Appearance
🌐 Remote Access & Ingress Architecture
This document describes the remote access, VPN mesh, ingress routing, authentication, and security layers protecting the homelab infrastructure.
🏛️ Ingress Architecture Overview
The homelab uses a defense-in-depth approach separating external access channels into two secure tiers:
- Public/External Web GUI Ingress (Cloudflare Tunnels): Used for seamless browser access to key web portals (Home Assistant, Proxmox VE Web UI) from outside the local network without exposing open router ports.
- Private Administrative Mesh (Tailscale): Used for full, unrestricted administrative and service access from personal mobile devices, laptops, and remote development environments.
🔒 Ingress Components & Configurations
1. Cloudflare Tunnels (docker-edge - LXC 183)
- Stack:
/opt/stacks/cloudflared/compose.yaml - Image:
cloudflare/cloudflared:latest - Network: Joins
traefik-publicDocker bridge network directly. - Role: Establishes outbound TLS connections to Cloudflare's edge network, allowing inbound traffic to be routed directly to Traefik without exposing router ports or hairpining LAN traffic.
- Protected Endpoints:
- Proxmox VE Web Management GUI
- Home Assistant Dashboard
- Identity & SSO gateways
2. Tailscale Private Mesh VPN (docker-edge - LXC 183)
- Service:
tailscaled.service(Systemd native on LXC host OS) - State Path:
/var/lib/tailscale/tailscaled.state - Subnet Advertised:
192.168.0.0/24(and Exit Node) - LXC Device Mapping:
/dev/net/tunpassed via/etc/pve/lxc/183.conf(lxc.cgroup2.devices.allow = c 10:200 rwm) - Role: WireGuard-based overlay network connecting trusted personal devices (e.g. mobile phones, admin laptops) directly to the homelab network with end-to-end encryption.
- Capabilities:
- Full internal subnet access (
192.168.0.0/24) - Out-of-band management & direct SSH / API execution across all cluster guests
- Zero exposed firewall ports required
- Full internal subnet access (
3. Edge Gateway, Reverse Proxy & Auth Hub (docker-edge - LXC 183)
LXC 183 (docker-edge, IP 192.168.0.183) hosts the edge security, reverse proxy, and terminal hub stack:
traefik: Primary reverse proxy handling TLS termination, route matching, and header transformations (:80, :443, :8088).- Dynamic File Provider: Pure YAML configuration model via
/opt/docker_container_config/traefik/dynamic/(local_network_hosts.yml,middlewares.yml). Decoupled from container labels for declarative, centralized auditing. - Centralized Middlewares: Standardized security middlewares defined in
middlewares.yml(tinyauth-forward-auth@file,crowdsec-bouncer@file,crowdsec-appsec@file,fail2ban-global@file). - Automated SSL/TLS: Let's Encrypt wildcard certificates via Cloudflare DNS-01 challenge (
delayBeforeCheck: 30,1.1.1.1:53resolvers). - Management Automation: Managed and synchronized alongside Glance dashboards using
scripts/homelab_add_service.py.
- Dynamic File Provider: Pure YAML configuration model via
cloudflared: Containerized Cloudflare Tunnel daemon connected totraefik-public.pocket-id: Lightweight OpenID Connect (OIDC) identity provider for single sign-on (SSO) (:1411).tinyauth: Authentication middleware ensuring only authenticated OIDC users reach internal web applications (:3000).crowdsec: Collaborative intrusion prevention engine analyzing connection logs to ban malicious IPs and brute-force attempts.glance: Quick-glance homelab status and feeds dashboard (:8080).termix/termix-guacd: Centralized web terminal and remote management portal (:8432).dockhand: Centralized multi-host Docker Compose management dashboard (:3488).