Skip to content

Manual teardown: retire the legacy hpe-01 tunnel + dead DNS records (explicit checklist) #321

Description

@ChrisonSimtian

Description

Explicit teardown list for the Cloudflare tunnels and DNS records left behind by the media-stack
rebuild and the Pangolin cutover (ADR-0005 → ADR-0007). Manual, by @Chrison88 — shared
account, so CLAUDE.md's add-only rule applies and none of this is automated.

Audited 2026-07-28. Six tunnels exist; two need work, four stay.

Tunnel inventory

Tunnel Connector Verdict
Homelab.Stacks.Core CT 2010 (hpe-01) + CT 2011 (nuc-01), HA pair keep — one dead rule to prune
Homelab.Stacks.DevOps keep (forgejo)
Homelab.Stacks.Media CT 5108 retire once #320 lands
erp-for-factory-games inside CT 2008 keep — separate project
hpe-01 (created 2026-02-24) CT 2001 cloudflared-01 RETIRE ENTIRELY ← the big one
topaz CT 2009 keep

1. The hpe-01 legacy tunnel — delete the whole thing

Predates the tunnel-per-stack convention. All eight of its ingress rules are dead, inert or
superseded:

Rule Origin Why it can go
seerr.tao-simon.family 10.10.48.42:5055 CT 5011 — now stopped, so already broken
audiobookshelf.tao-simon.family 10.10.162.226:13378 CT 5014, old fleet, tagged retired
shelfmark.tao-simon.family 10.10.52.82:8084 CT 5015, old fleet, tagged retired
shelfmark.chrison.dev 10.10.52.82:8084 same box — still serving HTTP 200, see warning below
proxmox.chrison.dev 192.168.179.1:8006 inert — DNS for this name points at the Core tunnel
proxmox.chrison.dev 10.0.0.1:8006 duplicate of the above, also inert
nuc-01.chrison.dev 192.168.179.1:8006 orphan — no DNS record exists
hpe-01.chrison.dev 192.168.179.3:8006 orphan — no DNS record exists

⚠️ shelfmark.chrison.dev is publicly serving the retired CT 5015 right now (HTTP 200),
with no Cloudflare Access app in front of it — only Shelfmark's own login. Same for
audiobookshelf.chrison.dev and forgejo.chrison.dev. Worth doing this one first.

⚠️ tao-simon.family is outside our API token's scope — reading it returns
Authentication error, which is correct per the minimal-scoping rule but means I could not
verify those records or confirm we created them. Check them in the dashboard by hand, and do
not assume they are ours.


2. Homelab.Stacks.Core — one dead rule

  • traefik.chrison.devhttp://10.10.0.12:80origin no longer exists; the
    hostname returns HTTP 502 today. Superseded by Pangolin's traefik.lab.chrison.dev
    (302, working). Delete the ingress rule and the DNS record.

The tunnel's other three rules (pangolin, pdm, proxmox) all stay — that is the
break-glass path and must not depend on Pangolin.


3. Homelab.Stacks.Media — retire after #320

Two rules, both duplicating a Pangolin resource against the identical origin:

Rule Origin Pangolin equivalent
seerr.chrison.dev 10.10.15.6:5055 seerr.arr.chrison.dev → same
audiobookshelf.chrison.dev 10.10.182.200:13378 audiobookshelf.arr.chrison.dev → same

Notes

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions