feat(librechat): LAN-only nspawn pilot (host netns, 192.168.0.30:3080) #4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "librechat-nspawn"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Second AI chat as a systemd-nspawn container, parallel-testing against open-webui (ai. stays on open-webui until cutover). LAN-only like open-webui: not on vlan50, no caddy vhost — access is http://192.168.0.30:3080, admitted by the host firewall for 192.168.0.0/24 only (OTBR 8081 pattern).
services.librechatwith local DB viaenableLocalDB(=services.mongodb,MONGO_URI localhost:27017) + meilisearchprivateNetwork = false(host netns) — the one non-vlan50 nspawn alongside OTBR; inner firewall off, host firewall owns exposureadmins); client registered in Authelia host state with the LAN callback, client id/secret resolve from the secrets dir like the other credsnixpkgs.config.allowUnfreeset inside the container config: the nspawn inner eval is a fresh nixpkgs, so the hostallowUnfreedoes not carry in — mongodb (SSPL) refused to evaluate otherwiseBootstrap (host state, done on the server):
/pool/services/librechat{,/secrets}with jwt/creds/meili/openid secret files; tmpfiles rule covers the data dir on other hosts.Follow-ups: kuma monitor
192.168.0.30:3080(fleet invariant, LAN-port pattern) with the deploy; mongodump into the db-dump/retic path once there is data worth keeping; AGENTS.md nspawn-fleet posture line for the second host-netns container.services.librechat + local mongodb (enableLocalDB -> services.mongodb) and meilisearch; Authelia OIDC gate, caddy-only firewall (.31 -> 3080). allowUnfree set inside the container config: the nspawn inner eval uses a fresh nixpkgs, so the host setting doesn't carry in. Bootstrap (host state, one-time): /pool/services/librechat{,/secrets} with jwt/creds/meili secret files (done on the server).feat(librechat): nspawn pilot container on vlan50 .38to feat(librechat): LAN-only nspawn pilot (host netns, 192.168.0.30:3080)