homelab-codex-ws/hosts/vps
oskar 11f3f808e6 fix(vps): M1 mitigation — NODE_TYPE=lte_node disables unfiltered prune
node-agent calls docker containers.prune() with no filters every
CHECK_INTERVAL (60 s on VPS). The Docker API removes EVERY non-running
container regardless of RestartPolicy or compose labels — this destroyed
ollama@solaria on 2026-07-30 (19 s after an operator `docker stop`).

On VPS the blast radius is worse: humanai-mailer and humanai-landing have
no compose definition in this repo (recreated by hand from `docker inspect`),
so a pruned container there is an irreversible loss of the only config source.

self.node_type is read only by run_safe_cleanup() (node_agent.py:648,654) and
two log lines (250, 1103). Verified additionally for VPS: the control-plane
filesystem rotation and health probe in run_once() are gated on
`node_name == VPS_NODE_NAME`, not node_type — so they keep running. Monitoring,
event shipping and action dispatch are likewise unaffected.

Temporary — remove once R1 (explicit-enumeration prune) is deployed.
Refs docs/incidents/2026-07-30-ollama-solaria-vanish.md §7 M1.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 16:20:02 +02:00
..
runtime fix(vps): M1 mitigation — NODE_TYPE=lte_node disables unfiltered prune 2026-08-04 16:20:02 +02:00
capabilities.yaml Add node capability model 2026-05-11 20:46:50 +02:00
host.yaml feat(hosts): add os_hostname field to all host.yaml files 2026-06-24 22:24:34 +02:00
README.md Add infrastructure standards and deployment conventions 2026-05-07 21:16:03 +02:00
services.yaml feat(hosts): reconcile desired state with reality on vps, piha, saturn, lustro 2026-07-30 15:36:23 +02:00

VPS - Public Edge + Ingress Node

Role

  • Public-facing reverse proxy.
  • HTTPS termination (Let's Encrypt).
  • Edge security and routing.

Configured Services

  • Nginx Proxy Manager (NPM)
  • Authelia / Authentik (Auth)

Runtime Data

  • /opt/homelab/data/npm