Commit Graph

  • 9ec1b1811b feat(stack-deploy): accept -e/--emergency and -f/--force flags, pass through to git-guard.sh add-force-emergency-deploy-flags Bot 2026-09-12 00:04:42 -07:00
  • 8fa085ebde feat(git-guard): add -e/--emergency (try alternate Gitea hosts) and -f/--force (skip sync check) Bot 2026-09-12 00:03:59 -07:00
  • 8ef1cea5b0 traefik: fix malformed LOCK_FILE variable in rotation wrapper fix/traefik-log-rotation Bot 2026-09-11 23:29:55 -07:00
  • 409971f741 traefik: document log rotation setup, rationale, and bootstrap steps Bot 2026-09-11 23:29:01 -07:00
  • 6ddb31c594 traefik: add one-time logrotate installer (run on each node) Bot 2026-09-11 23:29:01 -07:00
  • 4f4c5a467b traefik: add cron wrapper for coordinated multi-node log rotation Bot 2026-09-11 23:29:00 -07:00
  • e27d2f6ac2 traefik: add logrotate config for access/traefik logs Bot 2026-09-11 23:29:00 -07:00
  • 5ab1ae1e8b chore(traefik): re-trigger provision-secrets — traefik.env was found missing on disk post-migration main Bot 2026-09-11 23:17:13 -07:00
  • afc96a6d37 Merge pull request 'fix(traefik): migrate KEEPALIVED_PASSWORD to Pattern C (manifest-driven), stop committing traefik.env' (#21) from migrate-traefik-keepalived-secret into main AVB 2026-09-11 22:52:35 -07:00
  • cd42e35265 docs(secrets): mark traefik migration complete, add committed-env-file warning Bot 2026-09-11 22:42:06 -07:00
  • 2a3f2bdd1e docs(traefik): update secrets reference for manifest-driven Pattern C migration Bot 2026-09-11 22:42:04 -07:00
  • d9f151a1c3 feat(traefik): migrate keepalived password to manifest-driven Pattern C provisioning Bot 2026-09-11 22:40:36 -07:00
  • 201d8418ee feat(traefik): register traefik in manifest-driven secrets provisioning Bot 2026-09-11 22:38:39 -07:00
  • 5edebd977d fix(traefik): remove tracked traefik.env — never commit secret-bearing env files Bot 2026-09-11 22:38:39 -07:00
  • ffec3ea5b7 feat(traefik): add authoritative env template for manifest-driven provisioning Bot 2026-09-11 22:38:38 -07:00
  • 5dda5e0031 fix(frigate): publish go2rtc WebRTC port 8555 (tcp+udp) on frigate-nvr Bot 2026-09-09 22:09:30 -07:00
  • d5db4c1a4e fix(git-guard): use 'exec bash "$0"' for self-re-invocation (exec bit not required) (#20) AVB 2026-09-09 19:36:31 -07:00
  • 333bb82c16 fix(git-guard): use 'exec bash "$0"' instead of 'exec "$0"' for self-re-invocation fix-git-guard-exec-permission Bot 2026-09-09 14:01:26 -07:00
  • d72a8ebd04 Merge pull request 'fix(git-guard): stash-before-commit when dirty tree is also stale vs origin' (#19) from fix-git-guard-stash-before-commit into main Bot 2026-09-09 13:56:05 -07:00
  • e357907ee6 fix(git-guard): add unmerged-path guard + concrete remediation syntax for every failure branch Bot 2026-09-09 13:47:14 -07:00
  • bd69cc85d5 fix(git-guard): stash-before-commit when dirty tree is also stale vs origin Bot 2026-09-09 10:42:21 -07:00
  • 000792f702 ai: persist FlowAgent MSAL token cache via mcpo bind mount (#18) AVB 2026-09-09 08:45:02 -07:00
  • 9316a32ba5 ai: persist FlowAgent MSAL token cache via mcpo bind mount flowagent-auth-mount Bot 2026-09-09 00:16:35 -07:00
  • 5a5c8e56a9 Merge pull request 'Fix phantom verify failure: secrets/ is not a stack + errexit-proof verify' (#17) from fix-secrets-folder-stack-detection into main AVB 2026-09-07 22:28:36 -07:00
