Captures the full workspace state built up to this point:
- CLAUDE.md + README.md describing conventions and the four-host fleet
(ana-ml2, ana-docker, nh3-docker, esh-docker-vm).
- Per-host notes under servers/<host>/ with ssh-target fallback files
and latest system-details snapshots (two in-compose credential leaks
scrubbed; the upstream compose files still need to move those to .env).
- scripts/: server_inspect.sh (read-only remote diagnostic),
refresh-server-info.sh (dir-driven discovery + snapshot capture with
validation warnings), add-host.sh, sync-stacks.sh (pull
compose/conf trees), deploy-stack.sh (push with per-file diff + prompt).
- stacks/: canonical compose for backrest, beszel, dozzle, llama-swap,
rest-server-ana, rest-server-nh3, vllm-qwen3, plus the retired
infinity reference. All use the .env-driven + traefik-net + homepage
label pattern.
- configs/restic/ana-docker/: first resticprofile config + pre-backup
hook (Synapse pg_dump, Seafile mysqldump, Vaultwarden SQLite); templates
for the other three hosts to come.
- docs/pfi/: general infrastructure reference carried over.
- .gitignore excludes .env, stacks-mirror/, and assorted secret/state
filenames to prevent re-leaks on later commits.
2.6 KiB
dozzle
Container log viewer. One UI on ana-docker aggregates logs from every Docker host via remote agents.
Deploys to:
- ana-docker (hub) — UI at
http://10.250.50.70:8088 - ana-ml2 (agent) — listens on
10.250.50.54:7007 - nh3-docker (agent, cross-site) — listens on
10.100.50.40:7007
One compose.yaml lives on each host. The per-host .env sets COMPOSE_PROFILES=hub or COMPOSE_PROFILES=agent so docker compose up -d brings up the right service. On the hub, add every agent to DOZZLE_REMOTE_AGENT as a comma-separated list (e.g. 10.250.50.54:7007,10.100.50.40:7007).
Auth / TLS note
Dozzle agents and hub auto-generate mTLS certificates on first run. On the trusted LAN (10.250.0.0/16) the default config is fine. If you ever expose an agent beyond the LAN, generate and pin certificates explicitly per the Dozzle docs (dozzle generate). The web UI itself is unauthenticated by default — flip DOZZLE_AUTH_PROVIDER=simple and set DOZZLE_USERNAME/DOZZLE_PASSWORD in the hub .env if you want a login gate.
Deploy — hub (ana-docker)
ssh ana-docker
sudo mkdir -p /opt/docker/compose/dozzle
sudo chown $USER /opt/docker/compose/dozzle
cd /opt/docker/compose/dozzle
# scp compose.yaml + .env.example from this workspace, then:
cp .env.example .env
# Ensure:
# COMPOSE_PROFILES=hub
# DOZZLE_HOSTNAME=ana-docker
# DOZZLE_REMOTE_AGENT=10.250.50.54:7007
# DOZZLE_PORT=8088
docker compose config
docker compose up -d
docker compose logs -f
Deploy — agent (ana-ml2)
ssh ana-ml2
sudo mkdir -p /opt/docker/compose/dozzle
sudo chown $USER /opt/docker/compose/dozzle
cd /opt/docker/compose/dozzle
# scp the same compose.yaml + .env.example, then:
cp .env.example .env
# Edit to:
# COMPOSE_PROFILES=agent
# DOZZLE_HOSTNAME=ana-ml2
# DOZZLE_AGENT_PORT=7007
docker compose config
docker compose up -d
docker compose logs -f
Verify
# Hub health (from anywhere on LAN)
curl -s http://10.250.50.70:8088/healthz
# Agent reachable from the hub's perspective
ssh ana-docker 'nc -zv 10.250.50.54 7007'
# Open http://10.250.50.70:8088 — you should see two tabs:
# "ana-docker" (local containers) and "ana-ml2" (via agent).
Troubleshooting
- Hub shows only local containers: agent is unreachable. Check firewall rules on ana-ml2 (port 7007 must be open from 10.250.50.70) and that the agent is actually listening (
ss -tlnp | grep 7007). - Agent keeps restarting: verify the docker.sock bind mount is read-only and the socket exists.
- Certificate mismatch after image upgrade: delete the
dozzle_dataanddozzle_agent_datavolumes on both hosts and redeploy to regenerate.