created, modified, type, tags, aliases
created
modified
type
tags
aliases
2026-07-30
2026-08-29
note
Home Network Map
Overview
Network
Router/Gateway
Subnet
192.168.20.0/24
Gateway
192.168.20.1
DNS
Pi-hole on .13 (primary) + .35 (secondary)
Machines
.27 — sam-4screen-desktop (Main Desktop)
Property
Value
IP
192.168.20.27
Hostname
sam-4screen-desktop
OS
NixOS
SSH
✅ sam@192.168.20.27
Tailscale
✅ 100.65.228.31 (sam-4screen-desktop-1)
Role
Daily driver. 4 monitors, 62GB RAM, Nvidia GPU. Zellij, Neovim, pi coding agent.
Key services
pi (with pi-langfuse → traces to Langfuse .13:3001), pi-dashboard, Neovim, Zellij (with falcode + attention plugins), Home Manager managed
MCP tools
codebase-memory-mcp v0.9.0, code-review-graph v2.3.7 (per-project, installed via uv tool install)
Tunnels
ssh -fNL 7437:127.0.0.1:7437 192.168.20.13 (engram — must re-establish after reboot)
Docker containers
Archon
AI project flow coordinator (:3090)
Supabase
Local dev auth + database (kong :8001, postgres :5434, studio, meta :8080, rest, auth)
knowledge-service
Custom Python API (:8080)
langgraph-service
LangGraph agent framework (:8090)
opencode-brain
OpenCode AI service (:5000)
airflow
Workflow orchestration
.13 — nixos-desktop (Server)
Property
Value
IP
192.168.20.13
Hostname
nixos-desktop
OS
NixOS
SSH
✅ sam@192.168.20.13
Tailscale
✅ 100.114.62.46 (nixos-desktop)
Role
Docker host, OmniRoute LLM proxy, always-on server. 15.5GB RAM. GPU: GTX 760 (dead — see below).
Key services
Open WebUI v0.11.0 :3000 (NixOS native, not Docker)
GPU upgrade — dead GTX 760 → AMD RX 6600 (recommended)
Status (2026-08-25): GTX 760 (Kepler, PCI 10de:11c2) no longer works. nvidiaPackages.stable dropped Kepler support after driver branch 470; dmesg shows NVRM: does not include the required GPU ... probe failed (-1). The legacy 470 driver is EOL and very unlikely to build on kernel 6.18 (~10– 25% odds even with kernel pinning).
Recommended replacement: AMD RX 6600 (~$180– 210 USD)
Zero NixOS driver pain: in-kernel amdgpu — config becomes just services.xserver.videoDrivers = [ "amdgpu" ];. No legacy branches, no kernel-version roulette, ever.
No PSU gamble: many models need no PCIe power connector (132 W). Safe with the new PSU regardless of wattage headroom.
~6– 8× faster than the GTX 760; pairs cleanly with the Ryzen 5 5600. Flawless KDE/Wayland support.
Alternatives if a spare 8-pin + ≥450 W PSU confirmed: RX 7600 ($250), RTX 3060 12GB ($270, only if CUDA needed).
Swap procedure (safe): power off → swap card → boot. If display fails, SSH recovery path is proven (sam@192.168.20.27 → .13); previous NixOS generations remain bootable from the boot menu. Update videoDrivers to amdgpu, then nixos-rebuild switch.
Docker containers
OmniRoute
LLM proxy with combo routing (port 20128/20129). All pi LLM traffic routes through it. Combo default-opencode-go-ds-flash prioritises OpenCode-Go before falling through OpenRouter → DeepSeek direct → Google Gemini. See Pi Agent Extensions & Skills#OmniRoute — LLM Provider Router
Langfuse
LLM observability — receives pi traces via the pi-langfuse extension (port :3001, bumped from 3000 by Open WebUI)
worldmonitor
Geopolitical news dashboard (port 3002)
mosquitto
MQTT broker
pihole
DNS ad-blocking (primary)
nebula-sync
Pi-hole Gravity sync
headroom
Context compression proxy (port 8787)
engram
Journaling service (port 7437)
n8n
Workflow automation
voice_bridge + voice_whisper
MQTT audio bridge
piper_tts
Text-to-speech
Plus: pocketbase, doorbell_media, litellm, langfuse, airflow, trigger_dev, garage, garage-webui , t3_stack_react, sams-home-network
AI observability flow: pi (on .27/.13/.51) → pi-langfuse pi extension (npm:pi-langfuse, enabled per project) → Langfuse (.13:3001). One trace per pi conversation, grouped by session, with tokens + cost. Keys: ~/.pi/agent/pi-langfuse/config.json. See Pi Agent Extensions & Skills#pi-langfuse — LLM Observability for Pi
See Docker Containers for full container list.
.51 — sam-thinkpad (Laptop)
Property
Value
IP
192.168.20.51
Hostname
sam-thinkpad
OS
NixOS
SSH
✅ sam@192.168.20.51
Tailscale
✅ 100.88.161.102 (sam-thinkpad)
Role
Portable laptop. Used on-the-go and at home. pi, Neovim, Home Manager managed.
MCP tools
codebase-memory-mcp v0.9.0, code-review-graph v2.3.7 (installed via nix-shell -p uv)
Proxmox — Hypervisor
Property
Value
IP
192.168.20.28
Hostname
proxmox
OS
Proxmox VE
URL
https://192.168.20.28:8006 (also proxmox.home.lab via Caddy)
SSH
root@192.168.20.28 (admin via web UI)
Role
Hypervisor. VMs hosted: .35 (sam-ubuntu1 / Caddy), .23 (file-server), .30 (Home Assistant), .48 (Proxmox Backup Server)
Home Assistant
Property
Value
IP
192.168.20.30
Hostname
homeassistant (HAOS)
OS
Home Assistant OS v13.1
URL
http://192.168.20.30:8123 (also homeassistant.home.lab, homeassistant.lab.audasmedia.com.au, homeassistant.lab.quickweb.com.au via Caddy)
Role
Home automation VM on Proxmox (.28). Smart home control, automations, dashboards.
Routers
Host
IP
Notes
Main router (Netcom)
192.168.20.1
Gateway. Admin UI on port 8079
Second router
192.168.20.254
Secondary access point / router
.35 — caddy-server (Reverse Proxy)
Property
Value
IP
192.168.20.35
Hostname
caddy-server (aka sam-ubuntu1)
OS
Ubuntu 24.04 Server (VM on Proxmox .28)
SSH
✅ sam@192.168.20.35
Tailscale
Not installed
Role
Caddy reverse proxy. Runs ~50 Docker containers (apps, dashboards, media, monitoring).
Gitea
Git hosting: gitea-server-1 + gitea-db-1 (Docker). Web: .35:3001 ("Gitea: Audas Media"), SSH: .35:2222. Key repo: sam/pi-config (pi agent assets — every machine clones it)
Proxied domains:
Domain
Proxied to
omniroute.lab.audasmedia.com.au
.13:20129
worldmonitor.lab.audasmedia.com.au
.13:3002
gitea.lab.audasmedia.com.au
.35:3001 (web) / .35:2222 (SSH)
Websites I've built (public *.lab.audasmedia.com.au): console portal, media tools (photo/video/audio/lmms), DeepSeek Harness (dsh-*), family chat, resume/portfolio (sam-*, wiki), home dash. Full list → Websites on Nixos-Dekstop 13 .
See Docker Containers for full container list on .35.
.23 — file-server (Proxmox VM)
Property
Value
IP
192.168.20.23
Hostname
file-server
OS
(VM on Proxmox)
SSH
❌ No SSH access
Role
NFS/USB file server. Hosts the 2.7T usb_3tb share → mounted by .35 at /mnt/nfs_usb_3tb (Kopia + Restic/Backrest backup repos, Home Assistant backups)
.48 — Proxmox Backup Server
Property
Value
IP
192.168.20.48
Hostname
proxmox-backup
OS
Proxmox Backup Server
URL
https://192.168.20.48:8007 (also proxmox_backup.home.lab via Caddy)
SSH
root@192.168.20.48
Role
VM-level backup server for Proxmox — full VM backups (incl. .35, .23, .30)
.150 — Phone (Android)
Property
Value
IP
192.168.20.150 (static)
Device
Android phone
SSH
✅ Termux → ssh from/to other machines (port 8022, user: uO_a499)
Tailscale
✅ 100.101.49.17 (google-pixel-8a)
Role
Mobile access. Termux for SSH, Tailscale for remote, NTFY for notifications.