  • eee6e543b1 Fix phantom verify failure: exclude secrets/ from stack detection + errexit-proof verify's stack-ps fix-secrets-folder-stack-detection Bot 2026-09-07 22:26:43 -07:00
  • be587de5be Merge pull request 'Provisioning v2 (take 2): data-only manifest + full-file env template + generic provisioner — replaces #15' (#16) from secrets-provisioning-v3 into main AVB 2026-09-07 22:06:03 -07:00
  • ef7e3d015e provision-secrets: ai) case -> provision-stack.py + normalized env block (branch rebuilt on current main) secrets-provisioning-v3 Bot 2026-09-07 21:47:04 -07:00
  • 89a1e030c0 Add deploy/provision-stack.py — generic manifest-driven provisioner Bot 2026-09-07 21:43:57 -07:00
  • e82b754386 Add ai/ai.env.template — full-file authoritative env template (AI_<SERVICE>_* naming) Bot 2026-09-07 21:43:05 -07:00
  • 85734f4601 Add secrets/secrets-map.yaml — data-only provisioning manifest (ai stack first) Bot 2026-09-07 21:43:04 -07:00
  • cb10c2e22d provision-secrets: rebuild ai) migration on current main (fixes live env-name drift incl. WEB_UI/WEBUI OAuth secret mismatch) secrets-provisioning-v2 Bot 2026-09-06 22:52:38 -07:00
  • 24cc4e6655 ai.env.template: rebase onto main's AI_<SERVICE>_* naming (2026-09-06 renames) Bot 2026-09-06 22:46:16 -07:00
  • 264f4e7379 Change AWS_REGION_NAME variable AVB 2026-09-06 20:33:56 -07:00
  • 9bbbd5fae3 Add AWS Region Name variable AVB 2026-09-06 20:33:08 -07:00
  • e33fd8695f Update ai/ai.yaml AVB 2026-09-06 10:59:05 -07:00
  • 1828c89194 Update .woodpecker/deploy.yml AVB 2026-09-06 10:53:55 -07:00
  • 9ec5353d7e Fixed LITELLM Database URL AVB 2026-09-06 10:44:53 -07:00
  • dfa0d34a83 Update ai/ai.yaml AVB 2026-09-06 10:29:27 -07:00
  • 66638dd743 Update ai/ai.yaml AVB 2026-09-06 01:29:02 -07:00
  • 88b3e46f77 provision-secrets: replace broken ai) line-surgery with one-line call to provision-stack.py Bot 2026-09-03 22:49:03 -07:00
  • a91974caa1 Add deploy/provision-stack.py — generic manifest-driven provisioner Bot 2026-09-03 22:43:48 -07:00
  • 8ae2ddbe97 Add ai/ai.env.template — full-file authoritative env template for the ai stack Bot 2026-09-03 22:40:11 -07:00
  • 0869cd319d Add secrets/secrets-map.yaml — data-only provisioning manifest (ai stack first) Bot 2026-09-03 22:40:10 -07:00
  • 355ccada8c Update ai/ai.yaml Bot 2026-09-03 00:15:38 -07:00
  • 096ebd6de5 Update .woodpecker/deploy.yml Bot 2026-09-02 23:28:25 -07:00
  • 980c54f84e Update .woodpecker/deploy.yml Bot 2026-09-02 23:27:19 -07:00
  • 324a06ed2d Update .woodpecker/deploy.yml Bot 2026-09-02 23:26:30 -07:00
  • cee47822ec Update .woodpecker/deploy.yml Bot 2026-09-02 23:25:39 -07:00
  • 68365746a6 Update .woodpecker/deploy.yml Bot 2026-09-02 23:24:37 -07:00
  • eecfcf9367 Update .woodpecker/deploy.yml Bot 2026-09-02 23:23:57 -07:00
  • d01c763354 Update .woodpecker/deploy.yml Bot 2026-09-02 23:17:48 -07:00
  • 0baee47b67 Fixed duplicate env: "AI_OPEN_WEB_UI_ENABLE_OAUTH_SIG" Bot 2026-09-02 23:02:51 -07:00
  • 0435def8a0 Update .woodpecker/deploy.yml Bot 2026-09-02 23:01:44 -07:00
  • ded255decc Upgrade to open-webui:0.11.3 Bot 2026-09-02 22:26:15 -07:00
