06476745f1
New stack mirroring PFI convention (stacks/comfyui/) using
mmartial/comfyui-nvidia-docker:ubuntu24_cuda12.8-20260312. Both GPUs
exposed, pinned to CUDA 12.8 to match the host's 570.x driver and the
native cuda-toolkit already in place.
Layout — single tree under /worktank/comfyui/ (462G dedicated, 1%
used pre-deploy):
- basedir/ → /basedir user state (models, workflows, custom_nodes,
input, output); owned 1000:1000 so external
tools can edit workflow JSON directly.
- run/ → /comfy/mnt ComfyUI source + venv + pip cache (~7.8G
after bootstrap). Bind mount instead of
named volume — the image refuses to chown
mounted paths at startup, so keeping this
lkraven-owned avoids the sudo dance.
servers/irv-ml1/README.md refreshed: Docker upgraded to 29.4.1 with
traefik-net in place; dockge + beszel-agent + dozzle-agent already
present; /storetank dropped 92% → 64%; restic coverage to
rest-server-nh3 is operational (not "currently none" as prior text).
384 lines
21 KiB
Plaintext
384 lines
21 KiB
Plaintext
|
|
===== HOST =====
|
|
|
|
Hostname: irv-ml1.phasefinal.com
|
|
Date: 2026-04-23T22:25:44-07:00
|
|
Uptime: up 3 weeks, 1 day, 7 hours, 20 minutes
|
|
OS: Debian GNU/Linux 12 (bookworm)
|
|
Kernel: 6.1.0-37-amd64
|
|
Arch: x86_64
|
|
|
|
===== HARDWARE =====
|
|
|
|
CPU cores: 64
|
|
CPU model: AMD Ryzen Threadripper 3970X 32-Core Processor
|
|
MemTotal: 251.6 GB
|
|
MemAvailable: 246.6 GB
|
|
|
|
===== GPUS =====
|
|
|
|
index, name, memory.total [MiB], memory.free [MiB], driver_version
|
|
0, NVIDIA GeForce RTX 3090, 24576 MiB, 24126 MiB, 570.124.06
|
|
1, NVIDIA RTX A6000, 49140 MiB, 48539 MiB, 570.124.06
|
|
|
|
===== FILESYSTEMS (df) =====
|
|
|
|
Filesystem Size Used Avail Use% Mounted on
|
|
/dev/nvme0n1p2 1.8T 1.4T 393G 78% /
|
|
/dev/nvme0n1p1 511M 5.9M 506M 2% /boot/efi
|
|
worktank 462G 128K 462G 1% /worktank
|
|
storetank 1.8T 1.2T 660G 64% /storetank
|
|
|
|
===== PERSISTENT MOUNTS (/etc/fstab, non-comment) =====
|
|
|
|
UUID=a71486c6-b6db-4484-957f-a62e0b9dd127 / ext4 errors=remount-ro 0 1
|
|
UUID=6C3D-4DC5 /boot/efi vfat umask=0077 0 1
|
|
UUID=0f7132b5-ca2b-442a-bc1f-74b8fae44ccb none swap sw 0 0
|
|
|
|
===== TARGETED DATA PATHS =====
|
|
|
|
/opt (total: 187G)
|
|
total 140
|
|
drwxrwxrwx 34 root root 4096 2026-04-23 15:18 .
|
|
drwxr-xr-x 21 root root 4096 2025-05-31 22:46 ..
