Mac OS - Recovery

Mac OS - Recovery#


1. Pre-Crash Backup Checklist (Do This Now)#

Ensure these configurations are regularly backed up or pushed to GitHub to prevent data loss.

  • 1.1 Setup Brewfile Versioning: Dump, commit, and push your system package lists.
  • 1.2 Sync Packages & Scripts: Track changes to package lists using pushbrew and script/alias updates using pushscripts.
    • Details: Completed. Use pushbrew for package list updates and pushscripts for codebase updates. See Mac OS - Brewfile.
  • 1.3 Automate MCP Config Pushes: Update the mcp alias to push local configuration commits.
    • Details: Completed. mcp alias now auto-commits and pushes local changes to GitHub (MCP-Config-MacOS).
  • 1.4 Version-Control Custom Aliases: Migrate custom shortcuts out of local configurations.
  • 1.5 Double Check Git Hook Backups: Save a copy of your Git hooks.
    • Details: Completed. The mirror hook is backed up at ~/Scripts/MacOS/post-commit-hook.sh.

2. Workstation Rebuild Checklist (In Case of Crash)#

Follow these steps in order to restore the Mac Studio environment on a fresh macOS installation.

Proxmox - HP3 Wake-on-LAN (WOL) Monitoring & Sniffer

Proxmox - Wake-on-LAN (WOL) Monitoring & Sniffer#

This guide outlines a persistent, lightweight background service for monitoring and logging Wake-on-LAN (WOL) Magic Packets on the Proxmox network. The payload is retained so the target MAC can be identified even when a server has multiple NICs or alternate MAC addresses.

2026-08-03 Antigravity chat: agy –conversation=3b2d07f7-d649-4fed-9976-8f0deadf60f9


1. Overview & Purpose#

  • Primary Target: HP3 (10.1.1.13), documented MAC ec:b1:d7:7c:a9:48
  • Additional Targets: Any WOL target visible on the monitored segment, including HP2 (94:57:a5:65:7e:88)
  • Capture Host: MMProxmox / MacMini (10.1.1.10)
  • Capture Interface: bond0 (active-backup bond; nic1 currently active)
  • Objective: Capture the source IP, source Ethernet MAC, timestamp, VLAN, and WOL payload target MAC.
  • Resource Overhead: Near zero (~1 MB RAM, 0% CPU overhead).

2. Systemd Service Specification#

The sniffer uses tcpdump running as a background systemd daemon. It listens on the physical uplink (bond0) for UDP port 9/7 and raw Ethernet WOL traffic, retaining the complete packet payload in /var/log/wol_sniffer.log.

Unifi UNAS-Pro Usage Inventory Plan

Master Plan: UNAS Pro SMB Usage Inventory#

This document outlines the proposed step-by-step strategy to perform a comprehensive audit and inventory of all workloads, computers, virtual machines, Docker stacks, and scripts utilizing SMB shares from the UNAS Pro (10.1.2.2) NAS.

Active Share Matrices#

Workstations & Computers#

Server / Machine Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
MacBook Air X X X X X X X X X X X X X X X X X
MacBook Pro 15 X X X X X X X X X X X X X X X X X
MacBook Pro 16 X X X X X X X X X X X X X X X X X
iMac (MO) X X X X X X X X X X X X X X X X X

Mac Studio (10.1.2.4)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
Mac Studio (Host) X - X X X X X X X X X X X X - - -
    └─ open-webui - - - - - - - - - - - - - - - - -
    └─ portainer-agent - - - - - - - - - - - - - - - - -
    └─ cloudflared - - - - - - - - - - - - - - - - -
    └─ dockge - - - - - - - - - - - - - - - - -

