# Uptime Kuma

## Purpose

Uptime Kuma provides availability monitoring for the Bytek homelab.

Uptime Kuma monitors services at multiple layers so an outage can be isolated quickly.

Monitoring can determine whether a failure is caused by:

<div id="bkmrk-a-stopped-vm-or-lxc." style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- A stopped VM or LXC.
- A network problem.
- A Proxmox firewall rule.
- A stopped Docker container.
- An unhealthy application.
- A database problem.
- Pi-hole DNS.
- Traefik routing.
- An expired or invalid certificate.
- Authentik proxy authentication.
- The WireGuard tunnel.
- The public VPS.

---

</div>## Service Information

<div id="bkmrk-setting-value-servic" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Setting</th><th>Value</th></tr><tr><td>Service name</td><td>Uptime Kuma</td></tr><tr><td>Private IP address</td><td>`192.168.2.115`</td></tr><tr><td>Backend port</td><td>TCP 3001</td></tr><tr><td>Public hostname</td><td>`status.bytek.ca`</td></tr><tr><td>Deployment directory</td><td>`/opt/uptime-kuma`</td></tr><tr><td>Container name</td><td>`uptime-kuma`</td></tr><tr><td>Persistent data</td><td>`/app/data` inside the container</td></tr><tr><td>Database</td><td>Embedded MariaDB</td></tr><tr><td>Container DNS</td><td>`192.168.2.65`</td></tr><tr><td>Public routing</td><td>Traefik</td></tr><tr><td>Target authentication</td><td>Authentik Proxy Provider</td></tr><tr><td>Required Authentik group</td><td>`bytek-admin`</td></tr><tr><td>Backup coverage</td><td>Proxmox scheduled backup</td></tr><tr><td>Proxmox VM ID</td><td>Confirm current VM ID</td></tr></tbody></table>

</div></div></div>Dashboard:

<span class="___xxxjie0 f1w7gpdv f1gqqdtu" data-wra="1" style="opacity: 1; transition: opacity 500ms ease-out;">[Open Uptime Kuma](https://status.bytek.ca/)</span>

<div id="bkmrk-" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Architecture Role

Uptime Kuma monitors both private backends and routed application hostnames.

A routed monitor follows this path:

<div id="bkmrk-uptime-kuma-resolves" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Uptime Kuma resolves the application hostname through Pi-hole.
2. Pi-hole returns Traefik’s private IP address, `192.168.2.182`.
3. Uptime Kuma connects to Traefik.
4. Traefik selects the application router.
5. Traefik forwards the request to the private backend.
6. Uptime Kuma records the response status and latency.

</div>A direct backend monitor bypasses Traefik and connects directly to the application VM.

Using both monitor types helps distinguish infrastructure failures from reverse-proxy failures.

<div id="bkmrk--1" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Monitoring Layers

Each important service should have up to three monitoring layers.

### VM or LXC Monitor

A ping monitor verifies that the guest is reachable on the network.

A successful ping proves:

<div id="bkmrk-the-guest-is-running" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- The guest is running.
- The virtual network interface is active.
- The network path permits ICMP.

</div>A successful ping does not prove that the application is healthy.

### Direct Backend Monitor

A direct backend monitor connects to the private application address and port.

A successful backend monitor proves:

<div id="bkmrk-the-guest-is-reachab" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- The guest is reachable.
- The application port is open.
- The application or web service responds.

</div>A direct backend monitor bypasses:

<div id="bkmrk-pi-hole-hostname-res" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Pi-hole hostname resolution.
- Traefik routing.
- Public certificates.
- The VPS.
- WireGuard public ingress.

</div>### Routed Application Monitor

A routed monitor uses the normal HTTPS application hostname.

A successful routed monitor proves:

<div id="bkmrk-pi-hole-resolves-the" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Pi-hole resolves the hostname.
- Traefik is reachable.
- The router is loaded.
- The certificate is valid.
- The backend is reachable.
- The application responds.

---

</div>## Failure Interpretation

<div id="bkmrk-vm-monitor-backend-m" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>VM Monitor</th><th>Backend Monitor</th><th>Routed Monitor</th><th>Likely Failure</th></tr><tr><td>Down</td><td>Down</td><td>Down</td><td>VM, LXC, Proxmox, or network failure</td></tr><tr><td>Up</td><td>Down</td><td>Down</td><td>Docker, application, database, or backend firewall failure</td></tr><tr><td>Up</td><td>Up</td><td>Down</td><td>Pi-hole, Traefik, TLS, router, or Authentik failure</td></tr><tr><td>Up</td><td>Up</td><td>Up</td><td>Service is operating normally</td></tr><tr><td>Up</td><td>Down</td><td>Up</td><td>Monitor target or direct-backend firewall configuration may be incorrect</td></tr><tr><td>Down</td><td>Up</td><td>Up</td><td>ICMP is blocked, but the application is available</td></tr></tbody></table>

</div></div></div>A failed ping monitor does not always mean the VM is down. The guest or Proxmox firewall may block ICMP while allowing application traffic.

