Restructured Documentation
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s

This commit is contained in:
2026-09-05 14:08:43 -06:00
parent c4bd235eba
commit 289769a601
281 changed files with 5403 additions and 3563 deletions
@@ -0,0 +1,18 @@
---
tags:
- IredMail
- Email
---
## Purpose
Use this reference for iredmail connection settings and the environment-specific values recorded below.
!!! info "Recorded Connection Settings"
These values belong to the iRedMail example. Use the email guide to select the matching mail-server implementation before configuring a client.
| Server | Port(s) | Security | Auth Method | Username |
|:------------------|:----------------------------------------------|:----------|:----------------|:-------------------|
| `mail.bunny-lab.io` | **IMAP:** 143 `Internal`, 993 `External`<br>**SMTP:** 587, 25 `Fallback` | STARTTLS | Normal Password | user@bunny-lab.io |
## Related Documentation
- [Related Email Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
+31
View File
@@ -0,0 +1,31 @@
---
tags:
- Email
- Mailcow
- Microsoft Exchange
---
# Email
## Purpose
Choose the email environment before following a deployment or repair procedure. Mailcow with PMG, iRedMail, Microsoft Exchange, and the cPanel scaffold describe separate configurations; their presence here does not establish that they are all active in the lab.
## Includes
- Mailcow and PMG integration
- iRedMail deployment and connection settings
- Exchange maintenance and DAG recovery
## Mailcow and PMG
- [Deploy Mailcow](<../../../deployments/Applications/Email/mailcow.md>) — Configure the mail service and its documented proxy arrangement.
- [Integrate PMG with Mailcow](<../../../deployments/Applications/Email/Proxmox Mail Gateway/Integrate PMG with Mailcow.md>) — Follow the gateway, DNS, NAT, and mail-flow integration.
- [Repair Trusted Mail Delivery](<../../../workflows/Applications/Email/Proxmox Mail Gateway/Repair Trusted Mail Delivery Between PMG and Mailcow.md>) — Investigate sender-validation or relay-trust failures after integration.
## iRedMail
- [Deploy iRedMail](<../../../deployments/Applications/Email/iRedMail/Deploy iRedMail.md>) — Follow the separately documented mail-server implementation.
- [Client Connection Settings](<iRedMail Connection Settings.md>) — Find the recorded protocol and server settings.
- [Inspect the SMTP Queue](<../../../workflows/Applications/Email/iRedMail/Inspect the Outgoing SMTP Queue.md>) — Investigate outgoing messages on the iRedMail environment.
## Microsoft Exchange
- [Exchange SE Rolling Updates](<../../../workflows/Applications/Email/Microsoft Exchange/Perform Exchange SE DAG Rolling Updates.md>) — Use the complete maintenance cycle for the explicitly described three-member example.
- [DAG Database Copy Repairs](<../../../workflows/Applications/Email/Microsoft Exchange/Manage DAG Database Copies.md>) — Review the older example and version context before applying its recovery commands.
- [Cumulative Update Preparation Notes](<../../../workflows/Applications/Email/Microsoft Exchange/Prepare for Cumulative Updates.md>) — Review the separate preparation procedure and its environment assumptions.
- [Certificate Packaging](<../../../workflows/Identity and Certificates/Certificates/Convert Certificates to PFX.md>) — Find the documented certificate conversion workflow.
@@ -0,0 +1,101 @@
---
tags:
- Rclone
- PowerShell
- Synchronization
- Google Drive
---
## Purpose
This document explains the practical differences between the rclone `copy`, `sync`, `check`, and `bisync` commands and links to the separate workflow for configuring and recovering a bidirectional synchronization pair. The examples use PowerShell and assume that one side of the synchronization is a Google Drive remote.
Rclone is a command-line file-management program that supports cloud storage providers, object-storage platforms, local filesystems, and standard transfer protocols.
[Download rClone](https://rclone.org/downloads)
[Official rClone Documentation](https://rclone.org/docs/)
!!! info "Version Context"
This document was reviewed against rclone `v1.75.0`. Older releases may not support every bisync flag documented here, and future versions may change some recovery behavior.
!!! danger "Rclone Can Delete or Overwrite Data"
The `sync` and `bisync` commands can delete, replace, rename, or propagate the deletion of files. Always confirm the source and destination paths, maintain a separate backup or snapshot, and preview unfamiliar operations with `--dry-run` before allowing them to modify data.
A dry run is a preview and is not a replacement for a backup.
## Prepare the Command
Set the executable path in the PowerShell session before using the command examples. Replace the example path with the location of `rclone.exe` on the target machine.
```powershell
$Rclone = "C:\Path\To\rclone.exe"
```
## Command Behavior
The correct command depends on the intended relationship between the source and destination.
| **Command** | **Primary Behavior** | **Deletes Destination-Only Files** | **Direction** |
| :--- | :--- | :--- | :--- |
| `copy` | Adds or updates source files at the destination while retaining unrelated destination files | No | One-way |
| `sync` | Makes the destination match the source | Yes | One-way |
| `check` | Compares files without modifying either side | No | Read-only |
| `bisync` | Detects and propagates changes made on either side by comparing the current state against prior listings | Yes | Two-way |
### Use `copy` for Additive Transfers
Use `copy` when you need to add or update files without deleting files that already exist only at the destination.
```powershell
& $Rclone copy "Source" "Destination" --update --dry-run --verbose
```
The `--update` flag skips a source file when the corresponding destination file has a newer modification time. It does not create version history, and it does not prevent an older destination file from being replaced by a newer source file.
After reviewing the dry-run output, repeat the operation without `--dry-run`:
```powershell
& $Rclone copy "Source" "Destination" --update --verbose
```
### Use `sync` Only for Intentional Mirroring
Use `sync` when the destination must become a one-way mirror of the source.
!!! danger "`sync` Deletes Destination-Only Files"
The `sync` command removes files from the destination when they do not exist in the source. This is true even when `--update` is present.
The `--update` flag only prevents a newer destination file from being replaced by an older source file. It does not convert `sync` into an additive operation and does not protect destination-only files from deletion.
Preview the operation first:
```powershell
& $Rclone sync "Source" "Destination" --dry-run --verbose
```
Only remove `--dry-run` after confirming that every proposed copy, replacement, and deletion is intentional:
```powershell
& $Rclone sync "Source" "Destination" --verbose
```
### Use `check` for Read-Only Comparison
The `check` command compares files on both sides without copying, replacing, or deleting them.
```powershell
& $Rclone check "Source" "Destination" --combined "rclone-comparison.txt" --log-level INFO --log-file "rclone-check.log"
```
The combined report uses the following symbols:
| **Symbol** | **Meaning** |
| :--- | :--- |
| `=` | The file exists on both sides and matches |
| `+` | The file exists only in the source |
| `-` | The file exists only in the destination |
| `*` | The same path exists on both sides, but the files differ |
| `!` | The file could not be read or compared |
The `check` command compares files but does not report missing empty directories.
## Configure Two-Way Synchronization
Use [Configure and Recover Rclone Bisync](<../../../workflows/Applications/Files and Collaboration/Configure and Recover Rclone Bisync.md>) for initialization, normal runs, state handling, and recovery.
## Related Documentation
- [Related Files and Collaboration Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,42 @@
---
tags:
- Robocopy
- Batch
- Scripting
- Windows
---
## Purpose
Robocopy is a useful tool that can be leveraged to copy files and folders from one location to another (e.g. Over the network to another server) without losing file and folder ACLs (permissions / ownership data).
!!! warning "Run as Domain Admin"
When you run Robocopy, especially when transferring data across the network to another remote server, you need to be sure to run the command prompt under the session of a domain admin. Secondly, it needs to be ran as an administrator to ensure the command is successful. This can be done by going to the start menu and typing "**Command Prompt**" > **Right Clicking** > "**Run as Administrator**" while logged in as a domain administrator.
An example of using Robocopy is below, with a full breakdown:
```powershell
robocopy "E:\Source" "Z:\Destination" /Z /B /R:5 /W:5 /MT:4 /COPYALL /E
```
- `robocopy "Source" "Destination"` : Initiates the Robocopy command to copy files from the specified source directory to the designated destination directory.
- `/Z` : Enables Robocopy's restartable mode, which allows it to resume file transfer from the point of interruption once the network connection is re-established.
- `/B` : Activates Backup Mode, enabling Robocopy to override Access Control Lists (ACLs) and copy files regardless of the existing file or folder permissions.
- `R:5` : Sets the maximum retry count to 5, meaning Robocopy will attempt to copy a file up to five times if the initial attempt fails.
- `W:5` : Configures a wait time of 5 seconds between retry attempts, providing a brief pause before trying to copy a file again.
- `/MT:4` : Employs multi-threading with 4 threads, allowing Robocopy to process multiple files simultaneously, each in its own thread.
- `/COPYALL` : Instructs Robocopy to preserve all file and folder attributes, including security permissions, timestamps, and ownership information during the copy process.
- `/E` : Directs Robocopy to include all subdirectories in the copy operation, ensuring even empty directories are replicated in the destination.
!!! tip "Usage of Administrative Shares"
Whenever dealing with copying data from one server to another, try to leverage "Administrative Shares", also referred to as "Default Shares". These exist in such a way that, if the server exists in a Windows-based domain, you can type something like `\\SERVER\C$` or `\\SERVER\E$` to access files and bypass most file access restrictions (ACLs). This generally only applies to read-access, write-access may be denied in some circumstances.
An adjusted example can be seen below to account for this usage.
**This example assumes you are running robocopy from the destination computer**.
**Remember**: You are always **PULLING** data with administrative shares, not pushing it, the source should be the administrative share, and the destination should be local (in this example). There are scenarios where you can move data between two network shares, but its best (and cleaner) to always have a remote/local relationship in the transfer.
```powershell
robocopy "\\SERVER\E$\SOURCE" "E:\DESTINATION" /Z /B /R:5 /W:5 /MT:4 /COPYALL /E
```
## Related Documentation
- [Related Files and Collaboration Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,35 @@
---
tags:
- File Services
- Nextcloud
- Synchronization
---
# Files and Collaboration
## Purpose
Find the service that owns the data, then choose its integration, permissions, or transfer procedure. Distinguish an additive copy, a one-way mirror, and a two-way synchronization before running a transfer tool.
## Includes
- Nextcloud and office integration
- Windows DFS and permission reports
- File-copy and synchronization tools
## Applications and Office Integration
- [Nextcloud AIO](<../../../deployments/Applications/Files and Collaboration/Nextcloud AIO.md>) — Follow the AIO deployment and its integration requirements.
- [Separate Nextcloud Deployment](<../../../deployments/Applications/Files and Collaboration/Nextcloud.md>) — Consult the alternative container example.
- [Collabora](<../../../deployments/Applications/Files and Collaboration/Collabora Code Server.md>) — Connect the office service to the matching Nextcloud installation.
- [OnlyOffice](<../../../deployments/Applications/Files and Collaboration/OnlyOffice EE.md>) — Review the separately documented office-service option.
- [Upload to a Nextcloud Share](<../../../scripts/Applications/Files and Collaboration/Upload Data to a Nextcloud Share.md>) — Use the PowerShell or Bash example for a shared upload destination.
## Windows File Services
- [Deploy DFS](<../../../deployments/Applications/Files and Collaboration/Windows Server/DFS Namespaces with Replication.md>) — Build the namespaces and replication before using the reports.
- [Report DFS Configuration](<../../../scripts/Applications/Files and Collaboration/DFS/Report DFS Namespaces and Replication.md>) — Inspect namespace targets and replication configuration.
- [Report DFS Backlog](<../../../scripts/Applications/Files and Collaboration/DFS/Report DFS Replication Backlog.md>) — Check directional replication progress.
- [SMB Share Permissions](<../../../scripts/Applications/Files and Collaboration/SMB/Report SMB Share Permissions.md>) — Report the permissions assigned at the share layer.
- [NTFS Permissions](<../../../scripts/Applications/Files and Collaboration/SMB/Report NTFS Permissions Across Shares.md>) — Report filesystem ACLs beneath the shared paths.
## Choose a Transfer Procedure
- [Robocopy](<Robocopy Command Reference.md>) — Review the Windows copy and mirror examples and their permission handling.
- [Rclone Commands](<Rclone Command Reference.md>) — Compare copy, sync, check, and bisync behavior.
- [Rclone Bisync](<../../../workflows/Applications/Files and Collaboration/Configure and Recover Rclone Bisync.md>) — Configure a persistent two-way synchronization pair and its recovery state.
- [Netcat Transfer](<../../../workflows/Applications/Files and Collaboration/Transfer Files with Netcat.md>) — Review the dedicated transfer example and its transport limitations.
+23
View File
@@ -0,0 +1,23 @@
---
tags:
- Applications
- Reference
- Documentation
---
# Applications
## Purpose
Find applications by the service they provide, then continue to their deployment, authentication, data, and maintenance documentation.
## Includes
- Choose the Mailcow/PMG, iRedMail, or Exchange documentation that matches the environment.
- Connect Nextcloud, office integration, DFS, permissions, and file-transfer tools.
- Start with Home Assistant, then follow the camera and device integration links.
## Find the Right Document
- [Email](<Email/index.md>) — Choose the Mailcow/PMG, iRedMail, or Exchange documentation that matches the environment.
- [Files and Collaboration](<Files and Collaboration/index.md>) — Connect Nextcloud, office integration, DFS, permissions, and file-transfer tools.
- [Home Automation](<../../deployments/Applications/Home Automation/HomeAssistant.md>) — Start with Home Assistant, then follow the camera and device integration links.
- [Monitoring and Notifications](<../../deployments/Applications/Monitoring/Gatus.md>) — Find endpoint monitoring and the separately documented ntfy notification service.
- [Game Hosting](<../../deployments/Applications/Gaming and Media/Pterodactyl.md>) — Find the control panel alongside individual server deployments.
- [Application Deployments](<../../deployments/Applications/index.md>) — Browse the remaining asset-management, communication, dashboard, and utility services.
@@ -0,0 +1,48 @@
---
tags:
- Ansible
- Automation
---
## Purpose
Record AWX credential examples for Linux and Windows targets. The examples retain their original domain context and must be reconciled with the authentication method used by the target environment.
!!! info "Recorded Credential Examples"
These examples use the `MOONGATE.LOCAL` domain and record Kerberos limitations from that setup. The separate [AWX Kerberos implementation](<../../../workflows/Automation/AWX/AWX Kerberos Implementation.md>) describes a `BUNNY-LAB.IO` configuration. Confirm which environment applies before using either example.
## Windows-based Credentials
### NTLM
NTLM-based authentication is not exactly the most secure method of remotely running playbooks on Windows devices, but it is still encrypted using SSL certificates created by the device itself when provisioned correctly to enable WinRM functionality.
```text title="(NTLM) nicole.rappe@MOONGATE.LOCAL"
Credential Type: Machine
Username: nicole.rappe@MOONGATE.LOCAL
Password: <Encrypted>
Privilege Escalation Method: runas
Privilege Escalation Username: nicole.rappe@MOONGATE.LOCAL
```
### Kerberos
Kerberos-based authentication is generally considered the most secure method of authentication with Windows devices, but can be trickier to set up since it requires additional setup inside of AWX in the cluster for it to function properly. The separately documented AWX Kerberos implementation describes a different environment.
```text title="(Kerberos WinRM) nicole.rappe"
Credential Type: Kerberos WinRM
Username: nicole.rappe
Password: <Encrypted>
Kerberos Realm (Domain): MOONGATE.LOCAL
```
## Linux-based Credentials
```text title="(LINUX) nicole"
Credential Type: Machine
Username: nicole
Password: <Encrypted>
Privilege Escalation Method: sudo
Privilege Escalation Username: root
```
!!! note "Note"
`WinRM / Kerberos` based credentials do not currently work as-expected. That limitation belongs to this recorded example; consult the linked Kerberos workflow for the separate implementation.
## Related Documentation
- [Related AWX Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,38 @@
---
tags:
- Ansible
- WinRM
- Automation
---
## Purpose
Record the input and injector definitions for the custom AWX Kerberos WinRM credential type.
```yaml title="Input Configuration"
fields:
- id: username
type: string
label: Username
- id: password
type: string
label: Password
secret: true
- id: krb_realm
type: string
label: Kerberos Realm (Domain)
required:
- username
- password
- krb_realm
```
```yaml title="Injector Configuration"
extra_vars:
ansible_user: '{{ username }}'
ansible_password: '{{ password }}'
ansible_winrm_transport: kerberos
ansible_winrm_kerberos_realm: '{{ krb_realm }}'
```
## Related Documentation
- [Related AWX Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,43 @@
---
tags:
- Ansible
- Automation
---
## Purpose
Explain how AWX inventories describe hosts, groups, and connection variables. Use the lab inventory for environment-specific host records.
Keep in mind the "Group Variables" section varies based on your environment. NTLM is considered insecure, but may be necessary when you are interacting with Windows servers that are not domain-joined. Otherwise you want to use Kerberos authentication. This is outlined more in the [AWX Kerberos Implementation](<../../../workflows/Automation/AWX/AWX Kerberos Implementation.md#job-template-and-inventory-examples>) documentation.
!!! note "Inventory Data Relationships"
An inventory file consists of hosts, groups, and variables. A host belongs to a group, and a group can have variables configured for it. If you run a playbook / job template against a host, it will assign the variables associated to the group that host belongs to (if any) during runtime.
```ini title="https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/inventories/homelab.ini"
# Networking
pfsense-example ansible_host=192.168.3.1
# Servers
example01 ansible_host=192.168.3.2
example02 ansible_host=192.168.3.3
example03 ansible_host=example03.domain.com # FQDN is required for Ansible in Windows Domain-Joined Kerberos environments.
example04 ansible_host=example04.domain.com # FQDN is required for Ansible in Windows Domain-Joined Kerberos environments.
# Group Definitions
[linuxServers]
example01
example02
[domainControllers]
example03
example04
[domainControllers:vars]
ansible_connection=winrm
ansible_winrm_kerberos_delegation=false
ansible_port=5986
ansible_winrm_transport=ntlm
ansible_winrm_server_cert_validation=ignore
```
## Related Documentation
- [Related AWX Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,30 @@
---
tags:
- Ansible
- Automation
---
## Purpose
Record the fields and variables used by the example AWX job template that deploys a Hyper-V guest.
```text title="Deploy Hyper-V VM"
Name: Deploy Hyper-V VM
Inventory: (NTLM) MOON-HOST-01
Playbook: playbooks/Windows/Hyper-V/Deploy-VM.yml
Credentials: (NTLM) nicole.rappe@MOONGATE.local
Execution Environment: AWX EE (latest)
Project: Ansible Playbooks (Gitea)
Variables:
---
random_number: "{{ lookup('password', '/dev/null chars=digits length=4') }}"
random_letters: "{{ lookup('password', '/dev/null chars=ascii_uppercase length=4') }}"
vm_name: "NEXUS-TEST-{{ random_number }}{{ random_letters }}"
vm_memory: "8589934592" #Measured in Bytes (e.g. 8GB)
vm_storage: "68719476736" #Measured in Bytes (e.g. 64GB)
iso_path: "C:\\ubuntu-22.04-live-server-amd64.iso"
vm_folder: "C:\\Virtual Machines\\{{ vm_name_fact }}"
```
## Related Documentation
- [Related AWX Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,65 @@
---
tags:
- Ansible
- Automation
---
## Purpose
This is an indexed list of Ansible Playbooks / Workflows that I have developed to deploy and manage various aspects of my lab environment. The list is not dynamically updated, so it may sometimes be out-of-date.
