hermes/CC/OpenCode/pi) — see §2.5 |
2.4 LXC 106 — "wekan"¶
Debian 13.6, 2 cores / 2 GB RAM / 16 GB disk, under /opt/wekan:
- MongoDB 8.0.32 →
mongodsystemd service (bound to 127.0.0.1) - WeKan v12.06 →
wekansystemd service,main.jsrun as root, env file/etc/wekan-env,WRITABLE_PATH=/opt/wekan/uploads(without WRITABLE_PATH it crash-loops with "Universal file server" errors)
2.5 LXC 110 — "hindsight" (agent memory, 192.168.0.184)¶
Debian 13, 2 cores / 4 GB RAM / 12 GB disk, unprivileged + nesting (Docker).
Built via community-scripts ct/docker.sh (positional default arg makes it
non-interactive; interactive read prompts inside install/docker-install.sh
fail under lxc-attach but Docker is fully installed by then — CT is usable).
Runs Hindsight 0.10.2 — shared
long-term memory bank for Hermes (sysadmin first), Claude Code (ai-rig),
OpenCode, pi. MIT license, embedded Postgres (pg0 volume), local
embeddings/reranker; knowledge extraction via OpenRouter openai/gpt-oss-20b
(key injected via env_file, real key only on-box in
/root/hindsight/hindsight.env).
- REST + MCP (LAN, direct):
http://192.168.0.184:8888/.lanshort namehindsight.lan(physical-IP convention) - REST+MCP via HTTPS (LAN, NPM):
https://hindsight.p.makanilani.com— NPM proxy host 13 (→ 192.168.0.184:8888), Let's Encrypt DNS-01 cert id 16 via Cloudflare token on the VPS (/opt/pangolin/config/traefik/.cf-env); verified 2026-10-07 (200, SSL verify ok) - Control-plane UI:
http://192.168.0.184:9999(LAN only; NPM host covers :8888 only) - AdGuard rewrites:
hindsight.p.makanilani.com→ .129 (NPM),hindsight.lan→ .184 (physical) - Pangolin remote-access leg: intentionally NOT provisioned — add a site resource under the wildcard when outside-LAN use is actually needed
- Deploy:
/root/hindsight/docker-compose.yml+hindsight.env(in CT); template + Hermes plugin config in repo athindsight/ - Hermes wiring:
memory.provider = hindsightin profile config, pluginhindsight(catalog), config json at~/.hermes/profiles/<profile>/hindsight/config.jsonwithmode: local_external,api_url: http://192.168.0.184:8888,bank_id: infra - Endpoints used:
POST /v1/default/banks/{bank}/memories(retain),POST /v1/default/banks/{bank}/memories/recall(recall),GET /health
Do not run a local LLM sidecar here: 4 GB CT RAM cannot fit llama.cpp+API+Postgres ; llama.cpp mmap thrash caused 460 MB/s read storms on the Proxmox node (fixed by switching to OpenRouter).
Upgrade gotchas that cost real time — must do these in this order:
apt-get install -y nodejs mongodb unzip(node 20 works with current WeKan)- PostgreSQL 8.0 apt repo for Debian 13 (trixie) does not exist — use the Debian 12 (bookworm) repo of MongoDB 8.0, it works fine.
- Meteor bundles must be rebuilt:
cd /opt/wekan/bundle/programs/server && npm ci— if plainnpm installfails on the rebuild step withMETEOR_SKIP_NPM_REBUILDerrors, useMETEOR_SKIP_NPM_REBUILD=1 npm installthen runnode npm-rebuild.jsseparately. - Always restart
wekanafter config changes, then curlhttp://127.0.0.1:8081/returning HTTP 200 = healthy.
Configs:
- Pangolin: private resource (siteResourceId 3), domain domain1 (= p.makanilani.com
wildcard), subdomain wekan, destination 192.168.0.137:8081, attach user vr7wzkztoy9tcg8.
