c136daf reverted the renovate redis-8.x bump by restoring the pre-bump
file. Redis 8.10 wrote an RDB v15 dump to the shared volume; redis 7.4
cannot read it. Restore the 8.10-alpine tag so the dump loads.
Own watcher (docker:28-cli + handler.sh): attaches traefik to every docker
network labelled traefik.enable=true (daemon-side filter), 5-min periodic
resync + traefik-restart healing. dawarich/teslamate back on private
networks with the net label set.
Per request: TNC removed, all stacks back on default bridge with legacy
links for inter-container DNS (default bridge has no embedded DNS —
verified: nameserver passthrough to AdGuard). Kept: traefik router labels
(dnsweaver records), dawarich prod + SECRET_KEY_BASE, teslamate/bookorbit
hostport removals (service DNS now via links), komodo periphery as
separate project with 8120 hostport + server address change.
All HTTP-served containers (web UIs + metrics APIs) now carry explicit
router-rule labels so dnsweaver manages their arnoutvw.nl rewrites end
to end (no more relying on traefik defaultRule). krusader fixed to
noVNC 8080-ish label -> 6080. EXCLUDE_DOMAINS reduced to databases,
workers and agents (postgres14/mariadb/redis/postgresql17/komodo-mongo/
bookorbit-db/immich_postgres/immich_ml/dawarich_*db-redis-sidekiq/
influxdb/newt*/komodo-periphery/dockersocket/subsyncarr/wordpress-blues).
Region value=EU is not a UN M.49 subregion id (the only real invalid reason)
so rules are omitted entirely, matching how existing resources are configured.
port/ssl/healthcheck as labels arrive as strings and fail Zod (z.int/z.boolean);
drop those, rely on auto-detection (container hostname + exposed port, ssl
default on) and pangolin-side defaults for rules/auth.
Primary pangolin skips legacy proxy-resources labels entirely ('All
resources were invalid and skipped'); secondary ee-1.24 accepted them.
Switch gitea+komodo to current public-resources syntax with mode=http.
Per komodo discussion #223: periphery executes deploys; compose child
recreating its own parent dies mid-deploy. Core stack = mongo+core+mcp;
periphery = separate project on the same external komodo-internal network.
Renovate disabled for komodo-periphery/; update-stacks procedure excludes
both komodo stacks (manual host deploys).
Newt 1.18.1 enforces this feature; newt runs on the default bridge and
resource targets are host-IP ports, so the host-container lookup can never
match -> 'failed to find host container' on every docker event, breaking
docker-label blueprint provisioning (since 1.12.5->1.18.1 bump on Oct 2).
Same stack (pangolin ee-1.23.0, gerbil 1.5.1, traefik v3.7, crowdsec, grafana,
prometheus, dashboards, project pangolin); mounts absolute to /root on the
VPS; crowdsec-manager now mounted on the repo-managed compose file so it
edits the git-tracked source. Enables Renovate version bumps.
Production mode derives OTP/encryption keys from SECRET_KEY_BASE; app had
it, sidekiq did not -> 'OTP_ENCRYPTION_PRIMARY_KEY required in production'
crash loop. DB has 0 OTP users, so derived keys are safe.
Same stack (pangolin ee-1.21.1, gerbil 1.4.3, traefik v3.7, project pangolin);
bind mounts made absolute to /root/config on the VPS. Enables Renovate
version bumps.
traefik-network-connector attaches traefik to container networks labelled
traefik.enable=true, so stacks no longer need the default bridge:
- changedetection: app+sockpuppetbrowser on changedetection network, links out
- postiz: postiz-network, legacy links out
- teslamate: teslamate network, DB via service DNS (postgresql17), 5432
hostport dropped, teslamateapi -> teslamate:4000 internal
- download: bookorbit+bookorbit-db on bookorbit network (5435 hostport dropped)
- immich: immich network in .env host IP refs -> service/container DNS
All published host ports kept unless removed above; pangolin target
hostnames still point at 192.168.10.144 host ports.
:latest and floating tags pinned to the exact digest/tag each
container currently runs, verified against registry manifest
digests. Digest-pinned where no matching version tag exists
(mealie, homepage, syncthing, glances, telegraf, fileflows,
teslacamplayer, sockpuppetbrowser, postgres-exporter, cadvisor,
plex-exporter). Renovate can now update each to real releases.
- glances: new image crashes without TERM (curses init) — set TERM=xterm.
- photon: commented out. New image layout (no uv) and its OSM update
wants 153GB temp / 137GB available on docker.img nvme. Re-enable
after disk decision.
- Pocket-ID: ENCRYPTION_KEY contains $ — Komodo .env interpolation
eats it. Inline with $$ YAML escape (value already in git history
from master.yaml; rotate later).
- photon: image dropped uv; use image default CMD, strip stale PATH/JAVA.
- glances: PYTHON_VERSION must be 3.14 to match image venv.
Remove node_exporter (owned by infra stack), add Grafana service
from live container config. Secrets to ${VAR} (Komodo stack env),
strip Unraid template noise, normalize restart to unless-stopped.
Secrets to ${VAR} (Komodo stack env), strip Unraid template noise
(mac/hostname/PATH/unraid labels), normalize restart to unless-stopped.
Add phpmyadmin and Redis services from live container configs.
nbxyz image init fails to create its 'nbxyz' user for Unraid's
default 99/100 ('chown: unknown user/group nbxyz'), so nginx
crash-loops into FATAL state. 1000/1000 confirmed working upstream.
Refs https://github.com/netbootxyz/docker-netbootxyz/issues/96