<div id="bkmrk--2" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Docker Deployment

The Uptime Kuma deployment is managed using Docker Compose.

Deployment directory:

`/opt/uptime-kuma`

Before running Compose commands, move into the deployment directory using:

`cd /opt/uptime-kuma`

Check container state using:

`sudo docker compose ps`

View recent logs using:

`sudo docker compose logs --tail 100 uptime-kuma`

Follow logs live using:

`sudo docker compose logs -f uptime-kuma`

Validate the Compose configuration using:

`sudo docker compose config --quiet`

Apply normal configuration changes using:

`sudo docker compose up -d`

Recreate the container after changing Docker-level settings such as DNS, volumes, environment variables, or networking using:

`sudo docker compose up -d --force-recreate uptime-kuma`

<div id="bkmrk--3" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Persistent Data

Uptime Kuma stores its application data under `/app/data` inside the container.

The persistent host mapping should be confirmed from the current Compose file.

The persistent data includes information such as:

<div id="bkmrk-monitors.-monitor-hi" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Monitors.
- Monitor history.
- Notifications.
- Status pages.
- Maintenance windows.
- Application settings.
- User configuration.
- Embedded database files.
- Uploaded status-page assets.

</div>The persistent-data directory must remain mounted across container recreation.

Never remove the persistent volume while troubleshooting a container-startup problem.

<div id="bkmrk--4" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Database

The current Uptime Kuma deployment uses embedded MariaDB.

Database health is reported by the container health check.

The container should not be considered fully healthy until the database is available.

Check container health using:

`sudo docker inspect --format='{{.State.Health.Status}}' uptime-kuma`

Expected result:

<div id="bkmrk-healthy" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `healthy`

</div>If the result is `starting`, allow the health check to continue while reviewing logs.

If the result is `unhealthy`, inspect the Uptime Kuma logs before restarting or recreating the container.

<div id="bkmrk--5" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Docker DNS

The Uptime Kuma container explicitly uses Pi-hole at `192.168.2.65`.

This allows Uptime Kuma to resolve internal split-DNS records.

Verify container DNS using:

`sudo docker inspect --format='DNS={{json .HostConfig.Dns}}' uptime-kuma`

Expected result:

<div id="bkmrk-192.168.2.65-appears" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `192.168.2.65` appears in the DNS list.

</div>Test an internal hostname from inside the container using:

`sudo docker exec uptime-kuma getent hosts portal.bytek.ca`

Expected result:

<div id="bkmrk-portal.bytek.ca-reso" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `portal.bytek.ca` resolves to `192.168.2.182`.

</div>Test another internal hostname using:

`sudo docker exec uptime-kuma getent hosts projects.bytek.ca`

Expected result:

<div id="bkmrk-projects.bytek.ca-re" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `projects.bytek.ca` resolves to `192.168.2.182`.

---

</div>## DNS Failure After a Power Interruption

Docker DNS previously failed after an electrical outage.

Symptoms included:

<div id="bkmrk-monitors-failing-aft" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Monitors failing after services had restarted.
- Internal hostnames not resolving inside containers.
- Application hosts resolving correctly while container resolution failed.
- OIDC or certificate operations reporting unreachable endpoints.

</div>Recommended recovery sequence:

<div id="bkmrk-confirm-pi-hole-is-r" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Confirm Pi-hole is running.
2. Confirm Pi-hole owns `192.168.2.65`.
3. Confirm the Uptime Kuma VM resolves internal hostnames.
4. Confirm the Uptime Kuma container resolves internal hostnames.
5. Verify the container’s explicit DNS configuration.
6. Restart the Uptime Kuma container.
7. Recreate the container if Docker-level DNS configuration changed.
8. Confirm the monitors recover.

</div>Do not rebuild Uptime Kuma or delete persistent data because of a DNS-only failure.

