Files
esh-pfi-infrastructure/servers/ana-docker/system-details.txt
T
vh b443b5c220 Refresh ana-docker + esh-docker-vm snapshots after moving inline secrets to .env
Upstream compose files on both hosts now reference ${DB_ROOT_PW} (seafile)
  and ${ADGUARD_WIDGET_PASSWORD} (esh adguard) from their respective .env,
  so next refreshes no longer capture the literal passwords.
2026-04-20 14:30:07 -07:00

1379 lines
49 KiB
Plaintext

===== HOST =====
Hostname: ana-docker.phasefinal.com
Date: 2026-04-20T14:27:52-07:00
Uptime: up 2 weeks, 6 days, 15 hours, 36 minutes
OS: Debian GNU/Linux 12 (bookworm)
Kernel: 6.1.0-44-amd64
Arch: x86_64
===== HARDWARE =====
CPU cores: 8
CPU model: QEMU Virtual CPU version 2.5+
MemTotal: 15.6 GB
MemAvailable: 11.1 GB
===== GPUS =====
nvidia-smi not present (no NVIDIA GPUs or driver not installed)
===== FILESYSTEMS (df) =====
Filesystem Size Used Avail Use% Mounted on
/dev/sda1 245G 79G 153G 34% /
10.250.50.50:/mnt/docker 20T 0 20T 0% /mnt/compose
10.250.50.50:/mnt/backup 20T 1.1G 20T 1% /mnt/backup
10.250.50.50:/mnt/pve-VMStorage 22T 2.4T 20T 11% /mnt/tnvms
===== PERSISTENT MOUNTS (/etc/fstab, non-comment) =====
UUID=1f0fecb0-efcf-4403-a180-f67cb4615f48 / ext4 errors=remount-ro 0 1
UUID=ab0fa49a-61d4-4b2a-af7e-bc32f84bbd3b none swap sw 0 0
/dev/sr0 /media/cdrom0 udf,iso9660 user,noauto 0 0
10.250.50.50:/mnt/docker /mnt/tndocker nfs noauto,x-systemd.automount 0 0
10.250.50.50:/mnt/pve-VMStorage /mnt/tnvms nfs noauto,x-systemd.automount 0 0
10.250.50.50:/mnt/docker /mnt/compose nfs defaults 0 0
10.250.50.50:/mnt/backup /mnt/backup nfs defaults 0 0
===== TARGETED DATA PATHS =====
/opt (total: 6.1G)
total 16
drwxr-xr-x 4 root root 4096 2026-04-02 22:12 .
drwxr-xr-x 20 root root 4096 2026-03-30 22:49 ..
drwxr-xr-x 10 lkraven root 4096 2026-04-03 08:44 AIPA
drwxrwxrwx 6 root root 4096 2026-04-15 23:28 docker
/opt/docker (total: 6.0G)
total 32
drwxrwxrwx 6 root root 4096 2026-04-15 23:28 .
drwxr-xr-x 4 root root 4096 2026-04-02 22:12 ..
drwxr-xr-x 21 lkraven lkraven 4096 2026-04-19 22:47 compose
drwxr-xr-x 10 lkraven lkraven 4096 2026-04-18 18:57 conf
drwxr-xr-x 7 lkraven lkraven 4096 2025-02-05 19:28 data
drwxr-xr-x 8 lkraven lkraven 4096 2026-04-15 23:47 .git
-rw-r--r-- 1 lkraven lkraven 14 2024-05-30 18:44 .gitignore
-rw-r--r-- 1 lkraven lkraven 60 2024-05-30 15:33 README.md
/opt/docker/compose (total: 244K)
total 88
drwxr-xr-x 21 lkraven lkraven 4096 2026-04-19 22:47 .
drwxrwxrwx 6 root root 4096 2026-04-15 23:28 ..
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-19 22:11 backrest
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-19 00:50 beszel
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-15 23:02 crowdsec
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 18:50 dockge
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-19 00:25 dozzle-hub
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 18:50 gitea
drwxr-xr-x 2 lkraven lkraven 4096 2025-03-18 22:07 ittools
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 18:50 mailrise
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 18:50 mattermost
drwxr-xr-x 2 lkraven lkraven 4096 2025-02-05 21:53 openwebui
-rw-r--r-- 1 lkraven lkraven 25 2024-05-30 15:33 README.md
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 18:50 restic
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-19 22:47 rest-server-ana
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 18:50 rustdesk
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-20 14:26 seafile
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-18 18:55 searxng
drwxr-xr-x 2 lkraven lkraven 4096 2025-02-05 19:29 sillytavern
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-11 13:59 synapse
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 18:50 traefik
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 18:50 vaultwarden
/opt/docker/conf (total: 3.4M)
total 40
drwxr-xr-x 10 lkraven lkraven 4096 2026-04-18 18:57 .
drwxrwxrwx 6 root root 4096 2026-04-15 23:28 ..
drwxr-xr-x 11 lkraven root 4096 2026-04-16 17:56 crowdsec
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 16:16 mailrise
drwxr-xr-x 2 lkraven lkraven 4096 2024-05-30 16:19 mattermost
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-18 19:22 searxng
drwxr-xr-x 2 lkraven lkraven 4096 2025-03-18 22:50 sillytavern
drwxr-xr-x 2 linus linus 4096 2026-04-15 21:48 synapse
drwxr-xr-x 3 lkraven lkraven 4096 2024-05-30 16:11 traefik-ana
drwxr-xr-x 2 lkraven lkraven 4096 2026-04-16 16:28 vaultwarden
/var/lib/docker (total: 4.0K)
/data (total: 60K)
total 12
drwxr-xr-x 3 root root 4096 2023-06-12 22:33 .
drwxr-xr-x 20 root root 4096 2026-03-30 22:49 ..
drwxr-xr-x 4 root root 4096 2023-11-02 17:05 compose
/srv (total: 4.0K)
total 8
drwxr-xr-x 2 root root 4096 2023-04-03 00:06 .
drwxr-xr-x 20 root root 4096 2026-03-30 22:49 ..
