server infra
  • Python 49.5%
  • HTML 22.6%
  • CSS 10.5%
  • Shell 10.3%
  • JavaScript 4%
  • Other 3.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Corbin 4c3c0c6647
Some checks failed
Configuration checks / validate (push) Has been cancelled
Document QuizDock and LimeSurvey operations
2026-08-27 10:30:22 -05:00
.forgejo Add service catalog and Forgejo work tracking 2026-08-07 14:42:19 -05:00
.gitea/ISSUE_TEMPLATE Improve Forgejo project workflow 2026-08-01 21:38:37 -05:00
ansible Check Docker updates without Buildx 2026-08-23 11:28:17 -05:00
compose Add LAN-only Home Assistant foundation 2026-08-23 08:46:34 -05:00
config Automate AI-enhanced fleet health emails 2026-08-23 09:52:00 -05:00
docs Document QuizDock and LimeSurvey operations 2026-08-27 10:30:22 -05:00
output/pdf Configure bilingual Bazarr subtitles 2026-08-01 16:19:17 -05:00
scripts Expand weekly update intelligence 2026-08-23 11:23:18 -05:00
systemd Ensure Open WebUI starts after network 2026-08-23 11:35:20 -05:00
.gitattributes Revoke stale Forgejo credentials 2026-08-01 11:49:57 -05:00
.gitignore Ignore local site preview artifacts 2026-08-23 08:27:25 -05:00
AGENTS.md Document durable SSH host access 2026-08-25 02:27:59 -05:00
README.md Document QuizDock and LimeSurvey operations 2026-08-27 10:30:22 -05:00

Corbin Infrastructure

The operating record for Corbin's VPS, home server, public services, and recovery process.

Start Here

Need Go to
Find a service or its URL Home services
See what runs where Service catalog
Understand where things run Architecture
Restore something Backups and restore
Recover under pressure Recovery card
Rebuild after a major failure Disaster recovery runbook
Check access and exposure Security baseline
Find a hostname or DNS role Domain layout
See what changed Change log
Pick the next improvement Backlog
Track an idea, task, or incident Work tracking
Understand the local AI assistant AI assistant
Operate or restore the fax portal Fax portal
Connect remotely to home services WireGuard remote access
Connect to an Ubuntu host over SSH SSH access
Operate the NWOMS quizzes and staff survey QuizDock and LimeSurvey operations

Current Estate

Location Purpose Entry point
corbin-edge Public support site, mail, RustDesk, secure sharing, Vaultwarden, and monitoring corbinishelpingyou.online
corbin-media Media, documents, Git, automation, network services, and personal tools 192.168.4.103
corbin-core Fax portal, local AI experiments, and encrypted recovery replica 192.168.4.105
Forgejo Versioned configuration and documentation https://git.corbinishelpingyou.online
Homepage LAN service launchpad and health checks http://192.168.4.103:3002

Working Rules

  • Never commit passwords, private keys, API tokens, Wi-Fi credentials, database dumps, or filled .env files.
  • Back up before changing a live service, validate configuration before restart, then verify the result.
  • Keep public services on the VPS unless there is a deliberate reason to expose a home-hosted service.
  • Treat Git as the intended configuration record, not as a replacement for Restic backups.
  • Create an issue for an idea, incident, or maintenance task before it becomes a vague memory.

Daily Commands

cd ~/corbin-infrastructure
git status
docker ps
systemctl list-timers --all

/home/corbin/corbin-infrastructure on corbin-media is the only supported working checkout. Semaphore mounts that same checkout read-only. Dated or legacy directories must not be used for automation or treated as current documentation.

Repository Layout

  • compose/ - reproducible Docker Compose definitions and non-secret configuration.
  • ansible/ - home-server automation playbooks managed through Semaphore.
  • docs/ - operational notes, recovery procedures, service maps, and change history.
  • scripts/ - checked-in helper scripts; credentials stay on the hosts.
  • systemd/ - timers and service definitions that keep recurring jobs visible.

Before You Change Anything

  1. Read the matching service and recovery documentation.
  2. Create a focused issue if the work is not a quick repair.
  3. Make a backup or confirm the scheduled backup is current.
  4. Verify locally, then verify the public hostname only when that service is intentionally public.
  5. Update the change log and commit the non-secret configuration.