homelab-codex-ws/kb/subsystems/control-plane.md
oskar 4658089e21 fix(kb): przepiecie wszystkich odwolan wewnetrznych po migracji
126 plikow (md, yaml, sh, py) odwolywalo sie do sciezek sprzed migracji.

  15  markdown-linkow [..](..) -> policzona sciezka WZGLEDNA wobec pliku
      odsylajacego (wczesniej czesc z nich byla repo-root-relative i nie
      rozwiazywala sie z katalogu, w ktorym lezala)
 200  odwolan tekstowych (backticki, proza, yaml, importy w kodzie)
      -> nowa sciezka repo-root-relative, zgodnie z konwencja repo
   5  linkow rodzenstwa (gole nazwy plikow, np. "](DEPLOY.md)") — dzialaly
      tylko w starym katalogu; przeliczone recznie

Objete m.in.: CLAUDE.md (scripts/onboard/README.md -> kb/runbooks/
node-onboarding-tool.md, docs/backlog.md -> kb/phases/backlog.md),
README.md, .claude/skills/, 20 session logow, kod jobow.

Ostatnie 5 odwolan pochodzi z tresci wciagnietej rebasem z origin/master
(session log 2026-07-31, override node-agenta na SOLARII, dwie pozycje
backlogu) — wskazywaly na docs/incidents/, docs/kb/modules/ i
services/narty27/README.md sprzed migracji.

Dodany wzajemny link miedzy kb/services/control-plane.md (stub kodu)
a kb/subsystems/control-plane.md (opis, deprecated) — dwa dokumenty o tym
samym systemie, latwe do pomylenia.

Weryfikacja na 790 plikach: 0 odwolan do starych sciezek,
0 martwych linkow markdown. Lint OKF: 190/190 plikow ZGODNE.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 16:58:46 +02:00

4.2 KiB

okf type visibility status updated links superseded_by
0.1 subsystem private deprecated 2026-05-27
../services/control-plane.md
../runbooks/control-plane-deploy-recovery.md
przepisany tor redeploy, commity da151fc/79bfe8c 2026-08-03

VPS Control Plane

The VPS Control Plane is the orchestration brain of the homelab platform. It runs on the Hetzner VPS (Tailscale IP: 100.95.58.48) and provides observability, automated reconciliation, and a web-based operator interface.

Architecture

The control plane consists of four core services running as a Docker Compose stack under services/control-plane/:

Container Role
control-plane-observer Synthesizes world state from events in /opt/homelab/events/
control-plane-supervisor Detects drift between desired state (hosts/*/services.yaml) and actual state (world/services.json); writes pending actions
control-plane-executor Executes approved actions from /opt/homelab/actions/approved/
control-plane-ui Web interface for system monitoring and action approval; serves port 18180

All services use filesystem-first semantics with /opt/homelab/ as the data exchange layer. All four run with network_mode: host and as UID 1000 (homelab user).

Supervisor Behavior

Desired State

Loaded from hosts/*/services.yaml each reconcile cycle. Services with monitor: false are silently skipped — use this for services without a node-agent (e.g. homeassistant on chelsty-ha).

Drift Types

  • missing_service — service is in desired state but absent from services.json
  • unhealthy_service — service exists in services.json but status != healthy

Action Types

Trigger Action type Risk
containers_not_running, mqtt_unreachable container_restart low
Any other / unknown redeploy guarded
Node disk_pressure: high disk_cleanup guarded

Action ID Stability

Action IDs are deterministic: redeploy-{node}-{service} or container-restart-{node}-{service}. The same drift always produces the same filename, making reconcile truly idempotent across supervisor restarts.

Auto-Cancel

Pending redeploy and container_restart actions are automatically moved to cancelled/ when:

  • drift_resolved_auto — the service becomes healthy in actual state
  • service_removed_from_desired_state — the service was removed from services.yaml or marked monitor: false

Only pending actions are auto-cancelled. Approved/running actions have been committed to by the operator and are never cancelled automatically.

Node Name Resolution

The supervisor supports a NODE_ALIAS_MAP environment variable (JSON string) to map event/world-state node names to canonical topology names:

NODE_ALIAS_MAP='{"node-2": "chelsty-infra", "node-1": "piha"}'

Action Approval Workflow

Supervisor writes → /opt/homelab/actions/pending/<id>.json
                 → Operator UI (port 18180) or Telegram Bot notifies
                 → Operator clicks Approve
                 → /opt/homelab/actions/approved/<id>.json
                 → Executor executes → completed / failed

Possible action states: pending → approved → running → completed / failed / rejected
Auto-cancel path: pending → cancelled/

Integration

piha agent-system webui (port 18180 on piha)

The agent-system-runtime-materializer on piha polls the VPS control-plane API every 10 seconds and mirrors world state to piha's local /opt/homelab/world/. This ensures the "Copy for AI" button in the piha webui (agent-system-webui) reflects the same clean state as the VPS API.

Override: hosts/piha/runtime/agent-system/docker-compose.override.yml — sets CONTROL_PLANE_URL=http://100.95.58.48:18180.

Nginx Proxy Manager

The operator UI at port 18180 can be proxied via NPM for external access. No WebSocket support required.

Log Locations

  • Container logs: docker compose logs -f (from services/control-plane/)
  • Runtime events: /opt/homelab/events/YYYY-MM-DD/
  • World state: /opt/homelab/world/
  • Action queue: /opt/homelab/actions/{pending,approved,running,completed,failed,cancelled}/