windyboy
13032fd0bb
Merge origin/main (production Makefile) into pgdb runbooks delivery
2026-08-29 14:52:10 +08:00
windyboy
d2063e7496
Merge pgdb ops runbooks — health/restore/update (W1N-228)
2026-08-29 14:51:31 +08:00
windyboy
2d95f87897
docs(runbooks): pgdb ops runbooks — health / restore / update + facts refresh (W1N-228)
...
- runbooks/pgdb-health.md: read-only health check (8 diagnostics) — containers,
PG core + HA clients, write activity, TimescaleDB hypertables/compression,
pgweb auth/bookmarks, daily custom-format backups, disk/fstab, logs
- runbooks/pgdb-restore.md: procedure-type restore (pg_restore -Fc, temp-DB swap,
approval gates, rollback) — precondition command verified live
- runbooks/pgdb-update.md: gated command reference (pull -> config -q -> up -> verify;
rollback = /opt/database/run + old volumes)
- index + validate-repo.sh classification updated; hosts/pgdb.md refreshed
(SSH key auth works, scribe events hypertable, runbook cross-refs)
2026-08-29 14:51:20 +08:00
windyboy
b61513c93e
chore(pgdb): land W1N-227 compose-化 leftovers (compose source, host facts, inventory, scribe notes)
2026-08-29 14:51:20 +08:00
windyboy
ab808088b8
Add production Makefile for routine VPS ops
...
Wrap validate-repo.sh and routine Ansible playbooks with safe-by-default
targets: read-only health/audit flows, CONFIRM=1 gates for mutating work,
and LIMIT/TARGETS guards. Document entry point in AGENTS.md.
2026-08-26 11:27:02 +08:00
windyboy
c7dc4fd25c
chore: remove duplicate hook setup
...
Keep pre-commit configuration as the single validation path and tolerate deleted tracked Markdown during link validation.
2026-08-23 17:58:19 +08:00
windyboy
7bc7d3f99b
docs: align runbooks and validation structure
2026-08-23 17:42:31 +08:00
windyboy
fea9a6560f
chore: gitignore .opencode/ and .zcode/ local tool caches
2026-08-23 17:10:07 +08:00
windyboy
a95b626636
docs: Matter bulbs failure mode C — both bulbs announce mDNS but refuse TCP 5540 (08-23 read-only verification); record 08-22 add/loop saga, working bulb MAC change, 3-fabric map, PD rotation to 238:4812; refresh stale DHCP-reservation note on gw (W1N-207)
2026-08-23 11:06:35 +08:00
windyboy
27fe9c078e
docs: archive historical planning documents and fix references
...
Move self-described historical/upstream docs to docs/archive/:
- agent-runbook-guide.md
- lan-core-switch-upgrade-plan.md
- lan-rb5009-upgrade.md
- se5420-review-claim-verification-2026-08.md
Update archive/README.md manifest and fix relative links in active docs
and archived docs. Update AGENTS.md docs/ layout description.
2026-08-22 19:34:05 +08:00
windyboy
aaa4ee312e
docs: verify gw switch0 as limited capture point — SE5420 single-uplink (eth1 up, eth2/3 down), LAN55 wired hosts behind SE5420; record EdgeOS 3 CLI/access quirks (W1N-207)
2026-08-22 10:44:20 +08:00
windyboy
6b298491a8
docs: Matter packet-capture runbook v2 — hass end0 commissioner capture point, corrected AP-point scope (no wired↔wired unicast), UAP-AC-Lite model fix, SE5420 live status; fix hass interface end1→end0 (W1N-207)
2026-08-22 10:14:29 +08:00
windyboy
32631e2996
docs: add Matter pairing troubleshooting handbook; record bulb state + DHCP reservation mismatch (W1N-207)
2026-08-22 08:18:23 +08:00
windyboy
1426b4ecfe
docs: matrix_e2ee v0.3.12/v0.3.9 notes; gw/ubnt IPv6 re-verification; agent sandbox SSH quirk (2026-08-20)
2026-08-21 08:57:53 +08:00
windyboy
1f5e58bf17
docs: record Matter/IPv6 findings — stale matter-server mDNS address, SSID cleanup, ER-X ULA infeasibility (W1N-207)
2026-08-21 08:56:26 +08:00
windyboy
e5819eeba3
docs: correct hass hardware to x88 Pro physical box; sync CSG v1.3.2
...
- hass.windy.lan is a physical x88 Pro box (HAOS bare-metal, machine: green,
CPE x88pro20, virtualization empty) — not PVE VM 180 (verified live 2026-08-18)
- Record CSG v1.3.2 (934f58c, W1N-118) deploy in maintenance runbook verify
section and hosts live-tree section (backups now include w1n118)
2026-08-18 13:32:33 +08:00
windyboy
079332e082
docs: record matrix_e2ee v0.3.0 deploy; fix and rename matrix-e2ee update runbook
...