===== DOCKER =====
Server: 20.10.24+dfsg1 Client: 20.10.24+dfsg1
----- docker info -----
Containers: 26 (running 24, paused 0, stopped 2)
Images: 63
Runtimes: map[io.containerd.runc.v2:{runc [] <nil>} io.containerd.runtime.v1.linux:{runc [] <nil>} runc:{runc [] <nil>}]
Default runtime: runc
Storage driver: overlay2
Root dir: /var/lib/docker
Server version: 20.10.24+dfsg1
----- running containers -----
NAMES IMAGE STATUS PORTS
seafile seafileltd/seafile-mc:11.0-latest Up About a minute 0.0.0.0:9180->80/tcp, :::9180->80/tcp
seafile-mysql mariadb:10.6 Up About a minute 3306/tcp
seafile-memcached memcached:1.6.18 Up About a minute 11211/tcp
rest-server restic/rest-server:latest Up 3 hours (healthy) 0.0.0.0:8000->8000/tcp, :::8000->8000/tcp
backrest garethgeorge/backrest:latest Up 16 hours (healthy) 0.0.0.0:9898->9898/tcp, :::9898->9898/tcp
dockge-dockge-1 louislam/dockge:latest Up 19 hours (healthy) 0.0.0.0:5001->5001/tcp, :::5001->5001/tcp
searxng searxng/searxng:latest Up 26 hours (healthy) 0.0.0.0:9996->8080/tcp, :::9996->8080/tcp
beszel henrygd/beszel:latest Up 27 hours (healthy) 0.0.0.0:8090->8090/tcp, :::8090->8090/tcp
beszel-agent henrygd/beszel-agent:latest Up 27 hours
dozzle amir20/dozzle:latest Up 38 hours (healthy) 0.0.0.0:8088->8080/tcp, :::8088->8080/tcp
blocklist-mirror crowdsecurity/blocklist-mirror:latest Up 3 days 0.0.0.0:41412->41412/tcp, :::41412->41412/tcp
vaultwarden vaultwarden/server:latest Up 3 days (healthy) 0.0.0.0:9080->80/tcp, :::9080->80/tcp
crowdsec crowdsecurity/crowdsec:latest Up 3 days
traefik traefik:latest Up 3 days 0.0.0.0:80->80/tcp, :::80->80/tcp, 0.0.0.0:443->443/tcp, :::443->443/tcp, 0.0.0.0:8380->8080/tcp, :::8380->8080/tcp
gitea gitea/gitea:latest Up 3 days 0.0.0.0:3000->3000/tcp, :::3000->3000/tcp, 0.0.0.0:222->22/tcp, :::222->22/tcp
element-web vectorim/element-web:v1.11.80 Up 4 days 80/tcp
synapse matrixdotorg/synapse:v1.120.0 Up 4 days (healthy) 8008-8009/tcp, 8448/tcp
synapse-db postgres:16-alpine Up 4 days (healthy) 5432/tcp
sillytavern ghcr.io/sillytavern/sillytavern:latest Up 2 weeks 0.0.0.0:8100->8000/tcp, :::8100->8000/tcp
openwebui-open-webui-1 ghcr.io/open-webui/open-webui:main Up 2 weeks (healthy) 0.0.0.0:3100->8080/tcp, :::3100->8080/tcp
hbbs rustdesk/rustdesk-server:latest Up 2 weeks
hbbr rustdesk/rustdesk-server:latest Up 2 weeks
it-tools corentinth/it-tools:latest Up 2 weeks 0.0.0.0:8780->80/tcp, :::8780->80/tcp
mailrise yoryan/mailrise:latest Up 2 weeks 0.0.0.0:8025->8025/tcp, :::8025->8025/tcp
----- all containers -----
NAMES IMAGE STATUS
seafile seafileltd/seafile-mc:11.0-latest Up About a minute
seafile-mysql mariadb:10.6 Up About a minute
seafile-memcached memcached:1.6.18 Up About a minute
rest-server restic/rest-server:latest Up 3 hours (healthy)
backrest garethgeorge/backrest:latest Up 16 hours (healthy)
dockge-dockge-1 louislam/dockge:latest Up 19 hours (healthy)
searxng searxng/searxng:latest Up 26 hours (healthy)
beszel henrygd/beszel:latest Up 27 hours (healthy)
beszel-agent henrygd/beszel-agent:latest Up 27 hours
dozzle amir20/dozzle:latest Up 38 hours (healthy)
blocklist-mirror crowdsecurity/blocklist-mirror:latest Up 3 days
vaultwarden vaultwarden/server:latest Up 3 days (healthy)
crowdsec crowdsecurity/crowdsec:latest Up 3 days
traefik traefik:latest Up 3 days
gitea gitea/gitea:latest Up 3 days
simple-service-bar traefik/whoami Created
simple-service-foo traefik/whoami Created
element-web vectorim/element-web:v1.11.80 Up 4 days
synapse matrixdotorg/synapse:v1.120.0 Up 4 days (healthy)
synapse-db postgres:16-alpine Up 4 days (healthy)
sillytavern ghcr.io/sillytavern/sillytavern:latest Up 2 weeks
openwebui-open-webui-1 ghcr.io/open-webui/open-webui:main Up 2 weeks (healthy)
hbbs rustdesk/rustdesk-server:latest Up 2 weeks
hbbr rustdesk/rustdesk-server:latest Up 2 weeks
it-tools corentinth/it-tools:latest Up 2 weeks
mailrise yoryan/mailrise:latest Up 2 weeks
----- networks -----
NAME DRIVER SCOPE
bridge bridge local
host host local
it-tools_default bridge local
ittools_default bridge local
mailrise_default bridge local
none null local
portainer_default bridge local
synapse_synapse-internal bridge local
traefik-net bridge local
----- networks (external, non-default — worth knowing for compose external: true) -----
