Commit Graph
159 Commits
Author SHA1 Message Date
tiennm99 82892042dc fix(hermes): configure chat platforms in /opt/data/.env, not Coolify
The gateway's allow-lists read only the profile .env under the default
multiplex mode, so Telegram values passed from the environment left every
user blocked. Drop the passthrough and document the dashboard as the one
place to set them, plus the dashboard secret's 16-byte minimum.
2026-10-05 17:35:34 +07:00
tiennm99 d4256617f4 feat(openclaw): set the startup env doctor recommends on ARM hosts
Add NODE_COMPILE_CACHE and OPENCLAW_NO_RESPAWN, and record the remaining
doctor notes and the ARM64 browser path override in docs/openclaw.
2026-10-05 16:33:27 +07:00
tiennm99 0a7e8f9783 feat(gitea-mirror): split gitea-mirror out of the gitea stack into its own service 2026-10-05 15:59:04 +07:00
tiennm99 5caa497d7f refactor: rename the gitea-mirror service directory to gitea 2026-10-05 15:54:03 +07:00
tiennm99 d0eb7c8aa9 docs: fix stale references after removing services 2026-10-05 14:54:37 +07:00
tiennm99 d5d7121180 chore: remove the opencode service 2026-10-05 14:52:03 +07:00
tiennm99 2831651bd2 fix(owncloud): give redis a named data volume, as upstream does 2026-10-05 14:52:03 +07:00
tiennm99 1cbbf271ce refactor: align openclaw and hermes with their official Docker guides 2026-10-05 14:52:03 +07:00
tiennm99 77c12d5397 feat(hermes): pass Telegram gateway settings through 2026-10-05 14:18:36 +07:00
tiennm99 0d0a48221b refactor: switch openclaw and hermes to their official images 2026-10-05 13:22:01 +07:00
tiennm99 8d4c3d14a4 feat: add openclaw and hermes agent templates 2026-10-05 11:22:18 +07:00
tiennm99 7616ff9f89 feat(owncloud): add ownCloud with MariaDB and Redis 2026-10-05 10:49:47 +07:00
tiennm99 0b660eb106 feat(webtop): add dev toolchain mods and Docker access 2026-10-05 10:26:55 +07:00
tiennm99 1bda841d1c chore(webtop): default CUSTOM_USER to miti99 2026-10-05 10:00:22 +07:00
tiennm99 9cc483f63b feat(webtop): add Ubuntu XFCE web desktop 2026-10-05 09:54:03 +07:00
tiennm99 8bd14da5ca feat(open-webui): add Open WebUI chat interface 2026-10-05 09:03:35 +07:00
tiennm99 40a234e2ff fix(litellm): build config.yaml into the image instead of bind-mounting it 2026-10-05 00:21:32 +07:00
tiennm99 8291a3408e feat(litellm): add LiteLLM proxy with PostgreSQL and Redis 2026-10-04 23:08:09 +07:00
tiennm99 f544979a91 feat: add migrate-service skill for moving Coolify deployments onto this repo 2026-10-04 22:24:09 +07:00
tiennm99 dd7c951143 chore: drop required-env header comments from compose files 2026-10-04 21:53:29 +07:00
tiennm99 01102bdf06 refactor: comment out optional env vars in diun and code-server 2026-10-04 21:53:29 +07:00
tiennm99 5844ef5611 refactor(goclaw): comment out optional MiniMax and trace env vars 2026-10-04 21:50:15 +07:00
tiennm99 1d2010bbe4 docs: list optional env vars commented out in compose files 2026-10-04 21:50:15 +07:00
tiennm99 acb3628dc8 feat(goclaw): pass through auto-upgrade and MiniMax env, add healthcheck 2026-10-04 21:42:01 +07:00
tiennm99 a0b5e15d9d chore: ignore local plans directory 2026-10-04 18:25:07 +07:00
tiennm99 198329c008 docs: move service issue notes from READMEs into docs/<service>
Service READMEs now cover only what the service is and how to deploy it.
Known issues, log noise and troubleshooting move to docs/<service>/, named
after the service directory, so editing them never redeploys the service.
Drop alloy's validate workflow, which never ran from a subdirectory.
2026-10-04 09:46:08 +07:00
tiennm99 b6952d84df refactor: move gitea-mirror maintenance skill to the repo root
A skill under gitea-mirror/ redeployed the stack on every edit, since the
Coolify watch path is gitea-mirror/**, and only loaded once a session touched
that directory. Service directories now hold deploy files only; skills live
in the root .claude/skills/.
2026-10-04 09:26:22 +07:00
tiennm99 e92ed7914d feat(gitea-mirror): clean up mirrors left by renamed and deleted repos
Add cleanup-renamed-repos.sh, which groups Gitea mirrors and gitea-mirror
rows by GitHub repo id, keeps the copy at the current name (renaming a
case-only mismatch in place), deletes the rest and re-imports.

