bf02e29fd6
Secrets were removed from the repo and moved to .env files on the server. Added runbook step for restoring them from USB backup (or recreating from Bitwarden), updated the protection table in README, and added architecture note in CLAUDE.md.
3.1 KiB
3.1 KiB
argento
Configuration and recovery repo for the argento home server. This repo is the runbook -- it contains the actual config files and documents the manual steps between them.
- Rocky Linux 9 on NVMe
- ZFS storage (2 pools:
nextcloudmirror,threeterasraidz2) - Docker apps behind nginx reverse proxy
- Daily USB backup via rsync
Repo structure
scripts/ Backup, cert issuance, health monitoring, system config sync
docker/ Docker app configs (compose files, nginx confs)
nginx/ Reverse proxy + SSL termination
nextcloud/ Nextcloud + PostgreSQL
gitea/ Gitea + CI runner
jellyfin/ Media server
garage/ S3-compatible storage
minecraft/ MCSManager
smb/ Samba share (ZFS mountpoint, not in git)
system/ System config snapshots (smb.conf, sanoid.conf, firewalld, etc.)
Key files
| File | Purpose |
|---|---|
RUNBOOK.md |
Full recovery steps, top to bottom |
scripts/backup.sh |
Daily USB backup (DB dumps + rsync) |
scripts/issue-cert.sh |
Issue SSL certs via certbot webroot |
scripts/disk-health-check.sh |
SMART, ZFS, disk space monitoring (daily alerts + weekly reports via cron) |
scripts/sync-system.sh |
Auto-sync system configs to git |
system/tracked-configs |
Maps system config paths to repo paths |
docker/nginx/conf.d/_template.conf.example |
Template for new nginx app confs |
Workflows
Compose files -- edit in /opt/argento/, apply, commit:
cd /opt/argento/docker/<app>
vim compose.yaml
docker compose up -d
git add . && git commit && git push
System configs -- edit in place, auto-synced daily:
vim /etc/samba/smb.conf
systemctl restart smb
# sync-system.sh runs via cron, or run manually: /opt/argento/scripts/sync-system.sh
Nginx configs -- edit in repo, reload:
vim /opt/argento/docker/nginx/conf.d/<domain>.conf
docker exec nginx nginx -t
docker exec nginx nginx -s reload
git add . && git commit && git push
Adding a new app:
- Create
docker/<app>/compose.yamlwithcontainer_nameandsharednetwork docker compose up -d./scripts/issue-cert.sh <domain>cp docker/nginx/conf.d/_template.conf.example docker/nginx/conf.d/<domain>.confand fill in placeholdersdocker exec nginx nginx -t && docker exec nginx nginx -s reload- Commit and push
Recovery
See RUNBOOK.md for full disaster recovery steps.
What's protected where
| Data | Protection | Recovery |
|---|---|---|
| Configs (compose, nginx, system) | Git (Gitea + GitHub mirror) | git clone |
| Nextcloud files | ZFS mirror + sanoid snapshots + USB | rsync from USB |
| Media library | ZFS raidz2 + sanoid snapshots + USB | rsync from USB |
| Nextcloud DB (PostgreSQL) | ZFS dataset + pg_dumpall + USB |
rsync from USB |
| Garage S3 data | 2-node replication + USB | Replication or USB |
| Gitea repos + DB | SQLite .backup + USB |
rsync from USB |
| Secrets (.env files) | USB backup + Bitwarden | rsync from USB, or recreate from Bitwarden |
| SSL certificates | Re-issued from Let's Encrypt | ./scripts/issue-cert.sh |