docs: record backlog completion in CLAUDE.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -28,6 +28,15 @@ One login instead of logging into Proxmox, Zabbix, OMV, and every service separa
|
||||
contained. See `docs/ssh-collector-key-setup.md`, including the gotcha that `diskPaths` in
|
||||
`hosts.yaml` must be kept in sync **by hand** with the remote script's `DISK_<label>=` lines.
|
||||
- No Zabbix collector — see "Zabbix: intentionally skipped" below.
|
||||
- **Historical sparklines** (done): `/api/hosts` embeds the last ~40 samples per host (one windowed
|
||||
query, `ROW_NUMBER() OVER (PARTITION BY host_id ...)`), rendered as small hand-rolled SVG sparklines
|
||||
in each card — no charting library. Fixed a real bug while building this: the Proxmox **host node's**
|
||||
own mem/disk had been `null` the whole time (`/nodes/{node}/status` nests `memory`/`rootfs` objects;
|
||||
code assumed the flat shape the *LXC listing* endpoint uses). LXC entries were never affected.
|
||||
- **Hot-reload** (done): `sshHosts`/`knownDevices` in `config/hosts.yaml` are re-read on the next poll
|
||||
cycle (mtime check) — no container restart needed. Proxmox hosts already needed no config (auto-
|
||||
discovered every poll). See `docs/hot-reload.md` — includes a real single-file-bind-mount inode bug
|
||||
that silently broke this on first deploy, fixed by mounting `./config` as a directory.
|
||||
- Auth: local (bcrypt + signed session cookie) is **always** available — it's not an exclusive mode
|
||||
switch. OIDC via Authentik is an *additional* sign-in button, live when `OIDC_ENABLED=true`. See
|
||||
`docs/oidc-setup.md`. Deliberately additive so OIDC config problems can never lock out the admin login.
|
||||
@@ -79,8 +88,16 @@ integration entirely rather than finish configuring a service that's being repla
|
||||
issue #11 is closed as won't-do — if a metrics-alerting panel is wanted later, it should target
|
||||
Grafana/Prometheus once `homelab#15` lands, as a new issue, not a reopening of #11.
|
||||
|
||||
## Known gaps / explicitly deferred (see issues for detail)
|
||||
## Status: original backlog complete
|
||||
|
||||
- No historical charts yet — only the latest snapshot is shown (24h retention in SQLite unused by the UI so far).
|
||||
- Public exposure (issue #13) is half-done: NPM proxy host exists, Cloudflare DNS/tunnel route does not.
|
||||
Needs a Cloudflare API token (Zero Trust: Edit) from the user to finish.
|
||||
All 14 issues filed at project start are closed (10 shipped, #11/Zabbix closed as won't-do, no others
|
||||
skipped). `GET .../issues?state=open` on this repo should return empty. If picking this up again with
|
||||
no specific ask from the user, there's no queued work — check in with them for what's next rather than
|
||||
inventing scope. Remaining known gaps, none blocking:
|
||||
|
||||
- Nobody has clicked "Sign in with Authentik" through an actual browser yet (see note above) — worth
|
||||
confirming next time a human is at the dashboard.
|
||||
- OIDC client credentials aren't in Vaultwarden yet (Proxmox token and admin password are) — needs a
|
||||
`BW_SESSION` from the user, see prior session's request in the conversation history if resuming soon.
|
||||
- `diskPaths` in `hosts.yaml` vs. the remote forced-command scripts on omv/ripper is a manual-sync point
|
||||
(documented, not automated — only 2 hosts, hasn't been worth it).
|
||||
|
||||
Reference in New Issue
Block a user