1
0
Files
homelab-public-context/runtime/history/GITEA-READER-INGRESS-DISCOVERY-272.txt
T
2026-07-22 20:54:59 +00:00

118 lines
10 KiB
Plaintext

CHAT_OUTPUT_BEGIN
COMMAND_ID=GITEA-READER-INGRESS-DISCOVERY-272
STATUS=OK
RC=0
HOST=pve01
MODE=read-only
COMPONENT=cluster-audit
REFERENCE_REGISTER_CHECK=OK
REFERENCE_SHA256=5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e
ERROR_REGISTER_CHECK=OK
ERROR_REGISTER_SHA256=08b3a769b8e38eaa1acec915352fb328180d70caa7ff6cd9d1ec0da426262752
COMMAND_SHA256=d9cbc6f7e91d70c44f670ebe36565de022ff8d5362187c5679bb807fe099ca50
DUPLICATE_FAILED_COMMAND_BLOCKED=false
EXECUTION_STARTED=true
CHANGES_MADE=false
SANITIZED=yes
SECRETS_INCLUDED=no
PRIVATE_ADDRESSES_INCLUDED=no
RAW_EVIDENCE_SHA256=6b42b76faa0fb0a0b3aea018ab9845475aaa0f6e36e995881aa19ab1c96e4bba
SANITIZED_OUTPUT_SHA256=b2ca7f53ef5d7103cd7aa531fda36aeb11535cde362cddad7fda78f4d8ea20de
OUTPUT_BEGIN
PREVIOUS_COMMAND_ID=GITEA-READER-NGINX-ROOTCAUSE-271
=== LOCAL_NODE ===
pve01.gram1.ru
[PRIVATE_IP] [PRIVATE_IP] [PRIVATE_IP] 100.100.131.41 [PRIVATE_IPV6]
lo UNKNOWN 127.0.0.1/8 ::1/128
nic0 UP
enx6c1ff7c17576 DOWN
vmbr0 UP [PRIVATE_IP]/24 [PRIVATE_IP]/24 [LINK_LOCAL_IPV6]/64
podman0 UP [PRIVATE_IP]/16 [LINK_LOCAL_IPV6]/64
veth0@if2 UP [LINK_LOCAL_IPV6]/64
veth112i0@if2 UP
veth110i0@if2 UP
tap150i0 UNKNOWN
tap170i0 UNKNOWN
tap171i0 UNKNOWN
wt0 UNKNOWN 100.100.131.41/16 [PRIVATE_IPV6]/64
=== GITEA_DNS ===
[PRIVATE_IP] STREAM git.gram1.ru
[PRIVATE_IP] DGRAM
[PRIVATE_IP] RAW
=== WEB_EXECUTABLES ===
=== WEB_SERVICES ===
homelab-gitea-secondary-backup.service loaded inactive dead Create and copy a verified Gitea backup to pve03
=== LISTENERS ===
LISTEN 0 5 127.0.0.1:18788 0.0.0.0:* users:(("python3",pid=2649737,fd=3))
=== GITEA_SERVICE ===
LoadState=not-found
ActiveState=inactive
SubState=dead
FragmentPath=
No files found for gitea.service.
=== CLUSTER_CANDIDATES ===
pve03 qemu 130 edge-vm running
pve02 qemu 9130 edge-cold-standby stopped
=== CONFIG_DIRECTORIES ===
/etc/apache2/conf-available/javascript-common.conf
=== REFERENCE_MATCHES ===
/etc/pve/31_HOMELAB_REFERENCE.md:398:- pve01 timers cover VPN/NetBird health, health metrics, smartctl, disk space, MkDocs refresh, VPS identity audit, storage capacity, quality gate, evidence catalog, backup freshness, docker health, Filebrowser backup/offhost/restore, NPMplus/Kuma backup, NetBird VPS backup/offhost, Authentik/Gitea/Vaultwarden backup, SOPS secret coverage, mail cloud upload/restore, Immich/Memos/Paperless backup/offhost/restore, auto backup, edge-vm vzdump, secret sanity.
/etc/pve/31_HOMELAB_REFERENCE.md:546:- Role: edge application host / reverse proxy / monitoring / backup automation host.
/etc/pve/31_HOMELAB_REFERENCE.md:614:- git.gram1.ru -> [PRIVATE_IP].
