Files
mw-pfeddersheim-workstation/docs/tech/stack.md
T
mw cbe24c03df docs: add platform/packages/onlyoffice.docs localhost sites + cert regen to Caddy docs
- Added platform.localhost (-> localhost:10080) and packages.localhost
  (-> localhost:20080) to stack.md sites table (total now 17)
- Documented onlyoffice.docs.localhost (pre-existing in Caddy config, was undocumented)
- Regenerated mkcert cert with explicit SANs for the 3 new hostnames
  (onlyoffice.docs.localhost is multi-label, not covered by *.localhost wildcard)
- Fixed wildcard note: multi-label hosts require explicit SANs
- Updated manual-overrides with cert regeneration row + site delta
- Updated CHANGELOG with cert regen + site additions
2026-07-12 13:10:21 +02:00

139 lines
7.3 KiB
Markdown

---
description: >-
Detailed inventory of the core software stack, OS context, and maintenance
policies for the mw-pfeddersheim-workstation.
tags:
- software-stack
- inventory
- tech-stack
last_updated: '2026-07-12'
---
# Software Stack - mw-pfeddersheim-workstation
## Core Development Environment
| Technology | Version | Description |
|------------|---------|-------------|
| **Node.js** | 25.6.1 | Primary JavaScript/TypeScript runtime |
| **Python** | 3.14.3 | Secondary scripting and AI automation language |
| **PHP** | 8.5.3 (CLI) | Legacy and ERP integration language |
| **Ansible** | 2.20.2 (core) | Infrastructure provisioning and configuration |
| **Docker** | 29.2.1 | Containerization and environment isolation |
| **Git** | latest | Version control |
| **ripgrep** | latest | Fast line-oriented search tool (`rg`) |
| **bat** | latest | A `cat` clone with syntax highlighting |
| **rustdesk** | latest | Remote management via Tailscale |
## Desktop Environment
|| Technology | Version | Description |
||------------|---------|-------------|
|| **Hyprland** | 0.55.2 | Wayland compositor (uwsm-managed) |
|| **Waybar** | latest | Status bar (with USB auto-mount module) |
|| **Kitty** | latest | GPU-accelerated terminal emulator |
|| **Fuzzel** | latest | Application launcher (preferred over Wofi) |
|| **Dunst** | latest | Notification daemon |
|| **yazi** | latest | Terminal file manager (full deps: chafa, 7zip, resvg, etc.) |
## Known Issues (2026-05-22 Boot Audit)
| Domain | Issue | Status |
|--------|-------|--------|
| **PCIe slot** | GPU in bottom PCIEX4 slot (PCIe 2.0 x4, ~2 GB/s) instead of top PCIEX16 (PCIe 3.0 x16, ~16 GB/s). **8x bandwidth loss** | **Pending**: physical move required |
| **PCIe slot** | NVMe Samsung PM9A1 running Gen2 x4 (8 GT/s) instead of Gen3 x4 (16 GT/s). May resolve after GPU slot fix + BIOS Gen3 setting | **Pending**: BIOS tuning |
| **Idle daemon** | hypridle SEGV crash loop — sdbus-cpp 2.3.0 ABI break | **Fixed**: sdbus-cpp upgraded to 2.3.1-1 |
| **Webcam (UVC)** | Device 1-10 has multiple UVC control failures (zoom/pan/tilt/iris non-functional due to firmware non-compliance) | Known hardware limitation, core capture works |
| **KVM** | `/dev/kvm` unavailable — libvirtd cannot use hardware acceleration | Open — check BIOS VT-x/AMD-V |
| **Wi-Fi regulatory** | `regulatory.db` firmware missing — channels restricted | Open — install `wireless-regdb` |
| **D-Bus** | Stale `org.kde.kwalletd6.service` file; dunst/kscreen naming mismatches | **Fixed**: kwalletd6 stub removed; kscreen/kscreenlocker/libkscreen uninstalled (35 MiB) |
| **XDG portals** | Deprecated `UseIn` key usage (portals.conf preferred) | Low priority, functional |
**Removed (2026-05-22, ADR 0007)**: All X11 display managers (lightdm, sddm), X11 video/input drivers (xf86-*), X11 tools (xterm, xorg-xinit, x11vnc, etc.), entire KDE Plasma stack (kwin, plasma-desktop, plasma-workspace, plasma-nm, plasma-pa, powerdevil, etc.), and Dolphin (replaced by yazi). `greetd`+`tuigreet` is the active DM. Screenshots use `grim`+`slurp`+`grimblast`.
