Julien LutranandClaude Opus 5 7e6b8f2848 doc: make every LAN instance static, record the FTTH fallout
Follow-up to a7f1ac6. The Archer C7's DHCP reservations did not carry
over to the FTTH box, so anything still on DHCP was one lease renew away
from moving — as blocky already demonstrated by taking LAN DNS with it.
jellyfin-server and jellyfin-client are now static too; homeassistant
stays dynamic on purpose (it never had a reservation).

Records three things that cost time to find:

- jellyfin-client can never use netplan: the kiosk raw.lxc bind-mounts
  the host /run/udev read-only, so netplan generate fails and config
  silently does not regenerate at boot. It uses systemd-networkd now.
- LAPTOP719974 and patate also lost their reserved addresses.
- ks4 cannot serve as an IPv6 exit: it has a global v6 address and a
  default v6 route but no working v6 egress, so extending the torrent
  tunnel to ::/0 is not an option. IPv6 stays disabled in the container.

Also notes the C7 + LTE box kept as fallback: only the gateway differs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 10:33:17 +02:00

Personal infrastructure notes

Two repositories back this setup: doc (this one) and scripts (the cron drivers and their config files, deployed to /root/scripts on each host).

Start here:

  • backup-strategy.md — what is backed up, by which tool, on what schedule, and how to restore.
  • new-container.md — conventions for adding a service to ks4 (and getting it backed up automatically).

Tech notes

  • nuc/ — home lab on nuc: host, iGPU instances
  • nas/ — storage + backup host nas (Supermicro A1SAi-2750F): the 4 TB on direct SATA, media over NFS, backup pools
  • ks4/ — prod server ks4 at OVH: host, services, network flows
  • ks2/ — legacy backup server being decommissioned
  • archer-c7/ — home router (TP-Link Archer C7 v5 running on OpenWrt)

Conventions

  • One markdown file per topic in the correct subdir, containing the full implementation notes, configuration, and troubleshooting notes.
  • Containers are built from Debian/Ubuntu images and configured exclusively through incus exec/incus config so the doc is the single source of truth — rebuilding = re-running the script.
  • Adding a service to ks4: follow new-container.md (no Docker in containers — incus runs OCI images natively and incus-compose handles stacks; data paths go into scripts/restic-paths).
S
Description
No description provided
Readme
670 KiB
Languages
Markdown 100%