Migrate Karakeep from media1 Docker to native NixOS on Vega #185

Closed
opened 2026-08-21 20:23:16 +01:00 by nimmo · 0 comments
Owner

Scope

Migrate Karakeep (currently media1 Docker) to the native nixpkgs NixOS service on Vega, keeping media1 intact as rollback.

Constraints

  • Target Vega; Chaos remains reserved for awkward Docker-only workloads.
  • Do not edit SOPS secrets; user will populate the required Karakeep service environment secret.
  • Do not change Pangolin in this workstream.
  • Media1 may be stopped/restarted for a consistent transfer and rollback test, but no data, Docker volumes, images, or stack definitions may be deleted or pruned.

Completion criteria

  • Native Karakeep 0.33.1 is enabled on Vega and covered by the existing backup policy.
  • A documented secret contract is available for user population.
  • Vega configuration builds and deploys successfully.
  • Data can be copied from media1 with a reversible procedure.
  • Karakeep starts and passes local API/web/search/crawler validation before any public ingress change.
  • Docker-based MCP wrapper is replaced only after the hosted service migration is validated.

Checklist

  • Configure native Karakeep module on Vega
  • User provides encrypted service environment secret
  • Validate Nix build
  • Deploy staged service on Vega
  • Copy and validate SQLite/assets
  • Rebuild Meilisearch
  • Perform user-approved ingress cutover separately
  • Keep media1 stack available for rollback
## Scope Migrate Karakeep (currently media1 Docker) to the native nixpkgs NixOS service on Vega, keeping media1 intact as rollback. ## Constraints - Target Vega; Chaos remains reserved for awkward Docker-only workloads. - Do not edit SOPS secrets; user will populate the required Karakeep service environment secret. - Do not change Pangolin in this workstream. - Media1 may be stopped/restarted for a consistent transfer and rollback test, but no data, Docker volumes, images, or stack definitions may be deleted or pruned. ## Completion criteria - Native Karakeep 0.33.1 is enabled on Vega and covered by the existing backup policy. - A documented secret contract is available for user population. - Vega configuration builds and deploys successfully. - Data can be copied from media1 with a reversible procedure. - Karakeep starts and passes local API/web/search/crawler validation before any public ingress change. - Docker-based MCP wrapper is replaced only after the hosted service migration is validated. ## Checklist - [ ] Configure native Karakeep module on Vega - [ ] User provides encrypted service environment secret - [ ] Validate Nix build - [ ] Deploy staged service on Vega - [ ] Copy and validate SQLite/assets - [ ] Rebuild Meilisearch - [ ] Perform user-approved ingress cutover separately - [ ] Keep media1 stack available for rollback
nimmo closed this issue 2026-08-21 23:46:08 +01:00
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nimmo/nixos-config#185
No description provided.