/etc/pve/31_HOMELAB_REFERENCE.md:636:- Public listen ports on edge-vm: 0.0.0.0:80 and 0.0.0.0:443 by nginx/NPMplus.
/etc/pve/31_HOMELAB_REFERENCE.md:647:- git.gram1.ru -> http://127.0.0.1:3002, cert=29, ssl_forced=1, enabled=1.
/etc/pve/31_HOMELAB_REFERENCE.md:658:- gitea.vpn.gram1.ru -> http://127.0.0.1:3002, cert=32.
/etc/pve/31_HOMELAB_REFERENCE.md:696:- cert=29: git.gram1.ru, expires 2026-09-13 17:36:55.
/etc/pve/31_HOMELAB_REFERENCE.md:736:- gitea.
/etc/pve/31_HOMELAB_REFERENCE.md:771:- Data apps: immich, paperless, memos, gitea, netbox, actual-budget, homebox, mealie, n8n, node-red, vikunja, bookstack.
/etc/pve/31_HOMELAB_REFERENCE.md:778:- Gitea: 127.0.0.1:3002.
/etc/pve/31_HOMELAB_REFERENCE.md:889:- Gitea backup: STATUS=OK, archive under /mnt/staging/gitea-backups/snapshots.
/etc/pve/31_HOMELAB_REFERENCE.md:890:- Gitea offhost: STATUS=OK to pve02.
/etc/pve/31_HOMELAB_REFERENCE.md:891:- Gitea restore: STATUS=OK, DB integrity OK, tables counted.
/etc/pve/31_HOMELAB_REFERENCE.md:1000: - https://git.gram1.ru
/etc/pve/31_HOMELAB_REFERENCE.md:1056:- external canary checks include nc.gram1.ru, git.gram1.ru, auth.gram1.ru, backup.gram1.ru.
/etc/pve/31_HOMELAB_REFERENCE.md:1299:- Reverse proxy: NPMplus on edge-vm, container npmplus, host networking, admin bound to 127.0.0.1:81.
/etc/pve/31_HOMELAB_REFERENCE.md:1313:| git.gram1.ru | http://127.0.0.1:3002 | edge-vm / gitea | gitea backup/offhost/restore |
/etc/pve/31_HOMELAB_REFERENCE.md:1326:| gitea.vpn.gram1.ru | http://127.0.0.1:3002 | gitea |
/etc/pve/31_HOMELAB_REFERENCE.md:1864:- Discovery proof records DNS, HTTPS/TLS headers, reverse-proxy candidates, compose files, domain references and homepage config candidates without printing secrets.
/etc/pve/31_HOMELAB_REFERENCE.md:1968:- Explicit VPN duplicate cards were removed from Homepage with a short transparent perl edit: Homepage VPN, Authentik VPN, Gitea VPN and Uptime Kuma VPN.
/etc/pve/31_HOMELAB_REFERENCE.md:1984:- Removed targets: Homepage VPN, Authentik VPN, Gitea VPN and Uptime Kuma VPN, plus matching vpn.gram1.ru duplicate URLs.
/etc/pve/31_HOMELAB_REFERENCE.md:2089:- SURY PHP repo added; PHP 8.5.7 available and installed with Nginx 1.22.1, MariaDB 10.11.14 and required XenForo modules.
/etc/pve/31_HOMELAB_REFERENCE.md:2095:- Bulk import of five forums reached DB/files/nginx/php-fpm ready state, but frontend body stayed empty under PHP 8.5.7.
/etc/pve/31_HOMELAB_REFERENCE.md:2102:- Runtime: Debian 12, Nginx, MariaDB 10.11, PHP 8.3-FPM.
/etc/pve/31_HOMELAB_REFERENCE.md:2309:- Runtime services are configured: nginx, MariaDB, PHP 8.3 FPM, qemu-agent, cron, msmtp/sendmail transport.
/etc/pve/31_HOMELAB_REFERENCE.md:2337:- Runtime: nginx, MariaDB 10.11, PHP 8.3 FPM, qemu-agent, cron, msmtp/sendmail transport.
/etc/pve/31_HOMELAB_REFERENCE.md:2411:- NPMplus manual managed route files: /data/nginx/proxy_host/998.conf for newfi.ru, 997.conf for hapusya.ru and 996.conf for kingofwolk.ru.
/etc/pve/31_HOMELAB_REFERENCE.md:2425:- NPMplus managed route file: /data/nginx/proxy_host/995.conf.
