Files
obsidian-vault/300 areas/360 Dev-Ops Network Computers/Home Network Map Overview.md

16 KiB
Raw Blame History

created, modified, type, tags, aliases
created modified type tags aliases
2026-07-30 2026-09-06 note
network
dev-ops

Home Network Map

Overview

Network Router/Gateway
Subnet 192.168.20.0/24
Gateway 192.168.20.1
DNS Pi-hole on .13 (primary) + .35 (secondary)

Dev-Ops Tooling

Mermaid + Archify (diagrams), Vikunja (tasks) and Outline (docs) are documented as tools in Dev-Ops Tooling — Mermaid, Archify, Vikunja & Outline — including the per-project /docs/ artifact convention and pi-agent skills (project-diagramming-mermaid, project-diagramming-archify).


Machines

.27 — sam-4screen-desktop (Main Desktop)

Property Value
IP 192.168.20.27
Hostname sam-4screen-desktop
OS NixOS
SSH ✅ sam@192.168.20.27
Tailscale ✅ 100.65.228.31 (sam-4screen-desktop-1)
Role Daily driver. 4 monitors, 62GB RAM, Nvidia GPU. Zellij, Neovim, pi coding agent.
Key services pi, pi-dashboard, Neovim, Zellij (with falcode + attention plugins), Home Manager managed
MCP tools codebase-memory-mcp v0.9.0, code-review-graph v2.3.7 (per-project, installed via uv tool install)
Tunnels ssh -fNL 7437:127.0.0.1:7437 192.168.20.13 (engram — must re-establish after reboot)
Docker containers
Archon AI project flow coordinator (:3090)
Supabase Local dev auth + database (kong :8001, postgres :5434, studio, meta :8080, rest, auth)
knowledge-service Custom Python API (:8080)
langgraph-service LangGraph agent framework (:8090)
opencode-brain OpenCode AI service (:5000)
airflow Workflow orchestration

.13 — nixos-desktop (Server)

Property Value
IP 192.168.20.13
Hostname nixos-desktop
OS NixOS
SSH ✅ sam@192.168.20.13
Tailscale ✅ 100.114.62.46 (nixos-desktop)
Role Docker host, OmniRoute LLM proxy, always-on server. 15.5GB RAM. GPU: GTX 760 (dead — see below).
Key services Open WebUI v0.11.0 :3000 (NixOS native, not Docker)

Status (2026-08-25): GTX 760 (Kepler, PCI 10de:11c2) no longer works. nvidiaPackages.stable dropped Kepler support after driver branch 470; dmesg shows NVRM: does not include the required GPU ... probe failed (-1). The legacy 470 driver is EOL and very unlikely to build on kernel 6.18 (~10–25% odds even with kernel pinning).

Recommended replacement: AMD RX 6600 (~$180–210 USD)

  • Zero NixOS driver pain: in-kernel amdgpu — config becomes just services.xserver.videoDrivers = [ "amdgpu" ];. No legacy branches, no kernel-version roulette, ever.
  • No PSU gamble: many models need no PCIe power connector (132 W). Safe with the new PSU regardless of wattage headroom.
  • ~6–8× faster than the GTX 760; pairs cleanly with the Ryzen 5 5600. Flawless KDE/Wayland support.
  • Alternatives if a spare 8-pin + ≥450 W PSU confirmed: RX 7600 ($250), RTX 3060 12GB ($270, only if CUDA needed).

Swap procedure (safe): power off → swap card → boot. If display fails, SSH recovery path is proven (sam@192.168.20.27 → .13); previous NixOS generations remain bootable from the boot menu. Update videoDrivers to amdgpu, then nixos-rebuild switch.