it-tools_default
ittools_default
mailrise_default
portainer_default
synapse_synapse-internal
traefik-net
----- named volumes -----
VOLUME NAME DRIVER
0d2873a4373bfab9214f37bc8ad46d0ed5a90805fffa8dbef7b915493da66a7b local
1a587fdaf8f4f022cef113ce59f0ce171fcf2247c52f28df1f4e461985ff6a4f local
5b532eb6c5bb5a718a68824a004c9eee9ffb6d726a19bdf066ecb6348a6c697c local
6b7b248964ce54c151cf57a1f44cfc095d9c2bd1a9844eba2e05ad4e143e05ad local
9d1360a12bd6ca0b11d52b02a00248fd80712667510453b4ca882656798c69c8 local
28ae9933a241df783c23ff0de09882078851bef60d3440dad9243b5ba8766985 local
53bf6d927badb5904b71d4180d1f05ccac2a195b7362206a8b0ffece5771aa9a local
065fbcc9d093988c8a8c005688f119d87855407957745d82dee4ff0c4c615ea6 local
76ab976f6fb5f8f5cd322d32975206ae490f6f4644bfa315632e6ef6c3da54eb local
88b9750e458794db88b0694b5b9dd5bbe595651355f3e552bd84cbbe856fbc95 local
207f0f98a462e2b0a2da5176be52704c3aba26039f47c4ccc685619e81bf7a7a local
backrest_backrest_cache local
backrest_backrest_config local
backrest_backrest_data local
backrest_backrest_tmp local
beszel_beszel_agent_data local
beszel_beszel_data local
crowdsec_crowdsec-data local
crowdsec_traefik-logs local
dockge_dockge_data local
dozzle-hub_dozzle_data local
edf9fc3909e2faa49c147b4029db703466116f06d9fe2dc87d902bc27c6b77a0 local
gitea_gitea_data local
komodo_repo-cache local
mattermost_mattermost_data local
openwebui_open-webui local
rustdesk_rustdesk_data local
seafile_seafile_datastore local
seafile_seafile_db local
sillytavern_sillytavern_data local
sillytavern_sillytavern_extensions local
sillytavern_sillytavern_plugins local
synapse-data local
synapse_synapse-data local
synapse_synapse-db-data local
traefik_traefik-logs local
vaultwarden_vaultwarden_data local
----- compose projects currently running -----
backrest
beszel
crowdsec
dockge
dozzle-hub
gitea
ittools
mailrise
openwebui
rest-server-ana
rustdesk
seafile
searxng
sillytavern
synapse
traefik
vaultwarden
===== COMPOSE FILES (/opt/docker/compose/) =====
>>> /opt/docker/compose/backrest/compose.yaml
# Backrest — web UI over restic repositories.
#
# Role here: single central viewer for every host's restic repo on both
# site-local S3 endpoints (TrueNAS at ana, Synology at nh3). Per-host
# `restic` runs will still be driven by systemd timers on each host; this
# stack is how we see what ran, browse snapshots, and restore.
#
# Repos and S3 credentials are configured in the Backrest UI after first
# boot — nothing baked into this file. Data (its own SQLite + queue) lives
# in a named volume so the config survives container recreation.
#
# All tunables live in .env — edit that, not this file.
services:
backrest:
image: garethgeorge/backrest:${BACKREST_VERSION}
container_name: backrest
hostname: backrest
restart: unless-stopped
ports:
- ${BACKREST_PORT}:9898
volumes:
- backrest_data:/data
- backrest_config:/config
- backrest_cache:/cache
- backrest_tmp:/tmp
environment:
- BACKREST_DATA=/data
- BACKREST_CONFIG=/config/config.json
- XDG_CACHE_HOME=/cache
- TMPDIR=/tmp
- TZ=${TZ:-America/Los_Angeles}
- BACKREST_PORT=0.0.0.0:9898
healthcheck:
test:
- CMD
- wget
- -qO-
- http://localhost:9898/
interval: 30s
timeout: 10s
retries: 3
start_period: 15s
networks:
- tnet
labels:
- homepage.group=PFI-ANA
- homepage.name=Backrest
- homepage.icon=mdi-backup-restore
- homepage.description=Restic snapshot viewer / restore UI
- homepage.href=http://10.250.50.70:${BACKREST_PORT}
volumes:
backrest_data: null
backrest_config: null
backrest_cache: null
backrest_tmp: null
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/beszel/compose.yaml
# Beszel — lightweight server/container monitoring.
#
# Hub: single web UI with the SQLite store. Agents: per-host metric collectors
# that the hub pulls from over SSH.
#
# Multi-host layout via compose profiles:
# COMPOSE_PROFILES=hub → hub only (ana-docker)
# COMPOSE_PROFILES=hub,agent → hub + local agent on the same host
# COMPOSE_PROFILES=agent → agent only (ana-ml2)
#
# The agent uses network_mode: host so it sees real host CPU/mem/net/disk
# counters rather than container-scoped ones — that's why it can't share
# the tnet network with the hub.
#
# All tunables live in .env — edit that, not this file.
services:
beszel:
image: henrygd/beszel:${BESZEL_VERSION}
container_name: beszel
profiles:
- hub
restart: unless-stopped
ports:
- ${BESZEL_PORT}:8090
volumes:
- beszel_data:/beszel_data
networks:
- tnet
labels:
- homepage.group=PFI-ANA
- homepage.name=Beszel
- homepage.icon=mdi-chart-line
- homepage.description=Server + container monitoring
- homepage.href=http://10.250.50.70:${BESZEL_PORT}
healthcheck:
# The URL is relative to the container, not the host
test: ['CMD', '/beszel', 'health', '--url', 'http://localhost:8090']
start_period: 5s # Check 5 seconds after the container starts
interval: 120s # Then check every 120 seconds after that
beszel-agent:
image: henrygd/beszel-agent:${BESZEL_VERSION}
container_name: beszel-agent
profiles:
- agent
restart: unless-stopped
network_mode: host
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- beszel_agent_data:/var/lib/beszel-agent
environment:
- PORT=${BESZEL_AGENT_PORT:-45876}
- KEY=${BESZEL_HUB_KEY}
- HUB_URL=${HUB_URL}
- TOKEN=${BESZEL_TOKEN}
- EXTRA_FILESYSTEMS=${BESZEL_EXTRA_FS:-}
volumes:
beszel_data: null
beszel_agent_data: null
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/crowdsec/compose.yaml
# /opt/docker/compose/crowdsec/compose.yaml
#
# CrowdSec — collaborative intrusion prevention
#
# Agent: reads Docker container logs, parses events, makes decisions
# Bouncing: handled by CrowdSec Traefik plugin inside the Traefik container
# (no separate bouncer container needed)
#
# Protected services (via Traefik middleware):
services:
crowdsec:
image: crowdsecurity/crowdsec:latest
container_name: crowdsec
restart: unless-stopped
security_opt:
- no-new-privileges:true
volumes:
- crowdsec-data:/var/lib/crowdsec/data
- /var/run/docker.sock:/var/run/docker.sock:ro
- /opt/docker/conf/crowdsec:/etc/crowdsec
environment:
- COLLECTIONS=crowdsecurity/linux crowdsecurity/traefik LePresidente/gitea
- TZ=${TZ:-America/Los_Angeles}
- CROWDSEC_LAPI_BIND=0.0.0.0:8080
- DOCKER_API_VERSION=1.41
networks:
- traefik-net
blocklist-mirror:
image: crowdsecurity/blocklist-mirror:latest
container_name: blocklist-mirror
restart: unless-stopped
ports:
- 41412:41412
volumes:
- /opt/docker/conf/crowdsec/blocklist-mirror.yaml:/etc/crowdsec/bouncers/crowdsec-blocklist-mirror.yaml:ro
networks:
- traefik-net
volumes:
crowdsec-data: null
networks:
traefik-net:
external: true
>>> /opt/docker/compose/dockge/compose.yaml
services:
dockge:
image: louislam/dockge:latest
restart: unless-stopped
ports:
# Host Port : Container Port
- 5001:5001
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- dockge_data:/app/data
- /opt/docker/compose:/opt/docker/compose
labels:
- homepage.group=PFI-ANA
- homepage.name=Dockge
- homepage.icon=si-portainer
- homepage.description=Docker
- homepage.href=http://10.250.50.70:5001
environment:
# Tell Dockge where is your stacks directory
- DOCKGE_STACKS_DIR=/opt/docker/compose
networks:
- tnet
volumes:
