Files
esh-pfi-infrastructure/stacks/homepage/conf/services.yaml
T
vh 6770ba26d6 feat(booth): kept boards — a .forever sentinel and a standing link board
Agent sessions hand the operator URLs and they drown in terminal
scrollback. The Booth is the right home for them — it already has the one
property that decides adoption, which is that a session can publish with
mkdir and cp, no API key, no schema, no deploy — but everything in it dies
in 24h.

So: a booth containing `.forever` is never swept, and renders in its own
Kept lane at the top of the index. Opt-in per booth, so the ephemeral
default is untouched and nobody inherits a cleanup chore. `rm` the
sentinel and the board rejoins the sweep; the CLI verbs are sugar over
exactly that, which keeps the filesystem-is-the-state model honest.

The pin is deliberately NOT wired into is_expired(). That stays a pure age
question feeding the `expires_in` countdown; only sweep_once() honours the
sentinel. Keeping expiry arithmetic and reaper policy apart means they
cannot drift into each other.

Kept cards are visually separated per Australis: a 2px top edge in aurora
blue, the one accent border the system sanctions. They show "kept" instead
of a countdown, and they deliberately lose the one-click wipe button — a ×
next to the durable stuff is a footgun, so removing a kept board is a
two-step act.

`booth link <url> [description]` appends to the standing `links` board,
creating and keeping it on first use. Entries carry provenance (handle or
hostname, plus a timestamp) because a bare URL is unreadable three days
later. The append is one printf of one line to an O_APPEND fd — atomic
under PIPE_BUF on POSIX — which matters because many agents post to one
board and interleaved half-lines would be the obvious failure mode.

Seven tests cover the sentinel: detection, survival of a sweep that wipes
its neighbour, the deliberate is_expired/sweep_once split, the listing
flag, the sentinel not inflating item counts, and both lane-rendering
directions. Two of them originally asserted on the bare strings "Kept" and
"kept-grid", which passed for the wrong reason — those also appear in the
inlined stylesheet served on every page — so they now assert the full
class attribute. 55 pass.

Also corrects the Homepage card's description, which advertised a flat 24h
TTL that is no longer the whole story.
2026-08-19 09:34:53 -07:00

