Files
obsidian-vault/300 areas/360 Dev-Ops Network Computers/Home Network Map Overview.md

374 lines
16 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
created: 2026-07-30
modified: 2026-08-29
type: note
tags:
- network
- dev-ops
aliases: []
---
# Home Network Map
## Overview
| Network | Router/Gateway |
|---------|---------------|
| Subnet | `192.168.20.0/24` |
| Gateway | `192.168.20.1` |
| DNS | Pi-hole on .13 (primary) + .35 (secondary) |
---
## Dev-Ops Tooling
Mermaid + Archify (diagrams), Vikunja (tasks) and Outline (docs) are documented as tools in **[[Dev-Ops Tooling — Mermaid, Archify, Vikunja & Outline]]** — including the per-project `/docs/` artifact convention and pi-agent skills (`project-diagramming-mermaid`, `project-diagramming-archify`).
---
## Machines
### .27 — sam-4screen-desktop (Main Desktop)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.27` |
| **Hostname** | `sam-4screen-desktop` |
| **OS** | NixOS |
| **SSH** | ✅ `sam@192.168.20.27` |
| **Tailscale** | ✅ `100.65.228.31` (sam-4screen-desktop-1) |
| **Role** | Daily driver. 4 monitors, 62GB RAM, Nvidia GPU. Zellij, Neovim, pi coding agent. |
| **Key services** | pi (with pi-langfuse → traces to Langfuse .13:3001), pi-dashboard, Neovim, Zellij (with falcode + attention plugins), Home Manager managed
| **MCP tools** | `codebase-memory-mcp` v0.9.0, `code-review-graph` v2.3.7 (per-project, installed via `uv tool install`)
| **Tunnels** | `ssh -fNL 7437:127.0.0.1:7437 192.168.20.13` (engram — must re-establish after reboot) |
| **Docker containers** | |
|---|---|
| **Archon** | AI project flow coordinator (`:3090`) |
| **Supabase** | Local dev auth + database (`kong :8001`, postgres `:5434`, studio, meta `:8080`, rest, auth) |
| **knowledge-service** | Custom Python API (`:8080`) |
| **langgraph-service** | LangGraph agent framework (`:8090`) |
| **opencode-brain** | OpenCode AI service (`:5000`) |
| **airflow** | Workflow orchestration |
### .13 — nixos-desktop (Server)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.13` |
| **Hostname** | `nixos-desktop` |
| **OS** | NixOS |
| **SSH** | ✅ `sam@192.168.20.13` |
| **Tailscale** | ✅ `100.114.62.46` (nixos-desktop) |
| **Role** | Docker host, OmniRoute LLM proxy, always-on server. 15.5GB RAM. GPU: GTX 760 (dead — see below).
| **Key services** | Open WebUI v0.11.0 `:3000` (NixOS native, not Docker) |
#### GPU upgrade — dead GTX 760 → AMD RX 6600 (recommended)
**Status (2026-08-25):** GTX 760 (Kepler, PCI `10de:11c2`) no longer works. `nvidiaPackages.stable` dropped Kepler support after driver branch 470; dmesg shows `NVRM: does not include the required GPU ... probe failed (-1)`. The legacy 470 driver is EOL and very unlikely to build on kernel 6.18 (~10–25% odds even with kernel pinning).
**Recommended replacement: AMD RX 6600** (~$180–210 USD)
- **Zero NixOS driver pain:** in-kernel `amdgpu` — config becomes just `services.xserver.videoDrivers = [ "amdgpu" ];`. No legacy branches, no kernel-version roulette, ever.
- **No PSU gamble:** many models need no PCIe power connector (132 W). Safe with the new PSU regardless of wattage headroom.
- ~6–8× faster than the GTX 760; pairs cleanly with the Ryzen 5 5600. Flawless KDE/Wayland support.
- Alternatives if a spare 8-pin + ≥450 W PSU confirmed: RX 7600 (~$250), RTX 3060 12GB (~$270, only if CUDA needed).
