From ec6a723776ece80dff6ca0da9ef5aae847afdd71 Mon Sep 17 00:00:00 2001 From: Arnout van Westen Date: Fri, 2 Oct 2026 16:21:53 +0200 Subject: [PATCH] fix: pocketid encryption key inline, photon image layout, glances py 3.14 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Pocket-ID: ENCRYPTION_KEY contains $ — Komodo .env interpolation eats it. Inline with $$ YAML escape (value already in git history from master.yaml; rotate later). - photon: image dropped uv; use image default CMD, strip stale PATH/JAVA. - glances: PYTHON_VERSION must be 3.14 to match image venv. --- .idea/.gitignore | 8 +++++++ .idea/codeStyles/codeStyleConfig.xml | 5 ++++ .idea/compose-files.iml | 9 +++++++ .idea/developer-tools.xml | 6 +++++ .idea/google-java-format.xml | 6 +++++ .idea/misc.xml | 5 ++++ .idea/modules.xml | 8 +++++++ .idea/vcs.xml | 6 +++++ .junie/memory/errors.md | 0 .junie/memory/feedback.md | 0 .junie/memory/language.json | 1 + .junie/memory/memory.version | 1 + .junie/memory/tasks.md | 0 .mcp.json | 15 ++++++++++++ automation/compose.yaml | 35 ---------------------------- monitoring/compose.yaml | 2 +- pangolin/crowdsec-home-allowlist.sh | 29 +++++++++++++++++++++++ 17 files changed, 100 insertions(+), 36 deletions(-) create mode 100644 .idea/.gitignore create mode 100644 .idea/codeStyles/codeStyleConfig.xml create mode 100644 .idea/compose-files.iml create mode 100644 .idea/developer-tools.xml create mode 100644 .idea/google-java-format.xml create mode 100644 .idea/misc.xml create mode 100644 .idea/modules.xml create mode 100644 .idea/vcs.xml create mode 100644 .junie/memory/errors.md create mode 100644 .junie/memory/feedback.md create mode 100644 .junie/memory/language.json create mode 100644 .junie/memory/memory.version create mode 100644 .junie/memory/tasks.md create mode 100644 .mcp.json create mode 100755 pangolin/crowdsec-home-allowlist.sh diff --git a/.idea/.gitignore b/.idea/.gitignore new file mode 100644 index 0000000..13566b8 --- /dev/null +++ b/.idea/.gitignore @@ -0,0 +1,8 @@ +# Default ignored files +/shelf/ +/workspace.xml +# Editor-based HTTP Client requests +/httpRequests/ +# Datasource local storage ignored files +/dataSources/ +/dataSources.local.xml diff --git a/.idea/codeStyles/codeStyleConfig.xml b/.idea/codeStyles/codeStyleConfig.xml new file mode 100644 index 0000000..a55e7a1 --- /dev/null +++ b/.idea/codeStyles/codeStyleConfig.xml @@ -0,0 +1,5 @@ + + + + \ No newline at end of file diff --git a/.idea/compose-files.iml b/.idea/compose-files.iml new file mode 100644 index 0000000..c202173 --- /dev/null +++ b/.idea/compose-files.iml @@ -0,0 +1,9 @@ + + + + + + + + + \ No newline at end of file diff --git a/.idea/developer-tools.xml b/.idea/developer-tools.xml new file mode 100644 index 0000000..01cefa5 --- /dev/null +++ b/.idea/developer-tools.xml @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/.idea/google-java-format.xml b/.idea/google-java-format.xml new file mode 100644 index 0000000..2aa056d --- /dev/null +++ b/.idea/google-java-format.xml @@ -0,0 +1,6 @@ + + + + + \ No newline at end of file diff --git a/.idea/misc.xml b/.idea/misc.xml new file mode 100644 index 0000000..8e8da41 --- /dev/null +++ b/.idea/misc.xml @@ -0,0 +1,5 @@ + + + + + \ No newline at end of file diff --git a/.idea/modules.xml b/.idea/modules.xml new file mode 100644 index 0000000..1f47e61 --- /dev/null +++ b/.idea/modules.xml @@ -0,0 +1,8 @@ + + + + + + + + \ No newline at end of file diff --git a/.idea/vcs.xml b/.idea/vcs.xml new file mode 100644 index 0000000..35eb1dd --- /dev/null +++ b/.idea/vcs.xml @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/.junie/memory/errors.md b/.junie/memory/errors.md new file mode 100644 index 0000000..e69de29 diff --git a/.junie/memory/feedback.md b/.junie/memory/feedback.md new file mode 100644 index 0000000..e69de29 diff --git a/.junie/memory/language.json b/.junie/memory/language.json new file mode 100644 index 0000000..0637a08 --- /dev/null +++ b/.junie/memory/language.json @@ -0,0 +1 @@ +[] \ No newline at