<div id="bkmrk--6" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Public Dashboard Routing

The Uptime Kuma dashboard is available at:

<span class="___xxxjie0 f1w7gpdv f1gqqdtu" data-wra="1" style="opacity: 1; transition: opacity 500ms ease-out;">[Open Uptime Kuma](https://status.bytek.ca/)</span>

Internal clients resolve `status.bytek.ca` to Traefik at `192.168.2.182`.

External clients resolve `status.bytek.ca` to the public VPS at `38.29.213.101`.

The public path includes:

<div id="bkmrk-whc-public-dns.-publ" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. WHC public DNS.
2. Public VPS.
3. WireGuard.
4. Home WireGuard gateway.
5. Traefik.
6. Authentik embedded outpost when enabled.
7. Uptime Kuma at `192.168.2.115:3001`.

---

</div>## Authentication Design

Uptime Kuma does not use the same native OIDC design as Nextcloud, Vikunja, BookStack, and Proxmox.

The target design uses an Authentik Proxy Provider.

The expected authentication flow is:

<div id="bkmrk-the-administrator-op" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. The administrator opens `status.bytek.ca`.
2. Traefik forwards the request to the Authentik embedded outpost.
3. Authentik checks the existing authentication session.
4. Authentik requests credentials and MFA if required.
5. Authentik evaluates the application bindings.
6. Authentik proxies the request to Uptime Kuma.
7. Uptime Kuma displays the dashboard.

---

</div>## Authentik Application

<div id="bkmrk-setting-value-applic" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Setting</th><th>Value</th></tr><tr><td>Application name</td><td>Uptime Kuma</td></tr><tr><td>Application slug</td><td>`uptime-kuma`</td></tr><tr><td>Provider type</td><td>Proxy Provider</td></tr><tr><td>Provider mode</td><td>Proxy</td></tr><tr><td>External host</td><td>`https://status.bytek.ca`</td></tr><tr><td>Internal host</td><td>`http://192.168.2.115:3001`</td></tr><tr><td>Required group</td><td>`bytek-admin`</td></tr><tr><td>Required policy</td><td>`Allow bytek.ca users`</td></tr><tr><td>Policy engine</td><td>`ALL`</td></tr><tr><td>Outpost</td><td>Authentik Embedded Outpost</td></tr></tbody></table>

</div></div></div>Only users who satisfy both the group and policy requirements should reach the dashboard.

<div id="bkmrk--7" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Embedded Outpost Connectivity

The embedded outpost runs through the Authentik service at `192.168.2.162`.

Authentik must be able to reach Uptime Kuma at:

<div id="bkmrk-192.168.2.115-tcp-po" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `192.168.2.115`
- TCP port 3001

</div>The Uptime Kuma VM firewall must allow:

<div id="bkmrk-source-192.168.2.162" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Source `192.168.2.162`
- Destination TCP port 3001

</div>Test from the Authentik VM using:

`curl -I http://192.168.2.115:3001/`

A healthy Uptime Kuma response may redirect to `/dashboard`.

<div id="bkmrk--8" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Authentication Migration Safety

Do not disable Uptime Kuma’s local authentication before the Authentik proxy works.

Use this migration order:

<div id="bkmrk-create-the-authentik" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Create the Authentik application and Proxy Provider.
2. Assign the application to the embedded outpost.
3. Allow Authentik to reach TCP port 3001.
4. Route `status.bytek.ca` through the outpost.
5. Test Authentik authentication.
6. Confirm the Uptime Kuma local login still appears behind Authentik.
7. Test with the `bytek-admin` account.
8. Test denial with a non-administrator account.
9. Confirm public status pages still work if required.
10. Disable Uptime Kuma local authentication.
11. Enable Trust Proxy.
12. Restrict direct TCP 3001 access.
13. Test recovery.

</div>During the intermediate state, both Authentik and Uptime Kuma authentication may appear.

That is intentional until the Authentik path is validated.

<div id="bkmrk--9" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Disabling Local Authentication

Only disable local Uptime Kuma authentication after Authentik is proven reliable.

Before disabling local authentication:

<div id="bkmrk-record-the-uptime-ku" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Record the Uptime Kuma administrator password.
- Confirm Proxmox backup coverage.
- Create a Proxmox snapshot if desired.
- Confirm direct private access.
- Confirm Authentik access.
- Confirm a non-admin user is denied.
- Confirm public status pages.
- Document the recovery process.

</div>After disabling local authentication:

<div id="bkmrk-enable-trust-proxy.-" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Enable Trust Proxy.
- Restrict direct TCP 3001 access to the Authentik VM.
- Remove unnecessary direct Traefik-to-Kuma access if Traefik now routes to the outpost.
- Retain the original administrator password for recovery.