229 lines
8.5 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
# https://gethomepage.dev/latest/configs/services
#
# Groups are ordered by settings.yaml `layout`. This file holds the manual
# entries — infrastructure, BMCs, off-Docker endpoints, and a handful of
# well-known internal service URLs. Docker-labeled stacks auto-populate
# their own groups through the providers in docker.yaml, so most app
# entries don't need to appear here.
# The Monitoring group is fully Docker-auto-discovered — Beszel, Dozzle,
# Backrest and Uptime Kuma all carry homepage.group=Monitoring on their
# compose files. There is deliberately no manual block here.
#
# Uptime Kuma used to be listed manually here AND labelled
# homepage.group=Apps on its container, so it rendered twice — once in
# Monitoring without its widget, once in Apps with it. Fixed 2026-08-18 by
# deleting the manual entry and moving the container's label to Monitoring
# (stacks/uptimekuma/). This is the exact failure the warning below
# describes; it survived the 2026-08-17 audit because a duplicate reads as
# two plausible cards rather than as an error.
- Apps:
# Manual entry — the Booth is a user-level systemd service on nh3-dev
# (not a Docker-labeled stack), so it can't auto-discover; list it here.
- The Booth:
href: http://10.100.10.50:8090/
icon: mdi-filmstrip
siteMonitor: http://10.100.10.50:8090/healthz
description: Media drop + upload-for-pickup + the standing agent link board — nh3-dev, 24h TTL except kept boards
- Voice Design Studio:
href: http://10.100.79.3:8216/
icon: mdi-microphone
siteMonitor: http://10.100.79.3:8216/health
description: Mint, audition and keeper-mark synthetic fleet voices — irv-ml1, CPU-only
- The Henge:
href: http://park.phasefinal.com:8420/
icon: mdi-clipboard-check
siteMonitor: http://park.phasefinal.com:8420/healthz
description: Durable needs-attention / idea parking (stonehenge-park) — ana-docker
# The AI tab is fully Docker-auto-discovered. Each inference service carries
# a homepage.group=AI - <role> label on its compose file (AI - Inference,
# AI - Eval & Retrieval, AI - Gateways & Chat, AI - Speech (TTS),
# AI - Audio Tools, AI - Image & Media). Tab assignment, group order, and
# column counts live in settings.yaml. Do not add entries here or they'll
# double up. To move a service between AI groups, change the label on its
# compose file and recreate the container (labels only apply on recreate).
- Media:
- Plex:
href: http://10.0.50.56:32400
icon: si-plex
siteMonitor: http://10.0.50.56:32400
description: Media Server (esh-nas-pve 10.0.50.56)
widget:
type: plex
url: http://10.0.50.56:32400
key: '{{HOMEPAGE_VAR_PLEX_KEY}}'
- Jellyfin:
href: http://10.0.50.57:8096
icon: si-jellyfin
siteMonitor: http://10.0.50.57:8096
description: Media Server (esh-nas-pve 10.0.50.57)
widget:
type: jellyfin
url: http://10.0.50.57:8096
key: '{{HOMEPAGE_VAR_JELLYFIN_KEY}}'
enableBlocks: true
- Games:
- Pterodactyl:
href: http://10.250.50.55/
icon: mdi-gamepad-square
siteMonitor: http://10.250.50.55
description: Game server panel
- Infra - ANA:
- ANA-Firewall:
href: https://10.250.250.1
icon: mdi-wall-fire
siteMonitor: https://10.250.250.1
description: ana-gw FortiGate-80F, FortiOS 7.2.10 (ana-fw.phasefinal.com)
- PFI-r750xs-iDRAC:
href: https://10.250.250.30/
siteMonitor: https://10.250.250.30/
icon: si-dell
description: iDRAC (Dell R750xs) — OOB for pfi-pve @ 10.250.250.31
- PFI-PVE:
href: https://10.250.250.31:8006/
siteMonitor: https://10.250.250.31:8006/
icon: si-proxmox
description: Proxmox hypervisor (pfi-pve)
- ANA-NAS:
href: https://10.250.50.50:9090/
siteMonitor: https://10.250.50.50:9090/
icon: mdi-nas
description: Debian NAS (Cockpit)
- ANA-FileBot:
ping: 10.250.50.53
icon: mdi-sync-circle
description: File-task VM
- PFI-VM-Docker:
href: http://10.250.50.70:5001
icon: si-docker
siteMonitor: http://10.250.50.70:5001
description: Docker VM (ana-docker, Dockge at :5001)