!!! warning "DOCUMENT UNDER CONSTRUCTION"
This document is a "scaffold" document. It is missing significant portions of several sections and should not be read with any scrutiny until it is more feature-complete down-the-road. Come back later and I should have added more to this document hopefully by then.
## Linux Playbooks
### Deployments
Deployment playbooks are meant to be playbooks (or a series of playbooks forming a "Workflow Job Template") that deploy a server or piece of software.
- Authentik
- [1-Authentik-Bootstrapper.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/Authentik/1-Authentik-Bootstrapper.yml)
- [2-Deploy-Cluster.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/Authentik/2-Deploy-Cluster.yml)
- [3-Deploy-Authentik.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/Authentik/3-Deploy-Authentik.yml)
- [Check_Cluster_Nodes.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/Authentik/Check_Cluster_Nodes.yml)
- [Check_Cluster_Pods.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/Authentik/Check_Cluster_Pods.yml)
- Immich
- [Full_Deployment.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/Immich/Full_Deployment.yml)
- Keycloak
- [Deploy-Keycloak.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/Keycloak/Deploy-Keycloak.yml)
- Portainer
- [Deploy-Portainer.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/Portainer/Deploy-Portainer.yml)
- PrivacyIDEA
- [privacyIDEA.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Deployments/privacyIDEA.yml)
- Rancher RKE2 Kubernetes Cluster
- PLACEHOLDER (not documented)
- PLACEHOLDER (not documented)
- PLACEHOLDER (not documented)
- PLACEHOLDER (not documented)
- PLACEHOLDER (not documented)
### Kerberos
This playbook is designed to be chain-loaded before any playbooks that involve interacting with Active Directory Domain-Joined Windows Devices. It establishes a connection with Active Directory using domain credentials, sets up a keytab file (among other things), and makes it so the execution environment that the subsequent jobs are running in are able to run against windows devices. This ensures the connection is encrypted the entire time the playbooks are running instead of using lower-security authentication methods like NTLM, which don't even always work in most circumstances. You can find more information in the [Kerberos Authentication](<../../../workflows/Automation/AWX/AWX Kerberos Implementation.md#kerberos-implementation>) section of the AWX documentation. `It does require additional setup prior to running the playbook.`
- [Establish_Kerberos_Connection.yml](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/src/branch/main/playbooks/Linux/Establish_Kerberos_Connection.yml)
!!! warning "Ansible w/ Kerberos is **not** for beginners"
I advise against jumping into the deep-end with setting up Kerberos authentication for your playbooks until you have made yourself more comfortable with how Kubernetes works, or at the very least, you need to read the linked documentation above very closely to ensure nothing goes wrong during the setup.
### Security
Security playbooks do things like secure devices with additional auditing functionality, login notifications, enforcing SSH certificate-based authentication, things of that sort.
- Install SSH Public Key Authentication
- PLACEHOLDER (not documented)
- SSH Login Notifications
- PLACEHOLDER (not documented)
## Windows Playbooks
### Deployments
Deployment playbooks are meant to be playbooks (or a series of playbooks forming a "Workflow Job Template") that deploy a server or piece of software.
- Hyper-V - Deploy GuestVM
- PLACEHOLDER (not documented)
- Query Active Directory Domain Computers
- PLACEHOLDER (not documented)
- Install BGInfo
- PLACEHOLDER (not documented)
## Related Documentation
- [Related AWX Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,21 @@
---
tags:
- AWX
- Gitea
- Automation
---
## Purpose
Understand how an AWX project supplies playbooks and inventory files from source control. Maintain the Gitea connection settings in the connection workflow so the project reference does not become a second configuration source.
## Project Relationships
A project identifies the repository and source-control credential. An inventory source can consume an inventory file from that project, and a job template selects a playbook from the project.
## Configure the Connection
[Connect AWX to Gitea](<../../../workflows/Automation/AWX/Connect AWX to Gitea.md>) contains the source URL, credential fields, inventory source, and overwrite behavior.
## Continue to Job Execution
[The AWX guide](<index.md>) connects inventory structure, credential examples, and job-template configuration.
## Related Documentation
- [Related AWX Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
+36
View File
@@ -0,0 +1,36 @@
---
tags:
- AWX
- Ansible
- Automation
---
# AWX
## Purpose
Follow AWX from its Kubernetes deployment through source control, inventory, credentials, and job execution. Check the environment context on older Minikube and credential examples before combining them with the operator deployment.
## Includes
- Controller deployment and upgrades
- Projects, inventories, credentials, and templates
- Gitea and Windows authentication integration
## Build the Controller
- [Rancher RKE2](<../../../deployments/Containers/Kubernetes/Rancher RKE2.md>) — Prepare the cluster required by the AWX Operator procedure.
- [AWX Operator](<../../../deployments/automation/AWX/AWX Operator.md>) — Deploy the controller into the documented cluster.
- [Minikube Example](<../../../deployments/automation/AWX/AWX in Minikube.md>) — Consult the separate deployment approach and its recorded assumptions.
## Connect the Automation Objects
A project supplies repository content. An inventory identifies targets and variables. Credentials provide authentication, and a job template combines these objects with a playbook.
- [Connect AWX to Gitea](<../../../workflows/Automation/AWX/Connect AWX to Gitea.md>) — Create the source credential, project, and inventory source together.
- [Projects and Source Control](<Projects and Source Control.md>) — Understand the project role without maintaining a second copy of its connection settings.
- [Inventory Structure](<Inventory Structure and Variables.md>) — Understand host groups and variables before changing the lab inventory.
- [Credential Examples](<Credential Configuration Examples.md>) — Review the recorded environment and authentication limitations.
- [Job Templates](<Job Template Configuration.md>) — Connect the project, inventory, playbook, and credentials.
- [Lab Inventory](<../../Lab Map/Homelab Server Inventory.md>) — Locate the recorded hosts and inventory groups.
## Run Against Windows Targets
- [Prepare Windows Targets](<../../../workflows/Identity and Certificates/Windows/Enable WinRM over HTTPS.md>) — Configure the remote-management endpoint used by the automation examples.
- [Configure AWX Kerberos](<../../../workflows/Automation/AWX/AWX Kerberos Implementation.md>) — Follow the execution-environment and FQDN requirements recorded for this implementation.
- [Custom WinRM Credential](<Custom Kerberos WinRM Credential.md>) — Find the credential input and injector definitions.
- [Playbook Catalog](<Playbook Catalog.md>) — Find existing repository playbooks and the catalog completeness notes.
@@ -0,0 +1,23 @@
---
tags:
- Gitea
- GitOps
- Automation
---
## Purpose
Choose the documented Gitea configuration-delivery approach that matches the target host and execution environment. The examples preserve distinct implementations rather than a single interchangeable runner configuration.
## Documented Approaches
- [Docker Runner](<../../workflows/Automation/Gitea/Deliver Configuration with a Docker Runner.md>) — The May 2025 example runs jobs inside the runner container and writes to a bind-mounted destination.
- [Zensical Host Runner](<../../workflows/Automation/Gitea/Publish Zensical Documentation with a Host Runner.md>) — The Zensical-specific example uses a host service account, watchdog permissions, and `/srv/zensical/docs`.
- [Git Repo Updater](<../../deployments/Containers/Docker/Git Repo Updater.md>) — The earlier polling-container approach retains its deployment instructions and canonical watcher script.
- [Why I Adopted Runners](<../../blog/posts/05-16-2025 Learning to Leverage Gitea Runners.md>) — Read the dated account of the watcher limitations and runner experiment.
## Follow the Destination Service
- [Zensical Deployment](<../../deployments/automation/Documentation/Zensical.md>) — Prepare the service and destination before applying the host-runner workflow.
- [Traefik Configuration](<../../deployments/Networking and Access/Reverse Proxies/Traefik.md>) — Identify the dynamic configuration destination before selecting a delivery method.
- [ntfy Notifications](<../../deployments/Applications/Monitoring/Ntfy.md>) — Find the notification service used by the runner examples.
## Related Documentation
- [Related Automation Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
+23
View File
@@ -0,0 +1,23 @@
---
tags:
- Automation
- Reference
- Documentation
---
# Automation
## Purpose
Connect source control, automation controllers, managed hosts, and configuration delivery. Use the documented execution environment and authentication method for each workflow.
## Includes
- Follow deployment, source control, inventory, credentials, and job execution.
- Build the Puppet environment and its Gitea configuration integration.
- Use the related remote-execution tooling and target prerequisites.
## Find the Right Document
- [AWX](<AWX/index.md>) — Follow deployment, source control, inventory, credentials, and job execution.
- [Puppet](<../../deployments/automation/Puppet/Puppet.md>) — Build the Puppet environment and its Gitea configuration integration.
- [Puppet Bolt](<../../deployments/automation/Puppet/Puppet Bolt.md>) — Use the related remote-execution tooling and target prerequisites.
- [Gitea](<../../deployments/automation/Gitea/Gitea.md>) — Deploy the source-control service used by controllers and runners.
- [Choose a Configuration Delivery Method](<Gitea Configuration Delivery.md>) — Compare the documented watcher, Docker runner, and Zensical host runner.
- [FOG Imaging](<../../deployments/automation/FOG Project/Deploy FOG Project.md>) — Connect the imaging deployment to the matching DHCP/PXE configuration.
@@ -0,0 +1,52 @@
---
tags:
- Veeam
- Backup
- Disaster Recovery
---
## Purpose
The purpose of this document is to explain the core concepts / terminology of things seen in Veeam Backup & Replication from a relatively high-level. It's more of a quick-reference guide than a formal education.
## Backup Jobs
Backup jobs take many forms, but the most common are explained in more detail below. Note that this is not an exhaustive list of the different kinds of backup jobs, just the ones I am currently most familiar with.
- **Backup**: This is the simplest of the backup job options. A "Backup" backup job will take a backup of a workstation, server, File Server, specific local files and folders on a device, or a GuestVM running in a hypervisor such as Hyper-V, VMWare ESXi, or ProxmoxVE.
- **Backup Copy**:
- This is when you make a copy of backup data stored on the Veeam server, and send it somewhere else, such as an off-site "Service Provider" such as Veeam partners.
- You can also send backup copies to local drives, SMB network shares, NFS shares, File Servers, pretty much anywhere you can send normal backups, but with the key difference being the data is originating from the Veeam backup server itself instead of the original server/VM.
- **SureBackup**: This is where things get a little more complex. SureBackup is where you effectively "Verify" your backups by spinning them up inside of a lab environment. While they are spun up, they are checked to see if they fully boot, they can have antivirus scans, ransomware scans, custom scripts executed, and validate the integrity of the backups. The general core components are listed below:
- **Virtual Lab**: The virtual lab is a virtual machine environment that you set up for Veeam to leverage to spin up backups on a hypervisor that you configure, such as a remote Hyper-V server in the same building, or perhaps if you have Hyper-V locally installed on the same server as Veeam itself, you would configure the virtual lab's hypervisor to point to `127.0.0.1` or `localhost`.
- The virtual lab will have its own unique virtual networking for the VMs to communicate on, so they don't conflict with the production servers/VMs.
- **Application Groups**: Application groups are defined groups of devices that need to be running when the backups are being validated. For example, in my homelab, I have an application group named `Domain Controllers`, and I put `LAB-DC-01` and `LAB-DC-02` into that application group. I use this as the application group associated with the Virtual Lab because most of my services are authenticated with Active Directory, and if the DCs were missing during backup verification, a variety of issues would ensue. When the Backup Verification Lab (Virtual Lab) is launched on the targeted hypervisor, it spins up the application group devices from backups first, ensuring they are running and functional, before the virtual lab starts verifying backup objects designated in the "Linked Jobs", seen in the next section.
- **Linked Jobs**: These are the "Backup Jobs" you want to verify in in the virtual lab mentioned above. If you have a large backup job with a bunch of machines you don't want verified, you can configure "Exclusions" in the SureBackup job settings to exclude those objects/devices from verification.
## Replication Jobs
As the name states, Veeam Backup & Replication can also handle replicating Servers/VMs from either their original locations or from a recent backup and push them into a hypervisor for rapid failover/failback functionality. Very useful for workloads that need to be spun up nearly immediately due to strict RTO requirements. There are some additional notes regarding replication seen below.
!!! warning "Orchestrate Replication & Failover via Veeam, not the Hypervisor"
You want to coordinate anything replication-wise directly in Veeam Backup & Replication, not directly on the hypervisor itself. While you can do this, it is not only slower, but does not give you the option to failback replicas back into production if you spin up a replica directly on its hypervisor.
- **Replication Restore Points**: Similar to backups, replicas can have multiple restore points associated with them, so you have more than one option when spinning up a replica in a hypervisor.
- **Planned Failover**: A planned failover is when you are scheduling the hypervisor to be offline and simply don't have enough resources to live-migrate it to another cluster host, or you might not even have a virtualization cluster to work with in the first place. In cases like this, a "Planned Failover" tells Veeam to make a fresh replica right now, then shuts down the production VM on its hypervisor, and spins up the replica on the replica server. (If you installed Hyper-V on the Veeam server, it would spin up the replica on the backup server itself).
- A "Planned Failover" allows you to perform a "**Failback to Production**" when the failover event has concluded. This means that while the production VM was offline and the replica took over the production load, any changes made such as new files added, applications installed, etc will be replicated back to the production VM when the replica is "Failed back to Production". **This is the ideal choice in most circumstances**.
- **Failover Now**: Failover now means that the production hypervisor is likely completely dead, and may need to be re-built, or you simply dont need to replicate changes back to production hypervisor after the failover event has concluded, such as on a low-priority print server. Any changes made while the replica is operational will be completely lost when the production VM is turned back on again or a restore is pushed back onto a new hypervisor.
## Backup Infrastructure
### Backup Repository
A backup repository is simply a destination to send the backups or backup copies. It can be anything from direct attached storage to a SMB file share on a NAS, or even off-site storage like Backblaze B2 or Amazon S3.
- If you use object storage like Backblaze B2 or Amazon S3, you can configure an "Immutability Period" for backups that are sent to these destinations, meaning if your backup server was hit by ransomware or a malicious actor, neither they nor you could delete the backups in the off-site storage such as Backblaze B2 until the immutability period had passed, such as 7 days, 30 days, or however long you configured.
- You can adjust the immutability period after-the-fact, but backups that have already been pushed to a backup repository will be immutable for the time period configured when they were originally uploaded, and attempts to delete them will tell you when you are allowed to delete them. You won't be able to delete them even from Amazon or Backblaze's own internal tools / websites during this immutability period.
### Backup Proxy
A backup "proxy" simply refers to a machine that is running the "**Veeam Backup Transport**" agent on it. The Veeam Backup & Replication server installs a proxy onto itself, but it also deploys proxies onto workstations, servers, and hypervisors. These proxies are how the "Veeam Backup & Replication Console" interacts with the devices and performs backups and restores.
### Service Provider
Service Providers are not the same as cloud storage providers such as Backblaze B2, Amazon S3, etc. Service Providers are Veeam "partners" who manage, maintain, and deploy Veeam backup appliances at client environments, as well as providing support to clients within the Veeam ecosystem. You can also use Service Providers as a cloud backup destination in Veeam Backup & Replication for off-site backups.
## Misc Terminology
- **Unstructured Data**: This refers to a device such as a windows or linux server that you can use WinRM or SSH to access, and want to backup specific files and folders without backing up the entire device / VM. This is useful in cases where you cannot install a Veeam Agent or the operating system is unsupported by Veeam, or if the device is not operating under a hypervisor, such as a bare-metal server.
- When you add a device to Veeam's "Inventory" via the "Unstructured Data" section, if you want to perform backups on the device, you will have to make a special backup job under "**Backups > File Server**", because Veeam will treat the unstructured data as a file server.
## Related Documentation
- [Related Backup and Recovery Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,30 @@
---
tags:
- Veeam
- Backup
- Disaster Recovery
---
## Purpose
This is meant as a high-level generally-speaking best practice retention policy in most use-cases. This document will generally be pretty bare-bones, but the general idea is the following advanced GFS retention period is generally configured on backup copy jobs, specifically ones that have off-site backups, but can also be used for local backup repositories.
!!! info "Example Retention Policy"
This is the recorded policy example and its assumptions. Select retention for the actual workload and recovery requirements before applying these values.
Navigate to Jobs > Backup (or Backup Copy) > (Find a Backup Job) > Right-Click > Edit > Storage (or Target) > "**Keep Certain Full Backups for Archival Purposes**: Checked" > Click on the "**Configure**" button.
Optional: Click the "**Save as Default**" button before clicking the "**OK**" button to make this default behavior for new backup jobs.
| **Description** | **Status** | **Value** |
| :--- | :--- | :--- |
| Keep Weekly Full Backups | Enabled | 4 |
| Keep Monthly Full Backups | Enabled | 3 |
| Keep Yearly Full Backups | Enabled | 1 (`3 - 7 for Medical HIPAA`) |
!!! note "7 Daily Backups Assumption"
This document assumes that you at (least) keep 7 daily backups in the normal backup schedule. Meaning **7 daily, 4 weekly, 3 monthly, and 1 yearly** backup is maintained at all times.
**7 daily, 4 weekly, 3 monthly, and 1 yearly**
## Related Documentation
- [Related Backup and Recovery Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
+23
View File
@@ -0,0 +1,23 @@
---
tags:
- Backup and Recovery
- Reference
- Documentation
---
# Backup and Recovery
## Purpose
Find backup concepts, repository maintenance, and recovery dependencies. Select the procedure for the affected backup system and distinguish a backup restore from a replica or snapshot operation.
## Includes
- Understand jobs, repositories, application groups, and replica terminology.
- Find the recorded GFS policy and its assumptions.
- Move agent ownership to a replacement backup server.
## Find the Right Document
- [Veeam Concepts](<Veeam Concepts.md>) — Understand jobs, repositories, application groups, and replica terminology.
- [Retention Policy Example](<Veeam Retention Policy Example.md>) — Find the recorded GFS policy and its assumptions.
- [Adopt an Existing Backup Agent](<../../workflows/Backup and Recovery/Veeam/Backup Agent Takeover.md>) — Move agent ownership to a replacement backup server.
- [Manage Repository Capacity](<../../workflows/Backup and Recovery/Veeam/Manually Pruning Backups.md>) — Review the existing backup-chain removal procedure before deleting data.
- [Repair Gateway Certificate Trust](<../../workflows/Backup and Recovery/Veeam/Failed to Validate Certificates of Some Gateways.md>) — Follow the specific Cloud Connect certificate failure.
- [Hypervisor Recovery](<../Virtualization and Storage/index.md>) — Find the applicable Hyper-V replica or Proxmox migration procedure.
+23
View File
@@ -0,0 +1,23 @@
---
tags:
- Containers
- Reference
- Documentation
---
# Containers
## Purpose
Prepare the Docker or Kubernetes environment used by application deployments, then follow the operating procedures for building, moving, and exposing workloads.