---

</div>## Direct Backend Security

When Uptime Kuma local authentication is disabled, direct access to `192.168.2.115:3001` must be restricted.

Otherwise, a LAN client could bypass Authentik and reach an unauthenticated dashboard.

The final firewall should permit TCP port 3001 only from approved sources such as:

<div id="bkmrk-source-purpose-192.1" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Source</th><th>Purpose</th></tr><tr><td>`192.168.2.162`</td><td>Authentik embedded outpost</td></tr><tr><td>Administrative workstation during testing</td><td>Temporary recovery access</td></tr><tr><td>Approved monitoring source</td><td>Only if required</td></tr></tbody></table>

</div></div></div>Remove temporary direct access after validation.

<div id="bkmrk--10" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Public Status Pages

Some Uptime Kuma status pages may be intended for unauthenticated public viewing.

Authentik Proxy Provider exclusions may be required for:

<div id="bkmrk-published-status-pag" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Published status pages.
- Status-page API requests.
- Static assets.
- Uploaded status-page files.
- Badge endpoints.
- Push-monitor endpoints.
- Public icons.

</div>Unauthenticated-path exclusions must be as narrow as practical.

Do not exclude the entire Uptime Kuma API.

After configuring exclusions:

<div id="bkmrk-open-a-public-status" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Open a public status page in a private browser.
2. Confirm no Authentik login is required.
3. Open the dashboard.
4. Confirm Authentik login is required.
5. Test a push monitor.
6. Test a status badge if used.
7. Review Authentik and Traefik logs.

---

</div>## Push Monitors

Push monitors rely on a unique URL that an external process calls to report success.

If Uptime Kuma sits behind Authentik, the push path must remain reachable without an interactive login.

Protect push-monitor URLs as secrets.

Do not publish push URLs in BookStack.

If a push monitor stops updating after enabling Authentik:

<div id="bkmrk-confirm-the-push-pat" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Confirm the push path is excluded.
2. Confirm Traefik routes the request correctly.
3. Confirm the unique token is unchanged.
4. Review the Uptime Kuma monitor history.
5. Review Traefik access logs.
6. Review Authentik outpost logs.

---

</div>## Monitor Naming Standard

Use consistent names so the dashboard is easy to scan.

Recommended patterns include:

<div id="bkmrk-service-vm-service-b" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `Service VM`
- `Service Backend Direct`
- `Service Through Traefik`
- `Service External`
- `Service Certificate`
- `Service DNS`

</div>Examples:

<div id="bkmrk-nextcloud-vm-nextclo" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `Nextcloud VM`
- `Nextcloud AIO Apache`
- `Nextcloud Through Traefik`
- `Vikunja VM`
- `Vikunja Backend Direct`
- `Vikunja Through Traefik`
- `BookStack VM`
- `BookStack Backend Direct`
- `BookStack Through Traefik`

---

</div>## Core Infrastructure Monitors

Recommended core monitors include:

<div id="bkmrk-monitor-suggested-ty" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Monitor</th><th>Suggested Type</th><th>Target</th></tr><tr><td>Proxmox VE</td><td>HTTPS or TCP</td><td>`192.168.2.254:8006`</td></tr><tr><td>Pi-hole VM or LXC</td><td>Ping</td><td>`192.168.2.65`</td></tr><tr><td>Pi-hole DNS TCP</td><td>TCP</td><td>`192.168.2.65:53`</td></tr><tr><td>Pi-hole DNS UDP</td><td>UDP or DNS</td><td>`192.168.2.65:53`</td></tr><tr><td>WireGuard gateway</td><td>Ping</td><td>`192.168.2.64`</td></tr><tr><td>Public VPS</td><td>Ping or TCP</td><td>`38.29.213.101`</td></tr><tr><td>Public VPS HTTPS</td><td>TCP</td><td>`38.29.213.101:443`</td></tr><tr><td>Traefik VM</td><td>Ping</td><td>`192.168.2.182`</td></tr><tr><td>Traefik HTTPS</td><td>TCP</td><td>`192.168.2.182:443`</td></tr><tr><td>Authentik direct</td><td>HTTP</td><td>Direct readiness endpoint</td></tr><tr><td>Authentik routed</td><td>HTTPS</td><td>Routed readiness endpoint</td></tr></tbody></table>

</div></div>---

</div>## Nextcloud Monitors

<div id="bkmrk-monitor-type-target-" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Monitor</th><th>Type</th><th>Target</th></tr><tr><td>Nextcloud VM</td><td>Ping</td><td>`192.168.2.100`</td></tr><tr><td>Nextcloud AIO Apache</td><td>TCP</td><td>`192.168.2.100:11000`</td></tr><tr><td>Nextcloud Through Traefik</td><td>HTTPS</td><td>`https://cloud.bytek.ca/status.php`</td></tr></tbody></table>

</div></div></div>Expected routed status:

<div id="bkmrk-http-200." style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- HTTP 200.

