45437f27d09c864b1f0d90abf1d27e68e3d13679
清理 chore/recover-old-workspace 时发现以下内容已在线上使用,却只存在于未提交的工作区: - Authelia `backstage` OIDC client(与 helm 现网 values 逐键比对一致;仅含 pbkdf2 哈希, 与既有 client 写法相同)。 - `backstage.ad.ddupan.top` A 记录(现网已解析到 192.168.10.127)。 - CLAUDE.md:VyOS `cli-shell-api showConfig` 尾随节点名不会过滤、会输出含密钥的完整配置。 - .agents/skills/homelab-knowledge:让 agent 查询与维护 homelab-wiki 的技能说明。 Co-Authored-By: Claude Opus 5.5 <[email protected]>
homelab-infra
Infrastructure and service configuration for the homelab. Git is the source of intent; the live estate is being adopted gradually, so a file being present does not yet imply that Flux or CI owns the corresponding resource.
Layout
| directory | purpose |
|---|---|
clusters/homelab/ |
Flux composition and cluster-specific reconciliation entrypoint |
platform/ |
cluster-wide controllers, ingress, storage and observability |
apps/ |
user-facing and supporting applications |
infrastructure/ |
Proxmox, local hosts/VMs, identity, secrets, Cloudflare and OCI |
archive/ |
retired implementations retained for operational history |
docs/ |
architecture decisions, migration plans and runbooks |
Each component remains independently deployable. There is no shared root package or Terraform root, and service-specific Terraform states must remain isolated.
Safety
- Treat the homelab as household production.
- Run Terraform plan and Ansible check/diff before mutation.
- Existing resources require a zero-change adoption plan before CI may apply.
- Never commit Terraform plans/states, live Kubernetes Secrets or plaintext keys.
- Kubernetes will be reconciled by Flux; Backstage is a portal, not a deployer.
- Recovery of PVE, OpenBao and Git must not depend on k3s being healthy.
See the redesign record for the target architecture and phased migration.
Languages
Python
47%
HCL
22.4%
Jinja
20.1%
Go
4.1%
Shell
4%
Other
2.4%