dockge_data: null
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/dozzle-hub/compose.yaml
# Dozzle — container log viewer.
#
# Multi-host layout via compose profiles:
# COMPOSE_PROFILES=hub → runs the web UI (deploy on ana-docker)
# COMPOSE_PROFILES=agent → runs the remote agent (deploy on ana-ml2)
#
# Same compose.yaml on both servers; per-host `.env` picks the profile.
#
# All tunables live in .env — edit that, not this file.
services:
dozzle:
image: amir20/dozzle:${DOZZLE_VERSION}
container_name: dozzle
profiles:
- hub
restart: unless-stopped
ports:
- ${DOZZLE_PORT}:8080
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- dozzle_data:/data
environment:
- DOZZLE_HOSTNAME=${DOZZLE_HOSTNAME}
- DOZZLE_REMOTE_AGENT=${DOZZLE_REMOTE_AGENT:-}
- DOZZLE_AUTH_PROVIDER=${DOZZLE_AUTH_PROVIDER:-none}
- DOZZLE_USERNAME=${DOZZLE_USERNAME:-}
- DOZZLE_PASSWORD=${DOZZLE_PASSWORD:-}
healthcheck:
test:
- CMD
- /dozzle
- healthcheck
interval: 30s
timeout: 10s
retries: 3
start_period: 15s
networks:
- tnet
labels:
- homepage.group=PFI-ANA
- homepage.name=Dozzle
- homepage.icon=mdi-text-box-search
- homepage.description=Container logs (ana-docker + ana-ml2)
- homepage.href=http://10.250.50.70:${DOZZLE_PORT}
dozzle-agent:
image: amir20/dozzle:${DOZZLE_VERSION}
container_name: dozzle-agent
profiles:
- agent
restart: unless-stopped
command: agent
ports:
- ${DOZZLE_AGENT_BIND:-0.0.0.0}:${DOZZLE_AGENT_PORT}:7007
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- dozzle_agent_data:/data
environment:
- DOZZLE_HOSTNAME=${DOZZLE_HOSTNAME}
networks:
- tnet
volumes:
dozzle_data: null
dozzle_agent_data: null
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/gitea/compose.yaml
services:
server:
image: gitea/gitea:latest
container_name: gitea
environment:
- USER_UID=1000
- USER_GID=1000
- GITEA__database__DB_TYPE=postgres
- GITEA__database__HOST=${DB_IP}:5432
- GITEA__database__NAME=gitea
- GITEA__database__USER=gitea
- GITEA__database__PASSWD=gitea
- GITEA__service__DISABLE_REGISTRATION=true
- GITEA__log__MODE=console
- GITEA__log__LEVEL=Info
- GITEA__log__ROUTER=console
restart: unless-stopped
volumes:
- gitea_data:/data
- /etc/timezone:/etc/timezone:ro
- /etc/localtime:/etc/localtime:ro
ports:
- 3000:3000
- 222:22
labels:
- homepage.group=Apps
- homepage.name=Gitea
- homepage.icon=si-gitea
- homepage.description=Git Repo (ana)
- homepage.href=https://gitea.phasefinal.com
- traefik.enable=true
- traefik.http.routers.gitea.tls=true
- traefik.http.routers.gitea.rule=Host(`gitea.phasefinal.com`)
- traefik.http.routers.gitea.tls.certresolver=anaprod
- traefik.http.services.gitea.loadbalancer.server.port=3000
- traefik.http.routers.gitea.middlewares=crowdsec@file
- crowdsec.labels.type=gitea
networks:
- tnet
networks:
tnet:
name: traefik-net
external: true
volumes:
gitea_data: null
>>> /opt/docker/compose/ittools/compose.yaml
services:
it-tools:
image: corentinth/it-tools:latest
container_name: it-tools
restart: unless-stopped
ports:
- "8780:80"
labels:
- homepage.group=Apps
- homepage.name=IT Tools
- homepage.icon=mdi-tools
- homepage.description=IT Dev Tools
- homepage.href=http://10.250.50.70:8780
>>> /opt/docker/compose/mailrise/compose.yaml
#version: '3'
services:
mailrise:
image: yoryan/mailrise:latest
container_name: mailrise
labels:
- homepage.group=PFI-ANA
- homepage.name=Mailrise
- homepage.icon=mdi-mail
- homepage.description=Mail to Notification Agent
- homepage.href=http://10.250.50.70:8025
volumes:
- /opt/docker/conf/mailrise/mailrise.conf:/etc/mailrise.conf:ro
restart: unless-stopped
environment:
- USER=1000:1000
ports:
- 8025:8025
networks: {}
>>> /opt/docker/compose/mattermost/compose.yaml
#version: "2.4"
services:
mattermost:
image: mattermost/mattermost-team-edition:latest
restart: unless-stopped
tmpfs:
- /tmp
volumes:
# - mattermost_data:/mm
- mattermost_data:/mattermost
# - /opt/docker/conf/mattermost:/mattermost/config
# - /opt/docker/data/mattermost/data:/mattermost/data
# - /opt/docker/data/mattermost/logs:/mattermost/logs
# - /opt/docker/data/mattermost/plugins:/mattermost/plugins
# - /opt/docker/data/mattermost/client/plugins:/mattermost/client/plugins
# - /opt/docker/data/mattermost/bleve-indexes:/mattermost/bleve-indexes
environment:
TZ: America/Los_Angeles
DOMAIN: mm.phasefinal.com
MM_SQLSETTINGS_DRIVERNAME: postgres
MM_SQLSETTINGS_DATASOURCE: ${DATASOURCE}
ports:
- 8065:8065
- 8443:8443/udp
user: 1000:1000
labels:
- homepage.group=Apps
- homepage.name=MatterMost
- homepage.icon=si-mattermost
- homepage.description=Chat Application (ana)
- homepage.href=https://mm.phasefinal.com
- traefik.enable=true
- traefik.http.routers.mattermost.tls=true
- traefik.http.routers.mattermost.rule=Host(`mm.phasefinal.com`)
- traefik.http.routers.mattermost.tls.certresolver=anaprod
- traefik.http.services.mattermost.loadbalancer.server.port=8065
networks:
- tnet
networks:
tnet:
name: traefik-net
external: true
volumes:
mattermost_data: null
>>> /opt/docker/compose/openwebui/compose.yaml
version: "3"
services:
open-webui:
ports:
- 3100:8080
volumes:
- open-webui:/app/backend/data
restart: unless-stopped
image: ghcr.io/open-webui/open-webui:main
labels:
- homepage.group=AI Systems
- homepage.name=Open WebUI
- homepage.icon=mdi-chat
- homepage.description=Open WebUI Chat - ana - 3100
- homepage.href=http://10.250.50.70:3100
networks:
- tnet
env_file:
- .env
volumes:
open-webui: null
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/restic/compose.yaml
# ignored : docker pull restic/rest-server:latest
#version: "3.3"
services:
rest-server:
ports:
- 8000:8000
labels:
- homepage.group=PFI-ANA
- homepage.name=Restic
- homepage.icon=mdi-cloud-upload
- homepage.description=Restic Backup Server (8000:ana)
- homepage.href=http://10.250.50.70:8000
volumes:
- /mnt/backup/restic/repo/ana:/data
container_name: rest_server
image: restic/rest-server
networks:
- tnet
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/rest-server-ana/compose.yaml
# rest-server (Anaheim) — restic backup target for the fleet.
#
# Deploys to ana-docker. Data dir is on the TrueNAS NFS mount
# (/mnt/backup/restic/repo/ana) so snapshots on the NAS side protect the
# backup blobs themselves.
#
# Mirrors stacks/rest-server-nh3/ in every meaningful way — same auth
# model, same on-disk layout, same operational semantics — so each client
# host uses an identical URL shape against either endpoint:
#
# rest:http://<user>:<pw>@10.100.50.50:8000/<user>/ (NH3 Synology)
# rest:http://<user>:<pw>@10.250.50.70:8000/<user>/ (this stack)
#
# Auth model:
# --private-repos : URL path must start with /<user>/ and the HTTP
# basic-auth user must match. Per-host repos are
# strictly isolated.
# --append-only : on-disk data can be added but not removed or
# rewritten; a compromised host can't wipe its own
# history. Prune requires disabling this (see README).
#
# Credentials come from /data/.htpasswd — see README for populating it.
#
# All tunables live in .env — edit that, not this file.
services:
rest-server:
image: restic/rest-server:${REST_SERVER_VERSION}
container_name: rest-server
restart: unless-stopped
# Run as the UID that owns the NFS-backed data dir, so file I/O
# is not subject to NFS root_squash. On ana-docker this is lkraven (1000).
user: ${REST_UID:-1000}:${REST_GID:-1000}
ports:
- ${REST_PORT}:8000
volumes:
- ${DATA_DIR}:/data
environment:
- OPTIONS=--private-repos --append-only --prometheus ${EXTRA_OPTIONS:-}
- TZ=${TZ:-America/Los_Angeles}
healthcheck:
test: ["CMD", "nc", "-z", "localhost", "8000"]
interval: 30s
timeout: 10s
retries: 3
start_period: 15s
networks:
- tnet
labels:
- homepage.group=PFI-ANA
- homepage.name=Restic (rest-server)
- homepage.icon=mdi-cloud-upload
- homepage.description=Anaheim restic endpoint (data on TrueNAS NFS)
- homepage.href=http://10.250.50.70:${REST_PORT}
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/rustdesk/compose.yaml
version: "3"
services:
hbbs:
container_name: hbbs
image: rustdesk/rustdesk-server:latest
command: hbbs
volumes:
- rustdesk_data:/root
#- /opt/docker/data/rustdesk:/root
network_mode: host
depends_on:
- hbbr
restart: unless-stopped
hbbr:
container_name: hbbr
image: rustdesk/rustdesk-server:latest
command: hbbr
labels:
- homepage.group=PFI-ANA
- homepage.name=Rustdesk
- homepage.icon=si-rustdesk
- homepage.description=Rustdesk Relay Server (ana)
- homepage.href=https://rustdesk.phasefinal.com
volumes:
- rustdesk_data:/root
#- /opt/docker/data/rustdesk:/root
network_mode: host
restart: unless-stopped
networks: {}
volumes:
rustdesk_data: null
>>> /opt/docker/compose/seafile/compose.yaml
# version: '2.0'
services:
db:
image: mariadb:10.6
container_name: seafile-mysql
environment:
- MYSQL_ROOT_PASSWORD=${DB_ROOT_PW}
- MYSQL_LOG_CONSOLE=true
volumes:
- seafile_db:/var/lib/mysql # Requested, specifies the path to MySQL data persistent store.
networks:
- tnet
memcached:
image: memcached:1.6.18
container_name: seafile-memcached
entrypoint: memcached -m 256
networks:
- tnet
seafile:
image: seafileltd/seafile-mc:11.0-latest
container_name: seafile
ports:
- 9180:80
volumes:
- seafile_datastore:/shared # Requested, specifies the path to Seafile data persistent store.
environment:
- DB_HOST=db
- DB_ROOT_PASSWD=${DB_ROOT_PW}
- TIME_ZONE=America/Los_Angeles
- SEAFILE_ADMIN_EMAIL=${SEAFILE_ADMIN_EMAIL}
- SEAFILE_ADMIN_PASSWORD=${SEAFILE_ADMIN_PW}
depends_on:
- db
- memcached
labels:
- homepage.group=Apps
- homepage.name=SeaFile
- homepage.icon=mdi-sync-circle
- homepage.description=File Sync Service (ana)
- homepage.href=https://seafile.phasefinal.com
- traefik.enable=true
- traefik.http.routers.seafile.tls=true
- traefik.http.routers.seafile.rule=Host(`seafile.phasefinal.com`)
- traefik.http.routers.seafile.tls.certresolver=anaprod
networks:
- tnet
env_file:
- .env
volumes:
seafile_db: null
seafile_datastore: null
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/searxng/compose.yaml
services:
searxng:
image: searxng/searxng:latest
container_name: searxng
restart: unless-stopped
# ------------------------------------------------------------------
# Port binding — 9996 on all interfaces.
# Change to "127.0.0.1:9996:8080" to restrict to localhost only.
# Traefik handles public routing and TLS via the labels below.
# ------------------------------------------------------------------
ports:
- 9996:8080
# ------------------------------------------------------------------
# Volumes
# Config: settings.yml bind-mounted read-only into the container.
volumes:
- /opt/docker/conf/searxng/searxng-settings.yml:/etc/searxng/settings.yml:ro
# ------------------------------------------------------------------
# Environment — see https://docs.searxng.org/admin/settings/index.html
# SEARXNG_SECRET — required for cryptographic signing (cookies, etc.)
# BASE_URL — public URL SearXNG reports in pages/RSS/OPDS
# INSTANCE_NAME — shown in the page title / footer
# ------------------------------------------------------------------
environment:
- SEARXNG_SECRET=${SEARXNG_SECRET}
- BASE_URL=https://searxng.pfi.local/
- INSTANCE_NAME=SearXNG
# ------------------------------------------------------------------
# Resource limits — tune for VM 102's available RAM/CPU
# ------------------------------------------------------------------
deploy:
resources:
limits:
memory: 512M
cpus: "1.0"
reservations:
memory: 128M
# ------------------------------------------------------------------
# Health check — SearXNG /healthz is the canonical liveness probe.
# ------------------------------------------------------------------
healthcheck:
test:
- CMD
- wget
- --no-verbose
- --tries
- --spider
- http://localhost:8080/healthz
interval: 30s
timeout: 10s
retries: 3
start_period: 15s
networks:
- tnet
labels:
# Traefik configuration — auto-discovery via Docker provider
- traefik.enable=true
- traefik.http.routers.searxng.rule=Host(`searxng.pfi.local`)
- traefik.http.routers.searxng.entrypoints=websecure
- traefik.http.routers.searxng.tls=true
- traefik.http.routers.searxng.service=searxng
- traefik.http.services.searxng.loadbalancer.server.port=8080
networks:
tnet:
name: traefik-net
external: true
>>> /opt/docker/compose/sillytavern/compose.yaml
version: "3"
services:
sillytavern:
build: ..
container_name: sillytavern
hostname: sillytavern
image: ghcr.io/sillytavern/sillytavern:latest
ports:
- 8100:8000
volumes:
- sillytavern_data:/home/node/app/data
- sillytavern_plugins:/home/node/app/plugins
- sillytavern_extensions:/home/node/app/public/scripts/extensions/third-party
- /opt/docker/conf/sillytavern:/home/node/app/config
# - /opt/docker/data/sillytavern/data:/home/node/app/data
# - /opt/docker/data/sillytavern/plugins:/home/node/app/plugins
# - /opt/docker/data/sillytavern/extensions:/home/node/app/public/scripts/extensions/third-party
restart: unless-stopped
labels:
- homepage.group=AI Systems
- homepage.name=Silly Tavern
- homepage.icon=mdi-chat
- homepage.description=Silly Tavern AI - ANA-Docker 8100
- homepage.href=http://10.250.50.70:8100
networks:
- tnet
networks:
tnet:
name: traefik-net
external: true
volumes:
sillytavern_data: null
sillytavern_plugins: null
sillytavern_extensions: null
>>> /opt/docker/compose/synapse/compose.yaml
# ==============================================================================
# Matrix Synapse Stack — VM-102 (10.250.50.70)
# Domain: matrix.phasefinal.com
#
# Deploy: /opt/docker/compose/synapse/compose.yaml
# Config: /opt/docker/conf/synapse/homeserver.yaml
#
# Services:
# 1. synapse-db — Postgres 16 (internal only)
# 2. synapse — Matrix Synapse homeserver (port 8008)
# 3. element-web — Element Web client (port 8080)
#
# Stack uses traefik-net (tnet) for reverse proxy / TLS termination.
# Cert resolver: anaprod (matches existing VM-102 convention)
# ==============================================================================
services:
# ---------------------------------------------------------------------------
# Postgres database for Synapse
# ---------------------------------------------------------------------------
synapse-db:
image: postgres:16-alpine
container_name: synapse-db
restart: unless-stopped
environment:
POSTGRES_DB: synapse
POSTGRES_USER: synapse
POSTGRES_PASSWORD: MOV0AHc26hHw9jDkjgIZqLb1zmY0um0v
POSTGRES_INITDB_ARGS: --lc-collate=C --lc-ctype=C --encoding=UTF8
volumes:
- synapse-db-data:/var/lib/postgresql/data
networks:
- synapse-internal
healthcheck:
test:
- CMD-SHELL
- pg_isready -U synapse -d synapse
interval: 10s
timeout: 5s
retries: 5
# ---------------------------------------------------------------------------
# Matrix Synapse homeserver
# ---------------------------------------------------------------------------
synapse:
image: matrixdotorg/synapse:v1.120.0
container_name: synapse
restart: unless-stopped
depends_on:
synapse-db:
condition: service_healthy
volumes:
- /opt/docker/conf/synapse/homeserver.yaml:/data/homeserver.yaml:ro
- synapse-data:/data
- /opt/docker/conf/synapse/aipa_appservice.yaml:/conf/aipa_appservice.yaml:ro
networks:
- tnet
- synapse-internal
labels:
- traefik.enable=true
- traefik.http.routers.synapse.rule=Host(`matrix.phasefinal.com`)
- traefik.http.routers.synapse.tls=true
- traefik.http.routers.synapse.tls.certresolver=anaprod
- traefik.http.services.synapse.loadbalancer.server.port=8008
# ---------------------------------------------------------------------------
# Element Web client
# ---------------------------------------------------------------------------
element-web:
image: vectorim/element-web:v1.11.80
container_name: element-web
restart: unless-stopped
depends_on:
- synapse
volumes:
- /opt/docker/conf/synapse/element-config.json:/app/config.json:ro
networks:
- tnet
labels:
- traefik.enable=true
- traefik.http.routers.element.rule=Host(`chat.phasefinal.com`)
- traefik.http.routers.element.tls=true
- traefik.http.routers.element.tls.certresolver=anaprod
