---
created: 2026-07-30
modified: 2026-10-05
type: area
status: active
tags:
- network
- dev-ops
aliases: []
---
# Home Network Map
## Overview
| Network | Router/Gateway |
|---------|---------------|
| Subnet | `192.168.20.0/24` |
| Gateway | `192.168.20.1` |
| DNS | Pi-hole on **.35 (primary)** + **.13 (replica)** — confirmed live from `nebulasync` config: `PRIMARY=http://192.168.20.35`, `REPLICAS=http://192.168.20.13` |
---
## Dev-Ops Tooling
Mermaid + Archify (diagrams), Vikunja (tasks) and Outline (docs) are documented as tools in **[[Dev-Ops Tooling — Mermaid, Archify, Vikunja & Outline]]** — including the per-project `/docs/` artifact convention and pi-agent skills (`project-diagramming-mermaid`, `project-diagramming-archify`).
---
## Machines
### .27 — sam-4screen-desktop (Main Desktop)
| Property | Value |
| ---------------- | ------------------------------------------------------------------------------------------------------- |
| **IP** | `192.168.20.27` |
| **Hostname** | `sam-4screen-desktop` |
| **OS** | NixOS |
| **SSH** | ✅ `sam@192.168.20.27` |
| **Tailscale** | ✅ `100.65.228.31` (sam-4screen-desktop-1) |
| **Role** | Daily driver. 4 monitors, 62GB RAM, Nvidia GPU. Zellij, Neovim, pi coding agent. |
| **Key services** | pi, pi-dashboard, Neovim, Zellij (with falcode + attention plugins), Home Manager managed |
| **MCP tools** | `codebase-memory-mcp` v0.9.0, `code-review-graph` v2.3.7 (per-project, installed via `uv tool install`) |
| **Tunnels** | `ssh -fNL 7437:127.0.0.1:7437 192.168.20.13` (engram — must re-establish after reboot) |
| **Docker containers** | |
|---|---|
| **Archon** | AI project flow coordinator (`:3090`) |
| **Supabase** | Local dev auth + database (`kong :8001`, postgres `:5434`, studio, meta `:8080`, rest, auth) |
| **knowledge-service** | Custom Python API (`:8080`) |
| **langgraph-service** | LangGraph agent framework (`:8090`) |
| **opencode-brain** | OpenCode AI service (`:5000`) |
| **wherewoof-admin** | Where Woof admin UI — **exited** (6 weeks) |
> Corrected 2026-10-05: `airflow` does **not** run on `.27`. The only Airflow installs are on `.13` (see below).
### .13 — nixos-desktop (Server)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.13` |
| **Hostname** | `nixos-desktop` |
| **OS** | NixOS |
| **SSH** | ✅ `sam@192.168.20.13` |
| **Tailscale** | ✅ `100.114.62.46` (nixos-desktop) |
| **Role** | Docker host, OmniRoute LLM proxy, always-on server. 15 GiB RAM. GPU: GTX 760 (dead — see below).
| **Key services** | Outline wiki `:3000` (Docker). Open WebUI was removed 2026-08-26 |
| **NixOS** | 26.11 (Zokor) |
| **CPU** | AMD Ryzen 5 5600 — 6 cores / 12 threads |
| **Disks** | `sda2` 907G `/` (54% used) · `sdb2` `/mnt/storage` · `sdc2` `/mnt/data` · `sdd1` `/mnt/ubuntu_storage_3TB` (USB) · `sde1` Maxtor (unmounted) |
| **Live state**
(2026-10-05) | load avg **0.27** (12 threads) · RAM 6.8 GiB used of 15 GiB · **swap 7.1 GiB of 8.8 GiB used (81%)** |
> **`.13` is memory-bound, not CPU-bound.** The CPU is almost idle; the swap partition is 81% full. See [[Resource Use — .13 CPU & RAM]] and the project inventory at `~/chats/sys_config/resource_use_cpu_ram_13/SYSTEMS-INVENTORY.md`.