**Swap procedure (safe):** power off → swap card → boot. If display fails, SSH recovery path is proven (`sam@192.168.20.27 → .13`); previous NixOS generations remain bootable from the boot menu. Update `videoDrivers` to `amdgpu`, then `nixos-rebuild switch`.
| Docker containers | |
|---|---|
| **OmniRoute** | LLM proxy with combo routing (port 20128/20129). All pi LLM traffic routes through it. Combo `default-opencode-go-ds-flash` prioritises OpenCode-Go before falling through OpenRouter → DeepSeek direct → Google Gemini. See [[Pi Agent Extensions & Skills#OmniRoute — LLM Provider Router]] |
| **Langfuse** | LLM observability — receives pi traces via the **pi-langfuse** extension (port `:3001`, bumped from 3000 by Open WebUI) |
| **worldmonitor** | Geopolitical news dashboard (port 3002) |
| **mosquitto** | MQTT broker |
| **pihole** | DNS ad-blocking (primary) |
| **nebula-sync** | Pi-hole Gravity sync |
| **headroom** | Context compression proxy (port 8787) |
| **engram** | Journaling service (port 7437) |
| **n8n** | Workflow automation |
| **voice_bridge + voice_whisper** | MQTT audio bridge |
| **piper_tts** | Text-to-speech |
| **Plus:** pocketbase, doorbell_media, litellm, langfuse, airflow, trigger_dev, garage, **garage-webui**, t3_stack_react, sams-home-network | |
**AI observability flow:** pi (on .27/.13/.51) → **pi-langfuse** pi extension (npm:pi-langfuse, enabled per project) → Langfuse (`.13:3001`). One trace per pi conversation, grouped by session, with tokens + cost. Keys: `~/.pi/agent/pi-langfuse/config.json`. See [[Pi Agent Extensions & Skills#pi-langfuse — LLM Observability for Pi]]
See [[Docker Containers]] for full container list.
### .51 — sam-thinkpad (Laptop)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.51` |
| **Hostname** | `sam-thinkpad` |
| **OS** | NixOS |
| **SSH** | ✅ `sam@192.168.20.51` |
| **Tailscale** | ✅ `100.88.161.102` (sam-thinkpad) |
| **Role** | Portable laptop. Used on-the-go and at home. pi, Neovim, Home Manager managed.
| **MCP tools** | `codebase-memory-mcp` v0.9.0, `code-review-graph` v2.3.7 (installed via `nix-shell -p uv`) |
### Proxmox — Hypervisor
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.28` |
| **Hostname** | `proxmox` |
| **OS** | Proxmox VE |
| **URL** | `https://192.168.20.28:8006` (also `proxmox.home.lab` via Caddy) |
| **SSH** | `root@192.168.20.28` (admin via web UI) |
| **Role** | Hypervisor. VMs hosted: `.35` (sam-ubuntu1 / Caddy), `.23` (file-server), `.30` (Home Assistant), `.48` (Proxmox Backup Server) |
### Home Assistant
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.30` |
| **Hostname** | `homeassistant` (HAOS) |
| **OS** | Home Assistant OS v13.1 |
| **URL** | `http://192.168.20.30:8123` (also `homeassistant.home.lab`, `homeassistant.lab.audasmedia.com.au`, `homeassistant.lab.quickweb.com.au` via Caddy) |
| **Role** | Home automation VM on Proxmox (.28). Smart home control, automations, dashboards. |
### Routers
| Host | IP | Notes |
|------|-----|-------|
| **Main router (Netcom)** | `192.168.20.1` | Gateway. Admin UI on port `8079` |
| **Second router** | `192.168.20.254` | Secondary access point / router |
### .35 — caddy-server (Reverse Proxy)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.35` |
| **Hostname** | `caddy-server` (aka `sam-ubuntu1`) |
| **OS** | Ubuntu 24.04 Server (VM on Proxmox .28) |
| **SSH** | ✅ `sam@192.168.20.35` |
| **Tailscale** | Not installed |
| **Role** | Caddy reverse proxy. Runs ~50 Docker containers (apps, dashboards, media, monitoring). |
| **Gitea** | Git hosting: `gitea-server-1` + `gitea-db-1` (Docker). Web: `.35:3001` ("Gitea: Audas Media"), SSH: `.35:2222`. Key repo: `sam/pi-config` (pi agent assets — every machine clones it) |
**Proxied domains:**
| Domain | Proxied to |
|--------|-----------|
| `omniroute.lab.audasmedia.com.au` | `.13:20129` |
| `worldmonitor.lab.audasmedia.com.au` | `.13:3002` |
| `gitea.lab.audasmedia.com.au` | `.35:3001` (web) / `.35:2222` (SSH) |
**Websites I've built** (public `*.lab.audasmedia.com.au`): console portal, media tools (photo/video/audio/lmms), DeepSeek Harness (`dsh-*`), family chat, resume/portfolio (`sam-*`, wiki), home dash. Full list → [[Websites on Nixos-Dekstop 13]].