Docker containers
OmniRoute LLM proxy with combo routing (port 20128/20129). All pi LLM traffic routes through it. Combo default-opencode-go-ds-flash prioritises OpenCode-Go before falling through OpenRouter → DeepSeek direct → Google Gemini. See Pi Agent Extensions & Skills#OmniRoute — LLM Provider Router
Langfuse LLM observability — traces, evals, cost tracking ⛔ REMOVED 2026-09-06 (was port :3001, bumped from 3000 by Open WebUI). Stack + data deleted — resource hog.
worldmonitor Geopolitical news dashboard (port 3002)
mosquitto MQTT broker
pihole DNS ad-blocking (primary)
nebula-sync Pi-hole Gravity sync
headroom Context compression proxy (port 8787)
engram Journaling service (port 7437)
n8n Workflow automation
voice_bridge + voice_whisper MQTT audio bridge
piper_tts Text-to-speech
Plus: pocketbase, doorbell_media, litellm, airflow, trigger_dev, garage, garage-webui, t3_stack_react, sams-home-network

See Docker Containers for full container list.

.51 — sam-thinkpad (Laptop)

Property Value
IP 192.168.20.51
Hostname sam-thinkpad
OS NixOS
SSH ✅ sam@192.168.20.51
Tailscale ✅ 100.88.161.102 (sam-thinkpad)
Role Portable laptop. Used on-the-go and at home. pi, Neovim, Home Manager managed.
MCP tools codebase-memory-mcp v0.9.0, code-review-graph v2.3.7 (installed via nix-shell -p uv)

Proxmox — Hypervisor

Property Value
IP 192.168.20.28
Hostname proxmox
OS Proxmox VE
URL https://192.168.20.28:8006 (also proxmox.home.lab via Caddy)
SSH root@192.168.20.28 (admin via web UI)
Role Hypervisor. VMs hosted: .35 (sam-ubuntu1 / Caddy), .23 (file-server), .30 (Home Assistant), .48 (Proxmox Backup Server)

Home Assistant

Property Value
IP 192.168.20.30
Hostname homeassistant (HAOS)
OS Home Assistant OS v13.1
URL http://192.168.20.30:8123 (also homeassistant.home.lab, homeassistant.lab.audasmedia.com.au, homeassistant.lab.quickweb.com.au via Caddy)
Role Home automation VM on Proxmox (.28). Smart home control, automations, dashboards.

Routers

Host IP Notes
Main router (Netcom) 192.168.20.1 Gateway. Admin UI on port 8079
Second router 192.168.20.254 Secondary access point / router

.35 — caddy-server (Reverse Proxy)

Property Value
IP 192.168.20.35
Hostname caddy-server (aka sam-ubuntu1)
OS Ubuntu 24.04 Server (VM on Proxmox .28)
SSH ✅ sam@192.168.20.35
Tailscale Not installed
Role Caddy reverse proxy. Runs ~50 Docker containers (apps, dashboards, media, monitoring).
Gitea Git hosting: gitea-server-1 + gitea-db-1 (Docker). Web: .35:3001 ("Gitea: Audas Media"), SSH: .35:2222. Key repo: sam/pi-config (pi agent assets — every machine clones it)

Proxied domains:

Domain Proxied to
omniroute.lab.audasmedia.com.au .13:20129
worldmonitor.lab.audasmedia.com.au .13:3002
gitea.lab.audasmedia.com.au .35:3001 (web) / .35:2222 (SSH)

Websites I've built (public *.lab.audasmedia.com.au): console portal, media tools (photo/video/audio/lmms), DeepSeek Harness (dsh-*), family chat, resume/portfolio (sam-*, wiki), home dash. Full list → Websites on Nixos-Dekstop 13.

See Docker Containers for full container list on .35.

.23 — file-server (Proxmox VM)

Property Value
IP 192.168.20.23
Hostname file-server
OS (VM on Proxmox)
SSH ❌ No SSH access
Role NFS/USB file server. Hosts the 2.7T usb_3tb share → mounted by .35 at /mnt/nfs_usb_3tb (Kopia + Restic/Backrest backup repos, Home Assistant backups)

.48 — Proxmox Backup Server

Property Value
IP 192.168.20.48
Hostname proxmox-backup
OS Proxmox Backup Server
URL https://192.168.20.48:8007 (also proxmox_backup.home.lab via Caddy)
SSH root@192.168.20.48
Role VM-level backup server for Proxmox — full VM backups (incl. .35, .23, .30)

.150 — Phone (Android)

Property Value
IP 192.168.20.150 (static)
Device Android phone
SSH ✅ Termux → ssh from/to other machines (port 8022, user: uO_a499)
Tailscale ✅ 100.101.49.17 (google-pixel-8a)
Role Mobile access. Termux for SSH, Tailscale for remote, NTFY for notifications.