#### GPU upgrade — dead GTX 760 → AMD RX 6600 (recommended)
**Status (2026-08-25):** GTX 760 (Kepler, PCI `10de:11c2`) no longer works. `nvidiaPackages.stable` dropped Kepler support after driver branch 470; dmesg shows `NVRM: does not include the required GPU ... probe failed (-1)`. The legacy 470 driver is EOL and very unlikely to build on kernel 6.18 (~10–25% odds even with kernel pinning).
**Verified 2026-10-05:** no driver is bound at all. The only DRM device is `/dev/dri/card0` with `DRIVER=simple-framebuffer`; `/proc/driver/nvidia` does not exist. The desktop renders through software (llvmpipe/swrast) — this is why `.13`'s KDE processes use ~2.4 GB. Note `hardware.nvidia.open = true` in `configuration.nix` can never work on Kepler (open modules need Turing or newer).
**Recommended replacement: AMD RX 6600** (~$180–210 USD)
- **Zero NixOS driver pain:** in-kernel `amdgpu` — config becomes just `services.xserver.videoDrivers = [ "amdgpu" ];`. No legacy branches, no kernel-version roulette, ever.
- **No PSU gamble:** many models need no PCIe power connector (132 W). Safe with the new PSU regardless of wattage headroom.
- ~6–8× faster than the GTX 760; pairs cleanly with the Ryzen 5 5600. Flawless KDE/Wayland support.
- Alternatives if a spare 8-pin + ≥450 W PSU confirmed: RX 7600 (~$250), RTX 3060 12GB (~$270, only if CUDA needed).
**Swap procedure (safe):** power off → swap card → boot. If display fails, SSH recovery path is proven (`sam@192.168.20.27 → .13`); previous NixOS generations remain bootable from the boot menu. Update `videoDrivers` to `amdgpu`, then `nixos-rebuild switch`.
| Docker containers | |
|---|---|
| **OmniRoute** | LLM proxy with combo routing (port 20128/20129). All pi LLM traffic routes through it. Combo `default-opencode-go-ds-flash` prioritises OpenCode-Go before falling through OpenRouter → DeepSeek direct → Google Gemini. See [[Pi Agent Extensions & Skills#OmniRoute — LLM Provider Router]] |
| **~~Langfuse~~** | ~~LLM observability — traces, evals, cost tracking~~ **⛔ REMOVED 2026-09-06** (was port `:3001`, bumped from 3000 by Open WebUI). Stack + data deleted — resource hog. |
| **worldmonitor** | Geopolitical news dashboard (port 3002) |
| **mosquitto** | MQTT broker |
| **pihole** | DNS ad-blocking — **replica** of `.35` (web UI `:8080`) |
| **nebula-sync** | Pulls Pi-hole Gravity from `.35:8095` → `.13:8080` |
| **headroom** | JEV/context-compression proxy (port 8787) — `--proxy-extension fast_jev` → OmniRoute |
| **~~engram~~** | ⚠️ The *container* was created 2026-06-13 and **never started** (dead). The live engram is a **native user systemd service** `/home/sam/.local/bin/engram serve` on `:7437`, with data at `~/.engram/`. Its API reports **0 sessions, 0 observations, 0 prompts — it is empty and unused** |
| **n8n** | Workflow automation |
| **outline + outline_postgres + outline_redis** | Wiki / project documentation (`:3000`) |
| **voice_bridge + voice_whisper** | MQTT audio bridge + Whisper STT (`:5000`, model `small.en`, ~877 MB — largest container) |
| **piper_tts** | Text-to-speech |
| **prefect-server** | Photo-pipeline workflow server (`:4200`) — pair with the `prefect-worker` user service |
| **family-home-lab** (12 containers) | portal `:8500`, transcriber, gimp `:8087`, video `:8083`, audio `:8084`, lmms `:8085`, postgres, rabbitmq, redis, garage `:3900-3903`, garage-webui `:3909` |
| **dsh** (4 containers) | DeepSeek Harness per family member (`:3081-3084`) |
| **wherewoof** (3 containers) | `wherewoof-db :5434`, `wherewoof-admin :3031`, `wherewoof-minio :9010/9011` |
| **ai-resume** (4 containers) | backend `:8001`, db, knowledge-service `:8082`, langgraph-service `:8091` — the last two also duplicate `.27` |
| **worldmonitor** (4 containers) | dashboard `:3002`, redis, redis-rest, ais-relay |
| **Plus:** pocketbase `:8090`, doorbell_media `:8088`, metube `:8086`, kontra `:8600`, lite_llm `:4000`, lite_llm| |
| **⛔ Dead stacks** | `airflow` — 7 containers exited 4 weeks ago, **24 GB of logs** in `/home/sam/deployment/airflow/logs` · `engram` container (never started) · `trigger_dev` (not running) |
**Native services on `.13` (not Docker):** `caddy :8000` (serves `/var/www` resume + portfolio sites), `snapserver`, `librespot`, `mopidy`, `postgresql :5433` (`paperclip` DB), `voice-agent :8501` (Jervis), `offsite-web :8095`, `tailscaled`.
