Wiki

Guestwiki — LXC 115 @ 10.0.1.35
RoleStatic site host for this documentation
Tailnet— (HTTP-only; caddy proxies, like every other service)
Webroot/var/www/wiki
Update./deploy.sh local from the operator machine

Purpose

Serves the rendered Quartz build of this vault to tailnet users at wiki.«MYDOMAIN». A curated subset of the same content also publishes publicly to Cloudflare Pages — the two-audience split lives in the build, not in the guest.

Pipeline

The infra-wiki repo carries only content + config (Quartz 5, pinned OCI image — builds run in podman, no host Node needed):

  • ./sync-content.sh — rsync the sanitized docs mirror into content/
  • ./build.sh → public/ — the full site, deployed here
  • ./build.sh --portfolio → public-portfolio/ — portfolio.exclude drops whole pages; private HTML-comment markers in the docs source strip blocks / inline spans / table rows from kept pages (conventions and the malformed-marker guard are documented in build.sh)
  • ./deploy.sh local — rsync -az --delete public/ to the webroot over ssh (wiki alias → ProxyJump «HOSTNAME»; same jump path as devvm — the guest isn’t tailnet-joined because nothing non-HTTP is served)
  • ./deploy.sh portfolio — containerized wrangler uploads public-portfolio/ to Pages (huevoconchorizo.pages.dev; creds resolve env → .deploy.env → pass: infra-wiki/cloudflare-*)
  • WIKI_PAGE_TITLE / PORTFOLIO_PAGE_TITLE (env → .deploy.env → pass entries infra-wiki/site-title / infra-wiki/portfolio-title) override pageTitle per audience — the tailnet site shows the real project name without it ever entering the repo

Serving quirks

Quartz emits leaf pages as x.html and folder pages as x/index.html; caddy’s file_server doesn’t do .html resolution, so the guest Caddyfile needs try_files (this is what static hosts like Pages do natively — it isn’t automatic on a bare file server):

:80 {
	root * /var/www/wiki
	try_files {path} {path}.html {path}/index.html
	file_server
	encode zstd gzip

	handle_errors {
		rewrite * /404.html
		file_server
	}
}

Guest caddy is Debian 13’s packaged caddy — the cloudsmith repo’s signing key currently fails trixie’s sqv verification, so the distro package is the clean path anyway.

The site itself is fully self-contained: fonts and the graph libs are vendored in content/static/ + content/vendor/ (no runtime CDN), and a tiny local theme-default plugin seeds dark mode for first-time visitors.

Guest notes

  • pct create 115 — unprivileged, Debian 13 standard, 1 vCPU / 512 MiB / 4 GiB on main, vnet0 static IP, onboot. No nesting or keyctl — nothing containerized inside; builds happen elsewhere.
  • Needs rsync + caddy from apt; webroot writable by the deploy user (rsync --delete prunes stale emitted files).