.24 — skinnyspeakers (Raspberry Pi)
Property
Value
IP
192.168.20.24
Hostname
skinnyspeakers
OS
Raspbian 12 (bookworm)
SSH
✅ sam@192.168.20.24
Role
Raspberry Pi — likely Snapcast speaker/audio client. ⚠️ Identified 2026-08-29 — please confirm role
Web Deploy Sync (.27 → .13)
Web sites sync via manual lsyncd on .27 → rsync+ssh to .13 /var/www/:
Config: /home/sam/.config/lsyncd/lsyncd.conf.lua
Sites: sprinklers, sam-developer, sam-devops (+ any added in config)
New folder on .13: sudo chown -R sam:users /var/www/<folder> (NixOS users group)
Secrets env: ~/.config/environment.d/10-secrets.conf (git-safe on NixOS)
SSH Access Matrix
From ↓ / To →
.27 desktop
.13 server
.51 laptop
.35 caddy
.150 phone
.27 desktop
—
sam@192.168.20.13
sam@192.168.20.51
sam@192.168.20.35
uO_a499@192.168.20.150:8022
.13 server
sam@192.168.20.27
—
sam@192.168.20.51
sam@192.168.20.35
uO_a499@192.168.20.150:8022
.51 laptop
sam@192.168.20.27
sam@192.168.20.13
—
sam@192.168.20.35
uO_a499@192.168.20.150:8022
.150 phone
sam@192.168.20.27
sam@192.168.20.13
sam@192.168.20.51
sam@192.168.20.35
— (Termux local)
Proxmox (root@192.168.20.28) & PBS (root@192.168.20.48): admin via web UI or root SSH.
SSH config shortcut (~/.ssh/config):
(Added to .27 and .51. .13 needs home.nix update — ~/.ssh/config is a Nix store symlink.)
Key Apps & Ports
Port
Service
Machine
22
SSH
All
53
DNS (Pi-hole)
.13, .35
80/443
Caddy reverse proxy
.35
1883
MQTT (Mosquitto)
.13
3002
worldmonitor
.13
8022
SSH (Termux)
.150 phone
20129
OmniRoute API
.13
20128
OmniRoute dashboard
.13
7437
engram
.13
8787
Headroom proxy
.13
8079
Netcom Router admin
Router (192.168.20.1)
254
Secondary Router admin
Router (192.168.20.1)
8006
Proxmox VE web UI
.28
8007
Proxmox Backup Server web UI
.48
8123
Home Assistant web UI
.30
3000
Open WebUI
.13
3001
Langfuse
.13
2222
Gitea SSH (git remotes)
.35
3001
Gitea web UI
.35
3090
Archon
.27
8001
Supabase Kong
.27
8001
ai-resume-backend
.13
8080
knowledge-service
.27
8090
langgraph-service
.27
5000
opencode-brain
.27
1780
Snapcast (audio control)
.13
8765
python3 (unidentified)
.27
3900
Garage S3 API
.13
3902
Garage admin API
.13
3909
Garage Web UI (garage-webui)
.13
Web Apps by Machine
.27 — sam-4screen-desktop (Docker host)
App
URL
Notes
Archon
http://192.168.20.27:3090/chat
AI project flow coordinator
Supabase Studio
http://192.168.20.27:8001/project/default
Local dev auth + database GUI
knowledge-service
http://192.168.20.27:8080
Custom Python API
langgraph-service
http://192.168.20.27:8090
LangGraph agent framework
opencode-brain
http://192.168.20.27:5000
OpenCode AI endpoint
knowledge-service
http://192.168.20.27:8080
Custom Python API
langgraph-service
http://192.168.20.27:8090
LangGraph agent framework
opencode-brain
http://192.168.20.27:5000
OpenCode AI endpoint
.13 — nixos-desktop (Docker host)
App
URL
Notes
Snapcast
http://192.168.20.13:1780/