.24 — skinnyspeakers (Raspberry Pi)

Property Value
IP 192.168.20.24
Hostname skinnyspeakers
OS Raspbian 12 (bookworm)
SSH ✅ sam@192.168.20.24
Role Raspberry Pi — likely Snapcast speaker/audio client. ⚠️ Identified 2026-08-29 — please confirm role

Web Deploy Sync (.27 → .13)

Web sites sync via manual lsyncd on .27 → rsync+ssh to .13 /var/www/:

  • Config: /home/sam/.config/lsyncd/lsyncd.conf.lua
  • Sites: sprinklers, sam-developer, sam-devops (+ any added in config)
  • New folder on .13: sudo chown -R sam:users /var/www/<folder> (NixOS users group)
  • Secrets env: ~/.config/environment.d/10-secrets.conf (git-safe on NixOS)

SSH Access Matrix

From ↓ / To → .27 desktop .13 server .51 laptop .35 caddy .150 phone
.27 desktop — sam@192.168.20.13 sam@192.168.20.51 sam@192.168.20.35 uO_a499@192.168.20.150:8022
.13 server sam@192.168.20.27 — sam@192.168.20.51 sam@192.168.20.35 uO_a499@192.168.20.150:8022
.51 laptop sam@192.168.20.27 sam@192.168.20.13 — sam@192.168.20.35 uO_a499@192.168.20.150:8022
.150 phone sam@192.168.20.27 sam@192.168.20.13 sam@192.168.20.51 sam@192.168.20.35 — (Termux local)

Proxmox (root@192.168.20.28) & PBS (root@192.168.20.48): admin via web UI or root SSH.

SSH config shortcut (~/.ssh/config):

Host phone
    HostName 192.168.20.150
    Port 8022
    User uO_a499

(Added to .27 and .51. .13 needs home.nix update — ~/.ssh/config is a Nix store symlink.)


Key Apps & Ports

Port Service Machine
22 SSH All
53 DNS (Pi-hole) .13, .35
80/443 Caddy reverse proxy .35
1883 MQTT (Mosquitto) .13
3002 worldmonitor .13
8022 SSH (Termux) .150 phone
20129 OmniRoute API .13
20128 OmniRoute dashboard .13
7437 engram .13
8787 Headroom proxy .13
8079 Netcom Router admin Router (192.168.20.1)
254 Secondary Router admin Router (192.168.20.1)
8006 Proxmox VE web UI .28
8007 Proxmox Backup Server web UI .48
8123 Home Assistant web UI .30
3000 Open WebUI .13
3001 Langfuse — removed 2026-09-06 .13
2222 Gitea SSH (git remotes) .35
3001 Gitea web UI .35
3090 Archon .27
8001 Supabase Kong .27
8001 ai-resume-backend .13
8080 knowledge-service .27
8090 langgraph-service .27
5000 opencode-brain .27
1780 Snapcast (audio control) .13
8765 python3 (unidentified) .27
3900 Garage S3 API .13
3902 Garage admin API .13
3909 Garage Web UI (garage-webui) .13

Web Apps by Machine

.27 — sam-4screen-desktop (Docker host)

App URL Notes
Archon http://192.168.20.27:3090/chat AI project flow coordinator
Supabase Studio http://192.168.20.27:8001/project/default Local dev auth + database GUI
knowledge-service http://192.168.20.27:8080 Custom Python API
langgraph-service http://192.168.20.27:8090 LangGraph agent framework
opencode-brain http://192.168.20.27:5000 OpenCode AI endpoint
knowledge-service http://192.168.20.27:8080 Custom Python API
langgraph-service http://192.168.20.27:8090 LangGraph agent framework
opencode-brain http://192.168.20.27:5000 OpenCode AI endpoint