|
|
drwxr-xr-x 20 llmuser llmuser 4096 2025-03-04 15:08 ai-toolkit
|
|
drwxr-xr-x 14 llmuser llmuser 4096 2025-02-18 13:03 alltalk
|
|
drwxr-xr-x 12 llmuser llmuser 4096 2025-01-28 11:36 alltalkv2
|
|
drwxr-xr-x 2 llmuser llmuser 4096 2025-02-10 14:05 aphrodite
|
|
drwxr-xr-x 7 llmuser llmuser 4096 2023-09-26 15:44 bark
|
|
drwxr-xr-x 12 llmuser llmuser 4096 2023-09-27 16:23 bitsandbytes
|
|
drwxr-xr-x 10 llmuser llmuser 4096 2024-03-21 23:01 chat-ui
|
|
drwxr-xr-x 31 llmuser llmuser 4096 2025-05-04 09:30 ComfyUI
|
|
drwx--x--x 4 root root 4096 2026-04-23 15:18 containerd
|
|
drwxr-xr-x 2 llmuser llmuser 4096 2025-02-10 15:00 cuda
|
|
drwxr-xr-x 4 lkraven lkraven 4096 2026-04-23 14:56 docker
|
|
drwxr-xr-x 8 llmuser llmuser 4096 2025-03-07 14:03 fluxgym
|
|
drwxr-xr-x 3 root root 4096 2024-03-21 16:22 google
|
|
drwxr-xr-x 33 llmuser llmuser 4096 2024-03-21 16:39 h2ogpt
|
|
drwxr-xr-x 2 llmuser llmuser 4096 2025-03-23 22:51 koboldcpp
|
|
drwxr-xr-x 15 llmuser llmuser 4096 2025-06-04 15:34 kokoro
|
|
drwxr-xr-x 6 llmuser llmuser 4096 2025-02-05 23:05 kokovoicelab
|
|
drwxr-xr-x 24 llmuser llmuser 4096 2025-03-23 21:27 llama.cpp
|
|
drwxr-xr-x 2 llmuser llmuser 4096 2025-03-24 15:44 llama-swap
|
|
drwxr-xr-x 4 llmuser llmuser 4096 2024-03-18 10:50 lollms
|
|
drwxr-xr-x 4 root root 4096 2023-07-15 16:38 nvidia
|
|
drwxr-xr-x 2 llmuser llmuser 4096 2025-04-13 19:24 ollama
|
|
drwxr-xr-x 10 llmuser llmuser 4096 2025-03-21 22:00 Orpheus-FastAPI
|
|
drwxr-xr-x 24 llmuser llmuser 4096 2024-03-19 16:44 o-textgen
|
|
drwxr-xr-x 21 llmuser llmuser 4096 2023-09-27 10:06 sdnext
|
|
drwxr-xr-x 19 llmuser llmuser 4096 2025-03-05 13:50 SillyTavern
|
|
drwxrwxrwx 6 lkraven lkraven 4096 2023-07-17 19:55 SillyTavern-extras
|
|
|
|
/opt/docker (total: 48K)
|
|
total 16
|
|
drwxr-xr-x 4 lkraven lkraven 4096 2026-04-23 14:56 .
|
|
drwxrwxrwx 34 root root 4096 2026-04-23 15:18 ..
|
|
drwxr-xr-x 5 lkraven lkraven 4096 2026-04-23 16:50 compose
|
|
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-23 14:56 conf
|
|
|
|
/opt/docker/compose (total: 40K)
|
|
total 20
|
|
drwxr-xr-x 5 lkraven lkraven 4096 2026-04-23 16:50 .
|
|
drwxr-xr-x 4 lkraven lkraven 4096 2026-04-23 14:56 ..
|
|
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-23 17:09 beszel-agent-irv
|
|
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-23 15:04 dockge
|
|
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-23 16:57 dozzle-agent-irv
|
|
|
|
/opt/docker/conf (total: 4.0K)
|
|
total 8
|
|
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-23 14:56 .
|
|
drwxr-xr-x 4 lkraven lkraven 4096 2026-04-23 14:56 ..
|
|
|
|
/var/lib/docker (total: 4.0K)
|
|
|
|
/srv (total: 4.0K)
|
|
total 8
|
|
drwxr-xr-x 2 root root 4096 2023-07-15 13:51 .
|
|
drwxr-xr-x 21 root root 4096 2025-05-31 22:46 ..