## Browsers
| Technology | Version | Notes |
|------------|---------|-------|
| **Google Chrome** | 148.0.7778.178 (AUR) | Sole browser — Wayland-native, VA-API on NVIDIA |
| ~~Chromium~~ | ~~removed~~ | All artifacts cleaned 2026-05-22 (see ADR 0006) |
## OS Context
- **OS**: Linux (Manjaro/Arch Linux based)
- **Architecture**: x86_64
## Package Domain Classification (ADR 0007 Tier 4)
Packages previously listed as "Misc" reclassified to functional domains:
| Package | New Domain | Role |
|---------|-----------|------|
| uv | Python Toolchain | Fast Python package/env manager |
| jq | Shell/Terminal | JSON processor |
| inxi | Hardware | System hardware info |
| lsof | Core OS | List open files |
| iproute2 | Network | Advanced routing/networking |
| openresolv | Network | DNS resolver management |
| perl-image-exiftool | Dev Tools | Metadata read/write |
| icoutils | Dev Tools | ICO/ANE cursor extraction |
| innoextract-git | Dev Tools | Inno Setup installer extraction |
| opencl-headers | GPU Compute | OpenCL C headers |
| libxnvctrl-580xx | NVIDIA | NVML/XNVCTRL for 580xx |
| zram-generator | Core OS | Systemd zram swap generator |
| mkinitcpio-openswap | Core OS | Swap resume hook for mkinitcpio |
## Maintenance Policies
- **Updates**: System-wide updates via `pacman` managed through maintenance scripts.
- **Node.js**: Global packages managed via `pnpm`.
- **Python**: Use `uv` for environment management.
- **PHP**: Managed via system package manager, focused on CLI execution.
## Tool Path Summary
- **Ansible**: `/usr/bin/ansible`
- **Python**: `/usr/bin/python`
- **Docker**: `/usr/bin/docker`
## Local Dev Services (Manual - not Ansible-managed)
System-level services running on this workstation that are configured manually
outside this repo's Ansible roles. See `docs/tech/manual-overrides.md` for the
full override table and `docs/learnings/2026-07-06-caddy-onlyoffice-mcp-sse-investigation.md`
for the active Caddy/OnlyOffice investigation.
### Caddy (port 443, systemd `caddy.service`)
| Item | Value |
|------|-------|
| Package | `caddy` (pacman) |
| Service | `caddy.service` (enabled, runs as `caddy` user) |
| Config | `/etc/caddy/Caddyfile` + `/etc/caddy/conf.d/localhost-dev.conf` |
| TLS cert | mkcert-generated pair at `/etc/caddy/localhost{,-key}.pem`; includes explicit SANs for all 19 hostnames (wildcard `*.localhost` only covers single-label subdomains like `mcp.localhost`; multi-label hosts like `onlyoffice.docs.localhost` and `demo.satware.com.localhost` require explicit SANs) |
| Admin endpoint | Unix socket `/run/caddy/admin.socket` |
| Sites | 17 `*.localhost` virtual hosts (see table below) |
#### `*.localhost` sites
| Site | Backend / Handler | Notes |
|------|-------------------|-------|
| `mcp.localhost` | `reverse_proxy localhost:50880` | MCP server (node, pid 1167) |
| `artifacts.localhost` | `file_server browse` root `/var/www/artifacts` | Static artifacts |
| `onlyoffice.localhost` | `reverse_proxy localhost:3847` | OnlyOffice MCP server; emitting `context canceled` SSE aborts (issue [#92](https://gitlab.satware.com/satware/mcp/onlyoffice/-/work_items/92)) |
| `project-1.localhost` ... `project-10.localhost` | `respond "project-N - placeholder"` | 10 reserved placeholders |
| `demo.satware.com.localhost` | `reverse_proxy localhost:38081` | webdevops/php-apache-dev container |
| `platform.localhost` | `reverse_proxy localhost:10080` | amicron-platform Docker (Symfony 7.4 + Vue 3 + Firebird 3.0.14); `~/internal/amicron-platform` |
| `packages.localhost` | `reverse_proxy localhost:20080` | satis Docker (Composer package repository with token-based access control); `~/internal/satis` |
| `onlyoffice.docs.localhost` | `file_server` root `/home/mw/internal/onlyoffice/docs-site/dist` | Starlight static docs build |
Wildcard `*.localhost` only matches single-label subdomains (e.g. `mcp.localhost`).
Multi-label hosts like `onlyoffice.docs.localhost` and `demo.satware.com.localhost`
require explicit SANs in the mkcert cert - they are NOT covered by the wildcard.
### Useful Caddy commands
```bash
sudo caddy validate --config /etc/caddy/Caddyfile --adapter caddyfile
sudo systemctl reload caddy
sudo journalctl -u caddy --no-pager -n 50
curl -sk https://onlyoffice.localhost/ping # test (skips cert verify)
```