/etc/pve/31_HOMELAB_REFERENCE.md:2439:- NPMplus managed route file: /data/nginx/proxy_host/994.conf.
/etc/pve/31_HOMELAB_REFERENCE.md:2457:- Recommended future path: establish VPN/NetBird/WireGuard or reverse-proxy/private management endpoint first; then issue DNS-01 certificate on a trusted node and deploy cert/key to the router only over that private path.
/etc/pve/31_HOMELAB_REFERENCE.md:2502:- NPMplus route: /opt/npmplus/nginx/proxy_host/993.conf.
/etc/pve/31_HOMELAB_REFERENCE.md:2519:- Deploy hook copies renewed cert/key into NPMplus /data/tls/router-certs/taftauto.ru and reloads nginx after nginx -t.
/etc/pve/31_HOMELAB_REFERENCE.md:2525:- NPMplus cert copy and nginx config validate OK.
/etc/pve/31_HOMELAB_REFERENCE.md:2531:- Removed obsolete NPMplus route aliases without Homepage cards: auth.vpn.gram1.ru, gitea.vpn.gram1.ru, homepage.vpn.gram1.ru, kuma.vpn.gram1.ru.
/etc/pve/31_HOMELAB_REFERENCE.md:2532:- NPMplus nginx config validates after removal.
/etc/pve/31_HOMELAB_REFERENCE.md:2540:- NPMplus nginx config validates.
/etc/pve/31_HOMELAB_REFERENCE.md:2804:Destination: immutable Gitea runtime history with CONTEXT-AUTO UTC command IDs.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak-router-cli-20260630T215229Z:211:- A portal card is openable only when DNS, reverse-proxy host mapping, and target content are all valid.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak.20260721T112115Z:211:- A portal card is openable only when DNS, reverse-proxy host mapping, and target content are all valid.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak.20260721T112115Z:334:- Rule: avoid nested SSH heredoc/Python for this task; use simpler commands, generated nginx configs, or uploaded/local script files.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak.20260721T112115Z:352:- Rule: publish forum routes through backed-up manual nginx proxy_host configs, then issue proper certificates after DNS points to edge.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak.20260721T112115Z:375:- Important corrections: initial NPMplus API route failed; manual Nginx routes were used. Initial Cloudflare token had no zone access; corrected token passed zone/DNS probe.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak.20260721T112115Z:528:- Rule: validate `/.well-known/acme-challenge/<token>` for HTTP-01 readiness, not HTTP `/`; also scan all active NPMplus nginx config dirs for unmanaged domain conflicts before writing routes.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak.20260721T112115Z:533:- Rule: do not run another apply stage until active NPMplus nginx route selection for newfi.ru is diagnosed with nginx -T and Host-header probes.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak.20260721T112115Z:555:- Result: exact per-host route files 700-705 passed nginx -t but bare newfi.ru still hit HTTP->HTTPS redirect on ACME path.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak.20260721T112115Z:563:- Stage12 cleanup confirmed temp files 980-985 absent and nginx reload OK.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:211:- A portal card is openable only when DNS, reverse-proxy host mapping, and target content are all valid.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:334:- Rule: avoid nested SSH heredoc/Python for this task; use simpler commands, generated nginx configs, or uploaded/local script files.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:352:- Rule: publish forum routes through backed-up manual nginx proxy_host configs, then issue proper certificates after DNS points to edge.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:375:- Important corrections: initial NPMplus API route failed; manual Nginx routes were used. Initial Cloudflare token had no zone access; corrected token passed zone/DNS probe.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:528:- Rule: validate `/.well-known/acme-challenge/<token>` for HTTP-01 readiness, not HTTP `/`; also scan all active NPMplus nginx config dirs for unmanaged domain conflicts before writing routes.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:533:- Rule: do not run another apply stage until active NPMplus nginx route selection for newfi.ru is diagnosed with nginx -T and Host-header probes.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:555:- Result: exact per-host route files 700-705 passed nginx -t but bare newfi.ru still hit HTTP->HTTPS redirect on ACME path.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:563:- Stage12 cleanup confirmed temp files 980-985 absent and nginx reload OK.
/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md.bak-proof-repair-20260630T215529Z:211:- A portal card is openable only when DNS, reverse-proxy host mapping, and target content are all valid.
CHANGES_MADE=NO
OUTPUT_END
CHAT_OUTPUT_END