Commit Graph

567 Commits

Author SHA1 Message Date
Will Anderson 0341b570ab fix: gitea runner workingDir, README updates, monitoring domain
- Fix act-runner workingDir: /data on both init and main containers so
  .runner registration file is found at daemon startup
- Add servers/legion/README.md with full service catalog and deploy docs
- Update root README.md to be an index pointing to key docs
- Fix monitoring.tf comment: grafana.neuralplatform.ai (not nook.family)
- Fix AGENTS.md router model to TP-Link Deco BE5000
2026-03-24 12:55:29 -05:00
Will Anderson 5bd7702874 Add Gitea act-runner and fix ddclient deployment
- gitea-runner.tf: Secret for Gitea runner registration token
- apps/gitea-runner.yaml: Gitea act-runner deployment (init container
  registers with Gitea, main container runs daemon) — serves all Gitea
  Actions CI jobs on self-hosted,linux,x64,legion labels
- variables.tf: Add gitea_runner_token variable
- ddclient.tf: Switch to official ghcr.io/ddclient/ddclient image,
  remove linuxserver wrapper that was exhausting inotify instances
2026-03-24 12:51:22 -05:00
Will Anderson 087c5a79f4 Add native DNS-over-TLS (DoT) on dot.nook.family:853
- ddclient.tf: dynamic DNS daemon that keeps dot.nook.family A record
  pointing at the home public IP via Cloudflare API (updates every 5m)
- adguard.tf: cert-manager Certificate for dot.nook.family via DNS-01,
  updated TLS config block with DoT paths and port 853
- apps/adguard.yaml: mount adguard-dot-tls secret, expose port 853,
  init container enforces TLS/DoT settings on every restart
- adguard.tf: fix stale neuralplatform.dev → neuralplatform.ai rewrite

Android Private DNS: set to dot.nook.family
Router: forward TCP 853 → 192.168.68.77
2026-03-24 09:27:21 -05:00
Will Anderson 3518620360 fix: PGPASSWORD env var, neuron registry, gitea domain
- backup.tf: rename POSTGRES_PASSWORD → PGPASSWORD so pg_dumpall
  can authenticate (was silently failing for 2 days)
- neuron.yaml: fix image registry nook.family → neuralplatform.ai
- gitea.yaml: fix domain neuralplatform.dev → neuralplatform.ai
2026-03-24 08:08:40 -05:00
Will Anderson 1c8d7cecd8 monitoring: wire Alertmanager to #infrastructure-alerts in Slack
Routes all warning/critical alerts to the Neural Platform Slack workspace.
Suppresses Watchdog and info-level noise. Groups by namespace+alertname,
repeats every 4h. Uses bot token auth via chat.postMessage API.
2026-03-24 01:45:06 -05:00
Will Anderson f8bc853136 DR: full bootstrap script + recovery runbook
bootstrap.sh now covers a complete fresh Ubuntu 24.04 setup:
- NVIDIA driver 580 + container toolkit + k3s GPU config
- k3s install with nvidia as default runtime + device plugin
- Host cloudflared (Gitea SSH tunnel)
- Terraform + Helm
- systemd-resolved disabled, resolv.conf pinned

RUNBOOK.md documents the full 4-step recovery:
bootstrap → terraform apply → Gitea/Postgres restore → verify
Target: under 1 hour on a new machine.
2026-03-24 00:46:36 -05:00
Will Anderson 82b902f7c4 Move AdGuard to dns.nook.family, fix Agents.md service domains 2026-03-23 10:43:38 -05:00
Will Anderson bf2ec73983 Expose AdGuard DoH at dns.neuralplatform.ai 2026-03-23 10:29:42 -05:00
Will Anderson 8e208045de Fix init container: install pyyaml before import 2026-03-23 10:11:51 -05:00
Will Anderson 0e6b924e70 AdGuard: enforce filter lists and DNS upstreams via init container
ConfigMap adguard-defaults holds desired settings (upstreams, bootstrap DNS,
filter lists, rewrites). Init container merges them into the PVC config on
every pod start — no more manual kubectl edits needed.

- Switch upstreams to Cloudflare + Google DoH (Quad9 was failing)
- Bootstrap DNS IPv4-only (removes IPv6 timeout errors)
- Add OISD Big, EasyList, EasyPrivacy filter lists
- Fix DNS rewrites pointing to old IP 192.168.0.105
2026-03-23 10:05:41 -05:00
Will Anderson afe01d2ad9 Migrate all app deployments from Terraform to Argo CD
Move gitea, github-runner, neuron, cloudflared, ollama, verdaccio,
devpi, registry, and registry-ui deployments+services to apps/*.yaml
so Argo CD manages the app layer. Terraform retains namespaces, PVCs,
ConfigMaps, Secrets, and Ingresses.

New Secrets in Terraform:
- kubernetes_secret.github_runner_secret (ci/github-runner-secret)
- kubernetes_secret.cloudflared_secret (neuron/cloudflared-secret)

Hardcoded service names in ingress.tf and neuron.tf to remove
dependency on removed kubernetes_service resources.
2026-03-23 08:15:17 -05:00
Will Anderson b2b04c231c Migrate AdGuard deployment+service to Argo CD apps/ 2026-03-23 08:05:18 -05:00
Will Anderson 5231adc3a0 Configure Argo CD to watch servers/legion/apps/ in will/infrastructure 2026-03-23 08:00:37 -05:00
Will Anderson ef2ae715ee Argo CD on neuralplatform.ai, fix domain_suffix vs infra_domain usage 2026-03-23 07:57:10 -05:00
Will Anderson 13e71fd491 Add Argo CD — GitOps controller for legion app deployments 2026-03-23 07:52:07 -05:00
Will Anderson 7f022d3a67 Remove null_resources, add bootstrap.sh, fix k3s cert for new LAN IP 2026-03-23 07:49:57 -05:00
Will Anderson 0b4a236a88 Restructure: servers/legion/ layout, rename repo to infrastructure 2026-03-23 07:38:42 -05:00