## Includes
- Prepare the external network referenced by Docker deployment examples.
- Manage the Docker workloads described in the service pages.
- Prepare the Kubernetes cluster used by the AWX Operator guide.
## Find the Right Document
- [Create the Docker Network](<../../deployments/Containers/Docker/Create the Docker Network.md>) — Prepare the external network referenced by Docker deployment examples.
- [Deploy Portainer](<../../deployments/Containers/Docker/Deploy Portainer.md>) — Manage the Docker workloads described in the service pages.
- [Deploy Rancher RKE2](<../../deployments/Containers/Kubernetes/Rancher RKE2.md>) — Prepare the Kubernetes cluster used by the AWX Operator guide.
- [Move a Compose Workload to Kubernetes](<../../workflows/Containers/Kubernetes/Migrating Docker Compose YML to K8s.md>) — Follow the ntfy example through conversion, service exposure, and Traefik integration.
- [Move Docker Containers](<../../workflows/Containers/Docker/Transfer Docker Containers Between Hosts.md>) — Transfer the existing container data and configuration between hosts.
- [Build and Publish an Image](<../../workflows/Containers/Docker/Build and Publish a Container Image.md>) — Use the documented container development workflow.
@@ -0,0 +1,23 @@
---
tags:
- Active Directory
- LDAP
- Authentication
---
## Purpose
LDAP settings are used in various services from privacyIDEA to Nextcloud. This will outline the basic parameters in my homelab that are necessary to make it function.
| **Field** | **Value** | **Description** |
| :--- | :--- | :--- |
| Server Address(s) | `ldap://bunny-dc-01.bunny-lab.io` / `192.168.3.8`, `ldap://bunny-db-02.bunny.lab.io` / `192.168.3.9` | Domain Controllers |
| Port | `389` | Unencrypted LDAP |
| STARTTLS | `Disabled` | |
| Base DN | `CN=Users,DC=bunny-lab,DC=io` | This is where users are pulled from |
| User / Bind DN | `CN=Nicole Rappe,CN=Users,DC=bunny-lab,DC=io` | This is the domain admin used to connect to LDAP |
| User / Bind Password | `<Password for User / Bind DN>` | Domain Credentials for Domain Admin account |
| Login Attribute | ` LDAP Filter: (&(&(|(objectclass=person))(|(|(memberof=CN=Domain Users,CN=Users,DC=bunny-lab,DC=io)(primaryGroupID=513))))(samaccountname=%uid)) ` | Used by Nextcloud |
| Login Attribute | `(sAMAccountName=*)(objectCategory=person)` | Used by PrivacyIDEA |
## Related Documentation
- [Related Identity and Certificates Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,20 @@
---
tags:
- Keycloak
- OAuth2
- Authentication
---
## Purpose
Choose the documented Keycloak integration for an application or reverse proxy after Keycloak is deployed. Application OAuth settings and reverse-proxy authentication serve different integration points.
## Prepare Keycloak
[Deploy Keycloak](<../../deployments/Identity and Certificates/Keycloak/Deploy Keycloak.md>) includes the service and proxy-middleware configuration.
## Configure an Application
- [Gitea OAuth2](<../../workflows/Identity and Certificates/Keycloak/Connect Gitea to Keycloak.md>) — Configure the documented application client.
- [Portainer OAuth2](<../../workflows/Identity and Certificates/Keycloak/Connect Portainer to Keycloak.md>) — Configure the documented Portainer integration.
- [Firefox Proxy Authentication](<../../deployments/Networking and Access/Remote Access/Firefox.md>) — Review the deployment that explains the proxy authentication flow.
## Related Documentation
- [Related Identity and Certificates Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,23 @@
---
tags:
- Identity and Certificates
- Reference
- Documentation
---
# Identity and Certificates
## Purpose
Connect directory services, certificate trust, single sign-on, and application authentication. Start with the identity system involved, then follow the integration or maintenance procedure.
## Includes
- Build the documented offline root, online subordinate CA, and publication point.
- Publish and monitor CRLs after the PKI exists.
- Provide the trust material needed by directory clients.
## Find the Right Document
- [Deploy Certificate Services](<../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Build the documented offline root, online subordinate CA, and publication point.
- [Maintain Revocation Lists](<../../workflows/Identity and Certificates/Certificates/Publish and Maintain Certificate Revocation Lists.md>) — Publish and monitor CRLs after the PKI exists.
- [Export LDAPS Certificates](<../../workflows/Identity and Certificates/Certificates/Export Certificates for LDAPS Clients.md>) — Provide the trust material needed by directory clients.
- [LDAP Connection Settings](<Active Directory/LDAP Connection Settings.md>) — Locate the recorded directory connection parameters.
- [Keycloak Application Integrations](<Keycloak Integrations.md>) — Choose reverse-proxy authentication or an application-specific OAuth integration.
- [Windows Remote Management](<../../workflows/Identity and Certificates/Windows/Enable WinRM over HTTPS.md>) — Prepare Windows targets for the AWX or Puppet Bolt workflows that reference WinRM.
@@ -14,4 +14,7 @@ This document is meant to help keep track disks and their associated serial numb
| **Column 01** | **Column 02** | **Column 03** | **Column 04** |
| :--- | :--- | :--- | :--- |
| 240GB<br>`SN: 50026B77850B2DA9` | 240GB<br>`SN: 50026B7784D34038` | 240GB<br>`SN: 50026B7784E8A771` | 240GB<br>`SN: 50026B7784E8CB49` |
| 240GB<br>`SN: 50026B7784D3620D` | 240GB<br>`SN: 50026B7784D45C34` | 240GB<br>`SN: 50026B7784E8AC95` | 240GB<br>`SN: 50026B7784E8A983` |
| 240GB<br>`SN: 50026B7784D3620D` | 240GB<br>`SN: 50026B7784D45C34` | 240GB<br>`SN: 50026B7784E8AC95` | 240GB<br>`SN: 50026B7784E8A983` |
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -20,4 +20,7 @@ This document is meant to help keep track disks and their associated serial numb
| EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` | 600GB<br>`SN: 6XR31D8L` |
| EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` | 600GB<br>`SN: 6XR33F2W` |
| EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` | 600GB<br>`SN: 6XR32TFE` |
| EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` |
| EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` |
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -15,4 +15,7 @@ This document is meant to help keep track disks and their associated serial numb
| :--- | :--- | :--- | :--- |
| 8TB<br>`SN: X1P0A01NFDWF` | 8TB<br>`SN: WWZ1TJT2` | EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` |
| 8TB<br>`SN: VRK6M6MK` | 8TB<br>`SN: Y1L0A0QQFDWF` | EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` |
| 8TB<br>`SN: VRK6XEMK` | EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` | 1TB<br>`SN: 2417E8A9A7C1` |
| 8TB<br>`SN: VRK6XEMK` | EMPTY<br>`SN: N/A` | EMPTY<br>`SN: N/A` | 1TB<br>`SN: 2417E8A9A7C1` |
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -21,4 +21,7 @@ This document is meant to help keep track disks and their associated serial numb
| 960GB<br>`SN: 50026B7785270194` | 960GB<br>`SN: 50026B77853B0F4C` | 960GB<br>`SN: 50026B7785270EB4` | 960G<br>`SN: 50026B76870D497D` | 960GB<br>`SN: 50026B778526FCC8` |
| 960GB<br>`SN: 50026B778526F8F2` | 960GB<br>`SN: 50026B778526F8EB` | 960GB<br>`SN: 50026B778526FCFC` | 960GB<br>`SN: 50026B76870D47DF` | 960GB<br>`SN: 50026B778526F8EC` |
| 960GB<br>`SN: 50026B7785270E2A` | 960GB<br>`SN: 50026B7785270653` | 960GB<br>`SN: 50026B778526FF67` | 960GB<br>`SN: 50026B7384228B63` | 960GB<br>`SN: 50026B778526FF4A` |
| 960GB<br>`SN: 50026B778526FFAA` | 960GB<br>`SN: 50026B778526FFC7` | 960GB<br>`SN: 50026B778526FF49` | 1TB<br>`SN: SI04T000311404D40` | EMPTY<br>`SN: N/A` |
| 960GB<br>`SN: 50026B778526FFAA` | 960GB<br>`SN: 50026B778526FFC7` | 960GB<br>`SN: 50026B778526FF49` | 1TB<br>`SN: SI04T000311404D40` | EMPTY<br>`SN: N/A` |
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -14,4 +14,7 @@ This document is meant to help keep track disks and their associated serial numb
| **Slot 01** | **Slot 02** | **Slot 03** | **Slot 04** | **Slot 05** |
| :--- | :--- | :--- | :--- | :--- |
| 4TB<br>`SN: Z305ZNZM` | 4TB<br>`SN: Z305SPL8` | 4TB<br>`SN: Z3051AF8` | 4TB<br>`SN: Z305ZNM1` | 4TB<br>`SN: Z305S03R` |
| 4TB<br>`SN: Z305ZNZM` | 4TB<br>`SN: Z305SPL8` | 4TB<br>`SN: Z3051AF8` | 4TB<br>`SN: Z305ZNM1` | 4TB<br>`SN: Z305S03R` |
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,27 @@
---
tags:
- iLO
- Hardware
- Licensing
---
## Purpose
Preserve the recorded iLO license reference and its existing usage limitations for lab hardware.
!!! info "Assumptions of Usage"
It should go without saying, using one of these keys does not entitle you to support by Hewlett-Packard Enterprise. These are meant for homelab environments where licensing / auditing does not matter.
| **iLO Version** | **License Key** |
| :--- | :--- |
| iLO Standard Trial | `34T6L-4C9PX-X8D9C-GYD26-8SQWM` |
| iLO 1 Advanced | `247RH-ZPJ8S-7B17D-FCE55-DDD17` |
| iLO 2 / 3 / 4 Advanced | `35DPH-SVSXJ-HGBJN-C7N5R-2SS4W` |
| iLO 2 / 3 / 4 / 5 Advanced | `35SCR-RYLML-CBK7N-TD3B9-GGBW2` |
!!! warning "Do not Use in Production Work Environments"
In (rare) cases, these keys can be used as a temporary solution when working in a work environment, then promptly removed after the work is performed. Leaving them installed on a server could lead to legal consequences if Hewlett-Packard Enterprise asked for it while providing support, and it was using one of these keys, it could fail a software licensing audit.
`REMOVE THE KEY AFTER USAGE`
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -5,13 +5,19 @@ tags:
- Docker
---
## Purpose
Use this reference for homelab server inventory and the environment-specific values recorded below.
!!! info "Inventory Reconciliation"
This reference preserves the recorded host and group assignments. Some deployment examples use different hostnames or addresses; reconcile those differences with the running environment before changing inventory or applying a procedure.
## Overview
All servers (physical and virtual) are documented within this specific page. They are written in a specific annotated manner in order to make them copy/paste ready for the Ansible AWX Operator server that interacts with devices in the homelab over `SSH` and `WinRM` protocols. This allows me to automate functions such as updates across the entire homelab declaratively versus individually.
**Note**: This list does not include Docker/Kubernetes-based workloads/servers. Those can be found within the [Container Network IP Table](../../networking/ip-tables/192-168-5-0-container-network.md) document. Given that Ansible does not interact with containers in my homelab (*yet*), these devices are not listed within this document.
**Note**: This list does not include Docker/Kubernetes-based workloads/servers. Those can be found within the [Container Network IP Table](<Network Address Plans/192.168.5.0 Container Network.md>) document. Given that Ansible does not interact with containers in my homelab (*yet*), these devices are not listed within this document.
## Updating Ansible Inventory
Whenever changes are made here, they need to be replicated to the production Ansible AWX Inventory File. This ensures that Ansible AWX is always up-to-date. Simply copy/paste the codeblock below into the linked inventory file, and commit the change with a comment explaining what was added/removed from the inventory list.
Whenever changes are made here, they need to be replicated to the production Ansible AWX Inventory File. This ensures that Ansible AWX is always up-to-date. Simply copy/paste the codeblock below into the linked inventory file, and commit the change with a comment explaining what was added/removed from the inventory list.
[:material-ansible: Edit Ansible AWX Inventory File](https://git.bunny-lab.io/GitOps/awx.bunny-lab.io/_edit/main/inventories/homelab.ini){ .md-button }
@@ -173,7 +179,7 @@ ansible_connection=ssh
7. Immich Server @ `192.168.3.7` | [Documentation](https://immich.app/docs/install/docker-compose/)
8. Zensical Documentation Server @ `192.168.3.8` | [Documentation](https://hub.docker.com/r/zensical/zensical)
9. FOG Project @ `192.168.3.9` | [Documentation](https://fogproject.org/)
10. Ansible AWX @ `192.168.3.10` | [Documentation](../../../../deployments/automation/ansible/awx/deployment/awx-operator.md)
10. Ansible AWX @ `192.168.3.10` | [Documentation](<../../deployments/automation/AWX/AWX Operator.md>)
11. Minecraft - All The Mods 9 @ `192.168.3.11` | [Documentation](https://www.curseforge.com/minecraft/modpacks/all-the-mods-9)
12. Windows DHCPS Server @ `192.168.3.12`
13. Windows DHCPS Server @ `192.168.3.13`
@@ -181,18 +187,18 @@ ansible_connection=ssh
15. Proxmox Mail Gateway @ `192.168.3.15` | [Documentation](https://example.com)
16. Not Currently In-Use @ `192.168.3.16` | [Documentation](https://example.com)
17. Traefik Reverse Proxy @ `192.168.3.17` | [Documentation](https://example.com)
18. Keycloak Server @ `192.168.3.18` | [Documentation](../../../../deployments/services/authentication/keycloak/deployment.md)
19. Docker Container Environment (Portainer) @ `192.168.3.19` | [Documentation](../../../../deployments/platforms/containerization/docker/deploy-portainer.md)
20. PrivacyIDEA @ `192.168.3.20` | [Documentation](../../../../deployments/services/authentication/privacyidea.md)
21. Puppet Server @ `192.168.3.21` | [Documentation](../../../../deployments/automation/puppet/deployment/puppet.md)
18. Keycloak Server @ `192.168.3.18` | [Documentation](<../../deployments/Identity and Certificates/Keycloak/Deploy Keycloak.md>)
19. Docker Container Environment (Portainer) @ `192.168.3.19` | [Documentation](<../../deployments/Containers/Docker/Deploy Portainer.md>)
20. PrivacyIDEA @ `192.168.3.20` | [Documentation](<../../deployments/Identity and Certificates/Privacyidea.md>)
21. Puppet Server @ `192.168.3.21` | [Documentation](<../../deployments/automation/Puppet/Puppet.md>)
22. Not Currently In-Use @ `192.168.3.22` | [Documentation](https://example.com)
23. Hyper-V Failover Cluster @ `192.168.3.23` | [Documentation](../../../../deployments/platforms/virtualization/hyper-v/failover-cluster/deploy-failover-cluster-node.md)
23. Hyper-V Failover Cluster @ `192.168.3.23` | [Documentation](<../../deployments/Virtualization and Storage/Hyper-V/Failover Cluster/Deploy Failover Cluster Node.md>)
24. TrueNAS SCALE @ `192.168.3.24` | [Documentation](https://www.truenas.com/truenas-scale/)
25. Primary Domain Controller @ `192.168.3.25` | [Documentation](https://example.com)
26. Secondary Domain Controller @ `192.168.3.26` | [Documentation](https://example.com)
27. Blue Iris Surveillance @ `192.168.3.27` | [Documentation](https://blueirissoftware.com/)
28. ARK: Survival Ascended Server @ `192.168.3.28` | [Documentation](../../../../deployments/services/gaming/ark-survival-ascended.md)
29. Nextcloud AIO @ `192.168.3.29` | [Documentation](../../../../deployments/services/productivity/nextcloud-aio.md)
28. ARK: Survival Ascended Server @ `192.168.3.28` | [Documentation](<../../deployments/Applications/Gaming and Media/Ark Survival Ascended.md>)
29. Nextcloud AIO @ `192.168.3.29` | [Documentation](<../../deployments/Applications/Files and Collaboration/Nextcloud AIO.md>)
30. Dev-Testing Win11 Lab Environment @ `192.168.3.35` | [Documentation](https://example.com)
31. Windows 11 Work VM @ `192.168.3.31` | [Documentation](https://example.com)
32. Matrix Synapse HomeServer @ `192.168.3.32` | [Documentation](https://github.com/matrix-org/synapse)
@@ -239,7 +245,10 @@ ansible_connection=ssh
73. ProxmoxVE Headless Laptop Virtualization Node
74. Rancher Harvester Node
75. Rancher Harvester Cluster VIP
251. Borealis Engine Node 02
252. Borealis Engine Node 01
253. Fedora Workstation 42 VM
254. Core Infrastructure Switch 01 (Zyxel GS1920-48)
251. Borealis Engine Node 02
252. Borealis Engine Node 01
253. Fedora Workstation 42 VM
254. Core Infrastructure Switch 01 (Zyxel GS1920-48)
## Related Documentation
- [Related Lab Map Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -5,8 +5,11 @@ tags:
- Networking
---
## Purpose
Use this reference for 172.16.16.0 sophos network and the environment-specific values recorded below.
### IP Addresses
Documented IP addresses of Hyper-V Failover Cluster VMs that exist behind the Sophos XG Firewall VM. All of these machines are funneled through the Sophos XG Firewall VM before they are allowed to communicate on the physical network with other devices.
Documented IP addresses of Hyper-V Failover Cluster VMs that exist behind the Sophos XG Firewall VM. All of these machines are funneled through the Sophos XG Firewall VM before they are allowed to communicate on the physical network with other devices.
## 172.16.16.0/24 Network
| **IP Address** | **FQDN** | **Additional Notes** |
@@ -14,4 +17,7 @@ Documented IP addresses of Hyper-V Failover Cluster VMs that exist behind the So
| 172.16.16.1 | LAB-SOPHOS-01.bunny-lab.io | Sophos XG Firewall |
| 172.16.16.2 | LAB-IRIS-01 | Blue Iris Surveillance |
| 172.16.16.3 | `NOT IN USE` | `NOT IN USE` |
| 172.16.16.4 | `NOT IN USE` | `NOT IN USE` |
| 172.16.16.4 | `NOT IN USE` | `NOT IN USE` |
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -5,6 +5,12 @@ tags:
- Networking
---
## Purpose
Use this reference for 192.168.5.0 container network and the environment-specific values recorded below.
!!! info "Address Ownership"
Entries marked undocumented or unknown remain unresolved. Deployment examples elsewhere describe some of the same addresses, but they do not establish current ownership. Confirm the running service before updating this plan.
### IP Addresses
Documented IP addresses of containers.
@@ -52,7 +58,7 @@ Documented IP addresses of containers.
| 192.168.5.39 | speedtest.bunny-lab.io | Speedtest Tracker Database |
| 192.168.5.40 | apprise.bunny-lab.io | Apprise Notification Relaying Service |
| 192.168.5.41 | joplin.bunny-lab.io | Joplin Documentation |
| 192.168.5.42 | todo.bunny-lab.io | Tududi Server |
| 192.168.5.42 | todo.bunny-lab.io | Tududi Server |
| 192.168.5.43 | `UNDOCUMENTED - Active` | |
| 192.168.5.44 | `UNDOCUMENTED - Active` | |
| 192.168.5.45 | `UNDOCUMENTED - Active` | |
@@ -66,3 +72,6 @@ Documented IP addresses of containers.
| 192.168.5.53 | Kavita Server | |
| 192.168.3.54 | `UNDOCUMENTED - Active` | |
| 192.168.3.55 | Linkding Server | |
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,51 @@
---
tags:
- UPS
- APC
- Power
---
## Purpose
When an APC battery backup's battery dies, you can manually replace the cells and 'refurbish' the battery. The following diagram is how you rewire the cells.