cleanup-archived-repos.sh now deletes every mirror whose GitHub source 404s
when the source belongs to the gh user or an org it administers, keeps
third-party ones, and aborts on a GitHub rate limit.
2026-10-04 09:06:15 +07:00
tiennm99 bd0fe78994 fix(gitea-mirror): keep gitea-mirror waiting as long as Gitea clones
Gitea's migrate API stays silent until the clone ends, and Bun's fetch
drops a connection idle for 5 minutes. gitea-mirror then marked large
repositories failed while Gitea kept cloning, and a later retry took the
half-made repository for a finished mirror. GITEA_CLONE_TIMEOUT now also
sets BUN_CONFIG_HTTP_IDLE_TIMEOUT.
2026-10-03 13:38:02 +07:00
tiennm99 efd0848143 feat(gitea-mirror): add cleanup of archived copies of deleted repos
Deletes the archived-* Gitea copies gitea-mirror keeps when a source in the
given owners disappears, and removes their tracking rows so they are not
re-mirrored. Dry run by default.
2026-10-03 13:09:05 +07:00
tiennm99 4576b4dfd5 fix(gitea-mirror): match failed mirrors by source name in detection
gitea-mirror clears mirroredLocation when a mirror fails, so failed repos
were dropped from the status map and reported as status unknown.
2026-10-03 13:09:05 +07:00
tiennm99 9a9e4cddf7 refactor(gitea-mirror): run mirror maintenance through tea and the gitea-mirror API
The skill reached Gitea on localhost and the mirror database inside the
container, which only worked on a local host. It now uses tea for Gitea
and the gitea-mirror API key for repository status and retries, in bash.
Private upstreams are no longer probed anonymously, which reported them
as deleted.
2026-10-03 11:23:32 +07:00
tiennm99 a84e158738 feat(gitea-mirror): raise the Gitea clone timeout to one hour
Gitea's default migrate and fetch timeouts cut multi-gigabyte mirrors off
mid-clone. GITEA_CLONE_TIMEOUT sets both, defaulting to 3600 seconds.
2026-10-03 11:23:32 +07:00
tiennm99 d4882c6f3e fix(gitea-mirror): read auth and encryption secrets from the environment
Data encrypted under one secret is unreadable under another, so the
secrets must move with the data instead of being regenerated by the image.
2026-10-03 10:07:34 +07:00
tiennm99 3c737b05cd chore: add sources dir and debug-service skill, make Coolify primary
sources/ holds gitignored upstream checkouts for debugging a service
against its real code; the debug-service skill walks through it. Coolify
is now the primary deployment target and Dokploy optional.
2026-10-03 09:58:52 +07:00
tiennm99 67da7cd870 feat(gitea-mirror): serve gitea and gitea-mirror through the proxy
Drop the localhost-bound ports, read the database password and both
public URLs from the environment, pin gitea to its major tag, add a gitea
health check and disable gitea's SSH server.
2026-10-03 09:58:52 +07:00
tiennm99 b9042fb191 refactor: rename remaining docker-compose.yml files to compose.yml 2026-09-30 15:46:52 +07:00
tiennm99 ea5079fd4e feat(opencode): pass OPENCODE_API_KEY for OpenCode Go and Zen 2026-09-30 15:46:52 +07:00
tiennm99 4c66ec76e6 docs: keep each service README inside its own directory
A service README now describes only its own service: no links to other
services or to the root, and no restating of the shared conventions that
the root README and CLAUDE.md already carry. Each service is a separate
Coolify app on a <service>/** watch path, so a cross-link made editing one
service redeploy another. The rule is recorded at the root; the alloy
compose comment now points at a heading that exists.
2026-09-29 20:00:15 +07:00
tiennm99 daf18abf70 refactor(opencode): rename service directory from opencode-web to opencode 2026-09-29 19:36:11 +07:00
tiennm99 d211e42a4a chore(code-server): install bubblewrap 2026-09-28 15:54:27 +07:00
tiennm99 1d98f2ea95 chore(diun): check for updates once a day at midnight UTC 2026-09-21 08:41:48 +07:00
tiennm99 9da8546d19 feat(goclaw): add multi-tenant AI agent gateway with pgvector postgres 2026-09-20 14:34:57 +07:00
tiennm99 c2b508c171 chore: set restart: unless-stopped on every service
Coolify injects the same value when a compose service omits one, but Dokploy
runs the file as written, so in its default compose mode an omitted policy
leaves the container down after a crash or a host reboot.
2026-09-20 14:34:57 +07:00
tiennm99 b626c5b70d chore(diun): track moving image tags instead of exact pins
Diun follows the upstream major tag 4; the socket proxy follows latest,
since that project publishes no moving major tag.
2026-09-20 12:50:04 +07:00
tiennm99 ad122ab9f2 chore: drop the openhands service
Remove the directory and its row from the root table, the related-services link
in opencode-web, and the workspace-volume convention's reference to it.
2026-09-19 17:44:55 +07:00
tiennm99 24cefe80a2 feat(diun): add diun template reading the Docker API through a proxy
Diun needs the Docker API to enumerate containers and inspect each one's
image. Mounting the socket into it directly is host-root-equivalent, and :ro on
a socket mount is cosmetic, so the socket goes into a docker-socket-proxy
sidecar and Diun reaches it at tcp://dockerproxy:2375. POST is revoked there,
so container create and exec return 403.

CONTAINERS and IMAGES are both required: with CONTAINERS alone the provider
loads and enumerates containers, then every ImageInspect returns 403 and
nothing is analysed. Verified against a live watch cycle — 25 images analysed,
no errors.

Pin crazymax/diun:4.33 rather than :latest, since this is the service whose job
is to talk to the daemon.
2026-09-19 17:18:31 +07:00
tiennm99 c2502d5f44 chore: drop ollama, netdata, per-service licenses and stale plans
Rename gitea-mirror-local to gitea-mirror.
2026-09-19 12:43:05 +07:00
tiennm99 e6dcdfef48 docs(plans): add openhands/opencode-web plan and paseo docs audit 2026-09-18 17:43:03 +07:00
tiennm99 14a5720f7a chore: drop code-server-base
code-server covers the remaining use.
2026-09-18 17:38:07 +07:00