  • ac091999b4 Merge pull request 'FlowAgent MCP cutover: point ai.yaml's mcpo at flowagent-mcpo image + wire Azure secrets (matched pair)' (#14) from flowagent-ai-cutover into main Bot 2026-09-02 21:43:18 -07:00
  • a15e0100df provision-secrets: add flowagent_* case-entry to the ai) stack (matched pair with ai.yaml's mcpo cutover) flowagent-ai-cutover Bot 2026-09-02 16:53:10 -07:00
  • bcfb24b16d ai.yaml: cut mcpo over to the confirmed-working flowagent-mcpo image + wire flowagent Docker secrets (never touches mcpo-critical) Bot 2026-09-02 16:51:31 -07:00
  • 42d31e38e4 git stack: switch provision-secrets to Pattern B .env rewrite (test phase) + add git to bootstrap-tier guard Bot 2026-09-02 00:02:36 -07:00
  • 16a01a9ea5 Merge pull request 'Remove orphaned mcpo/ mirror (migrated to homelab/mcp-config)' (#13) from remove-orphaned-mcpo-mirror into main AVB 2026-08-29 20:57:58 -07:00
  • b6b23a7970 Remove mcpo/woodpecker-mcp.mjs — migrated unchanged to homelab/mcp-config remove-orphaned-mcpo-mirror admin 2026-08-29 20:46:01 -07:00
  • 150b262db3 Remove orphaned mcpo/config.json mirror — migrated to homelab/mcp-config admin 2026-08-29 20:46:00 -07:00
  • f7c8ebc05e Add flowagent secrets reference doc (placeholders only, no real values) flowagent-mcp-setup admin 2026-08-29 20:31:11 -07:00
  • 2ca0643439 Add FlowAgent entrypoint: non-interactive az login via Pattern C secrets admin 2026-08-29 20:31:10 -07:00
  • 5ae478272f Add FlowAgent MCP image (Dockerfile + entrypoint) — build only, not wired to any stack yet admin 2026-08-29 20:31:09 -07:00
  • 44babb6a22 Fix YAML alias-scanner crash: quote KEEPALIVED_PASSWORD/KEEPALIVED_VIRTUAL_IPS env values admin 2026-08-29 14:03:36 -07:00
  • 10c35138db Bump traefik-certs-dumper:v2.10.0 to 2.11.4 AVB 2026-08-29 13:56:35 -07:00
  • 162700bb4f Fix: stack-deploy.sh now picks export_raw/export_raw_merged for folder+extras stacks (docker compose config path) vs export/export_merged for single-file stacks, matching envparse.py's dual-escaping fix admin 2026-08-26 23:26:32 -07:00
  • 4af1209565 Fix: second double-interpolation bug in envparse.py - add export_raw/export_raw_merged (no escape_dollar) for the docker-compose-config render path, which already does its own dollar-escaping. Fixes IMMICH_KIOSK_BASICAUTH bcrypt hash corruption. admin 2026-08-26 23:25:46 -07:00
  • a557d9fb07 Refactor: unify stack-deploy.sh render paths into a single temp-file render step, then run mount-guard.py before docker stack deploy admin 2026-08-26 23:04:11 -07:00
  • f696efef11 Add: mount-guard.py - pre-deploy bind mount existence + Postgres empty-data heuristic check admin 2026-08-26 23:03:11 -07:00
  • 2e889323ef Fix: correct immich.env-example paths to match real on-disk data (UPLOAD_LOCATION, BULK_UPLOAD_LOCATION, DB_DATA_LOCATION) after 2026-08-26 incident where generic template paths were wrong admin 2026-08-26 22:51:37 -07:00
  • b620682a41 Fix: envparse.py strip mode now also drops top-level 'name:' key that docker compose config emits but Swarm's stack deploy schema rejects admin 2026-08-26 22:37:38 -07:00
  • 87a254c902 Fix: envparse.py strip mode now collapses long-form depends_on mapping to Swarm-compatible short-form list admin 2026-08-26 22:35:53 -07:00
  • efd8caa218 Fix: invoke git-guard.sh via bash explicitly so tracked file mode bit doesn't matter admin 2026-08-26 22:33:21 -07:00