!!! warning "Work in Progress"
This document is still being written
## Wiring Diagram
```mermaid
graph TB
%% Define cells and connections
Cell1["Cell 1<br>Black (Negative) to Black (Negative)"] -.-> AndersonNeg["Anderson Connector Negative<br>(Black)"]
Cell1 -->|"Red (Positive) to Black (Negative)"| Cell2["Cell 2<br>Red (Positive) to Black (Negative)"]
Cell2 -->|"Red (Positive) to Black (Negative)"| Cell3["Cell 3<br>Red (Positive) to Black (Negative)"]
Cell3 -->|"Red (Positive) to Fuse"| Fuse["30A Fuse"]
Fuse -->|"Red (Positive) to Black (Negative)"| Cell4["Cell 4<br>Red (Positive) to Black (Negative)"]
Cell4 -->|"Red (Positive) to Anderson Connector Positive"| AndersonPos["Anderson Connector Positive<br>(Red)"]
%% Define styles
classDef battery fill:#f2f2f2,stroke:#000,stroke-width:2px;
class Cell1,Cell2,Cell3,Cell4 battery;
classDef fuse fill:#ffcc00,stroke:#000,stroke-width:2px;
class Fuse fuse;
classDef anderson fill:#00ccff,stroke:#000,stroke-width:2px;
class AndersonPos,AndersonNeg anderson;
classDef positive fill:#ff0000,stroke:#000,stroke-width:2px;
class AndersonPos positive;
classDef negative fill:#000000,stroke:#fff,stroke-width:2px;
class AndersonNeg negative;
%% Define line colors for clarity
linkStyle 0 stroke:#000,stroke-width:2px;
linkStyle 1 stroke:#ff0000,stroke-width:2px;
linkStyle 2 stroke:#ff0000,stroke-width:2px;
linkStyle 3 stroke:#ff0000,stroke-width:2px;
linkStyle 4 stroke:#ff0000,stroke-width:2px;
linkStyle 5 stroke:#ff0000,stroke-width:2px;
```
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,19 @@
---
tags:
- UPS
- Backup
- Power
---
## Purpose
Record the devices connected to each lab UPS, their estimated runtime, and their shutdown thresholds. Use this reference when planning maintenance or checking power dependencies.
| **Battery Backup** | **Status** | **Connected Device(s)** | **Estimated Runtime** | **Shutdown Threshold** | **UPS Web Management** |
| :--- | :--- | :--- | :--- | :--- | :---: |
| Outer-Left `#1` | ![](https://status.bunny-lab.io/api/v1/endpoints/battery-backups_outer-left-1-(virt-node-01--10-port-10gbe-network-switch--pfsense-firewall)/uptimes/7d/badge.svg) | - VIRT-NODE-01<br>- 10-Port 10GbE Network Switch<br>- pfSense Firewall | 10 Minutes | 3 Minutes Remaining | [:fontawesome-solid-car-battery: Manage](http://192.168.3.4:3052){ .md-button } |
| Inner-Left `#2` | ![](https://status.bunny-lab.io/api/v1/endpoints/battery-backups_inner-left-2-(bunny-node-02--24-port-1gbe-network-switch)/uptimes/7d/badge.svg) | - BUNNY-NODE-02<br>- 24-Port 1GbE Network Switch | 12 Minutes | 3 Minutes Remaining | [:fontawesome-solid-car-battery: Manage](http://192.168.3.5:3052){ .md-button } |
| Inner-Right `#3` | ![](https://status.bunny-lab.io/api/v1/endpoints/battery-backups_inner-right-3-(moon-storage-01--wireless-ap)/uptimes/7d/badge.svg) | - MOON-STORAGE-01<br>- Wireless AP | 16 Minutes | 3 Minutes Remaining | [:fontawesome-solid-car-battery: Manage](http://192.168.3.3:3052){ .md-button } |
| Outer-Right `#4` | ![](https://status.bunny-lab.io/api/v1/endpoints/battery-backups_outer-right-4-(lab-draas-01--lab-pool-01--8-port-1gbe-network-switch--internet-modem--poe-surveillance-cameras)/uptimes/7d/badge.svg) | - LAB-DRAAS-01<br>- LAB-POOL-01<br>- 8-Port 1GbE Network Switch<br>- Internet Modem<br>- PoE Surveillance Cameras | 13 Minutes | 3 Minutes Remaining | [:fontawesome-solid-car-battery: Manage](http://192.168.3.33:3052){ .md-button } |
## Related Documentation
- [Related Lab Map Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
+23
View File
@@ -0,0 +1,23 @@
---
tags:
- Lab Map
- Reference
- Documentation
---
# Lab Map
## Purpose
Identify where a workload runs, which address plan describes it, and which hardware or power reference applies before following a deployment or repair procedure.
## Includes
- Find recorded host addresses, inventory groups, and service roles.
- Match container addresses to the services recorded for that subnet.
- Check the separate Sophos network before using its VPN procedures.
## Find the Right Document
- [Server Inventory](<Homelab Server Inventory.md>) — Find recorded host addresses, inventory groups, and service roles.
- [Container Address Plan](<Network Address Plans/192.168.5.0 Container Network.md>) — Match container addresses to the services recorded for that subnet.
- [Sophos Address Plan](<Network Address Plans/172.16.16.0 Sophos Network.md>) — Check the separate Sophos network before using its VPN procedures.
- [UPS Power Distribution](<Power/UPS Power Distribution.md>) — Identify the recorded devices, runtimes, and shutdown thresholds for each UPS.
- [Storage Node 01 Disk Layout](<Hardware/Storage Node 01 TrueNAS Core Disk Layout.md>) — Identify the physical drive before following the drive-replacement workflow.
- [Replace a TrueNAS Drive](<../../workflows/Virtualization and Storage/TrueNAS/Replace a Drive in Storage Node 01.md>) — Use the physical disk inventory during replacement and update it afterward.
@@ -0,0 +1,98 @@
---
tags:
- DNS
- Windows Server
- Windows
---
## Purpose
This document outlines best practices for DNS server configuration in Active Directory environments, focusing on both performance and security considerations. The goal is to enhance the stability, efficiency, and security of DNS infrastructure within enterprise networks.
## Performance Best Practices
!!! note "Performance Recommendations Overview"
The following list is organized in order of priority, with the most critical practices listed first.
### Redundancy and High Availability
- **Always have at least two DNS servers, preferably three (1 master, 2 slaves).**
Ensures redundancy and high availability.
### Internal DNS Usage
- **Domain-joined computers should only use internal DNS servers.**
This ensures that end-user computers can always resolve internal resources and simplifies troubleshooting and management.
- **Extended Reason:** Using only internal DNS servers increases security and streamlines DNS operations.
### DNS Server Self-Referencing
- **A DNS server should have `127.0.0.1` loopback as a secondary or tertiary DNS server.**
Improves the DNS server’s own performance and availability.
- **Extended Reason:** Setting the loopback address as the primary DNS can prevent Active Directory from locating replication partners. Use as secondary or tertiary only.
!!! info "Recent Changes"
The usage of `127.0.0.1` has been changed to pointing to the actual full IP address of the server itself. I need to research this more to determine where this updated guideline came from. For example, if the DNS server IP was `192.168.3.25` you would set that as the value for the secondary DNS server.
!!! warning "Do **NOT** Use `127.0.0.1` as Primary DNS Server"
When you are setting up domain controllers / DNS servers, you do not want to use the DC itself as the primary. This can cause all sorts of unexpected issues with reliability and replication. Always have another DNS server as the primary, THEN set the 127.0.0.1 localhost as secondary or tertiary.
### DNS Server Prioritization
- **Prioritize DNS servers based on proximity to endpoints.**
Assign the primary DNS server as the local server, and secondary as a remote branch server, to improve lookup speeds.
### DNS Record Aging and Scavenging
- **Enable DNS record aging/scavenging (preferably 7 days).**
Keeps DNS recordsets manageable, which improves lookup performance and troubleshooting.
### Use of CNAME Records
- **Use CNAME records for DNS aliasing. Avoid A records for aliases.**
Updating one host record updates all associated aliases, and PTR records remain properly configured.
## Security Best Practices
!!! note "Security Recommendations Overview"
The following list is organized in order of priority, with the most critical practices listed first.
### Network Exposure
- **DNS servers should never be publicly accessible from the internet.**
This prevents attackers from performing reconnaissance or planning attacks using exposed DNS infrastructure.
### Administrative Access
- **Restrict RDP/remote desktop access to DNS servers/domain controllers to a limited list of administrators.**
Reduces the risk of reconnaissance, reverse shell attacks, and malware installation.
### Use of Slave DNS Servers
- **End-users should be issued only replicated/slave DNS servers.**
Protects the master/authoritative DNS server from being directly exposed as an attack vector.
- **Extended Reason:** In branch office scenarios, assign the local replicated server as primary, and main office replicated servers as secondary and tertiary, keeping the master server isolated.
### DNS Server Cache Lockdown
- **Lock the DNS server cache to 100% (read-only).**
Prevents DNS cache poisoning by allowing cache changes only after TTL expiry.
### DNS Logging
- **Enable DNS logging.**
Facilitates troubleshooting and administration.
### DNS Security Filtering
- **Enable DNS security filtering via DNS forwarder or a security appliance.**
Use secure public DNS (e.g., 9.9.9.9) or a firewall appliance (e.g., Sophos XG Firewall) to add a security layer to all DNS queries.
### Enable DNSSEC
- **Enable DNSSEC (DNS Security Extensions).**
Protects against DNS record spoofing and related attacks.
### DNS Socket Port Randomization
- **Enable DNS socket port randomization.**
Prevents network attacks by making DNS queries originate from unpredictable ports.
- **Note:** Enabled by default on Windows Server 2016 and newer.
## Additional Notes
!!! note "Best Practices Analyzer"
It is recommended to run the official Windows Server DNS Best Practices Analyzer (BPA) on your managed servers for insights specific to your domain environment.
## Sources / References
- [Active Directory Pro: DNS Best Practices](https://activedirectorypro.com/dns-best-practices/)
- [Spiceworks: DNS Server Best Practice](https://community.spiceworks.com/topic/1110865-best-practice-for-dns-servers)
- [Microsoft Docs: Creating a DNS Infrastructure Design](https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/creating-a-dns-infrastructure-design)
- [PhoenixNAP: DNS Best Practices Security](https://phoenixnap.com/kb/dns-best-practices-security)
- [Monitis: Best Practices for Active Directory Integrated DNS](https://www.monitis.com/blog/best-practices-for-active-directory-integrated-dns)
- [DNS Knowledge: Authoritative Name Server](https://www.dnsknowledge.com/whatis/authoritative-name-server/)
## Related Documentation
- [Related Networking and Access Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
+23
View File
@@ -0,0 +1,23 @@
---
tags:
- Networking and Access
- Reference
- Documentation
---
# Networking and Access
## Purpose
Find the DNS, proxy, VPN, and remote-access instructions that connect users and services. Use the address plans to identify the intended network before changing connectivity.
## Includes
- Identify the container network before following service examples.
- Review the documented DNS configuration and its environment assumptions.
- Connect application routes and dynamic configuration delivery.
## Find the Right Document
- [Network Address Plans](<../Lab Map/Network Address Plans/192.168.5.0 Container Network.md>) — Identify the container network before following service examples.
- [Windows DNS Notes](<DNS/Windows DNS Configuration Notes.md>) — Review the documented DNS configuration and its environment assumptions.
- [Traefik](<../../deployments/Networking and Access/Reverse Proxies/Traefik.md>) — Connect application routes and dynamic configuration delivery.
- [Sophos Site-to-Site VPN](<../../deployments/Networking and Access/Sophos/Configure a Site-to-Site IPsec VPN.md>) — Build the documented tunnel, then use the related reset workflow if needed.
- [Guacamole](<../../deployments/Networking and Access/Remote Access/Apache Guacamole.md>) — Find the browser-based remote-access deployment and its target prerequisites.
- [UniFi Deployment Choices](<../../deployments/Networking and Access/UniFi/Deploy UniFi Controller with Docker.md>) — Start with the Docker example or follow its link to the Ubuntu installation notes.
@@ -0,0 +1,39 @@
---
tags:
- Proxmox
- iSCSI
- Storage
---
# Proxmox
## Purpose
Choose the Proxmox host, storage, and guest procedure that matches the environment you are operating. Shared LVM over iSCSI and the separate ZFS-over-iSCSI integration are documented alternatives with different management requirements.
## Includes
- Host and template deployment
- Storage design and capacity changes
- Migration, maintenance, and recovery
## Choose the Storage Design
- [Shared LVM over iSCSI](<../../../deployments/Virtualization and Storage/Proxmox/Configuring ISCSI Based Cluster Storage.md>) — Use the guide for the documented TrueNAS zvol and shared LVM cluster design.
- [ZFS over iSCSI Integration](<../../../deployments/Virtualization and Storage/Proxmox/ZFS over ISCSI.md>) — Use the separate integration guide when the environment uses its plugin and ZFS management model.
## Build Hosts and Guests
- [Deploy Proxmox VE](<../../../deployments/Virtualization and Storage/Proxmox/Deploy Proxmox VE.md>) — Review the recorded host version and network layout before applying the examples.
- [Create an Ubuntu Template](<../../../deployments/Virtualization and Storage/Proxmox/Create an Ubuntu Cloud-Init Template.md>) — Review the remaining incomplete configuration before using the template.
- [Install the Guest Agent](<../../../deployments/Virtualization and Storage/Guests/Install the QEMU Guest Agent.md>) — Prepare supported Linux guests for hypervisor integration.
## Expand Storage
The storage appliance, hypervisor disk, guest partition, and guest filesystem are separate layers. Identify the layer that needs capacity and use the procedure for that layout.
- [Expand a Linux Guest Filesystem](<../../../workflows/Virtualization and Storage/Linux/Expand a Linux Guest Filesystem.md>) — Continue inside a guest after its virtual disk has grown.
- [Expand ZFS on an iSCSI Client](<../../../workflows/Virtualization and Storage/Linux/Expand an iSCSI-Backed ZFS Filesystem.md>) — Use the workflow for a Linux client that consumes the iSCSI disk directly.
- [Expand a Windows OS Volume](<../../../workflows/Windows and Linux/Windows/Delete Windows Recovery Partition.md>) — Review the documented recovery-partition obstruction and its destructive boundary.
## Maintain and Recover
- [Upgrade Proxmox VE](<../../../workflows/Virtualization and Storage/Proxmox/Upgrade Proxmox VE from 8 to 9.md>) — Use the recorded release-transition procedure and readiness check.
- [Repair a Migrated Rocky Linux Guest](<../../../workflows/Virtualization and Storage/Proxmox/Repair Rocky Linux After a Veeam Migration.md>) — Follow the boot and network repair notes after a Veeam migration.
- [Repair iSCSI After Reboot](<../../../workflows/Virtualization and Storage/Proxmox/Repair iSCSI Connections After Reboot.md>) — Find the documented reconnection repair.
- [Activate a Missing Volume Group](<../../../workflows/Virtualization and Storage/Proxmox/Manually Activate a Volume Group.md>) — Use the existing LVM recovery commands for the matching layout.
- [Audit Orphaned VM Disks](<../../../workflows/Virtualization and Storage/Proxmox/Detect and Remove Orphaned VM Disks.md>) — Complete the reference checks before removing any volume.
- [Hardware and Power Map](<../../Lab Map/index.md>) — Locate the corresponding disks and UPS dependencies.
@@ -0,0 +1,23 @@
---
tags:
- Virtualization and Storage
- Reference
- Documentation
---
# Virtualization and Storage
## Purpose
Follow the relationship between hypervisors, shared storage, guest disks, and recovery procedures. Select the documented storage design before choosing a maintenance command.
## Includes
- Choose a storage design and find host, guest, migration, and repair procedures.
- Follow the Windows clustering deployment.
- Configure the documented non-clustered migration scenario.
## Find the Right Document
- [Proxmox and Shared Storage](<Proxmox/index.md>) — Choose a storage design and find host, guest, migration, and repair procedures.
- [Build a Hyper-V Cluster Node](<../../deployments/Virtualization and Storage/Hyper-V/Failover Cluster/Deploy Failover Cluster Node.md>) — Follow the Windows clustering deployment.
- [Hyper-V Live Migration Authentication](<../../workflows/Virtualization and Storage/Hyper-V/Kerberos Enabled VM Migration.md>) — Configure the documented non-clustered migration scenario.
- [Rebuild Hyper-V Cluster Replication](<../../workflows/Virtualization and Storage/Hyper-V/Failover Cluster/Rebuild Failover Cluster Replication.md>) — Recover an individual VM replica between the documented clusters.
- [Physical Lab References](<../Lab Map/index.md>) — Connect storage and hypervisor work to hardware and power records.
- [Backup and Recovery](<../Backup and Recovery/index.md>) — Find backup and replica context before a disruptive operation.
@@ -0,0 +1,23 @@
---
tags:
- Bash
- Time Sync
- Scripting
- Linux
---
## Purpose
The commands outlined in this short document are meant to be a quick-reference for setting the timezone and date/time of a Linux-based server.
### Set Timezone
```sh
sudo timedatectl set-timezone America/Denver
```
### Set Time and Date
```sh
date -s "1 JAN 2025 03:30:00"
```
## Related Documentation
- [Related Windows and Linux Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
+23
View File
@@ -0,0 +1,23 @@
---
tags:
- Windows and Linux
- Reference
- Documentation
---
# Windows and Linux
## Purpose
Find workstation and server operating-system setup, updates, and repairs. Storage, networking, and identity tasks are linked to their subject guides when they cross operating-system boundaries.
## Includes
- Follow the recorded workstation configuration and its local disk assumptions.
- Use the operating-system upgrade notes for the recorded release transition.
- Use the deployment script with its documented share and RMM requirements.
## Find the Right Document
- [Set Up the Fedora Workstation](<../../deployments/Windows and Linux/Fedora/Set Up the Fedora Workstation.md>) — Follow the recorded workstation configuration and its local disk assumptions.
- [Upgrade Fedora](<../../workflows/Windows and Linux/Linux/Fedora Workstation/Upgrading Versions.md>) — Use the operating-system upgrade notes for the recorded release transition.
- [Upgrade Windows 11](<../../scripts/Windows and Linux/Windows/Upgrade Windows 11 from a UNC Path.md>) — Use the deployment script with its documented share and RMM requirements.
- [Recover After a Windows Update](<../../workflows/Windows and Linux/Windows/Uninstall Updates via DISM.md>) — Work against an offline Windows installation when it cannot boot.
- [Expand Guest Storage](<../../workflows/Virtualization and Storage/Linux/Expand a Linux Guest Filesystem.md>) — Continue from the hypervisor disk change to the guest partition and filesystem.