See [[Docker Containers]] for full container list on .35.
### .23 — file-server (Proxmox VM)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.23` |
| **Hostname** | `file-server` |
| **OS** | (VM on Proxmox) |
| **SSH** | ❌ No SSH access |
| **Role** | NFS/USB file server. Hosts the 2.7T `usb_3tb` share → mounted by `.35` at `/mnt/nfs_usb_3tb` (Kopia + Restic/Backrest backup repos, Home Assistant backups) |
### .48 — Proxmox Backup Server
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.48` |
| **Hostname** | `proxmox-backup` |
| **OS** | Proxmox Backup Server |
| **URL** | `https://192.168.20.48:8007` (also `proxmox_backup.home.lab` via Caddy) |
| **SSH** | `root@192.168.20.48` |
| **Role** | VM-level backup server for Proxmox — full VM backups (incl. `.35`, `.23`, `.30`) |
### .150 — Phone (Android)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.150` (static) |
| **Device** | Android phone |
| **SSH** | ✅ Termux → `ssh` from/to other machines (port 8022, user: `uO_a499`) |
| **Tailscale** | ✅ `100.101.49.17` (google-pixel-8a) |
| **Role** | Mobile access. Termux for SSH, Tailscale for remote, NTFY for notifications. |
### .24 — skinnyspeakers (Raspberry Pi)
| Property | Value |
|----------|-------|
| **IP** | `192.168.20.24` |
| **Hostname** | `skinnyspeakers` |
| **OS** | Raspbian 12 (bookworm) |
| **SSH** | ✅ `sam@192.168.20.24` |
| **Role** | Raspberry Pi — likely Snapcast speaker/audio client. ⚠️ Identified 2026-08-29 — please confirm role |
---
## Web Deploy Sync (.27 → .13)
Web sites sync via **manual lsyncd** on .27 → rsync+ssh to .13 `/var/www/`:
- Config: `/home/sam/.config/lsyncd/lsyncd.conf.lua`
- Sites: `sprinklers`, `sam-developer`, `sam-devops` (+ any added in config)
- New folder on .13: `sudo chown -R sam:users /var/www/<folder>` (NixOS `users` group)
- Secrets env: `~/.config/environment.d/10-secrets.conf` (git-safe on NixOS)
---
## SSH Access Matrix
| From ↓ / To → | .27 desktop | .13 server | .51 laptop | .35 caddy | .150 phone |
|--------------|-------------|------------|------------|-----------|------------|
| **.27 desktop** | — | `sam@192.168.20.13` | `sam@192.168.20.51` | `sam@192.168.20.35` | `uO_a499@192.168.20.150:8022` |
| **.13 server** | `sam@192.168.20.27` | — | `sam@192.168.20.51` | `sam@192.168.20.35` | `uO_a499@192.168.20.150:8022` |
| **.51 laptop** | `sam@192.168.20.27` | `sam@192.168.20.13` | — | `sam@192.168.20.35` | `uO_a499@192.168.20.150:8022` |
| **.150 phone** | `sam@192.168.20.27` | `sam@192.168.20.13` | `sam@192.168.20.51` | `sam@192.168.20.35` | — (Termux local) |