- PFI-ANA-ML2:
ping: 10.250.50.54
icon: mdi-brain
description: GPU host (bare-metal)
- PFI-ANA-ML2 BMC:
href: https://10.250.250.50
icon: mdi-brain
siteMonitor: https://10.250.250.50
description: BMC (ana-ml2)
- SFsrv-ANA:
href: https://10.250.250.115:8006
icon: si-proxmox
siteMonitor: https://10.250.250.115:8006
description: Proxmox (SureFire tenant hypervisor at PFI colo)
- SF-R630-iDRAC:
href: https://10.250.250.110/
icon: si-dell
ping: 10.250.250.110
description: Dell R630 iDRAC (SureFire tenant hardware)
- PBS-ANA:
href: https://10.250.50.90:8007/
icon: mdi-backup-restore
siteMonitor: https://10.250.50.90:8007/
description: Proxmox Backup Server — primary (fleet vzdump target)
- Infra - NH3:
# NH3-Firewall (Fortigate 101F at 10.100.250.1) retired 2026-04-21,
# replaced by PFI-UDMSE (UniFi UDM Pro SE at 10.100.0.1, below).
# NH3-SW1 (Mikrotik CRS328-24P-4S+ at 10.100.250.2) retired from
# homepage 2026-04-22.
- PFI-UDMSE:
href: https://10.100.0.1
icon: si-ubiquiti
siteMonitor: https://10.100.0.1
description: UniFi Dream Machine Pro SE — gateway + controller (NH3 edge)
- NH3-NAS:
href: https://10.100.50.50:5001
icon: mdi-nas
siteMonitor: https://10.100.50.50:5001
description: Synology RS2418+ DSM (restic target + VM storage)
- NH3-PVE:
href: https://10.100.250.60:8006/
siteMonitor: https://10.100.250.60:8006/
icon: si-proxmox
description: Proxmox hypervisor (nh3-pve)
- NH3-VM-Docker:
href: http://10.100.50.40:5001
icon: si-docker
siteMonitor: http://10.100.50.40:5001
description: Docker VM (nh3-docker, Dockge at :5001)
- NH3-ExtDev:
ping: 10.100.50.42
icon: mdi-laptop
description: Manager / external-dev box (nh3-extdev, Debian 13) — successor to the retired nh3-ansible
- PBS-NH3:
href: https://10.100.50.90:8007/
icon: mdi-backup-restore
siteMonitor: https://10.100.50.90:8007/
description: Proxmox Backup Server — DR mirror (pulls from PBS-ANA)
- Infra - IRV:
# Irvine site — reachable only via WireGuard tunnel from NH3.
# The 10.100.79.0/24 subnet is the WG tunnel IP space; these cards
# only light up when the WG link is healthy.
- IRV-ML1:
ping: 10.100.79.3
icon: mdi-brain
description: GPU host (bare-metal, RTX 3090 + RTX A6000, native AI stacks)
- IRV-ML1-Dockge:
href: http://10.100.79.3:5001
icon: si-docker
siteMonitor: http://10.100.79.3:5001
description: Docker management (irv-ml1)
- Infra - ESH:
- ESH-UDMPM:
href: https://10.0.0.1
icon: si-ubiquiti
siteMonitor: https://10.0.0.1
description: UniFi Dream Machine Pro Max — gateway + controller (ESH)
- ESH-Firewall:
href: https://10.0.250.1
icon: mdi-wall-fire
siteMonitor: https://10.0.250.1
description: esh-gw
- Brother Printer:
href: http://10.0.90.125/
icon: mdi-printer
siteMonitor: http://10.0.90.125/
description: Brother (ESH)
- ESH-NAS:
href: https://10.0.50.50:9090
icon: mdi-nas
siteMonitor: https://10.0.50.50:9090
description: NAS share manager (Cockpit)
- ESH-PVE:
href: https://10.0.250.35:8006
siteMonitor: https://10.0.250.35:8006
icon: si-proxmox
description: Proxmox hypervisor (esh-pve)
- ESH-PVE-NAS:
href: https://10.0.50.55:8006
siteMonitor: https://10.0.50.55:8006
icon: si-proxmox
description: Proxmox hypervisor (esh-pve-nas, storage/media)
- ESH-FileBot:
ping: 10.0.50.70
icon: mdi-sync-circle
description: Restic / file-sync VM (esh-nas-pve) — role TBC
- ESH-VM-Docker:
href: http://10.0.50.45:5001
icon: si-docker
siteMonitor: http://10.0.50.45:5001
description: Docker VM (esh-docker-vm, Dockge at :5001)
# Service Networking group is now fully Docker-auto-discovered (Traefik ×2,
# AdGuard ×2, Dockge ×5, rest-server-ana, mailrise, etc. all carry
# homepage.group=Service Networking on their compose files). Position and
# layout live in settings.yaml. Do not add entries here or they'll double up.
#
# Mosquitto (ESH) note: still labeled Apps on its compose; once moved to
# Service Networking via a label change on esh-docker-vm, it auto-populates.