Skip to content

🌐 Remote Access & Ingress Architecture ​

This document describes the remote access, VPN mesh, ingress routing, authentication, and security layers protecting the homelab infrastructure.


🏛️ Ingress Architecture Overview ​

The homelab uses a defense-in-depth approach separating external access channels into two secure tiers:

  1. Public/External Web GUI Ingress (Cloudflare Tunnels): Used for seamless browser access to key web portals (Home Assistant, Proxmox VE Web UI) from outside the local network without exposing open router ports.
  2. Private Administrative Mesh (Tailscale): Used for full, unrestricted administrative and service access from personal mobile devices, laptops, and remote development environments.

🔒 Ingress Components & Configurations ​

1. Cloudflare Tunnels (docker-edge - LXC 183) ​

  • Stack: /opt/stacks/cloudflared/compose.yaml
  • Image: cloudflare/cloudflared:latest
  • Network: Joins traefik-public Docker bridge network directly.
  • Role: Establishes outbound TLS connections to Cloudflare's edge network, allowing inbound traffic to be routed directly to Traefik without exposing router ports or hairpining LAN traffic.
  • Protected Endpoints:
    • Proxmox VE Web Management GUI
    • Home Assistant Dashboard
    • Identity & SSO gateways

2. Tailscale Private Mesh VPN (docker-edge - LXC 183) ​

  • Service: tailscaled.service (Systemd native on LXC host OS)
  • State Path: /var/lib/tailscale/tailscaled.state
  • Subnet Advertised: 192.168.0.0/24 (and Exit Node)
  • LXC Device Mapping: /dev/net/tun passed via /etc/pve/lxc/183.conf (lxc.cgroup2.devices.allow = c 10:200 rwm)
  • Role: WireGuard-based overlay network connecting trusted personal devices (e.g. mobile phones, admin laptops) directly to the homelab network with end-to-end encryption.
  • Capabilities:
    • Full internal subnet access (192.168.0.0/24)
    • Out-of-band management & direct SSH / API execution across all cluster guests
    • Zero exposed firewall ports required

3. Edge Gateway, Reverse Proxy & Auth Hub (docker-edge - LXC 183) ​

LXC 183 (docker-edge, IP 192.168.0.183) hosts the edge security, reverse proxy, and terminal hub stack:

  • traefik: Primary reverse proxy handling TLS termination, route matching, and header transformations (:80, :443, :8088).
    • Dynamic File Provider: Pure YAML configuration model via /opt/docker_container_config/traefik/dynamic/ (local_network_hosts.yml, middlewares.yml). Decoupled from container labels for declarative, centralized auditing.
    • Centralized Middlewares: Standardized security middlewares defined in middlewares.yml (tinyauth-forward-auth@file, crowdsec-bouncer@file, crowdsec-appsec@file, fail2ban-global@file).
    • Automated SSL/TLS: Let's Encrypt wildcard certificates via Cloudflare DNS-01 challenge (delayBeforeCheck: 30, 1.1.1.1:53 resolvers).
    • Management Automation: Managed and synchronized alongside Glance dashboards using scripts/homelab_add_service.py.
  • cloudflared: Containerized Cloudflare Tunnel daemon connected to traefik-public.
  • pocket-id: Lightweight OpenID Connect (OIDC) identity provider for single sign-on (SSO) (:1411).
  • tinyauth: Authentication middleware ensuring only authenticated OIDC users reach internal web applications (:3000).
  • crowdsec: Collaborative intrusion prevention engine analyzing connection logs to ban malicious IPs and brute-force attempts.
  • glance: Quick-glance homelab status and feeds dashboard (:8080).
  • termix / termix-guacd: Centralized web terminal and remote management portal (:8432).
  • dockhand: Centralized multi-host Docker Compose management dashboard (:3488).

Authoritative operational repository and DR hub.