Author SHA1 Message Date
rock 6243ac40b7 feat(paperless-ai): enable intelligent timeline tagging with date extraction
- Add ENABLE_INTELLIGENT_TAGGING for advanced AI-powered tagging
- Add ENABLE_DATE_EXTRACTION for automatic date/timeline parsing
- Add ENABLE_TIMELINE_TAGGING to create temporal tags (YYYY, Q#-YYYY, Last-Month, etc)
- Set TAG_EXTRACTION_MODEL to reasoning for sophisticated analysis
- Configure timeline granularity (year, quarter, month)
- Add custom prompt for temporal context extraction
- Auto-create tags for historical and recent documents
2026-09-15 00:53:30 +09:00
rock d6fca68f33 chore(paperless-ai): switch LLM model to reasoning for document processing 2026-09-15 00:38:37 +09:00
rock e12327f963 fix(grafana): re-enable org role sync for OAuth groups
Re-enable skip_org_role_sync=false to sync Admin role from grafana-admins group.
User creation worked with skip_org_role_sync=true, now restore role sync.
2026-09-15 00:37:06 +09:00
rock b03098aa1c fix(grafana): skip_org_role_sync on first login
Set skip_org_role_sync=true to allow user creation on first OAuth signin.
When false, Grafana tries to sync org roles before user exists, causing creation to fail.
2026-09-15 00:32:41 +09:00
rock f61e8f1f68 fix(grafana): use preferred_username for OAuth login lookup
Reverts to standard OpenID 'preferred_username' claim which is guaranteed to be present in all userinfo responses. The 'email' claim requires explicit scope mapping in Authentik that may not be consistently returned.

Authentik user 'rock' has preferred_username='rock' which matches the existing Grafana user login.
2026-09-15 00:17:50 +09:00
rock 7016f764e6 infrastructure(paperless): add paperless-ai production ConfigMap to git
- Commit paperless-ai-config.yaml with production environment variables
- Configure Paperless API endpoint and token
- Enable AI processing with qwen2.5:3b model
- Set up auto-tagging, correspondent/document type extraction
- Configure 60s scan interval for document processing
- Add ConfigMap to kustomization.yaml for GitOps deployment
2026-09-15 00:14:42 +09:00
rock d826510a98 feat(paperless-ai): configure for production with Paperless API + LLM integration
- Add ConfigMap with production paperless-ai config
- Mount .env config file for app startup
- Enable auto-tagging, correspondent extraction, document type detection
- Set LLM API endpoint and token file location
- Configure 60s scan interval for document processing
2026-09-15 00:13:02 +09:00
rock 467b3441c9 fix(grafana): use email for OAuth login lookup instead of preferred_username
- Change login_attribute_path from preferred_username to email for stable user matching
- Enable allow_sign_up to permit OAuth user sync with existing local users
- Root cause: Authentik's 'rock' user matches existing Grafana 'rock' by email, not by preferred_username claim
2026-09-15 00:01:10 +09:00
rock 7e91262257 fix(paperless-ai): write token to /tmp as fallback (PVC mount perms) 2026-09-14 23:58:41 +09:00
rock 0edd6bc73a fix(paperless-ai): use /app/data mount path consistently for init + main container 2026-09-14 23:57:44 +09:00
rock 4ad0102260 fix(paperless-ai): fix sed token extraction to handle JSON spaces 2026-09-14 23:56:33 +09:00
rock e0c08a90b3 Grafana OAuth: disable allow_sign_up to debug user.sync failure 2026-09-14 23:56:04 +09:00
rock dfbe2cc920 fix(paperless-ai): use sed for JWT token extraction (jq not available) 2026-09-14 23:55:53 +09:00
rock ae93c7ca0d fix(paperless-ai): use jq for JWT token extraction instead of grep 2026-09-14 23:54:57 +09:00
4 changed files with 72 additions and 9 deletions
+1
View File
@@ -4,6 +4,7 @@ namespace: paperless
resources:
- pvc.yaml
- configmap.yaml
- paperless-ai-config.yaml
- redis.yaml
- deployment.yaml
- service.yaml
@@ -0,0 +1,49 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: paperless-ai-env
namespace: paperless
data:
paperless-ai-config.env: |
# Paperless-NGX API configuration
PAPERLESS_URL=http://paperless.paperless.svc.cluster.local:8000
PAPERLESS_API_TOKEN=7b89463e04c141f4172fbcddf78d623547d327ec
# AI Processing settings
ENABLE_AI_PROCESSING=yes
AI_MODEL=reasoning
LLM_API_URL=https://api.riotpiao.com/v1
LLM_API_TOKEN_FILE=/app/data/llm_token.txt
# Auto-tagging configuration
ENABLE_AUTO_TAGGING=yes
ENABLE_CORRESPONDENT_EXTRACTION=yes
ENABLE_DOCUMENT_TYPE_EXTRACTION=yes
ENABLE_TITLE_GENERATION=yes
# Advanced tagging with AI
ENABLE_INTELLIGENT_TAGGING=yes
ENABLE_DATE_EXTRACTION=yes
ENABLE_TIMELINE_TAGGING=yes
AUTO_CREATE_TAGS=yes
# Tagging prompts for custom extraction
CUSTOM_EXTRACTION_PROMPT=Extract document date, time period, financial year, and temporal context. Create tags like YYYY, Q1-YYYY, Last-Month, Current-Year, Historic
TAG_EXTRACTION_MODEL=reasoning
# Scanning behavior
SCAN_INTERVAL_SECONDS=60
PROCESS_EXISTING_DOCUMENTS=no
ADD_AI_TAG=yes
AI_TAG_NAME=ai-processed
# Date/Timeline tagging configuration
DATE_EXTRACTION_FORMAT=iso8601
TIMELINE_TAG_GRANULARITY=year,quarter,month
AUTO_TAG_HISTORICAL=yes
AUTO_TAG_RECENT=yes
# Performance
MAX_CONCURRENT_REQUESTS=2
REQUEST_TIMEOUT=60
DATE_EXTRACTION_TIMEOUT=30
+19 -6
View File
@@ -25,9 +25,15 @@ spec:
- name: paperless-ai-data
persistentVolumeClaim:
claimName: paperless-ai-data
- name: paperless-ai-env-config
configMap:
name: paperless-ai-env
initContainers:
- name: fetch-llm-token
image: curlimages/curl:8.12.0
securityContext:
runAsUser: 0
fsGroup: 0
command:
- sh
- -c
@@ -43,8 +49,8 @@ spec:
-d "client_secret=${LLM_AUTH_CLIENT_SECRET}" \
-d "scope=openid llm:inference" 2>/dev/null)
# Extract token
TOKEN=$(echo "$TOKEN_RESPONSE" | grep -o '"access_token":"[^"]*' | cut -d'"' -f4)
# Extract token from JSON response using sed (handles spaces after colons)
TOKEN=$(echo "$TOKEN_RESPONSE" | sed -n 's/.*"access_token"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p')
if [ -z "$TOKEN" ]; then
echo "[error] Failed to get token. Response: $TOKEN_RESPONSE"
@@ -52,9 +58,13 @@ spec:
fi
# Store token in file for main container to read
mkdir -p /data
echo "$TOKEN" > /data/llm_token.txt
echo "[init] Token fetched and stored successfully"
# Write to both locations for compatibility
mkdir -p /tmp/llm-token /app/data 2>/dev/null || true
echo "$TOKEN" | tee /tmp/llm-token/llm_token.txt > /dev/null 2>&1
echo "$TOKEN" > /app/data/llm_token.txt 2>/dev/null || true
echo "[init] Token fetched and stored"
[ -f /tmp/llm-token/llm_token.txt ] && echo " -> /tmp/llm-token/llm_token.txt"
[ -f /app/data/llm_token.txt ] && echo " -> /app/data/llm_token.txt"
env:
- name: LLM_AUTH_CLIENT_SECRET
valueFrom:
@@ -63,7 +73,7 @@ spec:
key: LLM_AUTH_CLIENT_SECRET
volumeMounts:
- name: paperless-ai-data
mountPath: /data
mountPath: /app/data
containers:
- name: paperless-ai
image: clusterzx/paperless-ai:latest
@@ -105,6 +115,9 @@ spec:
volumeMounts:
- name: paperless-ai-data
mountPath: /app/data
- name: paperless-ai-env-config
mountPath: /app/data/.env
subPath: paperless-ai-config.env
resources:
requests:
cpu: 100m
+3 -3
View File
@@ -73,7 +73,7 @@ grafana.ini:
auth.generic_oauth:
enabled: true
name: Authentik
allow_sign_up: true
allow_sign_up: true # Allow sync to create/update users from OAuth claims
client_id: grafana
scopes: openid email profile groups
auth_url: https://authentik.riotpiao.com/application/o/authorize/
@@ -84,13 +84,13 @@ grafana.ini:
# Authentik doesn't serve — request 404s with "Error getting email address"
# and the whole OAuth login fails.
email_attribute_path: email
login_attribute_path: preferred_username
login_attribute_path: preferred_username # Use preferred_username — OpenID standard claim, always present
name_attribute_path: name
role_attribute_path: "preferred_username == 'akadmin' && 'GrafanaAdmin' || contains(groups[*], 'homelab-admins') && 'Admin' || 'Viewer'"
allow_assign_grafana_admin: true
use_pkce: false
use_refresh_token: false
skip_org_role_sync: false
skip_org_role_sync: false # Sync org roles from OAuth groups
tls_skip_verify_insecure: true # Authentik uses self-signed cert; verify in prod
# GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET is injected from the grafana-oidc K8s