---

</div>## Vikunja Monitors

<div id="bkmrk-monitor-type-target--1" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Monitor</th><th>Type</th><th>Target</th></tr><tr><td>Vikunja VM</td><td>Ping</td><td>`192.168.2.121`</td></tr><tr><td>Vikunja Backend Direct</td><td>HTTP</td><td>`http://192.168.2.121:3456/health`</td></tr><tr><td>Vikunja Through Traefik</td><td>HTTPS</td><td>`https://projects.bytek.ca/health`</td></tr></tbody></table>

</div></div></div>Expected health status:

<div id="bkmrk-http-200.-1" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- HTTP 200.

</div>The Vikunja VM firewall must allow Uptime Kuma at `192.168.2.115` to reach TCP port 3456.

<div id="bkmrk--11" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## BookStack Monitors

<div id="bkmrk-monitor-type-target--2" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Monitor</th><th>Type</th><th>Target</th></tr><tr><td>BookStack VM</td><td>Ping</td><td>Confirm BookStack IP</td></tr><tr><td>BookStack Backend Direct</td><td>HTTP</td><td>BookStack IP on port 6875</td></tr><tr><td>BookStack Through Traefik</td><td>HTTPS</td><td>`https://docs.bytek.ca/login`</td></tr></tbody></table>

</div></div></div>Use accepted status codes from 200 through 399 if the application redirects to authentication.

The BookStack VM firewall must allow Uptime Kuma at `192.168.2.115` to reach TCP port 6875.

<div id="bkmrk--12" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Authentik Monitors

<div id="bkmrk-monitor-type-target--3" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Monitor</th><th>Type</th><th>Target</th></tr><tr><td>Authentik VM</td><td>Ping</td><td>`192.168.2.162`</td></tr><tr><td>Authentik Direct Readiness</td><td>HTTP</td><td>`http://192.168.2.162:9000/-/health/ready/`</td></tr><tr><td>Authentik Routed Readiness</td><td>HTTPS</td><td>`https://portal.bytek.ca/-/health/ready/`</td></tr><tr><td>Authentik Certificate</td><td>Certificate</td><td>`portal.bytek.ca`</td></tr><tr><td>Authentik Outpost</td><td>HTTP</td><td>Outpost ping endpoint</td></tr></tbody></table>

</div></div></div>Expected results:

<div id="bkmrk-direct-readiness-ret" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Direct readiness returns HTTP 200.
- Routed readiness returns HTTP 200.
- Outpost ping returns HTTP 204.

---

</div>## Traefik Monitors

<div id="bkmrk-monitor-type-target--4" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Monitor</th><th>Type</th><th>Target</th></tr><tr><td>Traefik VM</td><td>Ping</td><td>`192.168.2.182`</td></tr><tr><td>Traefik HTTPS</td><td>TCP</td><td>`192.168.2.182:443`</td></tr><tr><td>Traefik Dashboard</td><td>HTTPS</td><td>`https://proxy.bytek.ca/`</td></tr><tr><td>Traefik Certificate</td><td>Certificate</td><td>`proxy.bytek.ca`</td></tr></tbody></table>

</div></div></div>The dashboard monitor must account for Authentik and Basic Auth redirects if those protections are enabled.

Do not store Basic Auth credentials in BookStack.

<div id="bkmrk--13" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Proxmox Monitor Considerations

Proxmox may return a response that is valid but not HTTP 200 for some request methods.

Avoid relying on an unsupported HTTP HEAD request.

A TCP monitor on port 8006 can verify listener availability.

An HTTPS monitor can verify the login page if configured with an appropriate method and accepted status range.

Proxmox remains private and should be monitored using its private address.

<div id="bkmrk--14" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Certificate Monitoring

Important public hostnames should have certificate-expiry monitoring.

Recommended hostnames include:

<div id="bkmrk-portal.bytek.ca-clou" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `portal.bytek.ca`
- `cloud.bytek.ca`
- `projects.bytek.ca`
- `docs.bytek.ca`
- `status.bytek.ca`
- `proxy.bytek.ca`

</div>Certificate monitoring should alert before expiration.

A valid application response does not guarantee that certificate renewal automation remains healthy.