**Proxmox (`root@192.168.20.28`) & PBS (`root@192.168.20.48`):** admin via web UI or root SSH.
**SSH config shortcut (`~/.ssh/config`):**
```text
Host phone
HostName 192.168.20.150
Port 8022
User uO_a499
```
(Added to .27 and .51. .13 needs home.nix update — `~/.ssh/config` is a Nix store symlink.)
---
## Key Apps & Ports
| Port | Service | Machine |
|------|---------|---------|
| `22` | SSH | All |
| `53` | DNS (Pi-hole) | .13, .35 |
| `80/443` | Caddy reverse proxy | .35 |
| `1883` | MQTT (Mosquitto) | .13 |
| `3002` | worldmonitor | .13 |
| `8022` | SSH (Termux) | .150 phone |
| `20129` | OmniRoute API | .13 |
| `20128` | OmniRoute dashboard | .13 |
| `7437` | engram | .13 |
| `8787` | Headroom proxy | .13 |
| `8079` | Netcom Router admin | Router (192.168.20.1) |
| `254` | Secondary Router admin | Router (192.168.20.1) |
| `8006` | Proxmox VE web UI | .28 |
| `8007` | Proxmox Backup Server web UI | .48 |
| `8123` | Home Assistant web UI | .30 |
| `3000` | Open WebUI | .13 |
| `3001` | Langfuse | .13 |
| `2222` | Gitea SSH (git remotes) | .35 |
| `3001` | Gitea web UI | .35 |
| `3090` | Archon | .27 |
| `8001` | Supabase Kong | .27 |
| `8001` | ai-resume-backend | .13 |
| `8080` | knowledge-service | .27 |
| `8090` | langgraph-service | .27 |
| `5000` | opencode-brain | .27 |
| `1780` | Snapcast (audio control) | .13 |
| `8765` | python3 (unidentified) | .27 |
| `3900` | Garage S3 API | .13 |
| `3902` | Garage admin API | .13 |
| `3909` | **Garage Web UI** (`garage-webui`) | .13 |
---
## Web Apps by Machine
### .27 — sam-4screen-desktop (Docker host)
| App | URL | Notes |
|-----|-----|-------|
| Archon | `http://192.168.20.27:3090/chat` | AI project flow coordinator |
| Supabase Studio | `http://192.168.20.27:8001/project/default` | Local dev auth + database GUI |
| knowledge-service | `http://192.168.20.27:8080` | Custom Python API |
| langgraph-service | `http://192.168.20.27:8090` | LangGraph agent framework |
| opencode-brain | `http://192.168.20.27:5000` | OpenCode AI endpoint |
| knowledge-service | `http://192.168.20.27:8080` | Custom Python API |
| langgraph-service | `http://192.168.20.27:8090` | LangGraph agent framework |
| opencode-brain | `http://192.168.20.27:5000` | OpenCode AI endpoint |
### .13 — nixos-desktop (Docker host)
| App | URL | Notes |
|-----|-----|-------|
| Snapcast | `http://192.168.20.13:1780/` | Multi-room audio control — needs Caddy DNS |
| Langfuse | `http://192.168.20.13:3001/auth/sign-in` | LLM observability (traces, evals, cost) |
| ai-resume-backend | `http://192.168.20.13:8001` | Resume AI backend (Docker) |
### .35 — caddy-server (Reverse Proxy)
| App | URL | Notes |
|-----|-----|-------|
| OmniRoute dashboard | `http://omniroute.home.lab` | LLM routing proxy GUI |
| OmniRoute API | `http://omniroute.lab.audasmedia.com.au` | Public LLM API endpoint |
### Proxmox
| App | URL | Notes |
|-----|-----|-------|
| Proxmox VE | `https://192.168.20.28:8006` (or `proxmox.home.lab`) | Hypervisor — hosts .35 VM, .23 file-server, HA VM, .48 PBS |
