feat(librechat): LAN-only nspawn pilot (host netns, 192.168.0.30:3080) #4

Merged
Faris merged 2 commits from librechat-nspawn into main 2026-10-02 16:09:36 +01:00
Owner

Second AI chat as a systemd-nspawn container, parallel-testing against open-webui (ai. stays on open-webui until cutover). LAN-only like open-webui: not on vlan50, no caddy vhost — access is http://192.168.0.30:3080, admitted by the host firewall for 192.168.0.0/24 only (OTBR 8081 pattern).

  • services.librechat with local DB via enableLocalDB (= services.mongodb, MONGO_URI localhost:27017) + meilisearch
  • privateNetwork = false (host netns) — the one non-vlan50 nspawn alongside OTBR; inner firewall off, host firewall owns exposure
  • Authelia OIDC (auto-redirect, PKCE S256, role admins); client registered in Authelia host state with the LAN callback, client id/secret resolve from the secrets dir like the other creds
  • nixpkgs.config.allowUnfree set inside the container config: the nspawn inner eval is a fresh nixpkgs, so the host allowUnfree does not carry in — mongodb (SSPL) refused to evaluate otherwise
  • mongodb is NOT on cache.nixos.org (Hydra does not build SSPL): first deploy builds it from source (~hours)

Bootstrap (host state, done on the server): /pool/services/librechat{,/secrets} with jwt/creds/meili/openid secret files; tmpfiles rule covers the data dir on other hosts.

Follow-ups: kuma monitor 192.168.0.30:3080 (fleet invariant, LAN-port pattern) with the deploy; mongodump into the db-dump/retic path once there is data worth keeping; AGENTS.md nspawn-fleet posture line for the second host-netns container.

Second AI chat as a systemd-nspawn container, parallel-testing against open-webui (ai. stays on open-webui until cutover). LAN-only like open-webui: **not on vlan50, no caddy vhost** — access is http://192.168.0.30:3080, admitted by the host firewall for 192.168.0.0/24 only (OTBR 8081 pattern). - `services.librechat` with local DB via `enableLocalDB` (= `services.mongodb`, `MONGO_URI localhost:27017`) + meilisearch - `privateNetwork = false` (host netns) — the one non-vlan50 nspawn alongside OTBR; inner firewall off, host firewall owns exposure - Authelia OIDC (auto-redirect, PKCE S256, role `admins`); client registered in Authelia host state with the LAN callback, client id/secret resolve from the secrets dir like the other creds - `nixpkgs.config.allowUnfree` set inside the container config: the nspawn inner eval is a fresh nixpkgs, so the host `allowUnfree` does not carry in — mongodb (SSPL) refused to evaluate otherwise - mongodb is NOT on cache.nixos.org (Hydra does not build SSPL): first deploy builds it from source (~hours) Bootstrap (host state, done on the server): `/pool/services/librechat{,/secrets}` with jwt/creds/meili/openid secret files; tmpfiles rule covers the data dir on other hosts. Follow-ups: kuma monitor `192.168.0.30:3080` (fleet invariant, LAN-port pattern) with the deploy; mongodump into the db-dump/retic path once there is data worth keeping; AGENTS.md nspawn-fleet posture line for the second host-netns container.
feat(librechat): nspawn pilot container on vlan50 .38
All checks were successful
eval / eval (pull_request) Successful in 38s
dc706c32eb
services.librechat + local mongodb (enableLocalDB -> services.mongodb)
and meilisearch; Authelia OIDC gate, caddy-only firewall (.31 -> 3080).
allowUnfree set inside the container config: the nspawn inner eval uses
a fresh nixpkgs, so the host setting doesn't carry in.

Bootstrap (host state, one-time): /pool/services/librechat{,/secrets}
with jwt/creds/meili secret files (done on the server).
fix(librechat): LAN-only — host netns, drop vlan50 and the public vhost
All checks were successful
eval / eval (pull_request) Successful in 21s
97e837bb32
privateNetwork = false (OTBR pattern); host firewall admits
192.168.0.0/24 to 3080, so nothing on vlan50 and no caddy vhost —
nothing publicly routed. OIDC/canonical URLs repointed at the LAN
origin; no proxy hop, so TRUST_PROXY is gone. Register the Authelia
OIDC client (host state) with the LAN callback; client id/secret
resolve from the secrets dir like the other creds. Drop the unused
secretMount: it bound a nonexistent host path (nspawn crash-loop).
Faris changed title from feat(librechat): nspawn pilot container on vlan50 .38 to feat(librechat): LAN-only nspawn pilot (host netns, 192.168.0.30:3080) 2026-10-02 15:54:34 +01:00
Faris merged commit 9890d5d3b2 into main 2026-10-02 16:09:36 +01:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Faris/nixos!4
No description provided.