feat: infrastructure dashboard (Homepage) generated from the service registry
lint / yamllint + ansible-lint + syntax-check (push) Canceled after 0s

playbooks/dashboard.yml deploys Homepage as a second compose stack on the
monitoring LXC (CT 155) next to Uptime Kuma and renders its config from
homelab_services: one tile per service, link to its UI, grouped by Proxmox
node. Adding a service to the registry is enough — no second service list.

- new registry consumer: playbooks/dashboard.yml + playbooks/templates/homepage-*.j2
- homelab_dashboard_* vars in group_vars/all/services.yml (top-level, like
  homelab_reverse_proxy_*); image pinned by digest, floating tag needs an
  explicit -e dashboard_allow_floating_tag=true
- bootstrap-dashboard-pve-token.yml: read-only homepage@pve!dashboard token
  (PVEAuditor) for the Proxmox widget, secret in the root .env as DASHBOARD_PVE_*
- Makefile: dashboard, dry-dashboard, bootstrap-dashboard-token
- container binds the LAN address only (192.168.1.30:8082), not published via Caddy
- docs: architecture.md Monitoring section, plan.md active task, consumer lists

Deployed to CT 155 on 2026-09-03: container healthy, http://192.168.1.30:8082/
returns 200, `make dashboard` idempotent, `make validate` and `make lint` green.
Pending operator steps: `make bootstrap-dashboard-token` (blocked in the agent
session as credential creation) and an Uptime Kuma status page with slug homelab.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KbuZrUoevfBgCpf5DCF4DG
This commit is contained in:
Dmitry
2026-09-03 09:17:16 +03:00
co-authored by Claude Sonnet 5
parent ca48ef2696
commit 05d8c748ab
13 changed files with 484 additions and 2 deletions
@@ -0,0 +1,21 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
# {{ ansible_managed }}
# Рендерится playbooks/dashboard.yml (роль compose_service). Правь шаблон,
# а не файл на хосте: следующий прогон перезапишет.
services:
homepage:
image: {{ dash_image }}
container_name: homelab-homepage
restart: unless-stopped
env_file:
- ./homepage.env
environment:
HOMEPAGE_ALLOWED_HOSTS: "{{ dash_allowed_hosts | trim }}"
ports:
# Только LAN-адрес CT 155 -> контейнерный 3000. Наружу не публикуется.
- "{{ dash_bind }}:{{ dash_port }}:3000"
volumes:
- ./config:/app/config
# Docker-сокет намеренно НЕ монтируется: сервисы живут на других хостах,
# а лишний доступ к сокету на LAN-видимом контейнере не нужен.
networks: {}