  • 70814970c7 Harden .gitignore: broaden .env exclusion to *.env (with explicit exceptions for global.env and *.env-example templates), ignore stray .bak files admin 2026-08-26 22:32:32 -07:00
  • 32e30f7e8b Add: call git-guard.sh at top of stack-deploy.sh to enforce sync before deploy admin 2026-08-26 22:31:12 -07:00
  • 0bc117c868 Add: git-guard.sh - pre-deploy sync check to prevent local/Gitea divergence admin 2026-08-26 22:30:47 -07:00
  • 7b5273b4b4 Update ai/ai.yaml AVB 2026-08-26 21:36:48 -07:00
  • 9d0e9d9b60 Update ai/ai.yaml AVB 2026-08-26 21:28:03 -07:00
  • 08949ba3a4 Update ai/ai.yaml AVB 2026-08-26 21:24:17 -07:00
  • ef4bcfcb25 ai: trigger redeploy to apply $$ escaping fix (PR #8) to litellm secrets admin 2026-08-26 21:18:26 -07:00
  • 808483181b Merge pull request 'fix: exclude deploy/ folder from changed-stack detection' (#9) from fix-exclude-deploy-folder into main AVB 2026-08-26 21:13:40 -07:00
  • f6fc288aa6 fix: exclude deploy/ from changed-stack detection fix-exclude-deploy-folder admin 2026-08-26 21:10:59 -07:00
  • 701d1289ea Merge pull request 'fix: prevent envsubst+Compose double-interpolation from truncating $ secrets' (#8) from fix-dollar-double-interpolation into main AVB 2026-08-26 21:05:37 -07:00
  • d209fc3222 fix: escape literal $ in .env values before envsubst (Pattern B stacks) fix-dollar-double-interpolation admin 2026-08-26 20:56:23 -07:00
  • d7fe56f6fe ai: add doc comment noting secrets are now provisioned via Woodpecker admin 2026-08-25 23:48:47 -07:00
  • d1986678bc Merge pull request 'fix(ai): use AI_-prefixed AWS key names in ai) provisioning case' (#7) from fix-ai-aws-var-names into main AVB 2026-08-25 23:45:27 -07:00
  • 6af2633936 fix(ai): write AI_-prefixed AWS key names to ai.env, not plain names admin 2026-08-25 23:42:39 -07:00
  • 27df7cf58f Merge pull request 'HOTFIX: restore $${VAR} escaping dropped by AI secrets migration rewrite' (#6) from hotfix-dollar-escaping into main AVB 2026-08-25 23:34:08 -07:00
  • 5188aef250 hotfix: restore $${VAR} double-dollar escaping for all secret-backed vars admin 2026-08-25 23:27:47 -07:00
  • d4797d4b4b docs: note ai stack secrets in SECRETS.md (trivial commit to force clean pipeline run) admin 2026-08-25 23:19:14 -07:00
  • 7d26f97a1e Merge pull request 'ai: migrate AWS/LiteLLM/OpenWebUI/OAuth secrets to Woodpecker' (#4) from ai-secrets-migration into main AVB 2026-08-25 23:01:09 -07:00
  • 2959721d3c ai: migrate AWS/LiteLLM/OpenWebUI/OAuth secrets from ai.env to Woodpecker secrets admin 2026-08-25 22:40:05 -07:00
  • 52cecf2cf9 vaultwarden: rotate admin_token secret to v2 (hashed value) admin 2026-08-25 21:56:53 -07:00
  • 37ed671aaa Change AWS keys to use Woodpecker Secrets AVB 2026-08-25 20:16:54 -07:00
  • 1374a1dc1f Update open-webui to 0.11.1 AVB 2026-08-25 16:48:40 -07:00
  • c9b53ec3f0 Update homeassistant/homeassistant.yaml AVB 2026-08-24 21:48:11 -07:00
  • 2b9209d9d1 Deprecate: hwaccel.transcoding.yml - functionality moved to main immich.yml admin 2026-08-19 23:03:53 -07:00
  • 4907039db9 Deprecate: hwaccel.ml.yml - functionality moved to main immich.yml admin 2026-08-19 23:03:52 -07:00
  • bef97dd908 Fix: Add /dev/dri to immich-server for quicksync transcoding support admin 2026-08-19 23:03:37 -07:00