- traefik.http.services.element.loadbalancer.server.port=80
networks:
synapse-internal:
driver: bridge
tnet:
name: traefik-net
external: true
# =============================================================================
# Volumes
# =============================================================================
volumes:
synapse-db-data: null
synapse-data: null
>>> /opt/docker/compose/traefik/compose.yaml
services:
traefik:
image: traefik:latest
container_name: traefik
command:
- --configFile=/etc/traefik/traefik.yml
ports:
- 80:80
- 8380:8080
- 443:443
labels:
- homepage.group=PFI-ANA
- homepage.name=traefik
- homepage.icon=si-traefikproxy
- homepage.sitemonitor=http://10.250.50.70:8380
- homepage.href=http://10.250.50.70:8380
- homepage.widget.type=traefik
- homepage.widget.url=http://10.250.50.70:8380
- crowdsec.labels.type=traefik
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- /opt/docker/conf/traefik-ana/config:/etc/traefik
- /opt/docker/conf/traefik-ana/acme.json:/acme.json
- traefik-logs:/var/log/traefik # Important for CrowdSec
networks:
- tnet
restart: unless-stopped
networks:
tnet:
name: traefik-net
external: true
volumes:
traefik-logs: null
>>> /opt/docker/compose/vaultwarden/compose.yaml
#version: '3'
services:
vaultwarden:
image: vaultwarden/server:latest
container_name: vaultwarden
volumes:
- vaultwarden_data:/data
- /opt/docker/conf/vaultwarden/config.json:/data/config.json
#- /opt/docker/data/vaultwarden:/data
ports:
- 9080:80
restart: unless-stopped
labels:
- homepage.group=Apps
- homepage.name=Vaultwarden
- homepage.icon=si-bitwarden
- homepage.description=Password Vault (ana)
- homepage.sitemonitor=https://vaultwarden.phasefinal.com
- homepage.href=https://vaultwarden.phasefinal.com
- traefik.enable=true
- traefik.http.routers.vaultwarden.tls=true
- traefik.http.routers.vaultwarden.rule=Host(`vaultwarden.phasefinal.com`)
- traefik.http.routers.vaultwarden.tls.certresolver=anaprod
- crowdsec.labels.type=VaultWarden
networks:
- tnet
env_file:
- .env
networks:
tnet:
name: traefik-net
external: true
volumes:
vaultwarden_data: null
===== CONFIG LAYOUT (/opt/docker/conf/ — top 200 entries) =====
/opt/docker/conf
/opt/docker/conf/crowdsec
/opt/docker/conf/crowdsec/acquis.d
/opt/docker/conf/crowdsec/acquis.yaml
/opt/docker/conf/crowdsec/blocklist-mirror.yaml
/opt/docker/conf/crowdsec/collections
/opt/docker/conf/crowdsec/collections/base-http-scenarios.yaml
/opt/docker/conf/crowdsec/collections/gitea.yml
/opt/docker/conf/crowdsec/collections/http-cve.yaml
/opt/docker/conf/crowdsec/collections/linux.yaml
/opt/docker/conf/crowdsec/collections/sshd.yaml
/opt/docker/conf/crowdsec/collections/traefik.yaml
/opt/docker/conf/crowdsec/collections/vaultwarden.yml
/opt/docker/conf/crowdsec/collections/whitelist-good-actors.yaml
/opt/docker/conf/crowdsec/config.yaml
/opt/docker/conf/crowdsec/console.yaml
/opt/docker/conf/crowdsec/contexts
/opt/docker/conf/crowdsec/contexts/bf_base.yaml
/opt/docker/conf/crowdsec/contexts/http_base.yaml
/opt/docker/conf/crowdsec/dev.yaml
/opt/docker/conf/crowdsec/hub
/opt/docker/conf/crowdsec/hub/collections
/opt/docker/conf/crowdsec/hub/collections/crowdsecurity
/opt/docker/conf/crowdsec/hub/collections/Dominic-Wagner
/opt/docker/conf/crowdsec/hub/collections/LePresidente
/opt/docker/conf/crowdsec/hub/contexts
/opt/docker/conf/crowdsec/hub/contexts/crowdsecurity
/opt/docker/conf/crowdsec/hub/.index.json
/opt/docker/conf/crowdsec/hub/parsers
/opt/docker/conf/crowdsec/hub/parsers/s00-raw
/opt/docker/conf/crowdsec/hub/parsers/s01-parse
/opt/docker/conf/crowdsec/hub/parsers/s02-enrich
/opt/docker/conf/crowdsec/hub/postoverflows
/opt/docker/conf/crowdsec/hub/postoverflows/s00-enrich
/opt/docker/conf/crowdsec/hub/postoverflows/s01-whitelist
/opt/docker/conf/crowdsec/hub/scenarios
/opt/docker/conf/crowdsec/hub/scenarios/crowdsecurity
/opt/docker/conf/crowdsec/hub/scenarios/Dominic-Wagner
/opt/docker/conf/crowdsec/hub/scenarios/LePresidente
/opt/docker/conf/crowdsec/hub/scenarios/ltsich
/opt/docker/conf/crowdsec/local_api_credentials.yaml
/opt/docker/conf/crowdsec/notifications
/opt/docker/conf/crowdsec/notifications/email.yaml
/opt/docker/conf/crowdsec/notifications/file.yaml
/opt/docker/conf/crowdsec/notifications/http.yaml
/opt/docker/conf/crowdsec/notifications/sentinel.yaml
/opt/docker/conf/crowdsec/notifications/slack.yaml
/opt/docker/conf/crowdsec/notifications/splunk.yaml
/opt/docker/conf/crowdsec/online_api_credentials.yaml
/opt/docker/conf/crowdsec/parsers
/opt/docker/conf/crowdsec/parsers/s00-raw
/opt/docker/conf/crowdsec/parsers/s00-raw/cri-logs.yaml
/opt/docker/conf/crowdsec/parsers/s00-raw/docker-logs.yaml
/opt/docker/conf/crowdsec/parsers/s00-raw/syslog-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse
/opt/docker/conf/crowdsec/parsers/s01-parse/gitea-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse/sshd-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse/sshd-success-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse/traefik-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse/vaultwarden-logs.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich
/opt/docker/conf/crowdsec/parsers/s02-enrich/dateparse-enrich.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich/geoip-enrich.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich/http-logs.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich/public-dns-allowlist.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich/whitelists.yaml
/opt/docker/conf/crowdsec/patterns
/opt/docker/conf/crowdsec/patterns/aws
/opt/docker/conf/crowdsec/patterns/bacula
/opt/docker/conf/crowdsec/patterns/bro
/opt/docker/conf/crowdsec/patterns/cowrie_honeypot
/opt/docker/conf/crowdsec/patterns/exim
/opt/docker/conf/crowdsec/patterns/firewalls
/opt/docker/conf/crowdsec/patterns/haproxy
/opt/docker/conf/crowdsec/patterns/java
/opt/docker/conf/crowdsec/patterns/junos
/opt/docker/conf/crowdsec/patterns/linux-syslog
/opt/docker/conf/crowdsec/patterns/mcollective