<div id="bkmrk--15" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Notification Channels

Uptime Kuma can notify administrators when a monitor changes state.

The configured notification methods should be recorded after verification.

Potential channels may include:

<div id="bkmrk-email.-microsoft-tea" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Email.
- Microsoft Teams webhook.
- Discord webhook.
- Matrix.
- Telegram.
- Other supported notification services.

</div>Notification credentials must remain outside BookStack.

BookStack should document:

<div id="bkmrk-notification-channel-1" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Notification channel name.
- Intended recipients.
- Severity policy.
- Test date.
- Secret-storage location.

---

</div>## Notification Policy

Recommended notification behavior:

### Critical Infrastructure

Immediate notification for:

<div id="bkmrk-proxmox.-pi-hole-dns" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Proxmox.
- Pi-hole DNS.
- WireGuard.
- Traefik.
- Authentik.
- Public VPS.

</div>### Applications

Notify after enough failed checks to avoid alerts from brief application restarts.

### Maintenance

Create maintenance windows before:

<div id="bkmrk-proxmox-reboots.-app" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Proxmox reboots.
- Application upgrades.
- Docker stack recreation.
- Firewall maintenance.
- Planned internet outages.
- Storage maintenance.

</div>This prevents expected maintenance from generating unnecessary alerts.

<div id="bkmrk--16" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Monitor Timing

Monitor intervals should balance timely detection with unnecessary load.

Suggested principles:

<div id="bkmrk-critical-service-che" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Critical service checks may run more frequently.
- Application backends can use moderate intervals.
- Certificate checks need less frequent execution.
- Avoid aggressively monitoring database internals without a clear operational need.
- Use retries before marking services down.
- Configure heartbeat intervals based on expected update frequency.

</div>These values should be tuned after observing false positives and actual recovery behavior.

<div id="bkmrk--17" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Status Pages

Status pages provide a consolidated view of selected monitors.

A public status page should include only services appropriate for public disclosure.

Avoid publishing:

<div id="bkmrk-private-ip-addresses" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Private IP addresses.
- Proxmox details.
- Pi-hole details.
- Authentik backend details.
- Internal database status.
- Hypervisor storage status.
- Internal firewall information.

</div>A private administrative status page may include more detail behind Authentik.

<div id="bkmrk--18" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Maintenance Windows

Use maintenance windows for planned outages.

Common maintenance events include:

<div id="bkmrk-proxmox-host-reboot." style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Proxmox host reboot.
- Electrical maintenance.
- Docker upgrades.
- Authentik upgrades.
- Nextcloud AIO upgrades.
- Traefik configuration changes.
- Storage work.
- Firewall work.
- Backup restoration testing.

</div>Record:

<div id="bkmrk-reason-for-maintenan" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Reason for maintenance.
- Affected monitors.
- Date and time.
- Expected service impact.
- Actual result.

---

</div>## Firewall Requirements

Uptime Kuma requires outbound access to monitored services.

Application firewalls may require narrow inbound rules from:

<div id="bkmrk-192.168.2.115" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- `192.168.2.115`

</div>Known direct-monitor requirements include:

<div id="bkmrk-destination-port-pi-" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"><div aria-expanded="false" class="___5wvz9a0 ftgm304 f1oy3dpc fm6nont f48hbct" data-stable-ignore="true" data-tabster="{"restorer":{"type":1}}" role="presentation" tabindex="0"><div class="___1dmoc29 f10pi13n ftgm304 f1enuhaj fdclmfp f1nbblvp fat0sn4 f1ov4xf1 fekwl8i f1lmfglv f1oz7aqm f1abmfm4 f1w619qj f16h0jq8"><table class="___1vyiefv f1ddd56o f16vktn6 f1ahpp82 f11qra4b f1uinfot fibjyge fvueend f9yszdx f1fu4s3n f3l3pb3 f10ghnd0 f8fmt76 fjvbh62 f1qrqxae f1vw5qpk fc02sbz fxawf59 fymf513 f1aoyrul f1el8yx3 f1pymoxg f1ofu761 fe6itr f7coize f1794535 f1o0pw0q fbjjl9v fk1v6el f16pyhcb f1ixlhx9 f12zef0i flu5r5u f19haqzy f1owmcxx f1oddm8q f1004tna fcoaxci fh0ee9u f15v23i2 f1dmj53 f1r1gcv9 f14z1veh ffufd3x f1ypplot f1660cg"><tbody><tr><th>Destination</th><th>Port</th></tr><tr><td>Pi-hole</td><td>TCP and UDP 53</td></tr><tr><td>Proxmox VE</td><td>TCP 8006</td></tr><tr><td>Traefik</td><td>TCP 443</td></tr><tr><td>Authentik</td><td>TCP 9000</td></tr><tr><td>Nextcloud</td><td>TCP 11000</td></tr><tr><td>Vikunja</td><td>TCP 3456</td></tr><tr><td>BookStack</td><td>TCP 6875</td></tr></tbody></table>

</div></div></div>ICMP must be allowed if ping monitors are used.