MMProxmox (10.1.1.10)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
MMProxmox (Host) X - - - - - - - - - - - - - - - -
Pi-Hole (LXC 100) - - - - - - - - - - - - - - - - -
HomeAssistant (VM 200) - - - - - - - - - - - - - - - - -
MMDocker (VM 230) - OS Mounts X X - - X X X - X X X X X X - - -
    └─ Radarr - - - - - - X - - - - - - - - - -
    └─ Sonarr - - - - - - X - - - - - - - - - -
    └─ Lidarr - - - - - - X - - - - - - - - - -
    └─ qBittorrent - - - - - - X - - - - - - - - - -
    └─ Backup Sync - X - - - - - - - - - - - - - - -

HP1 Proxmox (10.1.1.11)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
HP1 Proxmox (Host) X - - - - - - - - - - - - - - - -
Pi-Hole-2 (LXC 101) - - - - - - - - - - - - - - - - -
VPSBackups (LXC 102) - - - - - - - - - - - - - - - - -
DatacenterManager (LXC 105) - - - - - - - - - - - - - - - - -
HP1TrueNAS (VM 201) - - - - - - - - - - - - - - - - -
HP1Docker (VM 202) - OS Mounts X - - X X X X - X X X X X X - - X
    └─ Backrest X - - - X X - - X X X X - - - - X
    └─ Paperless - - - X - - - - - - - - - - - - -
    └─ Paperless Sync (Cron) - - - - - X - - - - - - - - - - -
    └─ Hugo Publish (Cron) X - - - - - - - - - - - - - - - -
HP1BackupServer (VM 211) - OS Mounts X X - - - - - - - - - - - - - - -
    └─ PBS Daemon X X - - - - - - - - - - - - - - -
HP1Clouds (VM 217) - OS Mounts X - - X X X X - X X X X X X - - -
    └─ Nextcloud AIO X - - X X X X - X X X X X X - - -
    └─ Owncloud Server X - - X X X X - X X X X X X - - -
    └─ File Indexer (Cron) X - - X X X X - X X X X X X - - -
HP1SynologyDSM (VM 221) - - - - - - - - - - - - - - - - -
HP1GPU (VM 231) - OS Mounts X - - - X X X - X X X X X X - - -
    └─ Immich Server - - - - - - - - X - - X - - - - -
    └─ Emby - - - - - - X - - X - - X X - - -
    └─ Plex - - - - - - X - - X - X X X - - -
    └─ Navidrome - - - - - - - - - X - - - - - - -

Scripts & Automations#

Script / Automation Hook Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
Git Hook: post-commit X - - - - - - - - - - - - - - - -
proxmox_backup.sh X - - - - - - - - - - - - - - - -
HP1_UNAS_Pull_Backup.sh X - - - X X X X X X X X - - - - X
HP2_UNAS_Pull_Backup.sh X - - - X X - - X X X X - - - - X
HP3_UNAS_Pull_Backup.sh - - - - - - - - - - - - X X - - -
HP7_UNAS_Pull_Backup.sh X - - - X X - X X X X X - - - - X
HP8_UNAS_Pull_Backup.sh X - - - X X - X X X X X X X - - X

Target Inventory Scope#

The inventory will discover and map every dependency on the UNAS Pro SMB shares across four distinct layers:

UniFi UNAS-Pro Pool Migration Strategy

UniFi UNAS-Pro Pool Migration Strategy: Pool 1 (SSD) to Pool 2 (HDD)#

This document defines the operational plan, safety protocols, database update queries, and verification steps to migrate all shared folders from Storage Pool 1 (SSD - Degraded RAID5) to Storage Pool 2 (HDD - Healthy RAID5) on the master UniFi UNAS-Pro NAS (10.1.2.2) while preserving all access rights, Samba configurations, and TrueNAS backup operations.

Antigravity chat: agy –conversation=3dd15667-3c79-485d-af10-ebb5c4f9cc01


1. Executive Summary & Objective#

Due to hardware failures on Pool 1 (Slot 2 pulled, Slot 3 accumulating 75,000+ write failures), Pool 1 is operating with zero fault tolerance. To prevent data loss prior to receiving warranty replacement drives, all active shares on Pool 1 will be migrated to Pool 2.

