2026-08-03 12:26:42 +08:00
# us2.wsvc.info
| Item | Value |
|------|--------|
| Role | Multi-service VPS (Vaultwarden, Traefik, Soft Serve, …) |
| SSH | `ssh -4 windy@us2.wsvc.info` (prefer IPv4 from WSL) |
| IPv4 | `193.9.44.165` |
| Also DNS | `auth.wsvc.info` → this host; `repo.windy.me` → this host (Soft Serve) |
| Public HTTPS | Traefik on `:80` / `:443` (`/opt/traefik` ) |
## Vaultwarden (Bitwarden-compatible)
2026-08-29 19:54:32 +08:00
**Status: operational** (Postgres live, HTTPS 200, healthy containers, SMTP AUTH OK — last probe 2026-08-29).
2026-08-03 12:26:42 +08:00
Upstream docs: [docs/vaultwarden-upstream.md ](../docs/vaultwarden-upstream.md )
| Item | Value |
|------|--------|
| Install path | `/opt/vaultwarden` |
| Compose | `/opt/vaultwarden/docker-compose.yml` |
| Env file | `/opt/vaultwarden/.env` |
| Admin overrides | `/opt/vaultwarden/vw-data/config.json` (**wins over env**) |
| Public URL / `DOMAIN` | `https://auth.wsvc.info` |
2026-08-29 19:54:32 +08:00
| Image | `vaultwarden/server:1.37.2` (pinned) |
2026-08-03 12:26:42 +08:00
| Live DB | **Postgres 16** (`vw-db` / service `pg` ) via compose `DATABASE_URL` |
2026-08-29 19:54:32 +08:00
| Data (probe) | users=1, ciphers=1360 |
2026-08-03 12:26:42 +08:00
| Cold SQLite | `backups/sqlite-cold/db.sqlite3.pre-pg-20260801` (not used live) |
| Pre-migrate backup | `backups/pre-pg-migrate-20260801_161204/` |
| Data dir | `./vw-data` → `/data` (attachments, rsa keys, `config.json` ) |
| DB backups | `vaultwarden-backup` → `pg_dump` daily 02:00 (`scripts/backup.sh` ); latest e.g. `backups/vaultwarden_2026-08-01_16-23-03.sql.gz` |
| Reverse proxy | Traefik (`vw-net` ) → Host(`auth.wsvc.info` ), LE (`auth.wsvc.info` , valid → 2026-10-08) |
| SMTP | `mx2.windy.me:587` STARTTLS (`extra_hosts` → 194.163.160.244); from `zhiqiang@windy.me` |
| SMTP secrets | Keep ** `.env` **, ** `vw-data/config.json` **, and ** `.smtp-credentials` ** in sync — `config.json` wins; drift breaks mail |
| IP header | `X-Forwarded-For` |
| Signups | disabled (`signups_allowed=false` ); invitations allowed |
| pgweb | compose profile `debug` (stopped by default) |
| Secrets | `.env` , `.admin-token` , `.smtp-credentials` — **never commit** |
### Official documentation
| Topic | Link |
|-------|------|
| Config overview | https://github.com/dani-garcia/vaultwarden/wiki/Configuration-overview |
| Postgres / migration | https://github.com/dani-garcia/vaultwarden/wiki/Using-the-PostgreSQL-Backend |
| SMTP | https://github.com/dani-garcia/vaultwarden/wiki/SMTP-configuration |
| Proxy / Traefik | https://github.com/dani-garcia/vaultwarden/wiki/Proxy-examples |
| Full index | [docs/vaultwarden-upstream.md ](../docs/vaultwarden-upstream.md ) |
### Stack
| Container | Status |
|-----------|--------|
2026-08-29 19:54:32 +08:00
| `vaultwarden` | Up (healthy), `vaultwarden/server:1.37.2` |
2026-08-03 12:26:42 +08:00
| `vw-db` | Up (healthy) — **live** Postgres |
| `vaultwarden-backup` | Up (`pg_dump` ) |
| `vaultwarden-pgweb` | Exited (profile `debug` ) |
Effective `config.json` : domain `https://auth.wsvc.info` , SMTP 587/starttls to `mx2.windy.me` as `zhiqiang@windy.me` , `ip_header=X-Forwarded-For` . Password matched to `.env` (fixed 2026-08-01).