- [Identity and Remote Management](<../Identity and Certificates/index.md>) — Find domain trust, certificates, and WinRM guidance shared by host administration.
@@ -0,0 +1,22 @@
---
tags:
- Documentation
- Markdown
- Templates
---
## Purpose
Choose the canonical template that matches the primary intent of the document you are creating. The styling guideline remains the single source for template content.
## Choose by Intent
- [Deployment Templates](<Documentation Styling.md>) — Build a platform or service; use the container template for a Compose-based application.
- [Workflow Templates](<Documentation Styling.md>) — Perform maintenance, migration, recovery, or troubleshooting.
- [Script Templates](<Documentation Styling.md>) — Preserve a complete reusable script or a small operational command.
- [Reference and Inventory Template](<Documentation Styling.md>) — Record concepts, architecture, addresses, mappings, or stable facts.
- [Index and Blog Templates](<Documentation Styling.md>) — Introduce a subject folder or preserve a dated narrative.
## Place and Connect the Page
Use [Documentation Organization](<Documentation Organization.md>) to choose the subject and add links to the relevant guide and prerequisites.
## Related Documentation
- [Related Foundations Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,36 @@
---
tags:
- Documentation
- Information Architecture
- Reference
---
## Purpose
Keep Bunny Lab documentation discoverable by both its subject and its operational purpose. Topic guides connect the canonical documents across the five documentation roots.
## Choose the Document Role
| **Root** | **Primary Intent** |
| :--- | :--- |
| `Deployments` | Build or install the system |
| `Workflows` | Maintain, migrate, repair, or recover it |
| `Scripts` | Preserve a reusable operational utility |
| `Reference` | Explain concepts, inventory, architecture, and subject relationships |
| `Blog` | Preserve dated experience and the reasoning behind decisions |
## Choose the Subject
Use the same subject names across roots: Applications, Automation, Backup and Recovery, Containers, Identity and Certificates, Networking and Access, Virtualization and Storage, and Windows and Linux. Physical inventory and address plans belong in the Lab Map; authoring standards belong in Foundations.
## Connect the Knowledge
Link to the applicable prerequisite where it becomes necessary. Link a deployment to its independently useful maintenance procedures, and link those procedures back to the relevant environment or deployment. Keep one canonical copy of scripts and connection settings. A topic guide can describe alternative implementations and explain when each applies.
## Record Applicability
Use a short, specific admonition for incomplete instructions, version constraints, or conflicting environment notes. Mark an approach historical or superseded only when the recorded evidence supports that conclusion. A file move or formatting review does not establish that a procedure was executed successfully.
## Maintain Filenames and Links
Use descriptive Title Case filenames and lowercase `index.md` for landing pages. Repair source-relative Markdown links whenever either endpoint moves, including the case of filenames and any changed heading anchors. The [path-change reference](<Documentation Path Changes.md>) records the former locations for maintaining bookmarks or server-side redirects.
## Apply the House Style
Follow [Documentation Styling](<Documentation Styling.md>) for complete Markdown and document-type requirements.
## Related Documentation
- [Related Foundations Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,209 @@
---
tags:
- Documentation
- Migration
- Reference
---
## Purpose
Locate a document after the September 2026 subject reorganization. This reference maps former source paths to their canonical destinations for bookmarks, external references, and deployment-side redirect maintenance.
## Source Path Mapping
The paths below are relative to the documentation root. Internal source links use the new destinations. This table records the migration; it does not configure HTTP redirects on the documentation server.
| **Former Source Path** | **Current Document** |
| :--- | :--- |
| `deployments/automation/ansible/awx/Deployment/AWX Operator.md` | [AWX Operator](<../../deployments/automation/AWX/AWX Operator.md>) |
| `deployments/automation/ansible/awx/Deployment/AWX in Minikube.md` | [AWX in Minikube](<../../deployments/automation/AWX/AWX in Minikube.md>) |
| `deployments/automation/ansible/awx/Deployment/Upgrading Issues past 2 10 0.md` | [Repair Upgrades Beyond AWX Operator 2.10.0](<../../workflows/Automation/AWX/Repair Upgrades Beyond AWX Operator 2.10.0.md>) |
| `deployments/automation/puppet/deployment/Puppet Bolt.md` | [Puppet Bolt](<../../deployments/automation/Puppet/Puppet Bolt.md>) |
| `deployments/automation/puppet/deployment/puppet.md` | [Puppet](<../../deployments/automation/Puppet/Puppet.md>) |
| `deployments/platforms/containerization/Docker/Custom Containers/Container Development.md` | [Build and Publish a Container Image](<../../workflows/Containers/Docker/Build and Publish a Container Image.md>) |
| `deployments/platforms/containerization/Docker/Custom Containers/Git Repo Updater.md` | [Git Repo Updater](<../../deployments/Containers/Docker/Git Repo Updater.md>) |
| `deployments/platforms/containerization/Docker/Deploy Portainer.md` | [Deploy Portainer](<../../deployments/Containers/Docker/Deploy Portainer.md>) |
| `deployments/platforms/containerization/kubernetes/deployment/k8s.md` | [K8s](<../../deployments/Containers/Kubernetes/K8s.md>) |
| `deployments/platforms/containerization/kubernetes/deployment/Rancher RKE2.md` | [Rancher RKE2](<../../deployments/Containers/Kubernetes/Rancher RKE2.md>) |
| `deployments/platforms/index.md` | [Virtualization and Storage](<../../deployments/Virtualization and Storage/index.md>) |
| `deployments/platforms/virtualization/Hyper V/Failover Cluster/Deploy Failover Cluster Node.md` | [Deploy Failover Cluster Node](<../../deployments/Virtualization and Storage/Hyper-V/Failover Cluster/Deploy Failover Cluster Node.md>) |
| `deployments/platforms/virtualization/OpenStack/Ansible OpenStack.md` | [Ansible OpenStack](<../../deployments/Virtualization and Storage/OpenStack/Ansible OpenStack.md>) |
| `deployments/platforms/virtualization/OpenStack/Canonical OpenStack.md` | [Canonical OpenStack](<../../deployments/Virtualization and Storage/OpenStack/Canonical OpenStack.md>) |
| `deployments/platforms/virtualization/proxmox/Cloud Init Templates/Ubuntu Server.md` | [Create an Ubuntu Cloud-Init Template](<../../deployments/Virtualization and Storage/Proxmox/Create an Ubuntu Cloud-Init Template.md>) |
| `deployments/platforms/virtualization/proxmox/Configuring ISCSI Based Cluster Storage.md` | [Configuring ISCSI Based Cluster Storage](<../../deployments/Virtualization and Storage/Proxmox/Configuring ISCSI Based Cluster Storage.md>) |
| `deployments/platforms/virtualization/proxmox/Detecting and Removing Orphaned VM Disks.md` | [Detect and Remove Orphaned VM Disks](<../../workflows/Virtualization and Storage/Proxmox/Detect and Remove Orphaned VM Disks.md>) |
| `deployments/platforms/virtualization/proxmox/Fixing iSCSI Connections that Drop at Reboot.md` | [Repair iSCSI Connections After Reboot](<../../workflows/Virtualization and Storage/Proxmox/Repair iSCSI Connections After Reboot.md>) |
| `deployments/platforms/virtualization/proxmox/ProxmoxVE.md` | [Deploy Proxmox VE](<../../deployments/Virtualization and Storage/Proxmox/Deploy Proxmox VE.md>) |
| `deployments/platforms/virtualization/proxmox/ZFS over ISCSI.md` | [ZFS over ISCSI](<../../deployments/Virtualization and Storage/Proxmox/ZFS over ISCSI.md>) |
| `deployments/platforms/virtualization/Rancher Harvester/Harvester.md` | [Harvester](<../../deployments/Virtualization and Storage/Rancher Harvester/Harvester.md>) |
| `deployments/services/Asset Management/Homebox.md` | [Homebox](<../../deployments/Applications/Asset Management/Homebox.md>) |
| `deployments/services/Asset Management/Snipe IT.md` | [Snipe IT](<../../deployments/Applications/Asset Management/Snipe IT.md>) |
| `deployments/services/authentication/Active Directory/Certificate Services.md` | [Certificate Services](<../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) |
| `deployments/services/authentication/Active Directory/Group Policy/Desktop Shortcut to UNC Path.md` | [Create a Desktop Shortcut to a UNC Path](<../../workflows/Identity and Certificates/Active Directory/Create a Desktop Shortcut to a UNC Path.md>) |
| `deployments/services/authentication/Active Directory/LDAP Settings.md` | [LDAP Connection Settings](<../Identity and Certificates/Active Directory/LDAP Connection Settings.md>) |
| `deployments/services/authentication/Active Directory/Restore Domain Trust.md` | [Restore Domain Trust](<../../workflows/Identity and Certificates/Active Directory/Restore Domain Trust.md>) |
| `deployments/services/authentication/authelia.md` | [Authelia](<../../deployments/Identity and Certificates/Authelia.md>) |
| `deployments/services/authentication/authentik.md` | [Authentik](<../../deployments/Identity and Certificates/Authentik.md>) |
| `deployments/services/authentication/keycloak/deployment.md` | [Deploy Keycloak](<../../deployments/Identity and Certificates/Keycloak/Deploy Keycloak.md>) |
| `deployments/services/authentication/keycloak/oauth2/deployment.md` | [Keycloak Integrations](<../Identity and Certificates/Keycloak Integrations.md>) |
| `deployments/services/authentication/keycloak/oauth2/Gitea OAuth2.md` | [Connect Gitea to Keycloak](<../../workflows/Identity and Certificates/Keycloak/Connect Gitea to Keycloak.md>) |
| `deployments/services/authentication/keycloak/oauth2/Portainer OAuth2.md` | [Connect Portainer to Keycloak](<../../workflows/Identity and Certificates/Keycloak/Connect Portainer to Keycloak.md>) |
| `deployments/services/authentication/privacyidea.md` | [Privacyidea](<../../deployments/Identity and Certificates/Privacyidea.md>) |
| `deployments/services/Automation Tools/Activepieces.md` | [Activepieces](<../../deployments/automation/Tools/Activepieces.md>) |
| `deployments/services/Automation Tools/Node Red.md` | [Node Red](<../../deployments/automation/Tools/Node Red.md>) |
| `deployments/services/Automation Tools/Semaphore UI.md` | [Semaphore UI](<../../deployments/automation/Tools/Semaphore UI.md>) |
| `deployments/services/backup/kopia.md` | [Kopia](<../../deployments/Backup and Recovery/Kopia.md>) |
| `deployments/services/communication/niltalk.md` | [Niltalk](<../../deployments/Applications/Communication/Niltalk.md>) |
| `deployments/services/communication/rocketchat/Autotask Regex Replacer.md` | [Configure Autotask Link Replacement](<../../workflows/Applications/Communication/Rocketchat/Configure Autotask Link Replacement.md>) |
| `deployments/services/communication/rocketchat/deployment.md` | [Deploy Rocket.Chat](<../../deployments/Applications/Communication/Rocketchat/Deploy Rocket.Chat.md>) |
| `deployments/services/DNS/AdGuard Home.md` | [AdGuard Home](<../../deployments/Networking and Access/DNS/AdGuard Home.md>) |
| `deployments/services/DNS/Pi Hole.md` | [Pi Hole](<../../deployments/Networking and Access/DNS/Pi Hole.md>) |
| `deployments/services/DNS/Windows Server/Best Practices.md` | [Windows DNS Configuration Notes](<../Networking and Access/DNS/Windows DNS Configuration Notes.md>) |
| `deployments/services/dashboards/dashy.md` | [Dashy](<../../deployments/Applications/Dashboards/Dashy.md>) |
| `deployments/services/dashboards/Homepage Docker.md` | [Homepage Docker](<../../deployments/Applications/Dashboards/Homepage Docker.md>) |
| `deployments/services/devops/gitea.md` | [Gitea](<../../deployments/automation/Gitea/Gitea.md>) |
| `deployments/services/documentation/docusaurus.md` | [Docusaurus](<../../deployments/automation/Documentation/Docusaurus.md>) |
| `deployments/services/documentation/Material MkDocs.md` | [Material MkDocs](<../../deployments/automation/Documentation/Material MkDocs.md>) |
| `deployments/services/documentation/zensical.md` | [Zensical](<../../deployments/automation/Documentation/Zensical.md>) |
| `deployments/services/edge/nginx.md` | [Nginx](<../../deployments/Networking and Access/Reverse Proxies/Nginx.md>) |
| `deployments/services/edge/traefik.md` | [Traefik](<../../deployments/Networking and Access/Reverse Proxies/Traefik.md>) |
| `deployments/services/email/Microsoft Exchange/Configuring ACME Letsencrypt Bot.md` | [Configuring ACME Letsencrypt Bot](<../../deployments/Applications/Email/Microsoft Exchange/Configuring ACME Letsencrypt Bot.md>) |
| `deployments/services/email/Microsoft Exchange/Preparing for Cumulative Updates.md` | [Prepare for Cumulative Updates](<../../workflows/Applications/Email/Microsoft Exchange/Prepare for Cumulative Updates.md>) |
| `deployments/services/email/Proxmox Mail Gateway/Deploying PMG.md` | [Integrate PMG with Mailcow](<../../deployments/Applications/Email/Proxmox Mail Gateway/Integrate PMG with Mailcow.md>) |
| `deployments/services/email/iRedMail/Deploy iRedMail.md` | [Deploy iRedMail](<../../deployments/Applications/Email/iRedMail/Deploy iRedMail.md>) |
| `deployments/services/email/iRedMail/Query SMTP Outgoing Queue.md` | [Inspect the Outgoing SMTP Queue](<../../workflows/Applications/Email/iRedMail/Inspect the Outgoing SMTP Queue.md>) |
| `deployments/services/email/iRedMail/Quick Server Settings.md` | [iRedMail Connection Settings](<../Applications/Email/iRedMail Connection Settings.md>) |
| `deployments/services/email/mailcow.md` | [mailcow](<../../deployments/Applications/Email/mailcow.md>) |
| `deployments/services/File Services/Windows Server/DFS Namespaces with Replication.md` | [DFS Namespaces with Replication](<../../deployments/Applications/Files and Collaboration/Windows Server/DFS Namespaces with Replication.md>) |
| `deployments/services/gaming/Ark Survival Ascended.md` | [Ark Survival Ascended](<../../deployments/Applications/Gaming and Media/Ark Survival Ascended.md>) |
| `deployments/services/gaming/pterodactyl.md` | [Pterodactyl](<../../deployments/Applications/Gaming and Media/Pterodactyl.md>) |
| `deployments/services/gaming/valheim.md` | [Valheim](<../../deployments/Applications/Gaming and Media/Valheim.md>) |
| `deployments/services/Home and IOT/Frigate.md` | [Frigate](<../../deployments/Applications/Home Automation/Frigate.md>) |
| `deployments/services/Home and IOT/HomeAssistant.md` | [HomeAssistant](<../../deployments/Applications/Home Automation/HomeAssistant.md>) |
| `deployments/services/index.md` | [Applications](<../../deployments/Applications/index.md>) |
| `deployments/services/Media and Gaming/Emulatorjs.md` | [Emulatorjs](<../../deployments/Applications/Gaming and Media/Emulatorjs.md>) |
| `deployments/services/Media and Gaming/Pyload.md` | [Pyload](<../../deployments/Applications/Files and Collaboration/Pyload.md>) |
| `deployments/services/Microsoft 365/Change MFA Settings.md` | [Change MFA Settings](<../../workflows/Identity and Certificates/Microsoft 365/Change MFA Settings.md>) |
| `deployments/services/Microsoft 365/Seize Control of Personal OneDrive Data of Another User.md` | [Access Another User OneDrive Data](<../../workflows/Applications/Files and Collaboration/Microsoft 365/Access Another User OneDrive Data.md>) |
| `deployments/services/monitoring/gatus.md` | [Gatus](<../../deployments/Applications/Monitoring/Gatus.md>) |
| `deployments/services/monitoring/Speedtest Tracker.md` | [Speedtest Tracker](<../../deployments/Applications/Monitoring/Speedtest Tracker.md>) |
| `deployments/services/monitoring/uptimekuma.md` | [UptimeKuma](<../../deployments/Applications/Monitoring/UptimeKuma.md>) |
| `deployments/services/notifications/ntfy.md` | [Ntfy](<../../deployments/Applications/Monitoring/Ntfy.md>) |
| `deployments/services/productivity/Collabora Code Server.md` | [Collabora Code Server](<../../deployments/Applications/Files and Collaboration/Collabora Code Server.md>) |
| `deployments/services/productivity/Nextcloud AIO.md` | [Nextcloud AIO](<../../deployments/Applications/Files and Collaboration/Nextcloud AIO.md>) |
| `deployments/services/productivity/nextcloud.md` | [Nextcloud](<../../deployments/Applications/Files and Collaboration/Nextcloud.md>) |
| `deployments/services/productivity/OnlyOffice EE.md` | [OnlyOffice EE](<../../deployments/Applications/Files and Collaboration/OnlyOffice EE.md>) |
| `deployments/services/productivity/Stirling PDF.md` | [Stirling PDF](<../../deployments/Applications/Files and Collaboration/Stirling PDF.md>) |
| `deployments/services/productivity/trilium.md` | [Trilium](<../../deployments/Applications/Files and Collaboration/Trilium.md>) |
| `deployments/services/productivity/wordpress.md` | [Wordpress](<../../deployments/Applications/Files and Collaboration/Wordpress.md>) |
| `deployments/services/rmm/tacticalrmm.md` | [TacticalRMM](<../../deployments/automation/Remote Management/TacticalRMM.md>) |
| `deployments/services/Remote Access/Apache Guacamole.md` | [Apache Guacamole](<../../deployments/Networking and Access/Remote Access/Apache Guacamole.md>) |
| `deployments/services/Remote Access/Firefox.md` | [Firefox](<../../deployments/Networking and Access/Remote Access/Firefox.md>) |
| `deployments/services/Security and Utility/Changedetection.md` | [Changedetection](<../../deployments/Applications/Utilities/Changedetection.md>) |
| `deployments/services/Security and Utility/Cyberchef.md` | [Cyberchef](<../../deployments/Applications/Utilities/Cyberchef.md>) |
| `deployments/services/Security and Utility/IT Tools.md` | [IT Tools](<../../deployments/Applications/Utilities/IT Tools.md>) |
| `deployments/services/Security and Utility/Password Pusher.md` | [Password Pusher](<../../deployments/Identity and Certificates/Password Pusher.md>) |
| `deployments/services/Security and Utility/Searx.md` | [Searx](<../../deployments/Applications/Utilities/Searx.md>) |
| `deployments/services/Security and Utility/Vaultwarden.md` | [Vaultwarden](<../../deployments/Identity and Certificates/Vaultwarden.md>) |
| `deployments/services/cPanel/Creating Email Server.md` | [Create a cPanel Email Server](<../../deployments/Applications/Email/cPanel/Create a cPanel Email Server.md>) |
| `reference/foundations/Templates/Document Template.md` | [Choose a Document Template](<Choose a Document Template.md>) |
| `reference/infrastructure/hardware/Cluster Node 01/Disk Arrays.md` | [Cluster Node 01 Disk Layout](<../Lab Map/Hardware/Cluster Node 01 Disk Layout.md>) |
| `reference/infrastructure/hardware/Cluster Node 02/Disk Arrays.md` | [Cluster Node 02 Disk Layout](<../Lab Map/Hardware/Cluster Node 02 Disk Layout.md>) |