- AdGuard: two rewrites, both for the "no round trip to VPS" goal:
wekan.p.makanilani.com → 192.168.0.129 (NPM), and wekan.lan → 192.168.0.129 (same target)
- NPM: proxy host 9, wekan.p.makanilani.com → 192.168.0.137:8081,
with block_exploits + allow_websocket (must NOT use allow_websocket
via the normal field, we had to put the WS proxy headers into
advanced_config because allow_websocket isn't part of the v2.15 API schema),
+ cert id 10 (Let's Encrypt, Cloudflare DNS-01, renewed by NPM).
- HTTPS inside LAN works with real Let's Encrypt cert (via NPM), no warnings in browser.
Accounts:
- WeKan admin: ysakakibara / ysakakibara@gmail.com, isAdmin: true (auto-promoted
for first registered user).
- Agent accounts (2026-09-27, all isAdmin: false, temp password scheme
Wekan-Temp-<year>x — value lives in the sysadmin wekan-administration skill
and on the ai-rig at /home/ysakakibara/.wekan-credentials, not in git):
| Username | Purpose | |
|---|---|---|
claude-code |
claude-code@makanilani.com | ai-rig Claude Code (skill ~/.claude/skills/wekan/SKILL.md on the rig) |
hermes-sysadmin |
sysadmin@makanilani.com | Hermes sysadmin profile |
hermes-analyst |
analyst@makanilani.com | Hermes analyst profile |
hermes-main |
main@makanilani.com | Hermes default profile |
- Boards: Infrastructure
FqghMjSdsx997LmSC(private; all 4 agent accounts + Yasu, list "To Do"Xa2ky8vNXtDoQQhJi), VolSurfAEi538gzgcSwwMsyo6R(private; created by claude-code — board admin — plus Yasu as member), Forex System — Phase 1Nz3YRyab2xMNz2GpC(public; hermes-bot + Yasu). - Direct-mongo user creation rules (learned the hard way, 2026-09-27 — REST login 401s otherwise):
- Hash must be
bcrypt(sha256_hex(password))— Meteor never bcrypts the raw password; raw bcrypt always fails login. _idmust be a 17-char Meteor string id (Random.id alphabet). ObjectId_idusers pass bcrypt but fail token issuance with 403 "Invalid credentials"; ObjectId_idboards 404 on all REST routes. Fix = delete + re-insert with string id (username has a unique index), remappingmembers[].userIdrefs. Pre-fix backups:/root/wekan-users-backup.json,/root/wekan-board-backup.jsonon CT 106.GET /api/boards(the list) is admin-only by design — non-admin agents must call/api/boards/<boardId>directly.- REST cannot ADD board members (
POST .../members/<uid>only updates existing ones) — add via mongo$push members {...}with the full flag set (schema permodels/boards.js addMember). Assignees must be board members. - To reset a WeKan user to a temp password when needed, use mongo:
mongosh wekan --eval 'db.users.updateOne({username:"X"},{$set:bCryptHash})'and then reset via the client recovery paths described inwekandocs. - ADGuard password was rotated for API use — the login is
ysakakibara@gmail.comwith the HA password. If you don't know it, just re-type it in the HA UI and it'll re-bcrypt the file.
3. Credentials & tokens — where they live¶
| Item | Name in profile env | Location |
|---|---|---|
| Home Assistant API | HASS_TOKEN |
~/.hermes/profiles/sysadmin/.env |
| Proxmox API token | PROXMOX_API_TOKEN (+ PROXMOX_URL) |
same file |
| Pangolin API key | PANGOLIN_API_KEY, PANGOLIN_SERVER_URL |
same file |
| NPM admin | NPM_USERNAME, NPM_PASSWORD |
same file |
Cloudflare DNS (for makanilani.com) |
NOT in git — on the VPS at /opt/pangolin/config/traefik/.cf-env |
|
| Forgejo PAT (scoped, per-agent) | FORGEJO_TOKEN |
each profile env: default+sysadmin=agent-sysadmin, coder, claude_laptop=claude-laptop-pr (laptop). NOTE: reviewer profile env BLANKED 2026-10-02 (formal-reviewer token lives with Command Code, not with the reviewer profile) |
| Forgejo break-glass admin (ysakakibara) | break-glass-2026-10-01 |
sysadmin tmp/break_glass_forgejo.txt (mode 600) |
| SSH keys | ~/.ssh/forgejo_hermes, ~/.ssh/vpn_pangolin |
~/.ssh/ |
Rule of thumb: secrets never in git. infra-configs carries snapshots and
runbooks only.