end of file diff --git a/.junie/memory/memory.version b/.junie/memory/memory.version new file mode 100644 index 0000000..f398a20 --- /dev/null +++ b/.junie/memory/memory.version @@ -0,0 +1 @@ +3.0 \ No newline at end of file diff --git a/.junie/memory/tasks.md b/.junie/memory/tasks.md new file mode 100644 index 0000000..e69de29 diff --git a/.mcp.json b/.mcp.json new file mode 100644 index 0000000..4393de3 --- /dev/null +++ b/.mcp.json @@ -0,0 +1,15 @@ +{ + "mcpServers": { + "komodo": { + "type": "http", + "url": "https://komodo-mcp.arnoutvw.nl" + }, + "unraid-mcp": { + "type": "http", + "url": "http://192.168.10.144:8043/mcp", + "headers": { + "Authorization": "Bearer f359c9dbb97d44d98278e0a69e81190706225a4ab7b947ee149b4be470c40763" + } + } + } +} diff --git a/automation/compose.yaml b/automation/compose.yaml index f205337..8e45024 100644 --- a/automation/compose.yaml +++ b/automation/compose.yaml @@ -744,58 +744,23 @@ services: photon: - command: - - "uv" - - "run" - - "-m" - - "src.process_manager" - container_name: "photon" - entrypoint: - - "/bin/sh" - - "entrypoint.sh" - environment: - - "HOST_OS=Unraid" - - "HOST_HOSTNAME=Atlas" - - "HOST_CONTAINERNAME=photon" - "UPDATE_STRATEGY=SEQUENTIAL" - "UPDATE_INTERVAL=720h" - "TZ=Europe/Berlin" - - "PATH=/opt/java/openjdk/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" - - "JAVA_HOME=/opt/java/openjdk" - - "LANG=en_US.UTF-8" - - "LANGUAGE=en_US:en" - - "LC_ALL=en_US.UTF-8" - - "JAVA_VERSION=jdk-21.0.9+10" - - hostname: "df06e527b77c" image: "rtuszik/photon-docker:latest" ipc: "private" - labels: - net.unraid.docker.icon: "https://photon.komoot.io/static/img/photon_logo.png" - net.unraid.docker.managed: "dockerman" - net.unraid.docker.webui: "http://[IP]:[PORT:2322]/" - org.opencontainers.image.description: "Unofficial docker image for the Photon Geocoder" - org.opencontainers.image.documentation: "https://github.com/rtuszik/photon-docker#readme" - org.opencontainers.image.ref.name: "ubuntu" - org.opencontainers.image.source: "https://github.com/rtuszik/photon-docker" - org.opencontainers.image.title: "photon-docker" - org.opencontainers.image.url: "https://github.com/rtuszik/photon-docker" - org.opencontainers.image.version: "24.04" - logging: driver: "json-file" options: max-file: "1" max-size: "50m" - mac_address: "ee:2c:d1:6a:b5:c0" - network_mode: "bridge" ports: diff --git a/monitoring/compose.yaml b/monitoring/compose.yaml index 0b49b25..11b1248 100644 --- a/monitoring/compose.yaml +++ b/monitoring/compose.yaml @@ -71,7 +71,7 @@ services: environment: - "GLANCES_OPT=-w -C /config/glances.conf" - "TZ=Europe/Berlin" - - "PYTHON_VERSION=3.12" + - "PYTHON_VERSION=3.14" expose: - "61208/tcp" - "61209/tcp" diff --git a/pangolin/crowdsec-home-allowlist.sh b/pangolin/crowdsec-home-allowlist.sh new file mode 100755 index 0000000..95e5f7f --- /dev/null +++ b/pangolin/crowdsec-home-allowlist.sh @@ -0,0 +1,29 @@ +#!/bin/bash +# Sync CrowdSec allowlist "home_ddns" with the current A record of thuis.arnoutvw.nl. +# Install: /usr/local/bin/crowdsec-home-allowlist.sh (chmod 755) on pangolin.arnoutvw.nl +# Cron: echo "*/5 * * * * root /usr/local/bin/crowdsec-home-allowlist.sh" > /etc/cron.d/crowdsec-home-allowlist +set -euo pipefail +HOST=thuis.arnoutvw.nl +LIST=home_ddns +CS="docker exec crowdsec cscli" + +want=$(dig +short A "$HOST" @1.1.1.1 | grep -E '^[0-9.]+$' | sort -u || true) +if [ -z "$want" ]; then + logger -t crowdsec-home-allowlist "no A record for $HOST, keeping current allowlist" + exit 0 +fi +have=$($CS allowlists inspect "$LIST" -o json \ + | python3 -c 'import sys,json; [print(i["value"]) for i in (json.load(sys.stdin).get("items") or [])]' | sort -u) + +for ip in $want; do + if ! grep -qxF "$ip" <<<"$have"; then + $CS allowlists add "$LIST" "$ip" -d "$HOST" >/dev/null + logger -t crowdsec-home-allowlist "added $ip" + fi +done +for ip in $have; do + if ! grep -qxF "$ip" <<<"$want"; then + $CS allowlists remove "$LIST" "$ip" >/dev/null + logger -t crowdsec-home-allowlist "removed $ip" + fi +done