|
|
|
|
|
|
===== DOCKER =====
|
|
|
|
Server: 29.4.1 Client: 29.4.1
|
|
|
|
----- docker info -----
|
|
Containers: 4 (running 3, paused 0, stopped 1)
|
|
Images: 44
|
|
Runtimes: map[io.containerd.runc.v2:{{runc [] map[]} map[org.opencontainers.runtime-spec.features:{"ociVersionMin":"1.0.0","ociVersionMax":"1.2.1","hooks":["prestart","createRuntime","createContainer","startContainer","poststart","poststop"],"mountOptions":["async","atime","bind","defaults","dev","diratime","dirsync","exec","iversion","lazytime","loud","mand","noatime","nodev","nodiratime","noexec","noiversion","nolazytime","nomand","norelatime","nostrictatime","nosuid","nosymfollow","private","ratime","rbind","rdev","rdiratime","relatime","remount","rexec","rnoatime","rnodev","rnodiratime","rnoexec","rnorelatime","rnostrictatime","rnosuid","rnosymfollow","ro","rprivate","rrelatime","rro","rrw","rshared","rslave","rstrictatime","rsuid","rsymfollow","runbindable","rw","shared","silent","slave","strictatime","suid","symfollow","sync","tmpcopyup","unbindable"],"linux":{"namespaces":["cgroup","ipc","mount","network","pid","time","user","uts"],"capabilities":["CAP_CHOWN","CAP_DAC_OVERRIDE","CAP_DAC_READ_SEARCH","CAP_FOWNER","CAP_FSETID","CAP_KILL","CAP_SETGID","CAP_SETUID","CAP_SETPCAP","CAP_LINUX_IMMUTABLE","CAP_NET_BIND_SERVICE","CAP_NET_BROADCAST","CAP_NET_ADMIN","CAP_NET_RAW","CAP_IPC_LOCK","CAP_IPC_OWNER","CAP_SYS_MODULE","CAP_SYS_RAWIO","CAP_SYS_CHROOT","CAP_SYS_PTRACE","CAP_SYS_PACCT","CAP_SYS_ADMIN","CAP_SYS_BOOT","CAP_SYS_NICE","CAP_SYS_RESOURCE","CAP_SYS_TIME","CAP_SYS_TTY_CONFIG","CAP_MKNOD","CAP_LEASE","CAP_AUDIT_WRITE","CAP_AUDIT_CONTROL","CAP_SETFCAP","CAP_MAC_OVERRIDE","CAP_MAC_ADMIN","CAP_SYSLOG","CAP_WAKE_ALARM","CAP_BLOCK_SUSPEND","CAP_AUDIT_READ","CAP_PERFMON","CAP_BPF","CAP_CHECKPOINT_RESTORE"],"cgroup":{"v1":true,"v2":true,"systemd":true,"systemdUser":true,"rdma":true},"seccomp":{"enabled":true,"actions":["SCMP_ACT_ALLOW","SCMP_ACT_ERRNO","SCMP_ACT_KILL","SCMP_ACT_KILL_PROCESS","SCMP_ACT_KILL_THREAD","SCMP_ACT_LOG","SCMP_ACT_NOTIFY","SCMP_ACT_TRACE","SCMP_ACT_TRAP"],"operators":["SCMP_CMP_EQ","SCMP_CMP_GE","SCMP_CMP_GT","SCMP_CMP_LE","SCMP_CMP_LT","SCMP_CMP_MASKED_EQ","SCMP_CMP_NE"],"archs":["SCMP_ARCH_AARCH64","SCMP_ARCH_ARM","SCMP_ARCH_MIPS","SCMP_ARCH_MIPS64","SCMP_ARCH_MIPS64N32","SCMP_ARCH_MIPSEL","SCMP_ARCH_MIPSEL64","SCMP_ARCH_MIPSEL64N32","SCMP_ARCH_PPC","SCMP_ARCH_PPC64","SCMP_ARCH_PPC64LE","SCMP_ARCH_RISCV64","SCMP_ARCH_S390","SCMP_ARCH_S390X","SCMP_ARCH_X32","SCMP_ARCH_X86","SCMP_ARCH_X86_64"],"knownFlags":["