Scripts Management Standard

📜 Scripts Management Process#

Workstation Sync Shortcut: To automatically backup all your scripts and custom terminal aliases configuration (staging and pushing your entire ~/Scripts/ repository):

pushscripts

This will stage all modified files in ~/Scripts/, commit, and push updates directly to GitHub and your NAS (without running Homebrew operations).

Workstation Update Shortcut: To pull down the latest custom scripts and terminal aliases from GitHub on an existing machine (after the first-time setup is complete):

Unifi UNAS-Pro Backup Strategy

UniFi UNAS-Pro Master Backup Strategy: Native Rsync Daemon (Pull) Architecture#

This document defines the complete operational standard, architecture, schedule matrix, node-by-node configuration reference, and disaster recovery procedures for backing up all shared data from the master UniFi UNAS-Pro NAS (10.1.2.2) across the fleet of 5 TrueNAS SCALE storage nodes (HP1, HP2, HP3, HP7, HP8). It is designed to be sufficient to fully reconstruct the entire setup from scratch.

Antigravity Chat: agy –conversation=4c0c9b6d-2722-4fd6-a4aa-638c75ab46f4

Scripts Management Migration Plan

Scripts Management Migration Plan#

This document is the master architectural migration plan for establishing /Users/marc/Scripts as your primary local master Git repository, linked to git@github.com:marcoue/Scripts.git, with automated mirroring to the UNAS-Pro NAS (/Volumes/Software/Software/Scripts/) and automated pull execution by remote TrueNAS/Linux/Proxmox nodes.


1. Executive Summary & Architecture Goal#

🎯 Primary Master Architecture#

  1. Master Repository: /Users/marc/Scripts on your Mac SSD is your primary master repository for editing, testing, running, and managing all homelab scripts.
  2. GitHub Remote: Linked to git@github.com:marcoue/Scripts.git on branch main.
  3. Automated NAS Mirroring: A Git post-commit hook automatically syncs committed scripts from ~/Scripts/ to /Volumes/Software/Software/Scripts/ on UNAS-Pro.
  4. Remote Server Pull Execution: Remote servers (HP1, HP2, HP3, HP7, HP8, Proxmox, Linux) pull their scripts from UNAS-Pro (Software/Scripts/) on their scheduled runs.

🔄 Data & Deployment Flow#

  [Mac Workstation] (Primary Master Workspace)
   └── ~/Scripts/ (git@github.com:marcoue/Scripts.git)
        ├── MacOS/
        ├── Linux/
        ├── Proxmox/
        └── TrueNAS/
             ├── (git commit)
        [Git post-commit Hook]
             ├── (rsync auto-mirror)
  [UNAS-Pro Master NAS] (Distribution Mirror)
   └── /Volumes/Software/Software/Scripts/
        ├── MacOS/
        ├── Linux/
        ├── Proxmox/
        └── TrueNAS/ (Exposed as Rsync Module: root@10.1.2.2::Software/Scripts/TrueNAS/)
             ├── (Rsync pull on schedule)
  [Remote Nodes: HP1, HP2, HP3, HP7, HP8, Proxmox, Linux]
   └── Local Execution of Version-Controlled Scripts

📂 1.1 Filesystem Standard & Disaster Recovery Protocol#

  1. Standard POSIX Filesystem Path:
    • The destination path /Volumes/Software/Software/Scripts/ (and subfolders MacOS/, Linux/, Proxmox/, TrueNAS/) is a standard, plain-text directory tree residing on the mounted Software SMB share (smb://10.1.2.2/Software). There are zero proprietary databases, hidden hooks, or custom file structures on the NAS.
  2. Mac Auto-Mount Convenience (Login Items):
    • To ensure the SMB share is always available for Git post-commit auto-mirroring, add /Volumes/Software to macOS System Settings > General > Login Items.
  3. macOS Reinstall / Disaster Recovery:
    • Reinstalling or replacing macOS on your Mac Studio has zero effect on UNAS-Pro or TrueNAS servers. The NAS files remain intact, and TrueNAS backup cron jobs continue executing without interruption.
    • To restore your Mac workstation repo after a fresh macOS install:
      # Step 1: Clone master repository from GitHub
      git clone git@github.com:marcoue/Scripts.git ~/Scripts
      