/opt/docker/conf/crowdsec/patterns/modsecurity
/opt/docker/conf/crowdsec/patterns/mongodb
/opt/docker/conf/crowdsec/patterns/mysql
/opt/docker/conf/crowdsec/patterns/nagios
/opt/docker/conf/crowdsec/patterns/nginx
/opt/docker/conf/crowdsec/patterns/paths
/opt/docker/conf/crowdsec/patterns/postgresql
/opt/docker/conf/crowdsec/patterns/rails
/opt/docker/conf/crowdsec/patterns/redis
/opt/docker/conf/crowdsec/patterns/ruby
/opt/docker/conf/crowdsec/patterns/smb
/opt/docker/conf/crowdsec/patterns/ssh
/opt/docker/conf/crowdsec/patterns/tcpdump
/opt/docker/conf/crowdsec/postoverflows
/opt/docker/conf/crowdsec/postoverflows/s00-enrich
/opt/docker/conf/crowdsec/postoverflows/s00-enrich/rdns.yaml
/opt/docker/conf/crowdsec/postoverflows/s01-whitelist
/opt/docker/conf/crowdsec/postoverflows/s01-whitelist/cdn-whitelist.yaml
/opt/docker/conf/crowdsec/postoverflows/s01-whitelist/seo-bots-whitelist.yaml
/opt/docker/conf/crowdsec/profiles.yaml
/opt/docker/conf/crowdsec/scenarios
/opt/docker/conf/crowdsec/scenarios/apache_log4j2_cve-2021-44228.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2017-9841.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2019-18935.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-26134.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-35914.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-37042.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-40684.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-41082.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-41697.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-42889.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-44877.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-46169.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2023-22515.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2023-22518.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2023-49103.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2024-0012.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2024-38475.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2024-9474.yaml
/opt/docker/conf/crowdsec/scenarios/f5-big-ip-cve-2020-5902.yaml
/opt/docker/conf/crowdsec/scenarios/fortinet-cve-2018-13379.yaml
/opt/docker/conf/crowdsec/scenarios/gitea-bf.yaml
/opt/docker/conf/crowdsec/scenarios/gitea-scraper.yaml
/opt/docker/conf/crowdsec/scenarios/grafana-cve-2021-43798.yaml
/opt/docker/conf/crowdsec/scenarios/http-admin-interface-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-backdoors-attempts.yaml
/opt/docker/conf/crowdsec/scenarios/http-bad-user-agent.yaml
/opt/docker/conf/crowdsec/scenarios/http-crawl-non_statics.yaml
/opt/docker/conf/crowdsec/scenarios/http-cve-2021-41773.yaml
/opt/docker/conf/crowdsec/scenarios/http-cve-2021-42013.yaml
/opt/docker/conf/crowdsec/scenarios/http-cve-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-generic-bf.yaml
/opt/docker/conf/crowdsec/scenarios/http-generic-test.yaml
/opt/docker/conf/crowdsec/scenarios/http-open-proxy.yaml
/opt/docker/conf/crowdsec/scenarios/http-path-traversal-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-sap-interface-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-sensitive-files.yaml
/opt/docker/conf/crowdsec/scenarios/http-sqli-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-w00tw00t.yaml
/opt/docker/conf/crowdsec/scenarios/http-wordpress-scan.yaml
/opt/docker/conf/crowdsec/scenarios/http-xss-probing.yaml
/opt/docker/conf/crowdsec/scenarios/jira_cve-2021-26086.yaml
/opt/docker/conf/crowdsec/scenarios/netgear_rce.yaml
/opt/docker/conf/crowdsec/scenarios/pulse-secure-sslvpn-cve-2019-11510.yaml
/opt/docker/conf/crowdsec/scenarios/spring4shell_cve-2022-22965.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-bf.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-cve-2024-6387.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-generic-test.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-refused-conn.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-slow-bf.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-time-based-bf.yaml
/opt/docker/conf/crowdsec/scenarios/thinkphp-cve-2018-20062.yaml
/opt/docker/conf/crowdsec/scenarios/vaultwarden-bf.yaml
/opt/docker/conf/crowdsec/scenarios/vmware-cve-2022-22954.yaml
/opt/docker/conf/crowdsec/scenarios/vmware-vcenter-vmsa-2021-0027.yaml
/opt/docker/conf/crowdsec/simulation.yaml
/opt/docker/conf/crowdsec/user.yaml
/opt/docker/conf/mailrise
/opt/docker/conf/mailrise/mailrise.conf
/opt/docker/conf/mattermost
/opt/docker/conf/mattermost/config.json
/opt/docker/conf/searxng
/opt/docker/conf/searxng/searxng-settings.yml
/opt/docker/conf/sillytavern
/opt/docker/conf/sillytavern/config.yaml
/opt/docker/conf/synapse
/opt/docker/conf/synapse/aipa_appservice.yaml
/opt/docker/conf/synapse/element-config.json
/opt/docker/conf/synapse/homeserver.yaml
/opt/docker/conf/traefik-ana
/opt/docker/conf/traefik-ana/acme.json
/opt/docker/conf/traefik-ana/config
/opt/docker/conf/traefik-ana/config/acme.json
/opt/docker/conf/traefik-ana/config/dynamic.yml
/opt/docker/conf/traefik-ana/config/traefik.yml
/opt/docker/conf/vaultwarden
/opt/docker/conf/vaultwarden/config.json
===== LISTENING PORTS =====
0.0.0.0:111
0.0.0.0:22
0.0.0.0:222
0.0.0.0:3000
0.0.0.0:3100
0.0.0.0:41412
0.0.0.0:443
0.0.0.0:5001
0.0.0.0:80
0.0.0.0:8000
0.0.0.0:8025
0.0.0.0:8088
0.0.0.0:8090
0.0.0.0:8100
0.0.0.0:8380
0.0.0.0:8780
0.0.0.0:9080
0.0.0.0:9180
0.0.0.0:9898
0.0.0.0:9996
[::]:111
127.0.0.1:42675
*:21115
*:21116
*:21117
*:21118
*:21119
[::]:22
[::]:222
*:2375
[::]:3000
[::]:3100
[::]:41412
[::]:443
[::]:5001
[::]:80
[::]:8000
[::]:8025
[::]:8088
[::]:8090
[::]:8100
[::]:8380
[::]:8780
[::]:9080
[::]:9180
[::]:9898
[::]:9996
===== MODEL / HUGGINGFACE CACHES =====
===== DOCKER-ADJACENT SYSTEMD SERVICES =====
containerd.service running
docker.service running
===== DONE =====
Paste the above back into the chat, or pass a path as argv[1] to save.