Documentation Page Inventory
This register classifies every Markdown page in the handbook. It prevents a dated assessment, migration record, or compatibility URL from silently returning to the current operating path.
Last reviewed: 2026-07-17.
How to Read the Register
The lifecycle and authority in each row apply to every listed file. A volatile runtime fact is current only through the row's verification date. The evidence register defines confidence labels and source priority.
| Lifecycle | Meaning |
|---|---|
| Current | Supported entry point, reference, or procedure |
| Transitional | Useful current material still being consolidated |
| Historical | Evidence or a retired procedure; do not operate from it |
| Compatibility | Preserves an old URL and points to a current replacement |
Entry Points and Current Architecture
| Files | Purpose | Lifecycle | Last verified | Likely authority | Known conflict or replacement |
|---|---|---|---|---|---|
index.md; tutorials/getting-started.md |
Handbook entry and first administrator tutorial | Current | 2026-07-17 | Repository workflow and canonical pages | Replaces README-only onboarding |
current/index.md; current/inventory.md; current/network.md; current/dependencies.md |
Architecture, inventory, network, and dependency maps | Current, canonical | 2026-07-17 | Live read-only checks plus repository configuration | Replaces duplicated facts in migration and recovery pages |
current/proxmox.md; current/virtual-machines.md; current/containers.md; current/cloud-services.md |
Compute and cloud inventory | Current, canonical | 2026-07-17 | pveversion, qm, pct, and live host checks |
Older pve02, VM 110, and CT 100 records are historical |
current/opnsense.md |
Active firewall reference and safe validation path | Current with explicitly unverified runtime fields | 2026-07-17 attempt; last successful configuration evidence 2026-07-02 | Proxmox VM config, prior OPNsense evidence, approved UI/API path | Replaces current/pfsense.md |
current/podman-ecosystem.md; current/compose-to-quadlet.md |
Rootless Podman standard and conversion procedure | Current | 2026-07-17 runtime; procedure reviewed 2026-07-17 | CT 101 Quadlets, user systemd, and Podman state |
Replaces Docker and Compose as the production standard |
current/tailscale-headscale-client-onboarding.md; current/vps-headscale-headplane.md |
Remote access, control plane, nodes, and routes | Current | 2026-07-17 | Live Headscale and CT 105 state |
Earlier sections that name only the DMZ route are superseded by the dated route record |
current/publishing.md |
Canonical publication architecture | Current, canonical | 2026-07-17 | Forgejo workflow, runner config, CT 101 Quadlet, CT 103 Caddyfile |
Replaces Drone and direct CT 103 publication |
Operations and Reference
| Files | Purpose | Lifecycle | Last verified | Likely authority | Known conflict or replacement |
|---|---|---|---|---|---|
operations/index.md; current/runbooks.md |
Runbook entry and old-URL compatibility | Current / compatibility | 2026-07-17 | Current operations section | Former current-page procedure list was replaced |
operations/infrastructure-validation.md |
Read-only estate validation | Current | 2026-07-17 | Commands exercised against live hosts | None |
operations/documentation.md; operations/publishing.md |
Authoring, QA, build, CI failure, and stale-site procedures | Current | 2026-07-17 | scripts/docs_qa.py, MkDocs, workflow, live publishing path |
Replaces ambiguous local/Drone guidance |
operations/caddy.md; operations/static-sites.md; current/static-html-caddy-runbook.md |
Diagnose ingress and publish static sites through a separate backend; preserve the former URL | Current / compatibility | 2026-07-17 | Live CT 101 and CT 103 patterns |
Replaces direct static-file hosting on ingress CT 103 |
operations/backup-recovery.md |
Current backup scope, restore order, and publishing-artifact recovery | Current with gaps | 2026-07-17 | Live storage and repository scripts | Historical backup suite does not cover the full current estate |
operations/security.md; operations/redaction.md |
Secret handling and safe configuration evidence | Current | 2026-07-17 | Repository policy and redaction workflow | redaction.md retains a pfSense example solely for historical exports |
operations/change-and-retirement.md |
Add or update infrastructure records and retire systems safely | Current | 2026-07-17 | Handbook maintenance standard | None |
current/local-dns-certificate-runbook.md; current/kh3-cli.md |
Specialized operations | Transitional | 2026-07-17 review | Repository scripts and dated environment evidence | Verify live state before use |
current/podman-restore-runbook.md; current/post-recovery-validation.md; current/backups.md |
Podman recovery plus recovery validation and gap register | Current / historical where labelled | 2026-07-17 review | Podman scripts and current inventory | Old Docker-era validation is explicitly historical |
reference/evidence.md; reference/page-inventory.md; reference/image-sources.md; current/network-production-hardening.md |
Evidence rules, page and image lifecycle, and dated network findings | Current reference | 2026-07-17 | Live checks, user-confirmed facts, dated findings, and recorded image provenance | Hardening record is not authorization to change live policy |
Current Service Pages
| Files | Purpose | Lifecycle | Last verified | Likely authority | Known conflict or replacement |
|---|---|---|---|---|---|
services/index.md |
Canonical service catalog and lifecycle register | Current, canonical | 2026-07-17 | Live container, systemd, listener, and route checks | Retired services are separated below |
