Repository navigation
Releases: HoneyBearTech/homelab-ares
Releases · HoneyBearTech/homelab-ares
Release list
homelab-ares v0.1.0
The first release: the Ares stack as a Compose file, every image pinned by version tag and digest for
linux/arm64, with health checks, autoheal, backups and release signing around it.
Upgrading
- Uptime Kuma's slim image has no Chromium: change any "Real Browser" monitor to another type before upgrading.
- PeaNUT 6 runs as uid 1000 (
chown 1000:1000its settings directory), puts its web UI and API behind a login it
asks for on first start, and its metrics then need that login (HTTP Basic auth works for Prometheus). - Portainer updates are no longer merged automatically: the server and its agents are updated together.
Added
compose.yamlwith 6 services: Nginx Proxy Manager 2.16.0, Uptime Kuma 2.5.5 (slim), PeaNUT 6.0.0 and
Portainer CE 2.39.8 (Alpine variant), each pinned by version tag and digest forlinux/arm64, plus autoheal and
socket-proxy. Data paths, volumes and the proxy's network come from settings (NPM_DATA_PATH,
NPM_LETSENCRYPT_PATH,PROXY_NETWORK,UPTIME_KUMA_VOLUME,PEANUT_CONFIG_PATH,PORTAINER_VOLUME), so an
existing installation's data can be adopted; the proxy's network is created outside the stack, so its address
range survives rebuilding it.- A health check for every service, and autoheal, which restarts any service whose health check fails and can
post each restart to a webhook (WEBHOOK_URLin the optional, gitignoredautoheal.env). It reaches Docker only
throughsocket-proxy, which allows listing, inspecting, restarting and stopping containers and nothing else,
on an internal network with no published port. Labelled policy exceptions:docker-socketfor Portainer and
socket-proxy,latestfor autoheal. - The smoke test replaces
*_VOLUMEand*_NETWORKsettings with throwaway ones, and checks that autoheal
restarts a container that turns unhealthy. - Project policies (
SECURITY.md,CONTRIBUTING.md,GOVERNANCE.md,SUPPORT.md,CODE_OF_CONDUCT.md) and
docs: quick start, installing, upgrading, rebuilding, architecture, interfaces, security requirements,
assurance case, dependencies, roadmap and verifying releases. scripts/check_compose.py: the stack's policy check (every image pinned asname:tag@sha256:<digest>, no
latest, no build, nothing privileged, no added capabilities, host network or PID namespace, no Docker
socket mount, a health check on every service, unless a service'sorg.honeybeartech.ares.allow.<rule>
label gives the reason), and the CycloneDX SBOM of the images for releases; tests with a 90 % branch-coverage
floor.scripts/backup.shandscripts/restore.sh: back up every service's read-write data mounts and the
settings files with a manifest and checksums (readable only by the user who ran it), and restore them after
verifying the checksums and asking first.scripts/smoke-test.shstarts the stack with throwaway settings,
waits until every service is healthy and runs a backup and restore round trip.- CI on every change: ruff, yamllint, shellcheck, actionlint, gitleaks over the whole history, the checker's
tests, the policy check and the smoke test on an arm64 runner. CodeQL,
OpenSSF Scorecard, dependency review, a DCO check and a weekly image scan (Trivy) also run. - Dependabot for the images, the Python tools and the Actions; patch and minor updates merge automatically
once every required check passes, major updates wait for the maintainer. - A release workflow that publishes a source archive, the SBOM,
SHA256SUMSsigned keylessly with cosign,
and SLSA build provenance (docs/verifying-releases.md).
Security
- Triage of the first image scan (2,525 HIGH and CRITICAL alerts with a fix upstream): Uptime Kuma moves to the
slim image, without Chromium and the embedded MariaDB (1,890 → 146 alerts); Nginx Proxy Manager 2.16.0 (503 → 92);
PeaNUT 6.0.0 (87 → 26, three critical issues in its web framework fixed); Portainer 2.39.8 (60 → 8). What's left,
and why: docs/dependencies.md.
Verify this release: docs/verifying-releases.md