SECCOMP_FILTER_FLAG_TSYNC","SECCOMP_FILTER_FLAG_SPEC_ALLOW","SECCOMP_FILTER_FLAG_LOG"],"supportedFlags":["SECCOMP_FILTER_FLAG_TSYNC","SECCOMP_FILTER_FLAG_SPEC_ALLOW","SECCOMP_FILTER_FLAG_LOG"]},"apparmor":{"enabled":true},"selinux":{"enabled":true},"intelRdt":{"enabled":true},"mountExtensions":{"idmap":{"enabled":true}}},"annotations":{"io.github.seccomp.libseccomp.version":"2.5.4","org.opencontainers.runc.checkpoint.enabled":"true","org.opencontainers.runc.commit":"v1.3.5-0-g488fc13e","org.opencontainers.runc.version":"1.3.5\n"},"potentiallyUnsafeConfigAnnotations":["bundle","org.systemd.property.","org.criu.config"]}]} nvidia:{{nvidia-container-runtime [] map[]} map[org.opencontainers.runtime-spec.features:{"ociVersionMin":"1.0.0","ociVersionMax":"1.2.1","hooks":["prestart","createRuntime","createContainer","startContainer","poststart","poststop"],"mountOptions":["async","atime","bind","defaults","dev","diratime","dirsync","exec","iversion","lazytime","loud","mand","noatime","nodev","nodiratime","noexec","noiversion","nolazytime","nomand","norelatime","nostrictatime","nosuid","nosymfollow","private","ratime","rbind","rdev","rdiratime","relatime","remount","rexec","rnoatime","rnodev","rnodiratime","rnoexec","rnorelatime","rnostrictatime","rnosuid","rnosymfollow","ro","rprivate","rrelatime","rro","rrw","rshared","rslave","rstrictatime","rsuid","rsymfollow","runbindable","rw","shared","silent","slave","strictatime","suid","symfollow","sync","tmpcopyup","unbindable"],"linux":{"namespaces":["cgroup","ipc","mount","network","pid","time","user","uts"],"capabilities":["CAP_CHOWN","CAP_DAC_OVERRIDE","CAP_DAC_READ_SEARCH","CAP_FOWNER","CAP_FSETID","CAP_KILL","CAP_SETGID","CAP_SETUID","CAP_SETPCAP","CAP_LINUX_IMMUTABLE","CAP_NET_BIND_SERVICE","CAP_NET_BROADCAST","CAP_NET_ADMIN","CAP_NET_RAW","CAP_IPC_LOCK","CAP_IPC_OWNER","CAP_SYS_MODULE","CAP_SYS_RAWIO","CAP_SYS_CHROOT","CAP_SYS_PTRACE","CAP_SYS_PACCT","CAP_SYS_ADMIN","CAP_SYS_BOOT","CAP_SYS_NICE","CAP_SYS_RESOURCE","CAP_SYS_TIME","CAP_SYS_TTY_CONFIG","CAP_MKNOD","CAP_LEASE","CAP_AUDIT_WRITE","CAP_AUDIT_CONTROL","CAP_SETFCAP","CAP_MAC_OVERRIDE","CAP_MAC_ADMIN","CAP_SYSLOG","CAP_WAKE_ALARM","CAP_BLOCK_SUSPEND","CAP_AUDIT_READ","CAP_PERFMON","CAP_BPF","CAP_CHECKPOINT_RESTORE"],"cgroup":{"v1":true,"v2":true,"systemd":true,"systemdUser":true,"rdma":true},"seccomp":{"enabled":true,"actions":["SCMP_ACT_ALLOW","SCMP_ACT_ERRNO","SCMP_ACT_KILL","SCMP_ACT_KILL_PROCESS","SCMP_ACT_KILL_THREAD","SCMP_ACT_LOG","SCMP_ACT_NOTIFY","SCMP_ACT_TRACE","SCMP_ACT_TRAP"],"operators":