Stack analysis: feature gaps and divergence from other homelabs #116

Open
opened 2026-08-17 15:07:10 -04:00 by mysticalsoap · 1 comment
Owner

Analyze the stack via the repo and wiki and point out feature gaps and general improvements, especially things missing or different compared to other homelabbers. Plenty of additions are already planned; the interesting output is specifically where this stack diverges.

Analyze the stack via the repo and wiki and point out feature gaps and general improvements, especially things missing or different compared to other homelabbers. Plenty of additions are already planned; the interesting output is specifically where this stack *diverges*.
Author
Owner

Analysis done (repo + _helper/docs + open issues). Confirmed gaps filed as issues, each with the reasoning inside:

  • #121 — brute-force detection doesn't follow the ForwardAuth trades to Vaultwarden/Navidrome (the one real security follow-through the bypass model still owes)
  • #122 — Vaultwarden OIDC SSO exists upstream now; the exclusion reasoning predates it
  • #123 — no UPS (2026-08-10 outage was the rehearsal)
  • #124 — btrfs scrub misses the root fs and /mnt/support
  • #125 — offsite RPO is the USB swap cadence; VPS append-only restic copy fixes it
  • #126 — unhealthy containers alert nothing (Monitoring.md already says so)
  • #127 — no CAA record

Refinements commented on #94 (five concrete doc-drift items), #109 (VPN hub belongs on the VPS, not a home port), #101 (frps transport.tls.force + non-root unit).

Divergences that are deliberate and hold up (no action): frp+VPS instead of Cloudflare Tunnel, Renovate+digest pins instead of Watchtower, route-allowlisted socket proxies instead of raw docker.sock mounts, offline offsite instead of cloud, single host instead of Proxmox/VM sprawl (Podman migration is the tracked answer to its isolation half). Full writeup in the session log.

Analysis done (repo + `_helper/docs` + open issues). Confirmed gaps filed as issues, each with the reasoning inside: - #121 — brute-force detection doesn't follow the ForwardAuth trades to Vaultwarden/Navidrome (the one real security follow-through the bypass model still owes) - #122 — Vaultwarden OIDC SSO exists upstream now; the exclusion reasoning predates it - #123 — no UPS (2026-08-10 outage was the rehearsal) - #124 — btrfs scrub misses the root fs and /mnt/support - #125 — offsite RPO is the USB swap cadence; VPS append-only restic copy fixes it - #126 — unhealthy containers alert nothing (Monitoring.md already says so) - #127 — no CAA record Refinements commented on #94 (five concrete doc-drift items), #109 (VPN hub belongs on the VPS, not a home port), #101 (frps `transport.tls.force` + non-root unit). Divergences that are deliberate and hold up (no action): frp+VPS instead of Cloudflare Tunnel, Renovate+digest pins instead of Watchtower, route-allowlisted socket proxies instead of raw docker.sock mounts, offline offsite instead of cloud, single host instead of Proxmox/VM sprawl (Podman migration is the tracked answer to its isolation half). Full writeup in the session log.
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
mysticalsoap/docker#116
No description provided.