Multi-room audio control — needs Caddy DNS
Langfuse
http://192.168.20.13:3001/auth/sign-in
LLM observability (traces, evals, cost)
ai-resume-backend
http://192.168.20.13:8001
Resume AI backend (Docker)
.35 — caddy-server (Reverse Proxy)
App
URL
Notes
OmniRoute dashboard
http://omniroute.home.lab
LLM routing proxy GUI
OmniRoute API
http://omniroute.lab.audasmedia.com.au
Public LLM API endpoint
Proxmox
App
URL
Notes
Proxmox VE
https://192.168.20.28:8006 (or proxmox.home.lab)
Hypervisor — hosts .35 VM, .23 file-server, HA VM, .48 PBS
Proxmox Backup Server
https://192.168.20.48:8007 (or proxmox_backup.home.lab)
VM backups
Home Assistant
http://192.168.20.30:8123
Home automation
lan-mouse — Cross-Machine Mouse/Keyboard Sharing
Detail
Value
Version
v0.10.0 (pre-encryption, from GitHub releases )
Binary
~/.local/bin/lan-mouse (same binary on all three)
Service
~/.config/systemd/user/lan-mouse.service (enabled, auto-starts)
Config
~/.config/lan-mouse/config.toml
Port
UDP 4242
Encryption
None. v0.11.0 DTLS is broken — Alert is Fatal or Close Notify even on identical binaries.
Layout: .13 ← .27 → .51
.27: [left] ips = ["192.168.20.13", "192.168.20.46"] .46 is .13's Wi-Fi — required.
.27: [right] ips = ["192.168.20.51"]
.13: [right] ips = ["192.168.20.27"]
.51: [left] ips = ["192.168.20.27"]
Startup flags:
.27/.51: --daemon --capture-backend layer-shell
.13: --daemon --emulation-backend libei (KDE), uses wrapper script for NixOS libs
Release key: Press ASDF together to free trapped mouse back to .27.
⚠️ Gotchas:
Never use hostnames — Tailscale resolves to virtual IPs. Raw IPs only.
v0.11.0 does NOT work — DTLS broken everywhere.
.13 needs both IPs (wired .13 + Wi-Fi .46) in other machines' client list.
v0.10.0 limitation: Modifier keys (Super/Alt/Ctrl) not forwarded on wlroots. Basic typing/mouse works.
KDE (.13): Accept input emulation permission dialog on first run.
Tailscale (Tailnet)
Machine
Tailscale Name
Tailscale IP
Status
.27 desktop
sam-4screen-desktop-1
100.65.228.31
✅ Active
.13 server
nixos-desktop
100.114.62.46
✅ Active
.51 laptop
sam-thinkpad
100.88.161.102
✅ Active
.150 phone
google-pixel-8a
100.101.49.17
⚠️ Offline (last seen 1d ago)
.35 caddy
—
—
❌ Not installed
Account: samuelrolfe@gmail.com
DNS
Server
IP
Role
Pi-hole (primary)
192.168.20.35
DNS ad-blocking, local DNS for .home.lab domains
Pi-hole (secondary)
192.168.20.13
DNS ad-blocking, failover (nebula-sync from .35)
Local domains needing DNS records
Domain
Target
Status
omniroute.home.lab
.13:20128
✅ Created
omniroute.lab.audasmedia.com.au
.35→.13:20129
✅ Caddy proxied
worldmonitor.home.lab
.13:3002
❌ Needs Pi-hole record
worldmonitor.lab.audasmedia.com.au
.35→.13:3002
❌ Needs DNS + Caddy done
gitea.home.lab
.35:3001
✅ Pi-hole → .35
gitea.lab.audasmedia.com.au
public 144.6.86.11 → router → .35 (web .35:3001, SSH .35:2222)
✅ External DNS (used by git remotes)