["SCMP_CMP_EQ","SCMP_CMP_GE","SCMP_CMP_GT","SCMP_CMP_LE","SCMP_CMP_LT","SCMP_CMP_MASKED_EQ","SCMP_CMP_NE"],"archs":["SCMP_ARCH_AARCH64","SCMP_ARCH_ARM","SCMP_ARCH_MIPS","SCMP_ARCH_MIPS64","SCMP_ARCH_MIPS64N32","SCMP_ARCH_MIPSEL","SCMP_ARCH_MIPSEL64","SCMP_ARCH_MIPSEL64N32","SCMP_ARCH_PPC","SCMP_ARCH_PPC64","SCMP_ARCH_PPC64LE","SCMP_ARCH_RISCV64","SCMP_ARCH_S390","SCMP_ARCH_S390X","SCMP_ARCH_X32","SCMP_ARCH_X86","SCMP_ARCH_X86_64"],"knownFlags":["SECCOMP_FILTER_FLAG_TSYNC","SECCOMP_FILTER_FLAG_SPEC_ALLOW","SECCOMP_FILTER_FLAG_LOG"],"supportedFlags":["SECCOMP_FILTER_FLAG_TSYNC","SECCOMP_FILTER_FLAG_SPEC_ALLOW","SECCOMP_FILTER_FLAG_LOG"]},"apparmor":{"enabled":true},"selinux":{"enabled":true},"intelRdt":{"enabled":true},"mountExtensions":{"idmap":{"enabled":true}}},"annotations":{"io.github.seccomp.libseccomp.version":"2.5.4","org.opencontainers.runc.checkpoint.enabled":"true","org.opencontainers.runc.commit":"v1.3.5-0-g488fc13e","org.opencontainers.runc.version":"1.3.5\n"},"potentiallyUnsafeConfigAnnotations":["bundle","org.systemd.property.","org.criu.config"]}]} runc:{{runc [] map[]} map[org.opencontainers.runtime-spec.features:{"ociVersionMin":"1.0.0","ociVersionMax":"1.2.1","hooks":["prestart","createRuntime","createContainer","startContainer","poststart","poststop"],"mountOptions":["async","atime","bind","defaults","dev","diratime","dirsync","exec","iversion","lazytime","loud","mand","noatime","nodev","nodiratime","noexec","noiversion","nolazytime","nomand","norelatime","nostrictatime","nosuid","nosymfollow","private","ratime","rbind","rdev","rdiratime","relatime","remount","rexec","rnoatime","rnodev","rnodiratime","rnoexec","rnorelatime","rnostrictatime","rnosuid","rnosymfollow","ro","rprivate","rrelatime","rro","rrw","rshared","rslave","rstrictatime","rsuid","rsymfollow","runbindable","rw","shared","silent","slave","strictatime","suid","symfollow","sync","tmpcopyup","unbindable"],"linux":{"namespaces":["cgroup","ipc","mount","network","pid","time","user","uts"],"capabilities":["CAP_CHOWN","CAP_DAC_OVERRIDE","CAP_DAC_READ_SEARCH","CAP_FOWNER","CAP_FSETID","CAP_KILL","CAP_SETGID","CAP_SETUID","CAP_SETPCAP","CAP_LINUX_IMMUTABLE","CAP_NET_BIND_SERVICE","CAP_NET_BROADCAST","CAP_NET_ADMIN","CAP_NET_RAW","CAP_IPC_LOCK","CAP_IPC_OWNER","CAP_SYS_MODULE","CAP_SYS_RAWIO","CAP_SYS_CHROOT","CAP_SYS_PTRACE","CAP_SYS_PACCT","CAP_SYS_ADMIN","CAP_SYS_BOOT","CAP_SYS_NICE","CAP_SYS_RESOURCE","CAP_SYS_TIME","CAP_SYS_TTY_CONFIG","CAP_MKNOD","CAP_LEASE","CAP_AUDIT_WRITE","CAP_AUDIT_CONTROL","CAP_SETFCAP","CAP_MAC_OVERRIDE","CAP_MAC_ADMIN","CAP_SYSLOG","CAP_WAKE_ALARM","CAP_BLOCK_SUSPEND","CAP_AUDIT_READ","CAP_PERFMON","CAP_BPF","CAP_CHECKPOINT_RESTORE"],"cgroup":{"v1":true,"v2":true,"systemd":true,"systemdUser":true,"rdma":true},"seccomp":{"enabled":true,"actions":["SCMP_ACT_ALLOW","SCMP_ACT_ERRNO","SCMP_ACT_KILL","SCMP_ACT_KILL_PROCESS","SCMP_ACT_KILL_THREAD","SCMP_ACT_LOG","SCMP_ACT_NOTIFY","SCMP_ACT_TRACE","SCMP_ACT_TRAP"],"operators":["SCMP_CMP_EQ","SCMP_CMP_GE","SCMP_CMP_GT","SCMP_CMP_LE","SCMP_CMP_LT","SCMP_CMP_MASKED_EQ","SCMP_CMP_NE"],"archs":["SCMP_ARCH_AARCH64","SCMP_ARCH_ARM","SCMP_ARCH_MIPS","SCMP_ARCH_MIPS64","SCMP_ARCH_MIPS64N32","SCMP_ARCH_MIPSEL","SCMP_ARCH_MIPSEL64","SCMP_ARCH_MIPSEL64N32","SCMP_ARCH_PPC","SCMP_ARCH_PPC64","SCMP_ARCH_PPC64LE","SCMP_ARCH_RISCV64","SCMP_ARCH_S390","SCMP_ARCH_S390X","SCMP_ARCH_X32","SCMP_ARCH_X86","SCMP_ARCH_X86_64"],"knownFlags":["SECCOMP_FILTER_FLAG_TSYNC","SECCOMP_FILTER_FLAG_SPEC_ALLOW","SECCOMP_FILTER_FLAG_LOG"],"supportedFlags":["SECCOMP_FILTER_FLAG_TSYNC","SECCOMP_FILTER_FLAG_SPEC_ALLOW","SECCOMP_FILTER_FLAG_LOG"]},"apparmor":{"enabled":true},"selinux":{"enabled":true},"intelRdt":{"enabled":true},"mountExtensions":{"idmap":{"enabled":true}}},"annotations":{"io.github.seccomp.libseccomp.version":"2.5.4","org.opencontainers.runc.checkpoint.enabled":"true","org.opencontainers.runc.commit":"v1.3.5-0-g488fc13e","org.opencontainers.runc.version":"1.3.5\n"},"potentiallyUnsafeConfigAnnotations":["bundle","org.systemd.property.","org.criu.config"]}]}]
|
|
Default runtime: runc
|
|
Storage driver: overlay2
|
|
Root dir: /var/lib/docker
|
|
Server version: 29.4.1
|
|
|
|
----- running containers -----
|
|
NAMES IMAGE STATUS PORTS
|
|
beszel-agent henrygd/beszel-agent:latest Up 5 hours (healthy)
|
|
dozzle-agent amir20/dozzle:latest Up 5 hours 0.0.0.0:7007->7007/tcp, 8080/tcp
|
|
dockge louislam/dockge:latest Up 7 hours (healthy) 0.0.0.0:5001->5001/tcp, [::]:5001->5001/tcp
|
|
|
|
----- all containers -----
|
|
NAMES IMAGE STATUS
|
|
beszel-agent henrygd/beszel-agent:latest Up 5 hours (healthy)
|
|
dozzle-agent amir20/dozzle:latest Up 5 hours
|
|
dockge louislam/dockge:latest Up 7 hours (healthy)
|
|
boring_bartik nvidia/cuda:11.5.2-base-ubuntu20.04 Exited (0) 13 months ago
|
|
|
|
----- networks -----
|
|
NAME DRIVER SCOPE
|
|
bridge bridge local
|
|
docker_default bridge local
|
|
host host local
|
|
none null local
|
|
textgen_default bridge local
|
|
traefik-net bridge local
|
|
|
|
----- networks (external, non-default — worth knowing for compose external: true) -----