- Deploy v0.3.0 (main 216cc99, W1N-180 bot-initiated device verification
wizard) on hass.windy.lan; backup matrix_e2ee.bak-20260818-v0.2.10
- Fix runbook: tag-only prerequisite (v0.3.0 was untagged), working-tree
HEAD check, rsync exit-23 note, actual setup log line, post-deploy record
step, ssh_config.d -F /dev/null gotcha
- Rename runbook matrix-e2e-update.md -> matrix-e2ee-update.md and update
AGENTS.md/hosts references (domain is matrix_e2ee, double-e)
- Unify matrix_e2ee naming and update version history in
docs/home-assistant-matrix.md
2026-08-18 13:31:15 +08:00
windyboy
7cedba7f51
docs: rename integration name from matrix_e2ee to matrix_e2e
...
- Rename runbook: matrix-e2ee-update.md -> matrix-e2e-update.md
- Update all references in AGENTS.md, hass.windy.lan.md,
home-assistant-matrix.md to use the short name matrix_e2e
- The code domain stays matrix_e2ee (E2EE) in source; all
doc prose and command references now use matrix_e2e
2026-08-18 13:31:15 +08:00
windyboy and Cursor
343c5db415
feat: add gated Compose deploy and make inventory the host source of truth
...
Keep sanitized Compose sources in-repo with a confirmation-gated Ansible
playbook, add repo-wide validation, tighten runbook ownership/STOP/review
metadata, and archive stale research docs.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-08-17 17:36:39 +08:00
windyboy
885d977531
docs(runbooks): light-enhance home-assistant-maintenance and index it
...
Rebase onto origin/main surfaced runbooks/home-assistant-maintenance.md
(W1N-69) which predated the runbook reorg. Add Purpose/Scope/Safety
headers and add it to the README routing index (now 17/17 consistent).
2026-08-17 16:02:33 +08:00
windyboy
b0c01b2551
docs(runbooks): add runbook spec, template, index and 6 first-batch runbooks; light-enhance existing 10
...
- RUNBOOKS.md: repo-level spec (six-field model, naming, safety, maturity path)
- runbooks/_template.md + README.md: standard template and 16-entry routing index
- new: issue-to-merge, fix-ci, release, rollback, network-change, network-recovery
- light-enhance 10 existing runbooks with Purpose/Scope/Safety headers
- AGENTS.md: point step 3 at index/spec, add runbook execution rules
- docs/agent-runbook-guide.md: archive of Manus AI guide
2026-08-17 15:59:46 +08:00
windyboy
047ac03346
chore(skills): remove vendored encrypted-dns-skill (installed globally via skills CLI)
2026-08-15 12:35:55 +08:00
windyboy
1ec9246156
docs: treat ha backups list as ignored arg, not a subcommand
...
ha backups --help has no list; extra positional args still print
the default backup list with exit 0. Keep the ha host update fix.
2026-08-14 22:44:02 +08:00
windyboy
1936b8f5fe
docs: correct ha backups list CLI note in HA runbook
...
ha backups list exists on this host; only ha host update is missing.
2026-08-14 22:42:44 +08:00
windyboy
eda6536ddb
docs: record CSG v1.3.1 zip install and correct ha-maintenance restart failure
...
ha-maintenance.sh --restart-core --yes exited 1 in <1s without restarting
Core. Empty output is ssh failure hidden by 2>/dev/null + pipefail, not a
MOTD-strip after a successful restart. Direct `ha core restart` is the
working path.
2026-08-14 22:31:31 +08:00
windyboy
1dc880362d
docs: add HA Matrix integration notes and record .local rewrite removals
2026-08-14 18:17:26 +08:00
windyboy
70aea6cd72
feat(ednsdiag): add DoQ/DoH3/DNSCrypt transports, proxy support, probe & compare
2026-08-14 18:17:26 +08:00
windyboy
8303d78caf
Record W1N-105 CSG network step, P1, and fork master→main rename on hass.windy.lan.
2026-08-14 18:15:28 +08:00
windyboy
ebfe7b8488
docs(gw): document EdgeOS PPPoE redial procedure
2026-08-14 16:26:23 +08:00
windyboy
88eaefda33
Record W1N-104 CSG auto dual-stack deploy on hass.windy.lan.
...
end1 IPv6 is on, wlan0 stays off, and the live custom component is de01914
with ip_family=auto after the IPv4 blackhole.
2026-08-14 16:11:03 +08:00
windyboy
fcb76d3d5a
Record W1N-102 CSG deploy and IPv4 blackhole on hass.windy.lan.
...
The host note now states the aiohttp IPv4 client is live, Core loaded it,
and home PPPoE IPv4 to 95598.csg.cn is currently blackholed while IPv6
works on gw. HA still has IPv6 disabled (W1N-85).
2026-08-14 15:47:08 +08:00
windyboy
6ae835037b
hass.windy.lan: resolve health snapshot issues (W1N-70..76) and document findings
...
- Add tianqi weather recorder patch notes (W1N-75: _unrecorded_attributes)
- Document Bluetooth hci0 RTL8821CS instability (W1N-74) and eMMC lifetime
10% (W1N-76) as known issues
- Rewrite runbook known-issues section: all snapshot items resolved; link
hosts doc for the two remaining known issues
2026-08-13 19:48:18 +08:00
windyboy
b5617fd3a9
docs(ha): add Home Assistant maintenance runbook + ha CLI script (W1N-69)
...