**User services:** `paperclipai :3100` (~495 MB), `Paseo Daemon :6767`, `where-woof :3020` (Go), `photo-dashboard :8092`, `prefect-worker`, `engram :7437`, `chrome-pi :9222`, `lan-mouse`, KDE Plasma session (~2.4 GB).
See [[Docker Containers]] for full container list.
### .51 — sam-thinkpad (Laptop)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.51` |
| **Hostname** | `sam-thinkpad` |
| **OS** | NixOS |
| **SSH** | ✅ `sam@192.168.20.51` |
| **Tailscale** | ✅ `100.88.161.102` (sam-thinkpad) |
| **Role** | Portable laptop. Used on-the-go and at home. pi, Neovim, Home Manager managed.
| **MCP tools** | `codebase-memory-mcp` v0.9.0, `code-review-graph` v2.3.7 (installed via `nix-shell -p uv`) |
### Proxmox — Hypervisor
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.28` |
| **Hostname** | `proxmox` |
| **OS** | Proxmox VE |
| **URL** | `https://192.168.20.28:8006` (also `proxmox.home.lab` via Caddy) |
| **SSH** | `root@192.168.20.28` (admin via web UI) |
| **Role** | Hypervisor. VMs hosted: `.35` (sam-ubuntu1 / Caddy), `.23` (file-server), `.30` (Home Assistant), `.48` (Proxmox Backup Server) |
### Home Assistant
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.30` |
| **Hostname** | `homeassistant` (HAOS) |
| **OS** | Home Assistant OS v13.1 |
| **URL** | `http://192.168.20.30:8123` (also `homeassistant.home.lab`, `homeassistant.lab.audasmedia.com.au`, `homeassistant.lab.quickweb.com.au` via Caddy) |
| **Role** | Home automation VM on Proxmox (.28). Smart home control, automations, dashboards. |
### Routers
| Host | IP | Notes |
|------|-----|-------|
| **Main router (Netcom)** | `192.168.20.1` | Gateway. Admin UI on port `8079` |
| **Second router** | `192.168.20.254` | Secondary access point / router |
### .35 — caddy-server (Reverse Proxy)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.35` |
| **Hostname** | `caddy-server` (aka `sam-ubuntu1`) |
| **OS** | Ubuntu 24.04 Server (VM on Proxmox .28) |
| **SSH** | ✅ `sam@192.168.20.35` |
| **Tailscale** | Not installed |
| **Role** | Caddy reverse proxy. Runs ~50 Docker containers (apps, dashboards, media, monitoring). |
| **Gitea** | Git hosting: `gitea-server-1` + `gitea-db-1` (Docker). Web: `.35:3001` ("Gitea: Audas Media"), SSH: `.35:2222`. Key repo: `sam/pi-config` (pi agent assets — every machine clones it) |
**Proxied domains:**
| Domain | Proxied to |
|--------|-----------|
| `omniroute.lab.audasmedia.com.au` | `.13:20129` |
| `worldmonitor.lab.audasmedia.com.au` | `.13:3002` |
| `gitea.lab.audasmedia.com.au` | `.35:3001` (web) / `.35:2222` (SSH) |
**Websites I've built** (public `*.lab.audasmedia.com.au`): console portal, media tools (photo/video/audio/lmms), DeepSeek Harness (`dsh-*`), family chat, resume/portfolio (`sam-*`, wiki), home dash. Full list → [[Websites on Nixos-Desktop 13]].