|
|
docker_default
|
|
textgen_default
|
|
traefik-net
|
|
|
|
----- named volumes -----
|
|
VOLUME NAME DRIVER
|
|
beszel-agent-irv_beszel_agent_data local
|
|
dockge_dockge_data local
|
|
dozzle-agent-irv_dozzle_agent_data local
|
|
|
|
----- compose projects currently running -----
|
|
beszel-agent-irv
|
|
dockge
|
|
dozzle-agent-irv
|
|
|
|
===== COMPOSE FILES (/opt/docker/compose/) =====
|
|
|
|
|
|
>>> /opt/docker/compose/beszel-agent-irv/compose.yaml
|
|
# Beszel — lightweight server/container monitoring.
|
|
#
|
|
# Hub: single web UI with the SQLite store. Agents: per-host metric collectors
|
|
# that the hub pulls from over SSH.
|
|
#
|
|
# Multi-host layout via compose profiles:
|
|
# COMPOSE_PROFILES=hub → hub only (ana-docker)
|
|
# COMPOSE_PROFILES=hub,agent → hub + local agent on the same host
|
|
# COMPOSE_PROFILES=agent → agent only (ana-ml2, irv-ml1,
|
|
# nh3-docker, esh-docker-vm,
|
|
# vm-esh-nas)
|
|
#
|
|
# The agent uses network_mode: host so it sees real host CPU/mem/net/disk
|
|
# counters rather than container-scoped ones — that's why it can't share
|
|
# the tnet network with the hub.
|
|
#
|
|
# All tunables live in .env — edit that, not this file.
|
|
|
|
services:
|
|
beszel:
|
|
image: henrygd/beszel:${BESZEL_VERSION}
|
|
container_name: beszel
|
|
profiles: [hub]
|
|
restart: unless-stopped
|
|
ports:
|
|
- "${BESZEL_PORT}:8090"
|
|
volumes:
|
|
- beszel_data:/beszel_data
|
|
healthcheck:
|
|
test: ["CMD", "/beszel", "health", "--url", "http://localhost:8090"]
|
|
interval: 120s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 15s
|
|
networks:
|
|
- tnet
|
|
labels:
|
|
- homepage.group=Monitoring
|
|
- homepage.name=Beszel
|
|
- homepage.icon=mdi-chart-line
|
|
- homepage.description=Server + container monitoring
|
|
- homepage.href=http://10.250.50.70:${BESZEL_PORT}
|
|
|
|
beszel-agent:
|
|
image: henrygd/beszel-agent:${BESZEL_VERSION}
|
|
container_name: beszel-agent
|
|
profiles: [agent]
|
|
restart: unless-stopped
|
|
network_mode: host
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
- beszel_agent_data:/var/lib/beszel-agent
|
|
environment:
|
|
# Agent auth has two modes (v0.13+ supports both side-by-side):
|
|
# - KEY-mode: agent listens, hub connects inbound over SSH using KEY.
|
|
# Requires BESZEL_HUB_KEY in .env.
|
|
# - Token-mode: agent initiates an outbound connection to HUB_URL
|
|
# using TOKEN. Easier through NAT. Requires HUB_URL + BESZEL_TOKEN.
|
|
# Leave unused ones empty ("") in .env; both can be set simultaneously.
|
|
#
|
|
# For irv-ml1 (WireGuard-only): TOKEN mode is strongly preferred. The
|
|
# agent initiates outbound to the hub, so NAT/WG-firewall rules stay
|
|
# simple. KEY mode would require the hub to reach back into the WG
|
|
# tunnel to the agent's listening port.
|
|
- PORT=${BESZEL_AGENT_PORT:-45876}
|
|
- KEY=${BESZEL_HUB_KEY:-}
|
|
- HUB_URL=${HUB_URL:-}
|
|
- TOKEN=${BESZEL_TOKEN:-}
|
|
- EXTRA_FILESYSTEMS=${BESZEL_EXTRA_FS:-}
|
|
healthcheck:
|
|
test: ["CMD", "/agent", "health"]
|
|
interval: 120s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 15s
|
|
|
|
volumes:
|
|
beszel_data:
|
|
beszel_agent_data:
|
|
|
|
networks:
|
|
tnet:
|
|
name: traefik-net
|
|
external: true
|
|
|
|
>>> /opt/docker/compose/dockge/compose.yaml
|
|
# Dockge — per-host Docker Compose UI (https://dockge.kuma.pet/).
|
|
#
|
|
# One instance runs on every Docker host so the compose dir is manageable
|
|
# from a browser. Each host sets DOCKGE_HOST_LABEL + DOCKGE_HOST_IP in its
|
|
# .env so the homepage card points at the right place.
|
|
#
|
|
# All tunables live in .env — edit that, not this file.
|
|
|
|
services:
|
|
dockge:
|
|
image: louislam/dockge:${DOCKGE_VERSION:-latest}
|
|
container_name: dockge
|
|
restart: unless-stopped
|
|
ports:
|
|
- "${DOCKGE_PORT:-5001}:5001"
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock
|
|
- dockge_data:/app/data
|
|
- /opt/docker:/opt/docker
|
|
environment:
|
|
- DOCKGE_STACKS_DIR=/opt/docker/compose
|
|
networks:
|
|
- tnet
|
|
labels:
|
|
- homepage.group=Service Networking
|
|
- homepage.name=Dockge (${DOCKGE_HOST_LABEL})
|
|
- homepage.icon=sh-dockge.png
|
|
- homepage.description=Compose UI on ${DOCKGE_HOST_LABEL}
|
|
- homepage.href=http://${DOCKGE_HOST_IP}:${DOCKGE_PORT:-5001}
|
|
|
|
volumes:
|
|
dockge_data:
|
|
|
|
networks:
|
|
tnet:
|
|
name: traefik-net
|
|
external: true
|
|
|
|
>>> /opt/docker/compose/dozzle-agent-irv/compose.yaml
|
|
# Dozzle — container log viewer.
|
|
#
|
|
# Multi-host layout via compose profiles:
|
|
# COMPOSE_PROFILES=hub → runs the web UI (deploy on ana-docker)
|
|
# COMPOSE_PROFILES=agent → runs the remote agent (deploy on ana-ml2,
|
|
# irv-ml1, nh3-docker, esh-docker-vm, vm-esh-nas)
|
|
#
|
|
# Same compose.yaml on all servers; per-host `.env` picks the profile.
|
|
#
|
|
# irv-ml1 specific: listens on the WG tunnel IP only (10.100.79.3) by
|
|
# default — the hub on ana-docker reaches it through the tunnel. Set
|
|
# DOZZLE_AGENT_BIND=0.0.0.0 in .env if you ever need to accept from
|
|
# other interfaces.
|
|
#
|
|
# All tunables live in .env — edit that, not this file.
|
|
|
|
services:
|
|
dozzle:
|
|
image: amir20/dozzle:${DOZZLE_VERSION}
|
|
container_name: dozzle
|
|
profiles: [hub]
|
|
restart: unless-stopped
|
|
ports:
|
|
- "${DOZZLE_PORT}:8080"
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
- dozzle_data:/data
|
|
environment:
|
|
- DOZZLE_HOSTNAME=${DOZZLE_HOSTNAME}
|
|
- DOZZLE_REMOTE_AGENT=${DOZZLE_REMOTE_AGENT:-}
|
|
- DOZZLE_AUTH_PROVIDER=${DOZZLE_AUTH_PROVIDER:-none}
|
|
- DOZZLE_USERNAME=${DOZZLE_USERNAME:-}
|
|
- DOZZLE_PASSWORD=${DOZZLE_PASSWORD:-}
|
|
healthcheck:
|
|
test: ["CMD", "/dozzle", "healthcheck"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 15s
|
|
networks:
|
|
- tnet
|
|
labels:
|
|
- homepage.group=Monitoring
|
|
- homepage.name=Dozzle
|
|
- homepage.icon=mdi-text-box-search
|
|
- homepage.description=Container logs (ana-docker + ana-ml2)
|
|
- homepage.href=http://10.250.50.70:${DOZZLE_PORT}
|
|
|
|
dozzle-agent:
|
|
image: amir20/dozzle:${DOZZLE_VERSION}
|
|
container_name: dozzle-agent
|
|
profiles: [agent]
|
|
restart: unless-stopped
|
|
command: agent
|
|
ports:
|
|
- "${DOZZLE_AGENT_BIND:-0.0.0.0}:${DOZZLE_AGENT_PORT}:7007"
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
- dozzle_agent_data:/data
|
|
environment:
|
|
- DOZZLE_HOSTNAME=${DOZZLE_HOSTNAME}
|
|
networks:
|
|
- tnet
|
|
|
|
volumes:
|
|
dozzle_data:
|
|
dozzle_agent_data:
|
|
|
|
networks:
|
|
tnet:
|
|
name: traefik-net
|
|
external: true
|
|
|
|
===== CONFIG LAYOUT (/opt/docker/conf/ — top 200 entries) =====
|
|
|
|
/opt/docker/conf
|
|
|
|
===== LISTENING PORTS =====
|
|
|
|
0.0.0.0:22
|
|
0.0.0.0:5001
|
|
0.0.0.0:7007
|
|
*:11434
|
|
[::]:22
|
|
*:2375
|
|
[::]:5001
|
|
|
|
===== MODEL / HUGGINGFACE CACHES =====
|
|
|
|
/home/lkraven/.cache/huggingface (1.8M)
|
|
hub entries:
|
|
models--bert-base-uncased
|
|
models--openai--clip-vit-large-patch14
|
|
version.txt
|
|
|
|
|
|
===== DOCKER-ADJACENT SYSTEMD SERVICES =====
|
|
|
|
containerd.service running
|
|
docker.service running
|
|
|
|
===== DONE =====
|
|
|
|
Paste the above back into the chat, or pass a path as argv[1] to save.
|