- 2026-10-02 — formal
hermes_reviewertoken handoff: mintedreviewer-commandcode-2026-10-02(uid 6, scopes write:issue,write:repository,read:user) server-side on CT 103 (HTTP token create is 401-blocked on this build); stored at/home/hermes/.config/command-code/forgejo.env(mode 600, FORGEJO_TOKEN + FORGEJO_HOST). Command Code (npmcommand-code, binarycmd) installed user-level (/home/hermes/.local/bin/cmd, v1.74.1). Reviewer profile envFORGEJO_TOKENblanked (backup.env.bak-swap-2026-10-02); old token id 31reviewer-profilerevoked via direct DB delete + 401 probe. Default profileagent-*tokens untouched.
4. Access cheat-sheet¶
# VPS (Pangolin, Traefik, VPS AdGuard, wg0 personal VPN)
ssh -i ~/.ssh/vpn_pangolin root@vpn.makanilani.com
# HAOS raspi (AdGuard LAN, NPM, HA, Newt, Vaultwarden, …)
ssh -i ~/.ssh/forgejo_hermes root@192.168.0.129 # lands in "Advanced SSH" addon; `ha` CLI works
# Proxmox node
ssh -i ~/.ssh/forgejo_hermes root@192.168.0.131
# or API:
export PROXMOX_URL=https://192.168.0.131:8006
curl -sk -H "Authorization: PVEAPIToken=root@pam!hermes=$PROXMOX_API_TOKEN" \
$PROXMOX_URL/api2/json/version
# WeKan LXC
ssh -i ~/.ssh/forgejo_hermes root@192.168.0.137 # DHCP IP, check AdGuard rewrite for current
# Local services (LAN, no detour)
open http://192.168.0.129:81 # NPM
open http://192.168.0.129:8123 # HA
open https://192.168.0.131:8006 # Proxmox UI
open http://wekan.lan # WeKan via NPM on LAN
5. Self-documenting conventions¶
- Don't push secrets to GitHub. The
.env-in-hermes-profile file (or encrypted 1Password) is the only vault. Anything you'd hate to leak — CF token, AdGuard bcrypt hash, mongo passwords, WeKan user bcrypt hashes, Proxmox root — must not appear as plaintext here. - Prefer API-driven config edits over manual UI clicking, so changes are reproducible (especially: NPM proxy hosts, AdGuard rewrites, Pangolin resources).
- Infrastructure should be re-buildable from this repo: fresh VPS → redo file
copy for WireGuard/AdGuard → runinstall Pangolin → run the
vpn-vps/runbook. Wekan LXC: clone or rebuild via the notes above. - Own the docs. If you debug something new (that "Public key mismatch" 一汽, that 21820/51820 hole punch issue), add it to the relevant Gotchas section here instead of cursed know-how in your head.