See [[Docker Containers]] for full container list on .35.
### .23 — file-server (Proxmox VM)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.23` |
| **Hostname** | `file-server` |
| **OS** | (VM on Proxmox) |
| **SSH** | ❌ No SSH access |
| **Role** | NFS/USB file server. Hosts the 2.7T `usb_3tb` share → mounted by `.35` at `/mnt/nfs_usb_3tb` (Kopia + Restic/Backrest backup repos, Home Assistant backups) |
### .48 — Proxmox Backup Server
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.48` |
| **Hostname** | `proxmox-backup` |
| **OS** | Proxmox Backup Server |
| **URL** | `https://192.168.20.48:8007` (also `proxmox_backup.home.lab` via Caddy) |
| **SSH** | `root@192.168.20.48` |
| **Role** | VM-level backup server for Proxmox — full VM backups (incl. `.35`, `.23`, `.30`) |
### .150 — Phone (Android)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.150` (static) |
| **Device** | Android phone |
| **SSH** | ✅ Termux → `ssh` from/to other machines (port 8022, user: `uO_a499`) |
| **Tailscale** | ✅ `100.101.49.17` (google-pixel-8a) |
| **Role** | Mobile access. Termux for SSH, Tailscale for remote, NTFY for notifications. |
### .24 — skinnyspeakers (Raspberry Pi)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.24` |
| **Hostname** | `skinnyspeakers` |
| **OS** | Raspbian 12 (bookworm) |
| **SSH** | ✅ `sam@192.168.20.24` |
| **Role** | Raspberry Pi — likely Snapcast speaker/audio client. ⚠️ Identified 2026-08-29 — please confirm role |
---
## Web Deploy Sync (.27 → .13)
Web sites sync via **manual lsyncd** on .27 → rsync+ssh to .13 `/var/www/`:
- Config: `/home/sam/.config/lsyncd/lsyncd.conf.lua`
- Sites: `sprinklers`, `sam-developer`, `sam-devops` (+ any added in config)
- New folder on .13: `sudo chown -R sam:users /var/www/` (NixOS `users` group)
- Secrets env: `~/.config/environment.d/10-secrets.conf` (git-safe on NixOS)
---
## SSH Access Matrix
| From ↓ / To → | .27 desktop | .13 server | .51 laptop | .35 caddy | .150 phone |
|--------------|-------------|------------|------------|-----------|------------|
| **.27 desktop** | — | `sam@192.168.20.13` | `sam@192.168.20.51` | `sam@192.168.20.35` | `uO_a499@192.168.20.150:8022` |
| **.13 server** | `sam@192.168.20.27` | — | `sam@192.168.20.51` | `sam@192.168.20.35` | `uO_a499@192.168.20.150:8022` |
| **.51 laptop** | `sam@192.168.20.27` | `sam@192.168.20.13` | — | `sam@192.168.20.35` | `uO_a499@192.168.20.150:8022` |
| **.150 phone** | `sam@192.168.20.27` | `sam@192.168.20.13` | `sam@192.168.20.51` | `sam@192.168.20.35` | — (Termux local) |
**Proxmox (`root@192.168.20.28`) & PBS (`root@192.168.20.48`):** admin via web UI or root SSH.
**SSH config shortcut (`~/.ssh/config`):**
```text
Host phone
HostName 192.168.20.150
Port 8022
User uO_a499
```
(Added to .27 and .51. .13 needs home.nix update — `~/.ssh/config` is a Nix store symlink.)