      # Step 2: Re-install 1-line Git post-commit auto-mirror hook
      cat << 'EOF' > ~/Scripts/.git/hooks/post-commit
      #!/usr/bin/env bash
      if [ -d "/Volumes/Software/Software/Scripts" ]; then
          rsync -av --delete --exclude='.git' --exclude='*.log' /Users/marc/Scripts/ /Volumes/Software/Software/Scripts/
      fi
      EOF
      chmod +x ~/Scripts/.git/hooks/post-commit

2. Complete Script Inventory & Mapping#

The following table lists all existing scripts found across your NAS repository (git@github.com:marcoue/Scripts.git) and local Mac folder (~/Scripts/), mapped to their final category subfolders:

Unifi UNAS-Pro Backup Migration Plan

UNAS-Pro Backup Migration Plan: SMB (Push) to Native Rsync Daemon (Pull)#

Antigravity Chat: agy –conversation=4c0c9b6d-2722-4fd6-a4aa-638c75ab46f4

This document is the complete master migration plan for transitioning the UNAS-Pro backup strategy from the UniFi Drive UI-managed SMB (Push) setup to a Native Rsync Daemon (Pull) model.

Because the UniFi Drive UI natively supports Rsync server settings and shared folder modules, migrating to Rsync requires configuring your TrueNAS SCALE servers (HP1, HP2, HP3, HP7, HP8) to pull the backups directly from the UNAS-Pro Rsync daemon over TCP port 873.

2026-07-23 - UniFi WAN Security Audit Report

UniFi UDM-SE WAN, Security & IPv6 Audit Report#

Date: July 23, 2026
Gateway Device: Ubiquiti UniFi Dream Machine Special Edition (UDM-SE)
Firmware Version: 5.1.19.33549
Primary ISP (WAN1): Cogeco Connexion (1000 Mbps Down / 30 Mbps Up)
Failover ISP (WAN2): Vidéotron (Currently Down - Offline)
Secondary Backup ISP (WAN3): Starlink (CGNAT)


1. Executive Summary#

An in-depth audit of the UniFi Dream Machine SE gateway was performed via the UniFi API. The assessment evaluated the primary WAN (WAN1 - Cogeco Connexion), secondary failover WAN (WAN2 - Vidéotron), and backup satellite WAN (WAN3 - Starlink).

KVM - Tripp Lite Java Web Start Fix

Tripp Lite KVM Java Web Start (JNLP) Setup & SSL Fix#

This guide documents the fix for opening the Tripp Lite KVM virtual console (viewer.jnlp) on macOS when modern Java blocks connections due to legacy TLS/SSL cipher handshake failures.


1. Problem Overview#

When launching viewer.jnlp via Java Web Start (javaws), the applet fails with the following errors:

com.sun.deploy.net.FailedDownloadException: Unable to load resource: https://10.1.5.2:443/iClientJ12111.jar@pid=...
javax.net.ssl.SSLHandshakeException: Received fatal alert: handshake_failure

Cause#

Tripp Lite IP KVM switches (and rebranded ATEN/Avocent devices) rely on legacy SSL/TLS protocols (TLS 1.0 / TLS 1.1) and deprecated ciphers (e.g., 3DES, 1024-bit Diffie-Hellman keys). Modern Java runtimes (Java 8u291+ and newer) disable these protocols by default in java.security.