- runbooks/home-assistant-maintenance.md: access pattern (sudo -n -i ha),
command reference verified on host, recovery ops, families not scripted,
docs-vs-CLI discrepancies
- runbooks/scripts/ha-maintenance.sh: read-only health/logs + --yes-gated
update/restart/rebuild/rollback/reboot/backup/restore/app modes
- AGENTS.md: register runbook in table; hosts/hass: access pattern + link
2026-08-13 17:54:33 +08:00
windyboy
f5842568b9
docs: add Home Assistant API access notes
2026-08-13 17:20:49 +08:00
windyboy
6f8a4918f0
feat(ednsdiag): support custom DoH endpoint via --url
...
Allow overriding the provider preset with an explicit HTTPS DoH URL,
including validation that custom endpoints apply only to DoH queries.
2026-08-13 15:34:54 +08:00
windyboy
5b0f7950e6
docs: add hass.windy.lan Home Assistant host documentation
...
Document HAOS on PVE VM 180 (LAN55) with verified SSH access,
network details, and cross-links from lan-overview, inventory,
and AGENTS quick map.
2026-08-13 14:10:39 +08:00
windyboy
c0cf82d4af
tools(skills): add encrypted-dns-skill (ednsdiag CLI + agent skill)
2026-08-13 12:52:20 +08:00
windyboy
95ec2350af
docs(dns): record mosdns foreign DoH multi-upstream redundancy (W1N-62)
2026-08-13 10:56:40 +08:00
windyboy
3de4beb028
docs: add low-volume mono laser MFP buying guide (2026-08)
...
Decision tree for occasional B&W laser MFP purchases: Brother L1638W/L1848W
as default, cloud-subscription models as opt-in only, and one-veto checks
for AirPrint, Ethernet, and duplex/ADF needs.
2026-08-13 10:54:29 +08:00
windyboy
d54ec71aea
docs(dns): record gfw foreign branch DoH change (W1N-62)
...
Document encrypted DoH upstream for mosdns foreign queries and note that
DoH traffic goes direct to hk2, not via OpenClash proxy.
2026-08-13 10:50:16 +08:00
windyboy
2ffd9f9f9c
docs(se5420): align review claim verification with current guide (W1N-63)
...
Add historical snapshot header (baseline 35577d0 ), rewrite outdated
"current guide" assertions for post-ffb37a9 revisions, and add a
12-row status table mapping review claims to current §4.3/§11 sections.
2026-08-13 10:50:16 +08:00
windyboy
f255785b72
docs(se5420): add review claim verification record (2026-08-10)
...
Documents which deployment-guide review claims are confirmed by specs,
field read-only checks on gfw, and remaining pre-change evidence needs.
2026-08-13 10:12:06 +08:00
windyboy
2fd354c2a9
docs(dns): record mosdns fallback hardening for AGH outage (W1N-56)
2026-08-12 22:24:54 +08:00
windyboy
82203038f0
docs(dns): record mosdns sequence misconfig found+fixed (W1N-56)
2026-08-12 22:19:20 +08:00
windyboy
096e1ce8b6
docs(dns): correct idle-mosdns premise in alternatives research (W1N-56)
2026-08-12 22:12:32 +08:00
windyboy
8550053287
docs(dns): record Phase 0 verification evidence + final decision alignment (W1N-56)
2026-08-12 22:11:53 +08:00
windyboy
e501b93d65
docs(dns): correct gfw/.1 facts (W1N-56)
...
- hosts/gfw.windy.lan.md: 3 NICs (eth2/VLAN10 ubunt_upg live), mosdns is
now OpenClash's nameserver (not idle), rewrite VLAN10 Wi-Fi section to
live-verified state
- docs/lan-dns-architecture.md: mosdns on gfw no longer 闲置; note the
recommended AGH+.36 companion architecture is still pending review
2026-08-12 22:11:53 +08:00
windyboy
62b8fbb8b7
docs(dns): add LAN DNS architecture research + recommendation (W1N-56)
2026-08-12 22:11:53 +08:00
windyboy
efa6cf0899
docs(dns): record agh_ui_access LAN55 allow for Home Assistant (2026-08-12)
2026-08-12 22:11:53 +08:00
windyboy
086740b16e
docs: record pdns PDA removal, us4 firewalld ops, LAN DNS alternatives
...
- runbooks/pdns-health.md: note the legacy powerdns-admin (PDA) orphan was
removed 2026-08-12 (W1N-59).
- runbooks/ansible-operations.md: document the us4 firewalld reconciliation
playbook scope (audited public zone only, fail-closed, no reload).
- docs/agents/domain.md: single-context repo layout for domain docs.
- docs/lan-dns-alternatives.md: notes on LAN DNS alternatives.
- .gitignore: exclude local agent-harness config (.agents/ .claude/ .omp/
.mcp.json WATCHDOG.yml skills-lock.json) from the repo.
2026-08-12 21:16:31 +08:00