| `reference/infrastructure/hardware/Cluster Node 03/Disk Arrays.md` | [Cluster Node 03 Disk Layout](<../Lab Map/Hardware/Cluster Node 03 Disk Layout.md>) |
| `reference/infrastructure/hardware/index.md` | [Lab Map](<../Lab Map/index.md>) |
| `reference/infrastructure/hardware/Storage Node 01 Truenas Core/Disk Arrays.md` | [Storage Node 01 TrueNAS Core Disk Layout](<../Lab Map/Hardware/Storage Node 01 TrueNAS Core Disk Layout.md>) |
| `reference/infrastructure/hardware/Storage Node 01 Truenas Core/Replacing a Drive.md` | [Replace a Drive in Storage Node 01](<../../workflows/Virtualization and Storage/TrueNAS/Replace a Drive in Storage Node 01.md>) |
| `reference/infrastructure/hardware/Storage Node 02 Truenas Scale/Disk Arrays.md` | [Storage Node 02 TrueNAS Scale Disk Layout](<../Lab Map/Hardware/Storage Node 02 TrueNAS Scale Disk Layout.md>) |
| `reference/infrastructure/networking/Controllers/UniFi Controller.md` | [Deploy UniFi Controller with Docker](<../../deployments/Networking and Access/UniFi/Deploy UniFi Controller with Docker.md>) |
| `reference/infrastructure/networking/Controllers/UniFi Network Server Controller.md` | [Deploy UniFi Network Server on Ubuntu](<../../deployments/Networking and Access/UniFi/Deploy UniFi Network Server on Ubuntu.md>) |
| `reference/infrastructure/networking/Docker Networking/Creating a Macvlan Sub Interface for Docker.md` | [Create a Macvlan Subinterface](<../../workflows/Containers/Docker/Create a Macvlan Subinterface.md>) |
| `reference/infrastructure/networking/Docker Networking/Docker Networking.md` | [Create the Docker Network](<../../deployments/Containers/Docker/Create the Docker Network.md>) |
| `reference/infrastructure/networking/Firewall and Routing/Sophos/Configure LAN Bridging.md` | [Configure LAN Bridging](<../../workflows/Networking and Access/Sophos/Configure LAN Bridging.md>) |
| `reference/infrastructure/networking/Firewall and Routing/Sophos/VPN/SSL VPN/Configuring Remote VPN RDP Access.md` | [Configure RDP Access over SSL VPN](<../../workflows/Networking and Access/Sophos/Configure RDP Access over SSL VPN.md>) |
| `reference/infrastructure/networking/Firewall and Routing/Sophos/VPN/Site to Site VPNs/IPSEC/Automatic Tunnel Resetting.md` | [Automatically Reset an IPsec Tunnel](<../../workflows/Networking and Access/Sophos/Automatically Reset an IPsec Tunnel.md>) |
| `reference/infrastructure/networking/Firewall and Routing/Sophos/VPN/Site to Site VPNs/IPSEC/Tunnel Creation.md` | [Configure a Site-to-Site IPsec VPN](<../../deployments/Networking and Access/Sophos/Configure a Site-to-Site IPsec VPN.md>) |
| `reference/infrastructure/networking/IP Tables/172.16.16.0 Sophos Network.md` | [172.16.16.0 Sophos Network](<../Lab Map/Network Address Plans/172.16.16.0 Sophos Network.md>) |
| `reference/infrastructure/networking/IP Tables/192.168.5.0 Container Network.md` | [192.168.5.0 Container Network](<../Lab Map/Network Address Plans/192.168.5.0 Container Network.md>) |
| `reference/infrastructure/networking/IP Tables/Homelab Server Inventory.md` | [Homelab Server Inventory](<../Lab Map/Homelab Server Inventory.md>) |
| `reference/infrastructure/networking/index.md` | [Networking and Access](<../Networking and Access/index.md>) |
| `reference/infrastructure/networking/Linux Networking/Modifying IP Address of Server.md` | [Change a Server IP Address](<../../workflows/Networking and Access/Linux/Change a Server IP Address.md>) |
| `reference/infrastructure/networking/Misc/Tuya Smart Lights.md` | [Connect Tuya Smart Lights](<../../workflows/Applications/Home Automation/Connect Tuya Smart Lights.md>) |
| `reference/infrastructure/networking/vpn/netbird.md` | [Deploy NetBird on Rocky Linux](<../../deployments/Networking and Access/NetBird/Deploy NetBird on Rocky Linux.md>) |
| `scripts/Bash/Configure SSH Key Authentication.md` | [Configure SSH Key Authentication](<../../workflows/Networking and Access/Linux/Configure SSH Key Authentication.md>) |
| `scripts/Bash/Fix Displaylink Issues on Linux.md` | [Repair DisplayLink USB Authorization](<../../workflows/Windows and Linux/Linux/Repair DisplayLink USB Authorization.md>) |
| `scripts/Bash/Git Repo Updater.md` | [Git Repo Updater](<../../scripts/Automation/Gitea/Git Repo Updater.md>) |
| `scripts/Bash/Install QEMU Guest Agent.md` | [Install the QEMU Guest Agent](<../../deployments/Virtualization and Storage/Guests/Install the QEMU Guest Agent.md>) |
| `scripts/Bash/Install XRDP.md` | [Install XRDP on Ubuntu](<../../deployments/Networking and Access/Remote Access/Install XRDP on Ubuntu.md>) |
| `scripts/Bash/Mdadm Grow Array Size.md` | [Grow an mdadm Array](<../../scripts/Virtualization and Storage/Linux/Grow an mdadm Array.md>) |
| `scripts/Bash/Open Port Checker.md` | [Check Open Ports](<../../scripts/Networking and Access/Check Open Ports.md>) |
| `scripts/Bash/ProxmoxVE/Deeplab Rollback Script.md` | [Deeplab Rollback Script](<../../scripts/Virtualization and Storage/Proxmox/Deeplab Rollback Script.md>) |
| `scripts/Bash/Time Adjustment.md` | [Linux Time Commands](<../Windows and Linux/Linux Time Commands.md>) |
| `scripts/Bash/Transfer Docker Containers.md` | [Transfer Docker Containers Between Hosts](<../../workflows/Containers/Docker/Transfer Docker Containers Between Hosts.md>) |
| `scripts/Bash/Transfer Files with Netcat.md` | [Transfer Files with Netcat](<../../workflows/Applications/Files and Collaboration/Transfer Files with Netcat.md>) |
| `scripts/batch/Blue Iris/Server Watchdog.md` | [Blue Iris Server Watchdog](<../../scripts/Applications/Home Automation/Blue Iris Server Watchdog.md>) |
| `scripts/batch/robocopy.md` | [Robocopy Command Reference](<../Applications/Files and Collaboration/Robocopy Command Reference.md>) |
| `scripts/Powershell/Azure/Check Email Aliases.md` | [Check Email Aliases](<../../scripts/Identity and Certificates/Microsoft 365/Check Email Aliases.md>) |
| `scripts/Powershell/Azure/Connect to Azure AD.md` | [Connect to Azure AD](<../../scripts/Identity and Certificates/Microsoft 365/Connect to Azure AD.md>) |
| `scripts/Powershell/Exchange Online/Connect to Exchange Online.md` | [Connect to Exchange Online](<../../scripts/Applications/Email/Exchange Online/Connect to Exchange Online.md>) |
| `scripts/Powershell/General Purpose/DNS Hierarchy Correction.md` | [Correct DNS Server Priority](<../../scripts/Networking and Access/Correct DNS Server Priority.md>) |
| `scripts/Powershell/General Purpose/Directory Walker.md` | [Directory Walker](<../../scripts/Applications/Files and Collaboration/Directory Walker.md>) |
| `scripts/Powershell/General Purpose/File Finder.md` | [File Finder](<../../scripts/Applications/Files and Collaboration/File Finder.md>) |
| `scripts/Powershell/General Purpose/Fix Corrupted Windows Updates.md` | [Repair Windows Update Components](<../../scripts/Windows and Linux/Windows/Repair Windows Update Components.md>) |
| `scripts/Powershell/General Purpose/Force GPUpdate Domain Wide.md` | [Force Group Policy Updates Across the Domain](<../../scripts/Identity and Certificates/Active Directory/Force Group Policy Updates Across the Domain.md>) |
| `scripts/Powershell/General Purpose/Inactive User Profile Data Cleanup.md` | [Clean Up Inactive User Profiles](<../../scripts/Windows and Linux/Windows/Clean Up Inactive User Profiles.md>) |
| `scripts/Powershell/General Purpose/Rclone.md` | [Rclone Command Reference](<../Applications/Files and Collaboration/Rclone Command Reference.md>) |
| `scripts/Powershell/General Purpose/Remotely Change DNS Records.md` | [Change DNS Client Server Settings Remotely](<../../scripts/Networking and Access/Change DNS Client Server Settings Remotely.md>) |
| `scripts/Powershell/General Purpose/Restart Service Domain Wide.md` | [Start the RMM Agent Service Across the Domain](<../../scripts/Windows and Linux/Windows/Start the RMM Agent Service Across the Domain.md>) |
| `scripts/Powershell/General Purpose/Windows 11 Upgrade via UNC Path.md` | [Upgrade Windows 11 from a UNC Path](<../../scripts/Windows and Linux/Windows/Upgrade Windows 11 from a UNC Path.md>) |
| `scripts/Powershell/Hyper V/Collapse Differencing Disk Chains.md` | [Collapse Differencing Disk Chains](<../../scripts/Virtualization and Storage/Hyper-V/Collapse Differencing Disk Chains.md>) |
| `scripts/Powershell/Hyper V/Delete Locked VHDX File.md` | [Delete Locked VHDX File](<../../scripts/Virtualization and Storage/Hyper-V/Delete Locked VHDX File.md>) |
| `scripts/Powershell/Hyper V/Failover Cluster/Force Reboot Remote Cluster Node.md` | [Force Reboot Remote Cluster Node](<../../scripts/Virtualization and Storage/Hyper-V/Failover Cluster/Force Reboot Remote Cluster Node.md>) |
| `scripts/Powershell/Hyper V/Failover Cluster/Replication Bumper.md` | [Replication Bumper](<../../scripts/Virtualization and Storage/Hyper-V/Failover Cluster/Replication Bumper.md>) |
| `scripts/Powershell/Minecraft Server/Update Script.md` | [Update the ATM10 Minecraft Server](<../../scripts/Applications/Gaming and Media/Update the ATM10 Minecraft Server.md>) |
| `scripts/Powershell/Nextcloud/Upload Data to Nextcloud Share.md` | [Upload Data to a Nextcloud Share](<../../scripts/Applications/Files and Collaboration/Upload Data to a Nextcloud Share.md>) |
| `scripts/Powershell/Reporting/Get Password Expiration.md` | [Get Password Expiration](<../../scripts/Identity and Certificates/Active Directory/Reports/Get Password Expiration.md>) |
| `scripts/Powershell/Reporting/Inactive Computers.md` | [Inactive Computers](<../../scripts/Identity and Certificates/Active Directory/Reports/Inactive Computers.md>) |
| `scripts/Powershell/Reporting/Inactive Users.md` | [Inactive Users](<../../scripts/Identity and Certificates/Active Directory/Reports/Inactive Users.md>) |
| `scripts/Powershell/SMB/Detailed Permission Report All Shares.md` | [Report NTFS Permissions Across Shares](<../../scripts/Applications/Files and Collaboration/SMB/Report NTFS Permissions Across Shares.md>) |
| `scripts/Powershell/SMB/Top Level Permission Report All Shares.md` | [Report SMB Share Permissions](<../../scripts/Applications/Files and Collaboration/SMB/Report SMB Share Permissions.md>) |
| `scripts/Services/Email/Microsoft Exchange/DAG/Database Management.md` | [Manage DAG Database Copies](<../../workflows/Applications/Email/Microsoft Exchange/Manage DAG Database Copies.md>) |
| `scripts/Services/Email/Microsoft Exchange/DAG/Perform Exchange SE DAG Rolling Updates.md` | [Perform Exchange SE DAG Rolling Updates](<../../workflows/Applications/Email/Microsoft Exchange/Perform Exchange SE DAG Rolling Updates.md>) |
| `scripts/Services/Email/Microsoft Exchange/Restart Exchange Services.md` | [Start Exchange Services](<../../scripts/Applications/Email/Microsoft Exchange/Start Exchange Services.md>) |
| `scripts/Services/Email/Microsoft Exchange/Set Mailbox Auto Reply.md` | [Set Mailbox Auto Reply](<../../scripts/Applications/Email/Microsoft Exchange/Set Mailbox Auto Reply.md>) |
| `workflows/operations/automation/ansible/AWX/AWX Kerberos Implementation.md` | [AWX Kerberos Implementation](<../../workflows/Automation/AWX/AWX Kerberos Implementation.md>) |
| `workflows/operations/automation/ansible/AWX/Connect AWX to Gitea.md` | [Connect AWX to Gitea](<../../workflows/Automation/AWX/Connect AWX to Gitea.md>) |
| `workflows/operations/automation/ansible/credentials/Custom Credential Types/WinRM.md` | [Custom Kerberos WinRM Credential](<../Automation/AWX/Custom Kerberos WinRM Credential.md>) |
| `workflows/operations/automation/ansible/credentials/overview.md` | [Credential Configuration Examples](<../Automation/AWX/Credential Configuration Examples.md>) |
| `workflows/operations/automation/ansible/Enable WinRM on Windows Devices.md` | [Enable WinRM over HTTPS](<../../workflows/Identity and Certificates/Windows/Enable WinRM over HTTPS.md>) |
| `workflows/operations/automation/ansible/inventories/overview.md` | [Inventory Structure and Variables](<../Automation/AWX/Inventory Structure and Variables.md>) |
| `workflows/operations/automation/ansible/playbooks/playbooks.md` | [Playbook Catalog](<../Automation/AWX/Playbook Catalog.md>) |
| `workflows/operations/automation/ansible/projects/overview.md` | [Projects and Source Control](<../Automation/AWX/Projects and Source Control.md>) |
| `workflows/operations/automation/ansible/templates/overview.md` | [Job Template Configuration](<../Automation/AWX/Job Template Configuration.md>) |
| `workflows/operations/Backups and DR/Veeam Backup Replication/Backup Agent Takeover.md` | [Backup Agent Takeover](<../../workflows/Backup and Recovery/Veeam/Backup Agent Takeover.md>) |
| `workflows/operations/Backups and DR/Veeam Backup Replication/Core Veeam Concepts.md` | [Veeam Concepts](<../Backup and Recovery/Veeam Concepts.md>) |
| `workflows/operations/Backups and DR/Veeam Backup Replication/Manually Pruning Backups.md` | [Manually Pruning Backups](<../../workflows/Backup and Recovery/Veeam/Manually Pruning Backups.md>) |
| `workflows/operations/Backups and DR/Veeam Backup Replication/Migrating VMs to ProxmoxVE.md` | [Repair Rocky Linux After a Veeam Migration](<../../workflows/Virtualization and Storage/Proxmox/Repair Rocky Linux After a Veeam Migration.md>) |
| `workflows/operations/Backups and DR/Veeam Backup Replication/Migrating VSPC Backup Repositories.md` | [Migrating VSPC Backup Repositories](<../../workflows/Backup and Recovery/Veeam/Migrating VSPC Backup Repositories.md>) |
| `workflows/operations/Backups and DR/Veeam Backup Replication/Retention Best Practices.md` | [Veeam Retention Policy Example](<../Backup and Recovery/Veeam Retention Policy Example.md>) |
| `workflows/operations/Backups and DR/Veeam Backup Replication/Troubleshooting/Failed to Validate Certificates of Some Gateways.md` | [Failed to Validate Certificates of Some Gateways](<../../workflows/Backup and Recovery/Veeam/Failed to Validate Certificates of Some Gateways.md>) |
| `workflows/operations/Hardware Management/ILO/Generic ILO Advanced License Keys.md` | [iLO License Reference](<../Lab Map/Hardware/iLO License Reference.md>) |
| `workflows/operations/Linux/CachyOS/Restrict Monitors on Plasma Login Screen.md` | [Restrict Monitors on Plasma Login Screen](<../../workflows/Windows and Linux/Linux/CachyOS/Restrict Monitors on Plasma Login Screen.md>) |
| `workflows/operations/Linux/Expand ISCSI Based ZFS Filesystem.md` | [Expand an iSCSI-Backed ZFS Filesystem](<../../workflows/Virtualization and Storage/Linux/Expand an iSCSI-Backed ZFS Filesystem.md>) |
| `workflows/operations/Linux/Expanding Linux Filesystems.md` | [Expand a Linux Guest Filesystem](<../../workflows/Virtualization and Storage/Linux/Expand a Linux Guest Filesystem.md>) |
| `workflows/operations/Linux/Fedora Workstation/Full Setup.md` | [Set Up the Fedora Workstation](<../../deployments/Windows and Linux/Fedora/Set Up the Fedora Workstation.md>) |
| `workflows/operations/Linux/Fedora Workstation/Install DE into Fedora Server.md` | [Install XFCE and RustDesk on Fedora Server](<../../deployments/Networking and Access/Remote Access/Install XFCE and RustDesk on Fedora Server.md>) |
| `workflows/operations/Linux/Fedora Workstation/Install Flatpak Apps.md` | [Install Flatpak Apps](<../../workflows/Windows and Linux/Linux/Fedora Workstation/Install Flatpak Apps.md>) |
| `workflows/operations/Linux/Fedora Workstation/Upgrading Versions.md` | [Upgrading Versions](<../../workflows/Windows and Linux/Linux/Fedora Workstation/Upgrading Versions.md>) |
| `workflows/operations/Power and UPS/APC Cell Wiring Diagram.md` | [APC Battery Cell Wiring](<../Lab Map/Power/APC Battery Cell Wiring.md>) |
| `workflows/operations/Power and UPS/Battery Backup Power Distribution.md` | [UPS Power Distribution](<../Lab Map/Power/UPS Power Distribution.md>) |
| `workflows/operations/Windows/Change Windows Edition.md` | [Change Windows Edition](<../../workflows/Windows and Linux/Windows/Change Windows Edition.md>) |
| `workflows/operations/Windows/Delete Windows Recovery Partition.md` | [Delete Windows Recovery Partition](<../../workflows/Windows and Linux/Windows/Delete Windows Recovery Partition.md>) |
| `workflows/operations/Windows/Uninstall Updates via DISM.md` | [Uninstall Updates via DISM](<../../workflows/Windows and Linux/Windows/Uninstall Updates via DISM.md>) |
| `workflows/operations/Windows/VSS/Delete Shadow Copies.md` | [Delete Shadow Copies](<../../workflows/Windows and Linux/Windows/VSS/Delete Shadow Copies.md>) |
| `workflows/operations/Windows/Windows 11/Creating a Local Account on Win11.md` | [Creating a Local Account on Win11](<../../workflows/Windows and Linux/Windows/Windows 11/Creating a Local Account on Win11.md>) |
| `workflows/operations/Windows/Windows Server/SSL Certificates/Convert SSL Certificates into PFX Files.md` | [Convert Certificates to PFX](<../../workflows/Identity and Certificates/Certificates/Convert Certificates to PFX.md>) |
| `workflows/Platforms/Containerization/Kubernetes/Migrating Docker Compose YML to K8s.md` | [Migrating Docker Compose YML to K8s](<../../workflows/Containers/Kubernetes/Migrating Docker Compose YML to K8s.md>) |
| `workflows/Platforms/Virtualization/Hyper V/Failover Cluster/Rebuild Failover Cluster Replication.md` | [Rebuild Failover Cluster Replication](<../../workflows/Virtualization and Storage/Hyper-V/Failover Cluster/Rebuild Failover Cluster Replication.md>) |
| `workflows/Platforms/Virtualization/Hyper V/Forcefully Stop GuestVM.md` | [Forcefully Stop GuestVM](<../../workflows/Virtualization and Storage/Hyper-V/Forcefully Stop GuestVM.md>) |
| `workflows/Platforms/Virtualization/Hyper V/Kerberos Enabled VM Migration.md` | [Kerberos Enabled VM Migration](<../../workflows/Virtualization and Storage/Hyper-V/Kerberos Enabled VM Migration.md>) |
| `workflows/Platforms/Virtualization/Proxmox/Common Tasks.md` | [Remove a Node from a Proxmox Cluster](<../../workflows/Virtualization and Storage/Proxmox/Remove a Node from a Proxmox Cluster.md>) |
| `workflows/Platforms/Virtualization/Proxmox/Operations/Manually Activate Volume Group.md` | [Manually Activate a Volume Group](<../../workflows/Virtualization and Storage/Proxmox/Manually Activate a Volume Group.md>) |
| `workflows/Platforms/Virtualization/Proxmox/Operations/Upgrade PVE from 8 to 9.md` | [Upgrade Proxmox VE from 8 to 9](<../../workflows/Virtualization and Storage/Proxmox/Upgrade Proxmox VE from 8 to 9.md>) |
@@ -1,38 +0,0 @@
---
tags:
- Documentation
- Templates
- Markdown
---
**Purpose**: PLACEHOLDER
## Docker Configuration
```yaml title="docker-compose.yml"
PLACEHOLDER
```
```yaml title=".env"
PLACEHOLDER
```
## Traefik Reverse Proxy Configuration
If the container does not run on the same host as Traefik, you will need to manually add configuration to Traefik's dynamic config file, outlined below.