| Proxmox Backup Server | `https://192.168.20.48:8007` (or `proxmox_backup.home.lab`) | VM backups |
| Home Assistant | `http://192.168.20.30:8123` | Home automation |
---
## lan-mouse — Cross-Machine Mouse/Keyboard Sharing
| Detail | Value |
|--------|-------|
| **Version** | v0.10.0 (pre-encryption, from [GitHub releases](https://github.com/feschber/lan-mouse/releases/tag/v0.10.0)) |
| **Binary** | `~/.local/bin/lan-mouse` (same binary on all three) |
| **Service** | `~/.config/systemd/user/lan-mouse.service` (enabled, auto-starts) |
| **Config** | `~/.config/lan-mouse/config.toml` |
| **Port** | UDP 4242 |
| **Encryption** | None. v0.11.0 DTLS is broken — `Alert is Fatal or Close Notify` even on identical binaries. |
**Layout:** `.13 ← .27 → .51`
- .27: `[left] ips = ["192.168.20.13", "192.168.20.46"]` `.46` is .13's Wi-Fi — required.
- .27: `[right] ips = ["192.168.20.51"]`
- .13: `[right] ips = ["192.168.20.27"]`
- .51: `[left] ips = ["192.168.20.27"]`
**Startup flags:**
- .27/.51: `--daemon --capture-backend layer-shell`
- .13: `--daemon --emulation-backend libei` (KDE), uses wrapper script for NixOS libs
**Release key:** Press `ASDF` together to free trapped mouse back to .27.
**⚠️ Gotchas:**
- **Never use hostnames** — Tailscale resolves to virtual IPs. Raw IPs only.
- **v0.11.0 does NOT work** — DTLS broken everywhere.
- **.13 needs both IPs** (wired `.13` + Wi-Fi `.46`) in other machines' client list.
- **v0.10.0 limitation:** Modifier keys (Super/Alt/Ctrl) not forwarded on wlroots. Basic typing/mouse works.
- **KDE (.13):** Accept input emulation permission dialog on first run.
## Tailscale (Tailnet)
| Machine | Tailscale Name | Tailscale IP | Status |
|---------|---------------|-------------|--------|
| .27 desktop | sam-4screen-desktop-1 | `100.65.228.31` | ✅ Active |
| .13 server | nixos-desktop | `100.114.62.46` | ✅ Active |
| .51 laptop | sam-thinkpad | `100.88.161.102` | ✅ Active |
| .150 phone | google-pixel-8a | `100.101.49.17` | ⚠️ Offline (last seen 1d ago) |
| .35 caddy | — | — | ❌ Not installed |
Account: `samuelrolfe@gmail.com`
---
## DNS
| Server | IP | Role |
|--------|----|------|
| Pi-hole (primary) | `192.168.20.35` | DNS ad-blocking, local DNS for `.home.lab` domains |
| Pi-hole (secondary) | `192.168.20.13` | DNS ad-blocking, failover (nebula-sync from .35) |
### Local domains needing DNS records
| Domain | Target | Status |
|--------|--------|--------|
| `omniroute.home.lab` | `.13:20128` | ✅ Created |
| `omniroute.lab.audasmedia.com.au` | `.35`→`.13:20129` | ✅ Caddy proxied |
| `worldmonitor.home.lab` | `.13:3002` | ❌ Needs Pi-hole record |
| `worldmonitor.lab.audasmedia.com.au` | `.35`→`.13:3002` | ❌ Needs DNS + Caddy done |
| `gitea.home.lab` | `.35:3001` | ✅ Pi-hole → .35 |
| `gitea.lab.audasmedia.com.au` | public `144.6.86.11` → router → `.35` (web `.35:3001`, SSH `.35:2222`) | ✅ External DNS (used by git remotes) |