- nuc/README.md and ks4/README.md carry the host sections (+ network flows) that lived in the top-level README; links rebased - top README: repo links (doc/scripts on git.lutran.fr), index points at the new per-host pages - cross-repo references now use https://git.lutran.fr/julien/scripts instead of relative ../scripts paths that resolve nowhere - plakar-s3-data.md and plakar-incus-integration.md marked SUPERSEDED / RETIRED with pointers to restic-backup.md; their measurements and rationale kept - install.md, local-backup-cron.md, incus-copy.md: crontab sections updated to the live schedule (01:00 replicas, 05:00 restic, Sun maintenance); retired legs labelled as such - restic-backup.md: status live, cutover recorded, post-GC memory estimate, seed plan dated - seafile-gc.md: online GC noted, stale 'crons commented out' removed - ks2/: what-ks2-does-today rewritten (nothing writes to it any more), legs table and gates reflect restic, decommission steps updated - db-exclude replaces the plakar-era config name (script keeps a fallback) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Homelab: nuc
Incus host on the LAN.
- Debian 13, Intel Alder Lake-N (iGPU
i915, shared by both Jellyfin containers) — bare-metal reinstall: nuc-install.md - Instances are bridged onto the LAN (192.168.0.0/24)
- USB 4 TB WD Red: ZFS pool
usb4t—usb4t/backup→/backup(incus exports,nuc/+ks4/subdatasets, 1 TB quota) andusb4t/media→/srv/media(media library, shared into containers viashift=truedisk devices; works because ZFS ≥ 2.2 supports idmapped mounts) - Backups: all local instances replicated to the USB pool
(
/root/scripts/incus-copy.sh -p backup -s nucbackup; replicas stopped, autostart off) — see nuc-install.md; ks4 replicas pulled into poolks4backup— see ks4/incus-copy.md
Instances
| Name | IP | Doc | Features |
|---|---|---|---|
| jellyfin-server | 192.168.0.5 | ✅ | unprivileged, autostart; iGPU render node (gpu device, render gid) for QSV/VAAPI transcoding; /srv/media disk device (shift=true); proxy device → host :8096 |
| jellyfin-client | 192.168.0.6 | ✅ | privileged, autostart; full iGPU (gpu device, gid 44) → HDMI kiosk (cage + Jellyfin Media Player); custom raw.lxc (bind /dev/snd, /dev/input, host /run/udev); Pioneer USB audio as ALSA default; FR keymap; go-librespot Spotify Connect ("Pioneer A-70") |
| transmission-bt | 192.168.0.7 | ✅ | unprivileged, autostart; always-on WireGuard full tunnel → ks4 (egress = 193.70.35.17, kill switch: no default route); /srv/media disk device (shift=true), downloads to /media/downloads; web UI :9091 (LAN only) |
| blocky | 192.168.0.254 | — | unprivileged, autostart; DNS ad-blocker |
| privoxy | 192.168.0.11 | — | unprivileged, autostart; filtering HTTP proxy |
| homeassistant | (stopped) | — | virtual machine, 50 GiB root disk on pool data |