A failed ping monitor with a healthy HTTP monitor normally indicates blocked ICMP rather than a service outage.

<div id="bkmrk--19" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Health Validation

Check the VM address using:

`ip -br -4 addr`

Check the container state using:

`sudo docker compose ps`

Check container health using:

`sudo docker inspect --format='{{.State.Health.Status}}' uptime-kuma`

Confirm direct access using:

`curl -I http://192.168.2.115:3001/`

Confirm DNS inside the container using:

`sudo docker exec uptime-kuma getent hosts portal.bytek.ca`

Confirm the public route using:

`curl -I https://status.bytek.ca/`

Interpret redirects according to the currently enabled authentication layers.

<div id="bkmrk--20" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Logging

Review Uptime Kuma logs using:

`sudo docker compose logs --tail 100 uptime-kuma`

Follow logs live using:

`sudo docker compose logs -f uptime-kuma`

Review logs for:

<div id="bkmrk-database-startup-fai" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Database startup failures.
- Monitor connection failures.
- DNS errors.
- Certificate errors.
- Notification failures.
- Proxy-header errors.
- Authentication errors.
- File-permission problems.
- Persistent-volume errors.

</div>Do not paste access tokens, notification secrets, cookies, or push-monitor URLs into BookStack.

<div id="bkmrk--21" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Common Failure Scenarios

### Many Hostname Monitors Fail Simultaneously

Likely causes:

<div id="bkmrk-pi-hole-unavailable." style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Pi-hole unavailable.
- Container DNS failure.
- Traefik unavailable.
- WireGuard outage.
- VPS outage.

</div>Check direct IP monitors before assuming every application failed.

### Direct Backends Work but Routed Monitors Fail

Likely causes:

<div id="bkmrk-pi-hole-split-dns.-t" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Pi-hole split DNS.
- Traefik router.
- Certificate.
- Authentik proxy.
- Hostname mismatch.

</div>### VM Ping Fails but HTTP Works

Likely cause:

<div id="bkmrk-icmp-blocked-by-prox" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- ICMP blocked by Proxmox or guest firewall.

</div>The VM is likely available.

### Kuma Dashboard Works by IP but Not by Hostname

Check:

<div id="bkmrk-pi-hole.-traefik.-ce" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Pi-hole.
- Traefik.
- Certificate.
- Authentik provider.
- Browser DNS over HTTPS.

</div>### Authentik Login Works but Kuma Is Unreachable

Check:

<div id="bkmrk-internal-host-in-the" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Internal host in the Authentik Proxy Provider.
- Authentik VM firewall access to TCP 3001.
- Uptime Kuma container.
- Embedded outpost assignment.
- Host-header forwarding.

</div>### Public Status Page Requires Login

Check:

<div id="bkmrk-authentik-unauthenti" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Authentik unauthenticated-path patterns.
- Status-page slug.
- Static asset exclusions.
- Status API exclusions.
- Traefik routing.

</div>### Push Monitor Stops Working

Check:

<div id="bkmrk-push-path-exclusion." style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Push path exclusion.
- Push token.
- Traefik access logs.
- Authentik outpost logs.
- Monitor heartbeat interval.

---

</div>## Power-Failure Recovery

After a power interruption:

<div id="bkmrk-confirm-proxmox.-con" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Confirm Proxmox.
2. Confirm Pi-hole.
3. Confirm the WireGuard gateway.
4. Confirm Authentik.
5. Confirm Traefik.
6. Confirm the Uptime Kuma VM owns `192.168.2.115`.
7. Confirm Docker.
8. Confirm the container.
9. Confirm container DNS.
10. Confirm embedded MariaDB health.
11. Confirm direct dashboard access.
12. Confirm the routed dashboard.
13. Confirm monitors recover.
14. Restart or recreate the container only if DNS remains broken.

</div>Uptime Kuma should start after the core DNS, identity, and routing services when practical.

<div id="bkmrk--22" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Backup

The Uptime Kuma VM is included in the Proxmox scheduled backup job.