services/platform/forgejo.md; services/platform/dns.md; services/platform/caddy-docs.md |
Source control/CI, Technitium DNS, and documentation static backend | Current | 2026-07-17 | CT 101–103 runtime and configuration |
Replace Drone, Pi-hole/Cloudflared, and Nginx models |
services/data/postgresql.md; services/data/adminer.md |
Current shared database and administration UI | Current | 2026-07-17 | CT 101 Podman state and Quadlets |
MariaDB and MongoDB are historical |
services/applications/vaultwarden.md; services/applications/rustdesk.md |
Current application services | Current / RustDesk transitional until external validation | 2026-07-17 | CT 101 and CT 106 evidence plus repository scripts |
RustDesk work existed locally before this modernization and was preserved |
services/websites/index.md; services/websites/kh3-dev-site.md |
Website lifecycle catalog and active development site | Current | 2026-07-17 review; live site state dated in page | Quadlet and ingress evidence | Other website pages are historical |
Hardware
| Files | Purpose | Lifecycle | Last verified | Likely authority | Known conflict or replacement |
|---|---|---|---|---|---|
hardware/index.md; hardware/servers/index.md; hardware/servers/optiplex-7040.md |
Physical inventory and active Proxmox host | Current | Runtime 2026-07-17; chassis facts 2026-06-09 | Proxmox/DMI evidence and photographs | pve02 and Proxmox 8 records are superseded |
hardware/servers/rs816.md |
NAS/storage evidence | Unverified current endpoint | 2026-07-01 | Network probe and historical records | 192.168.100.250 is not accepted as current |
hardware/edge/starlink-gen3.md; hardware/edge/wifi6-router.md |
Edge equipment | Current / partially unverified | 2026-07-01 | Network observation and user confirmation | .100 is Starlink-side, not the internal LAN |
hardware/network/index.md; hardware/network/sf3000-24p.md; hardware/network/rt2600ac.md; hardware/network/hg8245w5.md |
Network-device inventory | Unverified | 2026-07-17 documentation review | On-site capture required | OPNsense remains the routed boundary |
hardware/network/hg8245h.md; hardware/servers/290-g1.md |
Replaced ISP and compute hardware | Historical | 2026-06-09 evidence | Repository photographs and inventory | Replacements are linked from each page |
Decisions
| Files | Purpose | Lifecycle | Date | Authority | Known conflict or replacement |
|---|---|---|---|---|---|
decisions/index.md; decisions/0001-rootless-podman.md; decisions/0002-dedicated-dns-ingress.md; decisions/0003-opnsense.md; decisions/0004-subnet-router.md; decisions/0005-forgejo-actions-docs.md; decisions/0006-docs-static-backend.md; decisions/0007-secrets-separation.md |
Consequential architecture decisions and rationale | Accepted | 2026-07-17 record; decisions date from June–July 2026 | Verified architecture and retained transition evidence | Superseded technologies are named in each ADR |
Historical and Compatibility Pages
| Files | Purpose | Lifecycle | Evidence date | Likely authority | Current replacement |
|---|---|---|---|---|---|
history/index.md; current/retired.md |
Historical entry and retired-system register | Historical index | 2026-07-17 review | Service catalog and dated records | Current architecture |
current/pfsense.md; current/docker.md |
Retired firewall and application runtime | Historical | June 2026 | Redacted exports and old runtime capture | OPNsense and rootless Podman |
current/caddy-technitium-migration.md; current/agent-handoff-caddy-technitium.md |
Completed migration evidence and old URL | Historical / compatibility | 2026-07-02 | Dated migration observations | Current architecture, DNS, and Caddy runbooks |
current/backup-runbook.md; current/clean-rebuild.md; current/pre-reinstall-checklist.md; current/recovery-assessment.md; current/recovery-assumptions.md; current/recovery-script-usage.md; current/restoration-runbook.md; current/restoration-validation.md |
Docker/pfSense recovery plans and experiments | Historical | June 2026 | Repository scripts and dated assessment | Current backup/recovery and Podman restore guides |
services/platform/nginx-docs.md; services/platform/docker.md; services/platform/traefik.md; services/platform/drone.md; services/platform/portainer.md |
Old documentation-serving and platform services | Historical / compatibility | June–July 2026 | Old configs and migration evidence | Static Caddy, Podman, Forgejo Actions |
services/data/mariadb.md; services/data/mongodb.md |
Retired or unverified databases | Historical | June 2026 | Old Docker inventory | PostgreSQL |
services/applications/appsmith.md; services/applications/homebox.md; services/applications/meshcentral.md; services/applications/receiptapp.md; services/applications/stirling-pdf.md |
Retired or unverified applications | Historical | June 2026 | Old Docker inventory | Service catalog |
services/websites/dashboard.md; services/websites/kh3website.md; services/websites/khysite.md; services/websites/khywebsite.md; services/websites/noticeboard.md; services/websites/website.md |
Retired website records | Historical | June 2026 | Old proxy and content records | Website catalog and KH3 development site |
reports/refactor-2026-06-09.md |
Dated documentation refactor report | Historical | 2026-06-09 | Repository change record | This handbook and page register |
Maintenance Procedure
- Add every new Markdown file to
mkdocs.yml. - Add it to this register or to a row whose scope explicitly includes it.
- Identify one canonical page for every new volatile fact.
- Add a historical label before retaining obsolete commands.
- Run
python3 scripts/docs_qa.pyandmkdocs build --strict.
The QA script enforces navigation coverage, but lifecycle and authority still require an administrator's review.