返回 Skill 列表
extension
分类: 开发与工程无需 API Key

home-network-admin

管理和故障排除Tim的家庭网络,通过SSH连接到设备,管理Synology NAS,并使用Tailscale。当用户想要 (1) 通过SSH连接或在远程机器(synology, dobro)上运行命令,(2) 管理Synology NAS(文件、包、Docker、备份、监控站),(3) 故障排除网络连接或DNS问题,(4) 检查Tailscale状态或管理tailnet,(5) 在机器之间传输文件,(6) 检查设备健康状况或磁盘使用情况,(7) 管理dobro上的Caddy反向代理(*.hopperhosted.com),(8) 任何家庭服务器或家庭网络管理任务时使用。

person作者: jakexiaohubgithub

Home Network Admin

Administer Tim's home network: devices connected over Tailscale, with a Synology NAS and Macs accessible via SSH.

Read references/network-inventory.md for the full device list, IPs, SSH config, and network topology before performing any task.

SSH Access

SSH configs are defined in ~/.ssh/config. Use the short aliases:

  • ssh synology - Synology NAS (custom port, user tdhopper)
  • ssh dobro - Mac (default port, user thopper)

SSH keys are managed via 1Password agent. If SSH fails with auth errors, verify 1Password is unlocked and the SSH agent is running.

Synology NAS Administration

The Synology runs DSM. Common admin tasks via SSH:

  • Packages: synopkg list (installed), synopkg status <pkg>, synopkg start/stop <pkg>
  • Docker/Container Manager: sudo docker ps, sudo docker logs <container>, sudo docker compose (compose files often in /volume1/docker/)
  • Disk/volume health: df -h, cat /proc/mdstat, synodisk --enum
  • Shared folders: typically under /volume1/
  • DSM web UI: https://synology:5001 or https://100.86.145.18:5001
  • Logs: /var/log/ and DSM log center

For destructive operations (deleting files, stopping services, modifying configs), confirm with the user first.

Tailscale

Tailscale connects all devices over a WireGuard mesh. Run tailscale status to discover the tailnet name and device list.

  • On macOS, the tailscale CLI may not be on PATH. Use: /Applications/Tailscale.app/Contents/MacOS/Tailscale
  • Check status: tailscale status (or the full path above)
  • Verify connectivity: tailscale ping <hostname>
  • All devices are reachable via MagicDNS (e.g., synology.<tailnet>.ts.net)

Caddy Reverse Proxy (on dobro)

Caddy runs on dobro, providing HTTPS reverse proxy for *.hopperhosted.com. The Caddyfile is at ~/Caddyfile (tracked in yadm). TLS uses Cloudflare DNS-01 challenge.

See references/network-inventory.md for the full list of proxied subdomains and backends.

  • Manage Caddy on dobro: ssh dobro then brew services restart caddy, caddy reload --config ~/Caddyfile
  • Logs: journalctl -u caddy or brew services info caddy depending on how it's managed
  • Edit Caddyfile locally: it's tracked in yadm dotfiles at ~/Caddyfile

File Transfer

  • Between local and remote hosts: scp or rsync using the SSH aliases
  • Example: rsync -avz ~/files/ synology:/volume1/backup/files/
  • For large transfers, prefer rsync with --progress

Troubleshooting

  1. Can't SSH: Check 1Password is unlocked, verify Tailscale is connected (tailscale status), ping the Tailscale IP
  2. DNS issues: Check if MagicDNS resolves (dig @100.100.100.100 synology.<tailnet>.ts.net), fall back to Tailscale IPs directly
  3. NAS unresponsive: Try ping, check DSM web UI, SSH may still work even if DSM is sluggish
  4. Slow network: Check if traffic is going through Tailscale relay (tailscale status shows DERP relay vs direct connection)