```yaml
http:
routers:
PLACEHOLDER:
entryPoints:
- websecure
tls:
certResolver: myresolver
service: PLACEHOLDER
rule: Host(`PLACEHOLDER.bunny-lab.io`)
services:
PLACEHOLDER:
loadBalancer:
servers:
- url: http://PLACEHOLDER:80
passHostHeader: true
```
+11 -37
View File
@@ -1,47 +1,21 @@
---
tags:
- Operations
- Index
- Foundations
- Reference
- Documentation
---
# Foundations
## Purpose
Defines the baseline documentation standards, shared references, and structural conventions used everywhere else in this knowledgebase.
Maintain the knowledgebase using the authoritative styling contract, document roles, and source-relative links.
## Includes
- Documentation styling contract
- Inventory and naming conventions
- Shared templates and glossary references
- Apply the authoritative Markdown and document-type contract.
- Choose the content role, subject, and related guides for a new page.
- Use the canonical template for the intended page type.
## New Document Template
````markdown
# <Document Title>
## Purpose
<one paragraph describing why this exists>
!!! info "Assumptions"
- <OS / platform / privilege assumptions>
- <required tools or prerequisites>
## Scope
- <what is covered>
- <what is explicitly out of scope>
## Procedure
```sh
# Commands go here (grouped and annotated)
```
## Validation
- <command + expected result>
## Troubleshooting
### Symptoms
- <what you see>
### Resolution
```sh
# Fix steps
```
````
## Find the Right Document
- [Documentation Styling](<Documentation Styling.md>) — Apply the authoritative Markdown and document-type contract.
- [Documentation Organization](<Documentation Organization.md>) — Choose the content role, subject, and related guides for a new page.
- [Choose a Document Template](<Choose a Document Template.md>) — Use the canonical template for the intended page type.
- [Documentation Path Changes](<Documentation Path Changes.md>) — Map former source paths to their new locations when maintaining external links.
+23 -5
View File
@@ -1,15 +1,33 @@
---
tags:
- Reference
- Index
- Documentation
---
# Reference
## Purpose
Stable supporting documentation used by deployments and workflows.
Start with a subject guide to connect the lab inventory, deployment instructions, operational procedures, and reusable scripts.
## Includes
- Documentation foundations and templates
- Hardware inventory and storage layouts
- Networking topology and infrastructure references
- Lab Map
- Virtualization and Storage
- Containers
- Networking and Access
- Identity and Certificates
- Automation
- Backup and Recovery
- Applications
- Windows and Linux
- Foundations
## Start with a Subject
- [Lab Map](<Lab Map/index.md>) — Identify where a workload runs, which address plan describes it, and which hardware or power reference applies before following a deployment or repair procedure.
- [Virtualization and Storage](<Virtualization and Storage/index.md>) — Follow the relationship between hypervisors, shared storage, guest disks, and recovery procedures. Select the documented storage design before choosing a maintenance command.
- [Containers](<Containers/index.md>) — Prepare the Docker or Kubernetes environment used by application deployments, then follow the operating procedures for building, moving, and exposing workloads.
- [Networking and Access](<Networking and Access/index.md>) — Find the DNS, proxy, VPN, and remote-access instructions that connect users and services. Use the address plans to identify the intended network before changing connectivity.
- [Identity and Certificates](<Identity and Certificates/index.md>) — Connect directory services, certificate trust, single sign-on, and application authentication. Start with the identity system involved, then follow the integration or maintenance procedure.
- [Automation](<Automation/index.md>) — Connect source control, automation controllers, managed hosts, and configuration delivery. Use the documented execution environment and authentication method for each workflow.
- [Backup and Recovery](<Backup and Recovery/index.md>) — Find backup concepts, repository maintenance, and recovery dependencies. Select the procedure for the affected backup system and distinguish a backup restore from a replica or snapshot operation.
- [Applications](<Applications/index.md>) — Find applications by the service they provide, then continue to their deployment, authentication, data, and maintenance documentation.
- [Windows and Linux](<Windows and Linux/index.md>) — Find workstation and server operating-system setup, updates, and repairs. Storage, networking, and identity tasks are linked to their subject guides when they cross operating-system boundaries.
- [Foundations](<foundations/index.md>) — Maintain the knowledgebase using the authoritative styling contract, document roles, and source-relative links.
@@ -1,46 +0,0 @@
---
tags:
- TrueNAS
- Storage
- Hardware
---
## Purpose
This document acts as a workflow to understand how to replace a drive on TrueNAS Core when it is hosted on an HPE Proliant server with HBA / IT Mode enabled. This enables you to hot-swap drives without rebooting TrueNAS Core.
### Offline the Disk
- You will log into the TrueNAS Core [WebUI](http://192.168.3.3).
- Navigate to "**Storage > Disks**"
- Look for the drive that is having issues / faults / unavailable and reference it's `da` number to reference later. (e.g. `da3`)
- Confirm the serial number of the drive and correlate that to the physical location in the [Disk Arrays](./disk-arrays.md) document,
- Navigate to "**Storage > Pools**"
- Look for the gear icon to the right of the storage pool and click on it
- Click on "**Status**"
- Locate the failing / failed drive and click on the "**...**" elipsis menu button
- Proceed to "**Offline**" the disk. This ensures that TrueNAS Core stops trying to use the disk.
### Physical Disk Replacement
At this point, we need to physically go to the server and pull out the failing drive and replace it.
- Take note of the new serial number on the replacement drive and update the [Disk Arrays](./disk-arrays.md) document accordingly.
- Insert the replacement drive back into the TrueNAS Core server
### Trigger Disk Re-Scan
Now we need to tell TrueNAS / FreeBSD to re-scan all disks to locate the new one.
- Within the TrueNAS Core WebUI, navigate to "**Shell**" and run the following command: `camcontrol rescan all`
- Navigate (back) to "**Storage > Pools > Status**"
- Locate the failed drive via it's `da` number again, and click the "**...**" elipsis menu button
- Proceed to "**Replace**" the disk, and when given a dropdown menu, only the new replacement disk should appear with the same `da` number
!!! success "Resilvering Started"
At this point, TrueNAS core will start taking parity data from the rest of the drives in the storage pool to reconstruct the replaced drive. This may take an hour or two depending on the speed of the drives and used capacity within the pool itself.
It is recommended to run a SCRUB right after resilvering to ensure that all data is accurate and healthy.
!!! info "Checking on Resilvering Process via CLI"
If you feel so inclined, you can check on the resilvering process by running the following command:
```sh
zpool status | grep "to go"
```
@@ -1,38 +0,0 @@
---
tags:
- Infrastructure
- Hardware
- Index
- Documentation
---
# Hardware
## Purpose
Physical assets, node inventories, storage layouts, and power topology for the lab.
## Includes
- Node build sheets and inventory
- Disk arrays and drive replacement procedures
- Power and UPS mapping
## New Document Template
````markdown
# <Document Title>
## Purpose
<what this hardware doc exists to describe>
!!! info "Assumptions"
- <hardware model / firmware / OS assumptions>
- <privilege assumptions>
## Inventory
- <serials, bays, disks, NICs, etc>
## Procedure
```sh
# Commands (if applicable)
```
## Validation
- <command + expected result>
````
@@ -1,48 +0,0 @@
---
tags:
- UniFi
- Networking
- Docker
---
**Purpose**: The UniFi® Controller is a wireless network management software solution from Ubiquiti Networks™. It allows you to manage multiple wireless networks using a web browser.
```yaml title="docker-compose.yml"
version: "2.1"
services:
controller:
image: lscr.io/linuxserver/unifi-controller:latest
container_name: controller
environment:
- PUID=1000
- PGID=1000
#- MEM_LIMIT=1024 #optional
#- MEM_STARTUP=1024 #optional
volumes:
- /srv/containers/unifi-controller:/config
ports:
- 8443:8443
- 3478:3478/udp
- 10001:10001/udp
- 8080:8080
- 1900:1900/udp #optional
- 8843:8843 #optional
- 8880:8880 #optional
- 6789:6789 #optional
- 5514:5514/udp #optional
restart: always
networks:
docker_network:
ipv4_address: 192.168.5.140
# ipv4_address: 192.168.3.140
networks:
default:
external:
name: docker_network
docker_network:
external: true
```
```yaml title=".env"
Not Applicable
```
@@ -1,45 +0,0 @@
---
tags:
- UniFi
- Networking
---
**Purpose**:
If you need to deploy Unifi Controller bare-metal into a virtual machine, you can do so with a few simple commands. You can feel free to reference the [original documentation](https://help.ui.com/hc/en-us/articles/220066768-Updating-and-Installing-Self-Hosted-UniFi-Network-Servers-Linux) if additional clarity is needed.
!!! note "Assumptions"
This document assumes that you are running Ubuntu Server (22.04 or higher). The instructions are not designed to accomodate RHEL-based Linux distributions.
!!! warning "INCOMPLETE DOCUMENT"
This document was originally written with the intention of comprehensively covering the deployment of the MongoDB server and Unifi Network Controller. However, I opted to use an automated scripted installation approach seen [here](https://community.ui.com/questions/UniFi-Installation-Scripts-or-UniFi-Easy-Update-Script-or-UniFi-Lets-Encrypt-or-UniFi-Easy-Encrypt-/ccbc7530-dd61-40a7-82ec-22b17f027776) that was almost turn-key instead.
```sh
apt-get update; apt-get install ca-certificates curl -y
curl -sO https://get.glennr.nl/unifi/install/install_latest/unifi-latest.sh && bash unifi-latest.sh
```
## Install Components
The installation will consist of a MongoDB server and a Unifi Network (controller) server. You will install the database first, then install the Unifi Controller second, so it can provision the newly-installed local MongoDB database server.
### General Configuration
We need to configure APT with a few commands to ensure that we can download the MongoDB and Unifi packages.
```sh
sudo apt-get update && sudo apt-get install ca-certificates apt-transport-https
echo 'deb [ arch=amd64,arm64 ] https://www.ui.com/downloads/unifi/debian stable ubiquiti' | sudo tee /etc/apt/sources.list.d/100-ubnt-unifi.list
sudo wget -O /etc/apt/trusted.gpg.d/unifi-repo.gpg https://dl.ui.com/unifi/unifi-repo.gpg
echo "deb [trusted=yes] https://repo.mongodb.org/apt/ubuntu bionic/mongodb-org/3.6 multiverse" | sudo tee /etc/apt/sources.list.d/mongodb-org-3.6.list
sudo apt-get update
```
!!! node "Alternative GPG Key Installation"
If you run into issues installing the GPG key for the Unifi packages, you can alternatively run the command seen below:
```sh
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv 06E85760C0A52C50
```
### MongoDB Server
Run the following commands install and enable automatic startup for the MongoDB server. Original reference documentation can be found [here](https://www.mongodb.com/docs/manual/tutorial/install-mongodb-on-ubuntu/).
```sh
```
@@ -1,26 +0,0 @@
---
tags:
- Docker
- Macvlan
- Networking
---
**Purpose**:
You may find that you only have one network adapter on a server / VM and need to have multiple virtual networks associated with it. For example, Home Assistant exists on the `192.168.3.0/24` network but it needs to also access devices on the `192.168.4.0/24` surveillance network. To facilitate this, we will make a MACVLAN Sub-Interface. This will make a virtual interface that is parented to the actual physical interface.
!!! info "Assumptions"
It is assumed that you are running Rocky Linux (or CentOS / RedHat).
## Create the Permanent Sub-Interface
You will begin with making a new interface, it will have the name `macvlan0`.
``` sh
nmcli connection add type macvlan ifname surveillance dev ens18 mode bridge ipv4.method manual ipv4.addresses 192.168.4.100/24
nmcli connection up macvlan-surveillance
nmcli connection show
```
## Bind a Docker Network to the Sub-Interface
Now you need to run the following command to allow docker to use this interface for the `surveillance_network`
``` sh
docker network create -d macvlan --subnet=192.168.4.0/24 --gateway=192.168.4.1 -o parent=surveillance surveillance_network
```
@@ -1,14 +0,0 @@
---
tags:
- Docker
- Networking
---
### Configure Docker Network
We want to use a dedicated subnet / network specifically for containers, so they don't trample over the **SERVER** and **LAN** networks. If you are unsure of the name of the network adapter, in this case `eth0`, just type `ipaddr` in the terminal to list the network interfaces to locate it.
```
docker network create -d macvlan --subnet=192.168.5.0/24 --gateway=192.168.5.1 -o parent=eth0 docker_network
```
!!! note
Be sure to replace `eth0` with the correct interface name using `ip addr` in the terminal. e.g. It may appear as something else like `ens18`, etc. If the interface doesn't exist, Docker will produce an error complaining about it.
@@ -1,38 +0,0 @@
---
tags:
- Sophos
- Firewall
- Routing
- LAN
- Networking
---
**Purpose**: You may have a Sophos XGS appliance and need more than one interface to act as additional LAN ports. You can achieve this with bridges.
!!! info "Assumptions"
It is assumed that your Sophos XGS appliance has at least 3 interfaces, one for `WAN`, one for `LAN`, and a third one that will act as a member of the bridge. You can have as many member interfaces of the bridge as needed, but you need at least one.
## Login to the Firewall
You will need to access the firewall either directly on the local network at `https://<IP-of-Firewall>:4444` or remotely in Sophos Central.
## Configure a LAN bridge
Navigate to "**Configure > Network > Interfaces > "Add Interface" > "Add Bridge"**"
| **Field** | **Value** |
| :--- | :--- |
| Name | `LAN Bridge` |
| Hardware | `br0` |
| Enable routing on this bridge pair | `<Unchecked>` |
| Member Interfaces | `<Interfaces-of-Additional-Ports> / Zone: "LAN"` |
!!! warning
The LAN interface itself needs to be a member of the bridge. If it is not, the Sophos Appliance will not allow you to use the same IP address as the existing LAN interface.
### IPv4 Configuration
| **Field** | **Value** |
| :--- | :--- |
| IP Assignment | `Static` |
| IPv4/netmask | `<IP-of-LAN-Interface> / <CIDR-of-LAN-Interface>` |
| Gateway IP | `<Blank>` |
| Member Interfaces | `<Interfaces-of-Additional-Ports> / Zone: "LAN"` |
@@ -1,44 +0,0 @@
---
tags:
- Sophos
- RDP
- SSL VPN
- VPN
- Firewall
---
## Purpose
This document exists to outline the generalized process to configuring remote access in a Sophos XGS Firewall to allow a VPN user to RDP into a workstation. *Setting up Remote SSL VPN Access is not covered in this document.*
### Create MAC Host for Destination Device
The first step in the process is to create a MAC address host for the device being RDP'd into, that way if it's IP rotates, the firewall rule will continue to work correctly.
- Navigate to **Sophos XGS Firewall > [System] Hosts and Services**
- Click on the **Mac Host** tab > "**Add**"
- Name: `<Device-Hostname>`
- Description: `<Workstation Remote Access for (username)>`
- Type: `Mac Address`
- MAC Address: `<mac address of device>`
Click **Save**
### Configure Firewall Rule
- Navigate to **[Protect] Rules and Policies > Add Firewall Rule (New Firewall Rule)**
- Rule Name: `Remote Workstation Access for (username)`
- Source Zone: `VPN`
- Source Networks and Devices: `Any`
- Destination Zone: `LAN`
- Destination Networks: `<MAC Host We Previously Made>`
- Services > Add New Item > `RDP`
- If `RDP` does not exist, click "Add", `Services`
- Name: `RDP`
- Description: `Remote Desktop Protocol`
- Type: `TCP/UDP`
- Protocol: `TCP`
- Source Port: `1:65535`
- Destination Port: `3389`
Click **Save**
- Check **Match Known Users**
- Under "Users or Groups" click "Add New Item"
- Search for the username of the person using the VPN that needs to access the workstation (e.g. `nicole.rappe@bunny-lab.io`)
- Click the **Save** button and have the user try to connect to the VPN, then RDP into their workstation.
@@ -1,168 +0,0 @@
---
tags:
- Sophos
- IPsec
- VPN
- Firewall
- Routing
---
**Purpose**: Generally speaking, when you have site-to-site VPN tunnels, you have to ensure that the *health* of the tunnel is operating as-expected. Sometimes VPN tunnels will report that they are online and connected, but in reality, no traffic is flowing to the remote side of the tunnel. In these instances, we can create a script that pings a device on the remote end, and if it does not respond in a timely manner, the script restart the VPN tunnel automatically.
!!! note "Assumptions"
This document assumes that you will be running a powershell script on a Windows environment. The `curl` commands can be used interchangably in Linux, but the example script provided here will be using `curl.exe` within a powershell script, and instead of running on a schedule using crontab, it will be using Windows Task Scheduler.
I will attempt to provide Linux-equivalant commands where-possible.