6. Change log (top = newest)¶
-
2026-10-09 — CT 107 deploy is now script + runbook: PR #3 merged —
home-proxmox/ct107-forex-deploy.md(the documented repeatable deploy runbook) andhome-proxmox/scripts/ct107-forex-deploy.sh(the deploy script, dry-run default,--yesrequired to restart) committed on main;home-proxmox/ct107-operating-guide.mdcross-references both. -
2026-10-08 — CT 107 forex agent-access grant: claude_laptop (Yasu's @claude_laptop agent) added to
/root/.ssh/authorized_keys(ssh-ed25519, comment "ysakakibara@gmail.com claude_laptop 2026-10-08"); grant requested in chat by Yasu. New operating doc:home-proxmox/ct107-operating-guide.md(access, services, safety rules from the 2026-10-02 wedge incident). -
2026-10-07 — infra-configs canonical remote is now Forgejo (git.makanilani.com/makanilani.com/infra-configs); GitHub mirror retired & archived, do not push there. Added LXC 110 "hindsight" (192.168.0.184): Hindsight 0.10.2 shared agent-memory (Hermes/CC/OpenCode/pi), OpenRouter
openai/gpt-oss-20bfor knowledge extraction, embedded Postgres, ports 8888 (REST+MCP) + 9999 (UI) bound to CT LAN IP; deploy template athindsight/. Hermes sysadmin wired via catalog plugin +local_externalmode, bankinfra. Do not run a local LLM in this CT (4 GB CT RAM; earlier llama.cpp attempt thrashed the node's disk at 460 MB/s — see §2.5). -
2026-10-04 — Forgejo identity/token re-provisioning (supersedes the 2026-10-01 rotation below): token table 17→8. Per-consumer tokens on
hermes(default/sysadmin/coder/dispatcher profiles — the shared-value pair split),claude_laptop,claude_rig, named<account>-<machine>-<consumer>-<date>, all scopedwrite:repository,write:issue,read:user. Revoked: old hermes profile tokens (ids 2,3,9,11), standing admin-scopeagents-rbac-1002(22), old claude_laptop (8) + claude_rig (19) tokens, 9 gate-test leftovers (23–30). Kept: break-glass id 6 (ysakakibara only), reviewer id 33 (Command Code, frozen scope). Verified per probe matrix: 200 on /user per new token, 403 on /admin/users, branch create+delete write-probe on infra-configs, 401 on every revoked value, final DB count = 8. Stale old-value copies purged (terminal snapshot caches, rotated logs, env backups); staging files destroyed after delivery. Runbook:home-proxmox/forgejo/rotate-forgejo-20261004-v2.sh(v1 aborted mid-flight on an env-path bug; its 6 orphan mints were revoked and names reused — mint-capture now persists to disk before any later phase can abort). Laptop/rig values delivered to owner in chat. -
2026-10-01 — Forgejo token rotation: shared admin-scoped
agent_accessPAT (existed in default/ coder/reviewer/sysadmin profile envs) revoked; replaced with per-agent scoped PATs on thehermesaccount (agent-sysadmin/coder/reviewer) + PR-capable token onclaude_laptop; break-glassallPAT minted for ysakakibara (stored in sysadmin tmp/, mode 600). Old token-value copies purged from env backups + terminal snapshot cache. -
2026-10-01 (later) — Forgejo webhook → Hermes pipeline live: authorized
hermessudoer account on CT103 (keyforgejo_hermes), fixed~/.sshroot-ownership StrictModes block, appended[webhook] ALLOWED_HOST_LIST = privateto app.ini (backup.bak-webhook-allowlist-20261001), hub on :8644 (hermes-gateway-sysadmin.service, linger on), routeforgejo-eventsw/ HMAC secret +forgejo-route-filter.py(makanilani.com PR/comment events only), hooks re-created on all 4 repos (ids 9–12 →http://192.168.0.132:8644/webhooks/forgejo-events, signed). Verified signed delivery Forgejo→Hermes end-to-end (hook_task id 13 → 200). Gotchas learned: X-Forgejo-Signature header is NOT accepted by Hermes — it validatesX-Hub-Signature-256;hook .../testsfires as event typepush(not the payload's embedded event), so route filter drops it — a real PR/comment event is what proves routing. -
