This page documents major changes in the Enclari server setup and documentation.
- SSH hardening: password and keyboard-interactive login disabled (
/etc/ssh/sshd_config.d/00-hardening.conf);
/ops/security previously claimed this, but the default PasswordAuthentication yes was active
- EventKit CI/CD: GitHub Actions builds and deploys on merge to
main; new restricted user deploy
(forced command + sudoers for /usr/local/bin/eventkit-deploy only)
- Deployed EventKit at eventkit.enclari.com
- Own project (Next.js + Payload 3), image from ghcr.io/kubasobecki/eventkit
- Postgres 17 on an isolated internal network (
internal: true)
- Daily pg_dump with 7-day local retention
- Integrated with backup.sh (Restic + pCloud)
- System update: all packages upgraded, kernel 6.8.0-142, Docker 29.8, Compose v5.5
- Removed orphaned Watchtower container (incompatible with the Docker 29 API, was restart-looping)
- Added documentation page: /apps/eventkit
- Wiki cleanup after on-server checks: fixed backup tags and commands (wordpress, twenty, portainer → system),
Wiki.js and Portainer compose/location, ForwardAuth is @file (not @docker), apps index and AI context links;
added Known issues to /ops/security
- Portainer put behind Authentik ForwardAuth (new
Portainer Gate proxy provider; OIDC login kept)
- Fixed Portainer OAuth login: Access token URL pointed to a non-existent domain (
auth.agenclarienta.com)
- Server type confirmed as CX33 (upgraded from CX32, date not recorded)
- Deployed Activepieces at flow.enclari.com
- Self-hosted automation platform (MIT), Docker Compose
- Integrated with backup.sh (Restic + pCloud)
- Installed Twenty CRM at crm.enclari.com
- Self-hosted CRM, Docker Compose
- Daily pg_dump with 7-day local retention
- Integrated with backup.sh (Restic + pCloud)
- Updated architecture diagram — removed Nextcloud, added Activepieces and Twenty CRM
- Added documentation pages: /apps/activepieces, /apps/twenty
- Added tags to all Wiki.js pages
- Added Wiki.js at https://docs.enclari.com
- Integrated with Authentik via OIDC
- Search configured with PostgreSQL (simple language)
- Logging set to JSON
- Completed initial documentation in Wiki.js
- Platform pages: Traefik, Authentik
- Apps: WordPress, Portainer, Dashy, Netdata, Wiki.js, Archived
- Ops: Backup, Security, Runbooks
- Meta: Changelog
- Deployed Authentik 2025.8.1
- Protected Traefik dashboard, Portainer, Dashy, Netdata, phpMyAdmin with ForwardAuth
- Integrated Wiki.js with OIDC
- Integrated Authentik into backup system (
service=authentik)
- WordPress restored and verified from backups
- phpMyAdmin deployed alongside WordPress stack
- Portainer installed for container management
- Dashy installed as a dashboard
- Nextcloud and Collabora removed (archived, backups kept)
- Backup script refactored to
/root/backup.sh with auto-discovery of services and volumes
- Initial VPS setup on Hetzner CX32 (later upgraded to CX33)
- Ubuntu 24.04 LTS
- Docker + Traefik reverse proxy
- Wildcard DNS with Hetzner DNS
- Let's Encrypt DNS-01 certificates
- WordPress + MariaDB deployed as first app
- Restic + rclone configured with pCloud backend
- Basic backup policies established
- Initial testing environment prepared
- First successful Docker + Traefik deployment