.13 — nixos-desktop (Docker host)

App URL Notes
Snapcast http://192.168.20.13:1780/ Multi-room audio control — needs Caddy DNS
ai-resume-backend http://192.168.20.13:8001 Resume AI backend (Docker)

.35 — caddy-server (Reverse Proxy)

App URL Notes
OmniRoute dashboard http://omniroute.home.lab LLM routing proxy GUI
OmniRoute API http://omniroute.lab.audasmedia.com.au Public LLM API endpoint

Proxmox

App URL Notes
Proxmox VE https://192.168.20.28:8006 (or proxmox.home.lab) Hypervisor — hosts .35 VM, .23 file-server, HA VM, .48 PBS
Proxmox Backup Server https://192.168.20.48:8007 (or proxmox_backup.home.lab) VM backups
Home Assistant http://192.168.20.30:8123 Home automation

lan-mouse — Cross-Machine Mouse/Keyboard Sharing

Detail Value
Version v0.10.0 (pre-encryption, from GitHub releases)
Binary ~/.local/bin/lan-mouse (same binary on all three)
Service ~/.config/systemd/user/lan-mouse.service (enabled, auto-starts)
Config ~/.config/lan-mouse/config.toml
Port UDP 4242
Encryption None. v0.11.0 DTLS is broken — Alert is Fatal or Close Notify even on identical binaries.

Layout: .13 ← .27 → .51

  • .27: [left] ips = ["192.168.20.13", "192.168.20.46"] .46 is .13's Wi-Fi — required.
  • .27: [right] ips = ["192.168.20.51"]
  • .13: [right] ips = ["192.168.20.27"]
  • .51: [left] ips = ["192.168.20.27"]

Startup flags:

  • .27/.51: --daemon --capture-backend layer-shell
  • .13: --daemon --emulation-backend libei (KDE), uses wrapper script for NixOS libs

Release key: Press ASDF together to free trapped mouse back to .27.

⚠️ Gotchas:

  • Never use hostnames — Tailscale resolves to virtual IPs. Raw IPs only.
  • v0.11.0 does NOT work — DTLS broken everywhere.
  • .13 needs both IPs (wired .13 + Wi-Fi .46) in other machines' client list.
  • v0.10.0 limitation: Modifier keys (Super/Alt/Ctrl) not forwarded on wlroots. Basic typing/mouse works.
  • KDE (.13): Accept input emulation permission dialog on first run.

Tailscale (Tailnet)

Machine Tailscale Name Tailscale IP Status
.27 desktop sam-4screen-desktop-1 100.65.228.31 ✅ Active
.13 server nixos-desktop 100.114.62.46 ✅ Active
.51 laptop sam-thinkpad 100.88.161.102 ✅ Active
.150 phone google-pixel-8a 100.101.49.17 ⚠️ Offline (last seen 1d ago)
.35 caddy — — ❌ Not installed

Account: samuelrolfe@gmail.com


DNS

Server IP Role
Pi-hole (primary) 192.168.20.35 DNS ad-blocking, local DNS for .home.lab domains
Pi-hole (secondary) 192.168.20.13 DNS ad-blocking, failover (nebula-sync from .35)

Local domains needing DNS records

Domain Target Status
omniroute.home.lab .13:20128 ✅ Created
omniroute.lab.audasmedia.com.au .35→.13:20129 ✅ Caddy proxied
worldmonitor.home.lab .13:3002 ❌ Needs Pi-hole record
worldmonitor.lab.audasmedia.com.au .35→.13:3002 ❌ Needs DNS + Caddy done
gitea.home.lab .35:3001 ✅ Pi-hole → .35
gitea.lab.audasmedia.com.au public 144.6.86.11 → router → .35 (web .35:3001, SSH .35:2222) ✅ External DNS (used by git remotes)