---
## Key Apps & Ports
| Port | Service | Machine |
|------|---------|---------|
| `22` | SSH | All |
| `53` | DNS (Pi-hole) | .13, .35 |
| `80/443` | Caddy reverse proxy | .35 |
| `1883` | MQTT (Mosquitto) | .13 |
| `3002` | worldmonitor | .13 |
| `8022` | SSH (Termux) | .150 phone |
| `20129` | OmniRoute API | .13 |
| `20128` | OmniRoute dashboard | .13 |
| `7437` | engram | .13 |
| `8787` | Headroom proxy | .13 |
| `8079` | Netcom Router admin | Router (192.168.20.1) |
| `254` | Secondary Router admin | Router (192.168.20.1) |
| `8006` | Proxmox VE web UI | .28 |
| `8007` | Proxmox Backup Server web UI | .48 |
| `8123` | Home Assistant web UI | .30 |
| `3000` | Outline wiki (was Open WebUI — removed 2026-08-26) | .13 |
| ~~`3001`~~ | ~~Langfuse — removed 2026-09-06~~ | .13 |
| `8000` | Caddy static sites (`/var/www`) | .13 |
| `5433` | Native PostgreSQL (`paperclip` DB) | .13 |
| `3100` | Paperclip agent harness | .13 |
| `6767` | Paseo Daemon (native, not Docker) | .13 |
| `3020` | Where Woof frontend (Go) | .13 |
| `8092` | photo-pipeline dashboard | .13 |
| `8095` | offsite status page | .13 |
| `9222` | Headless Chrome (pi browser harness, localhost) | .13 |
| `2222` | Gitea SSH (git remotes) | .35 |
| `3001` | Gitea web UI | .35 |
| `3090` | Archon | .27 |
| `8001` | Supabase Kong | .27 |
| `8001` | ai-resume-backend | .13 |
| `8080` | knowledge-service | .27 |
| `8090` | langgraph-service | .27 |
| `5000` | opencode-brain | .27 |
| `1780` | Snapcast (audio control) | .13 |
| `8765` | python3 (unidentified) | .27 |
| `3900` | Garage S3 API | .13 |
| `3902` | Garage admin API | .13 |
| `3909` | **Garage Web UI** (`garage-webui`) | .13 |
---
## Web Apps by Machine
### .27 — sam-4screen-desktop (Docker host)
| App | URL | Notes |
|-----|-----|-------|
| Archon | `http://192.168.20.27:3090/chat` | AI project flow coordinator |
| Supabase Studio | `http://192.168.20.27:8001/project/default` | Local dev auth + database GUI |
| knowledge-service | `http://192.168.20.27:8080` | Custom Python API |
| langgraph-service | `http://192.168.20.27:8090` | LangGraph agent framework |
| opencode-brain | `http://192.168.20.27:5000` | OpenCode AI endpoint |
| knowledge-service | `http://192.168.20.27:8080` | Custom Python API |
| langgraph-service | `http://192.168.20.27:8090` | LangGraph agent framework |
| opencode-brain | `http://192.168.20.27:5000` | OpenCode AI endpoint |
### .13 — nixos-desktop (Docker host)
| App | URL | Notes |
|-----|-----|-------|
| Snapcast | `http://192.168.20.13:1780/` | Multi-room audio control — needs Caddy DNS |
| ai-resume-backend | `http://192.168.20.13:8001` | Resume AI backend (Docker) |
| Outline wiki | `http://192.168.20.13:3000` | Project docs/wiki (Docker) |
| Caddy static sites | `http://192.168.20.13:8000` | `/var/www` — resume/portfolio + sprinklers, sequence, chat |
| Paperclip | `http://192.168.20.13:3100` | Agent harness manager (~495 MB) |
| Paseo | `http://192.168.20.13:6767` | Multi-agent GUI (native user service, not Docker) |
| Where Woof | `http://192.168.20.13:3020` | Go/HTMX frontend |
### .35 — caddy-server (Reverse Proxy)
| App | URL | Notes |
|-----|-----|-------|
| OmniRoute dashboard | `http://omniroute.home.lab` | LLM routing proxy GUI |