Protect:

<div id="bkmrk-persistent-%2Fapp%2Fdata" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Persistent `/app/data`.
- Docker Compose file.
- Environment file, if used.
- Any custom certificates.
- Notification configuration.
- Status-page assets.
- Monitor history.
- Embedded database.

</div>A stopped Proxmox backup provides the strongest whole-VM consistency for a baseline.

Snapshot-mode backup may be used for routine operation where downtime is undesirable.

<div id="bkmrk--23" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Recovery Procedure

If Uptime Kuma is corrupted or unavailable:

<div id="bkmrk-confirm-the-vm-is-ru" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Confirm the VM is running.
2. Confirm `192.168.2.115`.
3. Confirm Docker.
4. Confirm the persistent-data mount.
5. Confirm the container.
6. Review logs.
7. Confirm embedded database health.
8. Test direct TCP port 3001.
9. Test Pi-hole DNS.
10. Test the Traefik route.
11. Test the Authentik proxy.

</div>If the VM must be restored:

<div id="bkmrk-restore-the-latest-b" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Restore the latest backup under a temporary VM ID.
2. Disconnect the restored VM network adapter.
3. Verify Docker and persistent data.
4. Verify monitor configuration.
5. Shut down the failed production VM.
6. Assign the expected network identity.
7. Start the restored VM.
8. Confirm `192.168.2.115`.
9. Confirm the dashboard.
10. Confirm notifications and monitors.
11. Reconnect the Authentik route.

---

</div>## Authentik Recovery

If the Authentik proxy prevents access:

<div id="bkmrk-restore-the-known-go" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">1. Restore the known-good direct Traefik route.
2. Temporarily permit the administrative workstation to reach TCP 3001.
3. Access Uptime Kuma using the private IP.
4. Re-enable Uptime Kuma local authentication.
5. Repair the Authentik Proxy Provider.
6. Test Authentik with a private browser.
7. Confirm `bytek-admin` access.
8. Confirm a normal user is denied.
9. Disable local authentication again only after validation.
10. Restrict TCP 3001 again.

</div>Record the original administrator password securely even after local authentication is disabled.

<div id="bkmrk--24" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">---

</div>## Security Checklist

<div id="bkmrk-uptime-kuma-is-not-d" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Uptime Kuma is not directly exposed publicly on TCP 3001.
- Dashboard access requires `bytek-admin`.
- Authentik policy engine uses `ALL`.
- Direct backend access is restricted after local authentication is disabled.
- Trust Proxy is enabled when required.
- Public status-page exclusions are narrow.
- Push URLs are treated as secrets.
- Notification credentials are protected.
- Container DNS is `192.168.2.65`.
- Persistent data is backed up.
- Local recovery credentials are stored securely.
- Proxmox backup includes the Uptime Kuma VM.
- Public status pages do not reveal sensitive infrastructure details.

---

</div>## Validation Checklist

<div id="bkmrk-uptime-kuma-vm-owns-" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- Uptime Kuma VM owns `192.168.2.115`.
- Docker is active.
- Uptime Kuma container is running.
- Container health is `healthy`.
- Embedded MariaDB is available.
- Persistent data is mounted.
- Container DNS uses Pi-hole.
- Internal Bytek names resolve.
- Direct TCP 3001 responds.
- Routed dashboard responds.
- Authentik Proxy Provider works.
- `bytek-admin` is allowed.
- Normal users are denied.
- Public status pages work as intended.
- Push monitors work.
- Notifications are tested.
- Certificate monitoring works.
- Proxmox backup includes the VM.
- Recovery access has been tested.

---

</div>## Document Control

<div id="bkmrk-owner%3A-bryan-gagne-p" style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;">- **Owner:** Bryan Gagne-Plante
- **Private address:** `192.168.2.115`
- **Backend port:** TCP 3001
- **Public hostname:** `status.bytek.ca`
- **Deployment directory:** `/opt/uptime-kuma`
- **Database:** Embedded MariaDB
- **Container DNS:** `192.168.2.65`
- **Authentication:** Authentik Proxy Provider
- **Required group:** `bytek-admin`
- **Proxmox VM ID:** Confirm current VM ID
- **Last verified:** YYYY-MM-DD
- **Last notification test:** YYYY-MM-DD
- **Last Authentik proxy test:** YYYY-MM-DD
- **Last public status-page test:** YYYY-MM-DD
- **Last restore test:** YYYY-MM-DD
- **Known limitation:** Monitoring, status history, and alerting depend on one Uptime Kuma VM

</div>