2026-09-30 — Cinny restore: Pangolin site-resource had been deleted ( unearthed by cinny outage; ONLY vault/options/wekan/wiki remained; cinny served 404 from the wildcard catchall). Re-provisioned via Integration API (PUT /org/…/private-resource → siteResourceId 5, target row arrived correct, NO legacy resources-row needed — 1.23 generates routers straight from siteResources; the 3-step realign dance in the provisioning skill is legacy-era for this install). LAN legs restored independently: NPM proxy host 12 (cinny.p.makanilani.com → 192.168.0.136:8080, cert id 13, DNS-01 via Cloudflare, allow_websocket NOT in schema — WS headers in advanced_config) + AGH rewrite cinny.p.makanilani.com → .129 (cinny.lan → .136 already existed). Learned: anonymous curl on a 1.23 site-resource now ALWAYS shows
<title>Private Placeholder(badger session-gated, middlewaresite-resource-cert-N-rewriteon ALL of vault/options/wekan/cinny) — the placeholder title is NOT a misconfiguration tell anymore; differentiator is a client-side test with an authenticated client (or compare vs a known-good resource serving the same shape). - 2026-10-03 — Japan Media Landscape OKF bundle published as SECTION of the
infra wiki (Yasu-approved option 2 = subpath, not hostname takeover):
https://wiki.p.makanilani.com/japan-media-landscape/. Bridge mechanism = hooks.py mount: copied the bundle intodocs/japan-media-landscape/, addedjapan-media-landscapetoextra.abs_link_mountsin mkdocs.yml (mount name = first path segment), amended sync.sh to re-copy from the read-only source bundle (/home/hermes/Documents/okf_bundles/japan-media-landscape/) at the start of every sync run (so it survives rebuilds and never goes silently stale). Source bundle NOT committed anywhere — build artefact only. Config versioned athome-proxmox/wiki-serve/(mkdocs.yml, sync.sh, classify_links.py; first versioning of these files — they had lived on-box only). Link health after publish: actionable=12 source-citations=110, at the 2026-09-29 baseline (12), no regression. Same sync run also surfaced one known-good WARN:templates/concept.mdbundles an intentional placeholder wikilink (00-foundations/example.md), bundle-intended. Pangolin finding (live-falsified from the VPS WAN vantage): git.p has sso=true → 401 from outside LAN (gate exists), while wiki.p showed sso=0, passwordId/pincodeId/whitelist/headerAuthId all null, users/roles/rules empty → 200 from outside LAN, NO auth. wiki.p is an UNAUTHENTICATED hostname; note in the private-resources table above. 2026-09-27's change row called it a "Pangolin private resource" — misleading; private resources are gated by default so this one was likely created with SSO off. - 2026-09-29 — Wiki LAN access without Pangolin: NPM proxy host 10
wiki.p.makanilani.com→ 192.168.0.132:8898 with Let's Encrypt cert id 11 (Cloudflare DNS-01); AdGuard rewrites added:wiki.p.makanilani.com→ .129 (NPM, keeps TLS by Host header) andwiki.lan→ .132 (physical IP, direct :8898). Pangolin resource id 4 unchanged for remote/tunnel path. Proxmox node SSH re-enabled for forgejo_hermes key (authorized_keys had lost it). - 2026-09-27 — Wiki server live on hermesagent LXC (:8898): mkdocs-material
build of options-system-wiki + infra WIKI.md, wiki-sync.timer every 5 min,
Pangolin private resource
wiki.p.makanilani.com→ 192.168.0.132:8898 (resource id 4, site-resource target via newt; Integration API worked at pangolin container IP :3003, not via api.p/pangolin.p hostnames). - 2026-09-27 — WeKan LXC (CT 106) live: Pangolin private resource, NPM LAN
reverse-proxy with Let's Encrypt cert id 10 (Cloudflare DNS-01), AdGuard
rewrites for
wekan.p.makanilani.comandwekan.lan. - 2026-09-26 — Proxmox API token
root@pam!hermes+ privilege separation disabled so hermesagent can create LXCs. Pangolin integration API enabled, routed atapi.p.makanilani.com/v1. - 2026-09-24 — tmp WIP pitfalls resolved: Pangolin Android client punch bug
(fosrl#3478),
pangctl delete-clientonly real way to remove user clients. - 2026-09-23 — first connection of Pixel-9a Pangolin (OLM) — rackner edge needed udp/21820 open in addition to host ufw.
- 2026-09-22 — initial Pangolin install on VPS; wildcard LE certificate via Cloudflare DNS-01; HAOS Newt connector site "home".