## Sophos Environment
### Configure Sophos XGS Firewall ACLs
You need to configure a user account that will be specifically used for leveraging the API controls that allow resetting the VPN tunnel(s). At this stage, you need to log into your Sophos XGS Firewall. For this example, we will assume you can reach your firewall at https://172.16.16.16:4444 and log in as the administrator.
### Create API Access Profile
You need to create a profile that the API User will leverage to issue commands to the firewall's VPN settings. Without this profile, the user may have either not enough, or too much access.
- Navigate to **System > Profiles > Device Access > "Add"**
- Profile Name: `VPNTunnelAPI`
- Check the radio box column named "**None**" to Deny all permissions to all areas of the firewall
- Expand the "**VPN**" section of the permission tree, and check the box for "**Read-Write**" next to "**Connect Tunnel**"
- Click the "**Save**" button to save the access profile
### Create API Access User
Now we need to make a user account that we will use inside the script to authenticate against the firewall using the previously-mentioned access profile
- Navigate to **Configure > Authentication > Users > "Add"**
- Username: `TunnelCheckerAPIUser`
- Name: `TunnelCheckerAPIUser`
- User Type: `Administrator`
- Profile: `VPNTunnelAPI`
- Password: `01_placeholder_PASSWORD_here_02`
- Group: `Open Group`
- Click the "**Save**" button to save the API user account
### Create Device Access ACL
Now we need to configure an ACL within the Firewall to allow API access from the specific server we will be using in the next section.
- Navigate to **Administration > Device Access > Local service ACL exception rule > "Add"**
- Rule Name: `API Access (IPSec Tunnel Heartbeat Script)`
- Source Zone: `The Zone of the Server/Device that will be used to run the script, such as a server network.
- Source Network/Host: `<IP_HOST_OF_DEVICE_RUNNING_SCRIPT>`
- Destination Host: `XGS Firewall (Local IP)` (*This is an IP host pointing to the internal IP of the Firewall*)
- Services: `HTTPS`
- Action: `Accept`
### Configure API Access via IP
Lastly, you need to configure the API access to allow communication from the IP of the device. I know this seems redundant to the previous "Device Access ACL" but its required for this to work, otherwise you will get an `Sophos API Operations are not allowed from the requester IP address` error when running the script.
- Navigate to **System > Backup & Firmware > API > API Configuration**
- Add the IP of the Server/Device
- Click the "**Apply** button
## Server Environment
### Choose a Server
It is important to choose a server/device that is able to communicate with the devices on the remote end of the tunnel. If it cannot ping the remote device(s), it will assume that the tunnel is offline and do an infinite loop of restarting the VPN tunnel.
### Prepare the Script Folder
You need a place to put the script (and if on Windows, `curl.exe`). Follow the instructions specific to your platform below:
=== "Windows"
Download `curl.exe` from this location: [Download](https://curl.se/windows/dl-8.10.0_1/curl-8.10.0_1-win64-mingw.zip) and place it somewhere on the operating system, such as `C:\Scripts\VPN_Tunnel_Checker`. Then copy this script into that same folder and call it `Tunnel_Checker.ps1` with the content below:
!!! note "Curl Files Extraction"
You will want to extract all of the files included in the zip file's `bin` folder. Specifically, copy the following files into the `C:\Scripts\VPN_Tunnel_Checker` folder:
- `curl.exe`
- `curl-ca-bundle`
- `libcurl-x64.def`
- `libcurl-x64.dll`
``` powershell
function Reset-VPN-Tunnel {
Write-Host "VPN Tunnel Broken - Bringing VPN Tunnel Down..."
.\curl -k https://172.16.16.16:4444/webconsole/APIController?reqxml=<Request><Login><Username>TunnelCheckerAPIUser</Username><Password>01_placeholder_PASSWORD_here_02</Password></Login><Set><VPNIPSecConnection><DeActive><Name>VPN_TUNNEL_NAME</Name></DeActive></VPNIPSecConnection></Set></Request>
Start-Sleep -Seconds 5
Write-Host "Bringing VPN Tunnel Up..."
.\curl -k https://172.16.16.16:4444/webconsole/APIController?reqxml=<Request><Login><Username>TunnelCheckerAPIUser</Username><Password>01_placeholder_PASSWORD_here_02</Password></Login><Set><VPNIPSecConnection><Active><Name>VPN_TUNNEL_NAME</Name></Active></VPNIPSecConnection></Set></Request>
}
function Check-VPN-Tunnel {
# Server Connectivity Check
Write-Host "Checking Tunnel Connection to PLACEHOLDER..."
if (-not (Test-Connection '10.0.0.29' -Quiet)) {
Reset-VPN-Tunnel
}
# Server Connectivity Check
Write-Host "Checking Tunnel Connection to PLACEHOLDER..."
if (-not (Test-Connection '10.0.0.30' -Quiet)) {
Reset-VPN-Tunnel
}
}
function Trace-VPN-Tunnel {
Write-Host "Tracing Path to PLACEHOLDER:"
pathping -n -w 500 -p 100 10.0.0.29
Write-Host "Tracing Path to PLACEHOLDER:"
pathping -n -w 500 -p 100 10.0.0.30
}
CD "C:\Scripts\VPN_Tunnel_Checker"
Check-VPN-Tunnel
#Write-Host "Checking Tunnel Quality After Running Script..."
#Trace-VPN-Tunnel
```
!!! note "Optional Reporting"
You may find that you want some extra logging enabled so you can track the script doing its job to ensure its working. You can add the following to the script above to add that functionality.
Add the following to the bottom of each server in the `Check-VPN-Tunnel` function, directly below the `Reset-VPN-Tunnel` function.
``` powershell
Add-Content -Path "C:\Scripts\VPN_Tunnel_Checker\Tunnel.log" -Value "$(Get-Date -Format 'yyyy-MM-dd HH:mm:ss') PLACEHOLDER Connection Down"
```
Lastly, change the very end of the script under where the `Check-IHS-Tunnel` function is being called to look like this if you want to log heartbeats and not just when a VPN tunnel is down. The purpose of this is to show the script is actually running. I recommend only temporarily implementing it during initial deployment.
``` powershell
CD "C:\Scripts\VPN_Tunnel_Checker"
Check-VPN-Tunnel
Add-Content -Path "C:\Scripts\VPN_Tunnel_Checker\Tunnel.log" -Value "$(Get-Date -Format 'yyyy-MM-dd HH:mm:ss') Heartbeat"
```
=== "Linux"
``` sh
PLACEHOLDER
```
### Create Scheduled Task
At this point, you need this script to run automatically on its own every 5 minutes or so, so you need to create a task in the Windows Task Scheduler in order to achieve this.
=== "Windows"
- Open "**Task Scheduler**" on the device
- Expand "**Task Scheduler Library**" in the tree on the left-hand side
- Right-click anywhere in the task list and select "**Create New Task...**"
- **General**:
- Name: `Check VPN Tunnel Every 5 Minutes`
- When running this task, use the following user account: `SYSTEM`
- **Triggers**:
- Click "**New...**"
- Begin the Task: `On a Schedule`
- Settings: `Daily`
- Advanced Settings > Repeat Task Every: `5 Minutes` > for a duration of `1 Day`
- **Actions**:
- Click "**New...**"
- Action: `Start a Program`
- Program/Script: `C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe`
- Add Arguments: `-ExecutionPolicy Bypass -File "C:\Scripts\VPN_Tunnel_Checker\Tunnel_Checker.ps1"`
- Press the "**OK**" button to save the scheduled task, then wait for 5 minutes to ensure it triggers as-expected.
=== "Linux"
- PLACEHOLDER
- PLACEHOLDER
@@ -1,105 +0,0 @@
---
tags:
- Sophos
- IPsec
- VPN
- Firewall
- Routing
---
**Purpose**: You may have two Sophos XGS appliances (or a mixed configuration) and need to set up a site-to-site VPN tunnel between two remote locations. You can achieve this with a simple passphrase-based IPSec VPN tunnel.
!!! info "Assumptions"
This documentation only provides instruction for Sophos XGS based devices. It does not account for third-party vendors or other manufactured hardware. If you need to set up a mixed VPN tunnel with a different brand of networking device, you need to do your best to match the settings on the tunnels manually. (e.g. Encryption Type, Phase Lifetimes, etc).
## Architecture
!!! tip "Best Practices - Initiators / Responders"
If you have a hub-and-spoke network, where one location acts as a central authority (e.g. domain controllers, auth servers, identity providers, headquarters, etc), you will set up the central "hub" as a VPN responder on its side of the VPN tunnel, and all the remote "spoke" locations would behave as VPN initiators.
``` mermaid
graph TB
Responder((Responder<br/>Headquarters))
Initiator1((Initiator<br/>Remote Site 1))
Initiator2((Initiator<br/>Remote Site 2))
Initiator3((Initiator<br/>Remote Site 3))
Initiator4((Initiator<br/>Remote Site 4))
Initiator5((Initiator<br/>Remote Site 5))
Initiator1 --> Responder
Initiator2 --> Responder
Initiator3 --> Responder
Initiator4 --> Responder
Initiator5 --> Responder
```
## Login to the Firewall
You will need to access the firewall either directly on the local network at `https://<IP-of-Firewall>:4444` or remotely in Sophos Central.
## Configure an IPSec VPN Tunnel
Navigate to "**Configure > Site-to-Site VPN > Add**"
### General settings
| **Field** | **Value** |
| :--- | :--- |
| Name | `<ThisLocation> to <RemoteLocation>` |
| IP Version | `Dual` |
| Connection Type | `Tunnel Interface` (*Also known as a "Route-Based VPN"*) |
| Gateway Type | `Initiate the Connection` / `Respond Only` (*See "Best Practices" Section*) |
### Encryption
| **Field** | **Value** |
| :--- | :--- |
| Encryption Profile | `Custom_IKEv2_Initiator` / `Custom_IKEv2_Responder` (*Based on the "Gateway Type"*) |
| Authentication Type | `Preshared Key / Passphrase` |
### Gateway Settings
| **Field** | **Value** |
| :--- | :--- |
| Listening Interface | `<WAN Interface / Generally "Port2">` (*Internal IP Address*) |
| Gateway Address | `<Public IP of Remote Firewall>` |
| Local ID Type | `IP Address` (*Usually Optional*) |
| Remote ID Type | `<If the Remote Firewall has one, enter it, otherwise leave blank>` (*Usually Optional*)|
| Local Subnet | `<Leave Blank>` |
| Remote Subnet | `<Leave Blank>` |
!!! note "Tunnel IDs / Subnets"
If one side of the tunnel indicates a Local ID, you need to input that as the Remote ID on the other end of the tunnel. While Tunnel IDs are generally optional, if one side uses them, both need to.
- "Route-Based" VPNs do not need subnets indicated / configured
- "Policy-based" VPNs require subnets indicated / configured
## Configure IPSec Encryption Profile
Navigate to "**System > Profiles > IPSec Profiles > Custom_IKEv2_`<Initiator>/<Responder>`**"
!!! info "Explanation of Phases and their Relation to Initiators/Responders"
Phase 1 could be described as establishing the initial tunnel's connectivity from the Initiator to the Responder. (Local to Remote). While phase 2 would be considered individual devices establishing connections through the VPN tunnel. (Individual Endpoint Connectivity).
The responder's phase 1 & 2 lifetime values are 300 seconds longer than the initiator's phase 1 & 2 lifetime values.
=== "Initiator Phase Lifetime Values"
| **Field** | **Value** | **Notes** |
| :--- | :--- | :--- |
| Phase 1 Lifetime | *Default Value*: `28800` | `<Longer Lifetime Compared to Phase 2>` |
| Phase 2 Lifetime | *Default Value*: `14400` | `<Shorter Lifetime Compared to Phase 1>` |
=== "Responder Phase Lifetime Values"
| **Field** | **Value** | **Notes** |
| :--- | :--- | :--- |
| Phase 1 Lifetime | *Default Value + 300 Seconds*: `328800` | `<Longer Lifetime Compared to Phase 2>` |
| Phase 2 Lifetime | *Default Value + 300 Seconds*: `314400` | `<Shorter Lifetime Compared to Phase 1>` |
!!! warning "Remote / Local Phase Lifetimes"
Within the context of the remote and local VPN tunnels, the lifetime of the Phase 1 and Phase 2 encryption keys needs to be shorter on the intiator than the responder sides of the VPN tunnel.
## Repeat Steps on Remote Firewall
You will need to repeat the steps on both firewalls, so one firewall is the initiator, and one is configured as the responder. Keep special note of the admonitions regarding initiator / responder / local / remote differences.
## Connect the IPSec Tunnels
Now you need to start the tunnel on the Initiator side first, then start the tunnel on the responder side. If both sides show green status indicators, the tunnel should be active.
@@ -1,34 +0,0 @@
---
tags:
- Linux
- Networking
---
**Purpose**: This is a scaffold document outlining the high level of changing an IP address of a server in either Debian or RHEL based operating systems.
=== "Ubuntu / Debian"
``` sh
# Edit Netplan File
nano /etc/netplan/<name-of-netplan-file>
# <edit existing networking> --> <save file>
# Apply Netplan Changes
netplan apply
```
=== "Rocky / Fedora / RHEL"
``` sh
# Modify the Existing Connection via nmcli
nmcli connection modify ens18-connection \
ipv4.addresses 192.168.3.13/24 \
ipv4.gateway 192.168.3.1 \
ipv4.dns "192.168.3.25,192.168.3.26" \
ipv4.method manual
# Bring the Connection Online
sudo nmcli connection down ens18-connection
sudo nmcli connection up ens18-connection
```
@@ -1,31 +0,0 @@
---
tags:
- Tuya
- Networking
---
### pfSense DHCP Reservations for Tuya-Based Smart Devices
| **Description** | **IP Address** | **MAC Address** | **Hostname** | **Device ID** | **Local Key** |
| :--- | :--- | :--- | :--- | :--- | :--- |
| Bottom of Stairs | 10.0.0.200 | bcddc29072bf | ESP\_9072BF | 50316010bcddc29072bf | 5c92ba765b22a96f |
| Right Monitor | 10.0.0.201 | bcddc2901aef | ESP\_901AEF | 50316010bcddc2901aef | ea4852cf67fbff52 |
| Downstairs Light | 10.0.0.202 | bcddc28fe4c4 | ESP\_8FE4C4 | 74160333bcddc28fe4c4 | c207fffba7143bdb |
| Right TV Light | 10.0.0.203 | b4e62d4bc3fe | ESP\_4BC3FE | 36087764b4e62d4bc3fe | 9e807e03a398a31c |
| Nightstand | 10.0.0.204 | b4e62d4bc3cb | ESP\_4BC3CB | 36087764b4e62d4bc3cb | 739fca9d40634ad5 |
| Top of Stairs | 10.0.0.205 | bcddc2904ed9 | ESP\_904ED9 | 50316010bcddc2904ed9 | 23452028cfe464c0 |
| Bathroom | 10.0.0.206 | 2cf432220421 | ESP\_220421 | 105480752cf432220421 | 03099191b6ab585e |
| Front Porch | 10.0.0.207 | bcddc2947aae | ESP\_947AAE | 50316010bcddc2947aae | 18d074fa9ff47087 |
| Left Monitor | 10.0.0.208 | 2cf43221af1a | ESP\_21AF1A | 105480752cf43221af1a | aef4f6067548c3a9 |
| Puppy Nook | 10.0.0.209 | cc50e3feaa2b | ESP\_FEAA2B | 76380710cc50e3feaa2b | 7c881c27da5079b6 |
| TV | 10.0.0.210 | cc50e378bab9 | ESP\_78BAB9 | 35138222cc50e378bab9 | 89b366574278e990 |
| Left TV Light | 10.0.0.211 | cc50e378916d | ESP\_78916D | 10548075cc50e378916d | a2d0aeb1ad676b9f |
| Bedroom Light | 10.0.0.212 | bcddc2907645 | | 50316010bcddc2907645 | d73b0af93d1bf2da |
| Garden Water Pump | 10.0.0.213 | 98f4abef7c2c | | 2182401498f4abef7c2c | 4715733dd7850f00 |
| wifi Water Timer | 10.0.0.214 | | | eb54e6ae7c7536a4bbawyw | 2a72efa9b2f36437 |
| Tech Room Light Strips | 10.0.0.215 | | | eb7dd0deaab376a2ffsqwl | 2a72efa9b2f36437 |
| Irrigation Hub | 10.0.0.216 | 10d5615ab16b | | eb3b374a82a993d252j7v9 | 2a72efa9b2f36437 |
| Front Lawn Sprinkler | | | | ebace67e93f8fde4ccdv7p | 2a72efa9b2f36437 |
### Misc Color Profile Notes:
- **1 NAME 3 4 0 255 2 5 1500 8000**
- 20 NAME 22 23 29 1000 21 24 2700 6500
@@ -1,38 +0,0 @@
---
tags:
- Infrastructure
- Networking
- Index
- Documentation
---
# Networking
## Purpose
Network topology, addressing, firewalling, VPN, and network service dependencies.
## Includes
- IP tables and address plans
- Firewall and VPN configurations
- Network controllers and DNS-related services
## New Document Template
````markdown
# <Document Title>
## Purpose
<what this network doc exists to describe>
!!! info "Assumptions"
- <platform or appliance assumptions>
- <privilege assumptions>
## Architecture
<ASCII diagram or concise topology notes>
## Procedure
```sh
# Commands or config steps
```
## Validation
- <command + expected result>
````
@@ -1,52 +0,0 @@
---
tags:
- NetBird
- VPN
- Networking
- Docker
---
## Purpose
Netbird is a free and open-source VPN server and client platform. The following document will illustrate how to deploy Netbird into a homelab or business environment.
!!! note "Assumptions"
It is assumed that you are running Rocky Linux 10. You can technically use anything, but the command syntax will be different depending on the platform, and this document will not outline every possible operating system.
### Install Prerequisites
You need to install a few things before we can begin with the deployment of Netbird. Run the following commands set up the server environment before Netbird deployment. This also assumes that you opened all of the necessary ports listed in the [official Netbird deployment documentation](https://docs.netbird.io/selfhosted/selfhosted-quickstart) as well as set up a reverse proxy pointing to port 80 on the Netbird server.
!!! warning "Run as Non-Sudo"
Run all of the commands below as a normal user, do not use `sudo su` when deploying Netbird.
```sh
# Update system & install necessary packages
sudo dnf update -y
sudo dnf config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo
sudo dnf install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin jq
sudo systemctl enable docker --now
# Configure normal user to have docker privileges
sudo usermod -aG docker nicole
# Logout and log back in via SSH
exit
ssh nicole@192.168.3.65
# Create Netbird project directory and pull down installation files
sudo mkdir -p /srv/containers/netbird
sudo chmod -R 770 /srv/containers/netbird
sudo chown -R nicole:docker /srv/containers/netbird
cd /srv/containers/netbird
curl -sSLO https://github.com/netbirdio/netbird/releases/latest/download/getting-started-with-zitadel.sh
# Deploy Netbird
export NETBIRD_DOMAIN=vpn.bunny-lab.io
bash getting-started-with-zitadel.sh
```
### Example Deployment Output
If everything is working correctly, you can go make some coffee and come back. When everything is done getting set up, you will see output similar to the below:
```sh
```