### Client use
- Server URL: `https://auth.wsvc.info`
- Admin: `https://auth.wsvc.info/admin`
### Ops / runbooks
- [vaultwarden-health ](../runbooks/vaultwarden-health.md )
- [vaultwarden-sqlite-to-postgres ](../runbooks/vaultwarden-sqlite-to-postgres.md )
- [vaultwarden-upstream docs ](../docs/vaultwarden-upstream.md )
```bash
2026-08-03 16:01:35 +08:00
cd ansible
ansible-playbook playbooks/health-report.yml --limit vaultwarden
# after a reviewed Vaultwarden configuration change (and only if auth 404s):
ansible-playbook playbooks/compose-reconcile.yml --limit vaultwarden \
-e '{"service_reconcile_confirm": true, "service_reconcile_targets": ["vaultwarden"], "service_reconcile_restart_traefik": true}'
2026-08-03 12:26:42 +08:00
```
2026-08-06 15:48:48 +08:00
## Other running services on this host
2026-08-03 12:26:42 +08:00
2026-08-06 15:48:48 +08:00
| Container | Status | Image / notes |
|-----------|--------|---------------|
2026-08-30 13:19:05 +08:00
| `soft-serve` | Up | `charmcli/soft-serve:v0.12.2` (`repo.windy.me:2222` ) |
| `soft-serve-backup` | Up | alpine + sqlite3 sidecar (daily backup 02:00 / prune 03:00, crond) |
Soft Serve details (verified/updated 2026-08-30; 核查 [W1N-244 ](https://linear.app/w1ndy/issue/W1N-244 ), 修复 [W1N-245 ](https://linear.app/w1ndy/issue/W1N-245 )/[W1N-246 ](https://linear.app/w1ndy/issue/W1N-246 )/[W1N-247 ](https://linear.app/w1ndy/issue/W1N-247 )):
- `/opt/soft-serve/compose.yml` (+ `Dockerfile.backup` , `scripts/` , `backups/` ); data `/opt/soft-serve/data` → `/var/lib/soft-serve` (sqlite `soft-serve.db` , 12 repos + `windyboy` ); env `.env` (`SOFT_SERVE_INITIAL_ADMIN_KEYS` = admin pubkey, first-boot only). 仓库镜像: `compose/soft-serve/` (参考, 服务器文件为准)
- No host ports published: Traefik TCP entrypoint `ssh` (`:2222` → `soft-serve:23231` , `HostSNI(*)` , `tls=false` ) on `vw-net` . Container listens 23231 SSH / 23232 HTTP (git smart-http, no web UI) / 9418 git / 23233 stats (localhost only)
- **镜像已固定** `charmcli/soft-serve:v0.12.2` (digest `sha256:554cc770…` , Docker Hub 稳定源; GHCR 为 dev/nightly 源且无 v0.12.x tag); `/soft-serve` 由 named volume `soft-serve_soft-serve-app` 承载, 旧匿名卷已清理(2026-08-30)
- **非 root 运行**(2026-08-30, [W1N-248 ](https://linear.app/w1ndy/issue/W1N-248 )): compose `user: "1000:1000"` (uid=windy, 镜像无内置用户); data 全量 `chown 1000:1000` , 容器内 `id` = uid 1000, 功能验证通过
- **`ssh.public_url` 已修复**(2026-08-30): `config.yaml` → `ssh://git@repo.windy.me:2222` ; 失效 env `SOFT_SERVE_SSH_PUBLIC_URL` 已删(v0.12 不读取); `http` /`git` public_url 保持 `localhost` (未对外暴露)
- **备份**: sidecar `soft-serve-backup` 每日 02:00 → `backups/soft-serve_<TS>/{repos-config.tar.gz, soft-serve.db}` (db 用 `sqlite3 .backup` 在线快照), 03:00 prune 保留 14 份; 产物 chown windy:windy 600(含 `ssh/` host keys)。**恢复**: `docker compose stop soft-serve` → 解包 `repos-config.tar.gz` + 放回 `soft-serve.db` 到 `data/` → `docker compose up -d` 。异地副本(hk2/WSL 每日拉取)= follow-up(见 W1N-247)
2026-08-06 15:48:48 +08:00
| `traefik` | Up | `traefik:v3.6.2` (`/opt/traefik` , public `:80` /`:443` ) |
| `nghttpx-proxy` + `squid-backend` | Up | HTTP forward-proxy stack (`/opt/nghttpx` ), network `nghttpx_internal-net` ; details TBD |
Directories for `authelia` , `conduit` , `dendrite` , `mastodon` , `rustdesk` , `zitadel` , etc. exist under `/opt` but have no running containers; treat them as dormant, not documented services.
2026-08-03 12:26:42 +08:00
## Verified
2026-08-29 19:54:32 +08:00
Last checked: **2026-08-29** — operational.
2026-08-03 12:26:42 +08:00
- `vaultwarden` + `vw-db` healthy; `DATABASE_URL` → `pg:5432/vaultwarden`
- `https://auth.wsvc.info/` **200** , `/admin` **200** , `/api/config` OK (`disableUserRegistration: true` )
2026-08-29 19:54:32 +08:00
- SMTP: container → `mx2:587` OK; **AUTH OK** with effective `config.json` password (synced with `.env` / `.smtp-credentials` , fingerprint match)
- PG counts: users=1, ciphers=1360
- Image `vaultwarden/server:1.37.2` (**upgraded 2026-08-29** from 1.37.1; required for Bitwarden clients 2026.8.0+); post-upgrade 404 fixed by Traefik restart, then 200
- vps-health local check **installed 2026-08-29** (`vps-healthcheck.timer` daily 06:15 + `/usr/local/lib/vps-health/run` ); `health-report.yml --limit vaultwarden` now passes (**ok**, was failing due to missing check infra + script bugs fixed: trim_blocks render, pgweb debug-profile false positive, SMTP probe moved host-side since image lacks python3)