| OmniRoute API | `http://omniroute.lab.audasmedia.com.au` | Public LLM API endpoint |
### Proxmox
| App | URL | Notes |
|-----|-----|-------|
| Proxmox VE | `https://192.168.20.28:8006` (or `proxmox.home.lab`) | Hypervisor — hosts .35 VM, .23 file-server, HA VM, .48 PBS |
| Proxmox Backup Server | `https://192.168.20.48:8007` (or `proxmox_backup.home.lab`) | VM backups |
| Home Assistant | `http://192.168.20.30:8123` | Home automation |
---
## lan-mouse — Cross-Machine Mouse/Keyboard Sharing
| Detail | Value |
|--------|-------|
| **Version** | v0.10.0 (pre-encryption, from [GitHub releases](https://github.com/feschber/lan-mouse/releases/tag/v0.10.0)) |
| **Binary** | `~/.local/bin/lan-mouse` (same binary on all three) |
| **Service** | `~/.config/systemd/user/lan-mouse.service` (enabled, auto-starts) |
| **Config** | `~/.config/lan-mouse/config.toml` |
| **Port** | UDP 4242 |
| **Encryption** | None. v0.11.0 DTLS is broken — `Alert is Fatal or Close Notify` even on identical binaries. |
**Layout:** `.13 ← .27 → .51`
- .27: `[left] ips = ["192.168.20.13", "192.168.20.46"]` `.46` is .13's Wi-Fi — required.
- .27: `[right] ips = ["192.168.20.51"]`
- .13: `[right] ips = ["192.168.20.27"]`
- .51: `[left] ips = ["192.168.20.27"]`
**Startup flags:**
- .27/.51: `--daemon --capture-backend layer-shell`
- .13: `--daemon --emulation-backend libei` (KDE), uses wrapper script for NixOS libs
**Release key:** Press `ASDF` together to free trapped mouse back to .27.
**⚠️ Gotchas:**
- **Never use hostnames** — Tailscale resolves to virtual IPs. Raw IPs only.
- **v0.11.0 does NOT work** — DTLS broken everywhere.
- **.13 needs both IPs** (wired `.13` + Wi-Fi `.46`) in other machines' client list.
- **v0.10.0 limitation:** Modifier keys (Super/Alt/Ctrl) not forwarded on wlroots. Basic typing/mouse works.
- **KDE (.13):** Accept input emulation permission dialog on first run.
## Tailscale (Tailnet)
| Machine | Tailscale Name | Tailscale IP | Status |
|---------|---------------|-------------|--------|
| .27 desktop | sam-4screen-desktop-1 | `100.65.228.31` | ✅ Active |
| .13 server | nixos-desktop | `100.114.62.46` | ✅ Active |
| .51 laptop | sam-thinkpad | `100.88.161.102` | ✅ Active |
| .150 phone | google-pixel-8a | `100.101.49.17` | ⚠️ Offline (last seen 1d ago) |
| .35 caddy | — | — | ❌ Not installed |
Account: `samuelrolfe@gmail.com`
---
## DNS
| Server | IP | Role |
|--------|----|------|
| Pi-hole (primary) | `192.168.20.35` | DNS ad-blocking, local DNS for `.home.lab` domains — **confirmed 2026-10-05** |
| Pi-hole (replica) | `192.168.20.13` | DNS ad-blocking, failover (nebula-sync pulls from .35 → .13) |
### Local domains needing DNS records
| Domain | Target | Status |
|--------|--------|--------|
| `omniroute.home.lab` | `.13:20128` | ✅ Created |
| `omniroute.lab.audasmedia.com.au` | `.35`→`.13:20129` | ✅ Caddy proxied |
| `worldmonitor.home.lab` | `.13:3002` | ❌ Needs Pi-hole record |
| `worldmonitor.lab.audasmedia.com.au` | `.35`→`.13:3002` | ❌ Needs DNS + Caddy done |
| `gitea.home.lab` | `.35:3001` | ✅ Pi-hole → .35 |
| `gitea.lab.audasmedia.com.au` | public `144.6.86.11` → router → `.35` (web `.35:3001`, SSH `.35:2222`) | ✅ External DNS (used by git remotes) |