diff --git a/README.md b/README.md index b8b45c5..da47b69 100644 --- a/README.md +++ b/README.md @@ -10,6 +10,11 @@ Ansible playbooks for deploying MeshCore monitoring nodes (Raspberry Pi Zero W / | dm-ashwell | Pi Zero 2 W (armv7) | zero2_w | | dm-edworth | Pi Zero 2 W (armv7) | zero2_w | +There's also a fourth capture node, **dotminipc** (device name `dm-stotfold`) — +not managed by this repo (it's a Docker container on the shared dotnetwork +host, not a dedicated Pi), but documented below since it's the same upstream +software and shares config with the Pi fleet. See "dotminipc" below. + ## Prerequisites **Local machine:** @@ -72,7 +77,7 @@ You'll be prompted for a Tailscale auth key — leave blank if the node is alrea 1. **wifi** — configures NetworkManager connections for `dotnetwork` (home), `dotmobile` (phone hotspot, field troubleshooting fallback), and the host's deployed-location network 2. **base** — apt upgrade, installs screen/pipx/vnstat/git, sets MOTD, authorizes SSH keys for both laptop partitions, installs Tailscale (always) and authenticates it (only if `tailscale_auth_key` is set — otherwise run `sudo tailscale up` manually once, see checklist above) 3. **meshcore_cli** — installs `meshcore-cli` via pipx -4. **meshcore_capture** — runs the agessaman/meshcore-packet-capture install script (skipped once already installed — see "meshcore-packet-capture install is interactive" above, this needs a manual first run), writes `.env.local` config, enables `meshcore-capture.service`, deploys update/log helper scripts +4. **meshcore_capture** — runs the agessaman/meshcore-packet-capture install script (skipped once already installed — see "meshcore-packet-capture install is interactive" above, this needs a manual first run), writes config (TOML `config.d/99-user.toml` on current "system"-layout nodes, legacy `.env.local` on the two nodes still on the old layout — see `meshcore_capture_layout` in `group_vars/all/vars.yml`), enables the capture service, deploys update/log helper scripts 5. **scripts** — deploys `voltage.sh` and `bandwidth.sh` ## Config @@ -91,3 +96,43 @@ ansible-vault edit --vault-password-file ../.vault_pass host_vars/dm-edworth/vau `*/vault.yml.example` shows the expected keys. `group_vars/meshcore.yml` (MQTT credentials) is still plaintext — consider moving it into the vault too if this repo is shared further. + +## dotminipc (Docker node, not managed by this repo) + +A fourth capture point, device name `dm-stotfold`, runs as a Docker container +(`ghcr.io/agessaman/meshcore-packet-capture:latest`) on **dotminipc** +(172.16.31.92), the shared Docker/HA host documented in the sibling +`dotnetwork` repo. It isn't part of this repo's inventory — no Ansible role +here touches it — but it's the same upstream software as the Pi fleet, so +config drift between the two is worth knowing about. + +- Compose file: `dotnetwork/docker/dotminipc/meshcore-packet-capture/docker-compose.yml` +- Config: `dotnetwork/docker/dotminipc/meshcore-packet-capture/config.d/99-user.toml` + — host-only, gitignored (contains MQTT credentials), same TOML shape as + this repo's `meshcore_capture` role template + (`ansible/roles/meshcore_capture/templates/99-user.toml.j2`); keep the + broker list in sync between the two if either changes. The committed + `config.d/99-user.toml.example` in the dotnetwork repo is the sanitized + reference copy. +- Deploy/restart: `ssh david@172.16.31.92`, then from `/opt/docker`: + `docker compose up -d meshcore-capture --force-recreate`. Logs: + `docker logs -f meshcore-packet-capture`. + +**2026-07-27 outage, for reference**: the `:latest` image was rebuilt +2026-07-25 and switched its config format from `.env.local` to TOML +(`/etc/meshcore-packet-capture/config.toml` + `config.d/*.toml` — +the same "system" layout `meshcore_capture_layout` already models for the Pi +fleet). It silently stopped reading `.env.local` at all — despite upstream's +own README still describing that as a supported "legacy" path, in practice it +was just ignored — so the container fell back to the image's baked-in +defaults (`connection_type = "ble"`, `serial.ports = ["/dev/ttyUSB0"]`, no +owner key, only 2 of 5 brokers) and crash-looped on +`could not open port /dev/ttyUSB0`. Fix was to mount a full TOML override at +`config.d/99-user.toml` instead (see above) — same pattern as the Pi +`meshcore_capture` role already uses for `system`-layout nodes. Also found in +the process: the old `.env.local` had `PACKETCAPTURE_MQTT5_SERVER` set to +`mqtt.meshmapper.cc`, which fails TLS handshake — the correct domain is +`mqtt.meshmapper.net` (confirmed via `openssl s_client`; `.net` presents a +valid Let's Encrypt cert, `.cc` returns a TLS alert). If the Pi fleet's +`99-user.toml.j2` broker list is ever regenerated from a stale copy of this +node's old config, watch out for that typo resurfacing.