Files
family_home_lab/deploy/service-controller/services.toml

97 lines
2.5 KiB
TOML

# service-controller allowlist — ON_OFF.md §3/§4.
#
# Only services listed here can be started/stopped. Everything else 404s.
# Safety (non-negotiable, §6): never list console deps, house-critical audio,
# voice/whisper/HA path, or n8n/prefect-server (shared infra, always on).
#
# kind:
# container -> docker start/stop <target> (sam is in the docker group)
# systemd-user-> systemctl --user start/stop <target>
#
# group "media": family-facing editors (shared by everyone).
# group "pipeline": photo ingestion (prefect worker + dashboard) — admin only.
# group "admin": heavy infra someone may pause when idle — admin only.
[[services]]
id = "gimp"
kind = "container"
target = "family-home-lab-gimp-1"
group = "media"
label = "GIMP"
ram_mb = 233
default_state = "stopped"
who = ["sam", "finn", "harry", "jo"]
[[services]]
id = "video-editor"
kind = "container"
target = "family-home-lab-video-editor-1"
group = "media"
label = "Video Editor (KdenLive)"
ram_mb = 237
default_state = "stopped"
who = ["sam", "finn", "harry", "jo"]
[[services]]
id = "audio-editor"
kind = "container"
target = "family-home-lab-audio-editor-1"
group = "media"
label = "Audio Editor (Audacity)"
ram_mb = 201
default_state = "stopped"
who = ["sam", "finn", "harry", "jo"]
[[services]]
id = "lmms"
kind = "container"
target = "lmms"
group = "media"
label = "LMMS Music Studio"
ram_mb = 798 # incl. webtop desktop; Xvfb fixed to 2560x1440 (2026-10-07)
default_state = "stopped"
who = ["sam", "finn", "harry", "jo"]
[[services]]
id = "paperclip"
kind = "systemd-user"
target = "paperclipai"
group = "admin"
label = "Paperclip"
ram_mb = 495
default_state = "stopped"
who = ["sam"]
# Photo ingestion pipeline — admin controlled. Do NOT stop while ingesting
# Google Photos (user actively working on it, 2026-10-07).
[[services]]
id = "prefect-worker"
kind = "systemd-user"
target = "prefect-worker"
group = "pipeline"
label = "Prefect worker (photo pool)"
ram_mb = 129
default_state = "running"
who = ["sam"]
[[services]]
id = "photo-dashboard"
kind = "systemd-user"
target = "photo-dashboard"
group = "pipeline"
label = "Photo pipeline dashboard"
ram_mb = 112
default_state = "running"
who = ["sam"]
# WorldMonitor — 4-container group (UI + relay + redis + rest). One switch for all.
[[services]]
id = "worldmonitor"
kind = "container"
targets = ["worldmonitor", "worldmonitor-ais-relay", "worldmonitor-redis", "worldmonitor-redis-rest"]
group = "admin"
label = "World Monitor"
ram_mb = 120
default_state = "running"
who = ["sam"]