docs/boxes: Document deployed boxes
Add per-site and per-box inventories, consolidate shared network design, and relocate the switch and access-point references under the home site.
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
# kelder-acquisition
|
||||
|
||||
The media acquisition stack for the kelder site — Transmission (forced over VPN), the *arrs
|
||||
and Jellyfin in one NixOS container.
|
||||
|
||||
- **Source:** [`nixos/boxes/kelder/containers/acquisition/`](../../../../nixos/boxes/kelder/containers/acquisition)
|
||||
- **Host:** NixOS container on [`kelder`](../README.md)
|
||||
- **nixpkgs:** `mine`
|
||||
|
||||
## Role
|
||||
|
||||
### Transmission
|
||||
|
||||
`transmission_4` is bound to the VPN wait-online unit and uses AirVPN's forwarded peer port. Upload,
|
||||
download and seed-ratio limits are configured in the service source. Downloads use
|
||||
`/mnt/media/downloads/torrents`, backed by the host's `/mnt/storage/media`.
|
||||
|
||||
### Media services
|
||||
|
||||
Jackett, Radarr and Sonarr share the `media` group with a group-writable umask. Jellyfin uses the
|
||||
host's bind-mounted `/dev/dri` with `intel-vaapi-driver` / `intel-ocl`; its user belongs to
|
||||
`render`.
|
||||
|
||||
## Network assignments
|
||||
|
||||
See the consolidated [network assignments](../../../networking.md#box-assignments) table (this box: `kelder-acquisition`).
|
||||
|
||||
## Networking
|
||||
|
||||
- `internal` assignment (name `acquisition-ctr`) on the host's `ctrs` bridge, MTU 1460 to
|
||||
match the site WAN.
|
||||
- All non-site traffic goes over an AirVPN WireGuard tunnel (`vpn` netdev, AirVPN IE endpoint).
|
||||
Policy rules keep traffic to and from the kelder prefixes on the main table and push everything
|
||||
else through the VPN's dedicated table.
|
||||
- An nftables input chain drops new TCP connections from the VPN interface except the
|
||||
Transmission peer port; the web UI ports (9091 Transmission, 9117 Jackett, 7878 Radarr,
|
||||
8989 Sonarr, 8096 Jellyfin) are accepted from the site. When built as a dev VM, those ports
|
||||
are forwarded to the host.
|
||||
- Sonarr still needs the EOL .NET 6 runtime, allowed via
|
||||
`nixpkgs.config.permittedInsecurePackages`.
|
||||
|
||||
## Notable config files
|
||||
|
||||
- [`nixos/boxes/kelder/containers/acquisition/default.nix`](../../../../nixos/boxes/kelder/containers/acquisition/default.nix) — services and users.
|
||||
- [`nixos/boxes/kelder/containers/acquisition/networking.nix`](../../../../nixos/boxes/kelder/containers/acquisition/networking.nix) — AirVPN tunnel + firewall.
|
||||
@@ -0,0 +1,50 @@
|
||||
# kelder-spoder
|
||||
|
||||
The web container for the kelder site: Nextcloud plus an nginx (OpenResty) reverse proxy for
|
||||
the site's services.
|
||||
|
||||
- **Source:** [`nixos/boxes/kelder/containers/spoder/`](../../../../nixos/boxes/kelder/containers/spoder)
|
||||
- **Host:** NixOS container on [`kelder`](../README.md)
|
||||
- **nixpkgs:** `mine`
|
||||
|
||||
## Role
|
||||
|
||||
- **Nextcloud** (`nextcloud32`) at `cloud.hentai.engineer` (trusted alias
|
||||
`cloud-local.hentai.engineer`), SQLite backend, data in `/mnt/storage/nextcloud`
|
||||
(`/mnt/storage` is bind-mounted from the host).
|
||||
- **nginx reverse proxy** (`openresty`) terminating TLS for the site's public vhosts, with a
|
||||
wildcard ACME cert for `hentai.engineer` via Cloudflare DNS. The kelder host forwards
|
||||
`http`/`https` to this container; uploads are unlimited (`clientMaxBodySize = 0`) for
|
||||
Nextcloud's sake.
|
||||
|
||||
## Network assignments
|
||||
|
||||
See the consolidated [network assignments](../../../networking.md#box-assignments) table (this box: `kelder-spoder`).
|
||||
|
||||
## Proxy vhosts
|
||||
|
||||
All under `hentai.engineer`, each with a `*-local` alias:
|
||||
|
||||
| vhost | Target | Auth |
|
||||
| --- | --- | --- |
|
||||
| `monitor` | `netdata` on the kelder host (:19999) | `htpasswd` |
|
||||
| `kontent` | Jellyfin on `kelder-acquisition` (:8096, incl. websocket) | — |
|
||||
| `torrents` | Transmission on `kelder-acquisition` (:9091) | `htpasswd` |
|
||||
| `jackett` | Jackett on `kelder-acquisition` (:9117) | `htpasswd` |
|
||||
| `radarr` | Radarr on `kelder-acquisition` (:7878) | `htpasswd` |
|
||||
| `sonarr` | Sonarr on `kelder-acquisition` (:8989) | `htpasswd` |
|
||||
| `cloud` | Nextcloud (local) | — |
|
||||
|
||||
An `init_worker_by_lua` timer polls `v4.ident.me` periodically to track the site's public IP; it
|
||||
feeds `localRedirect` rewrites (bounce public-IP clients to the `*-local` name) that
|
||||
are currently **disabled** (commented out — Virgin Media filters DNS answers containing local
|
||||
IPs, so the split doesn't work as intended).
|
||||
|
||||
## Networking
|
||||
|
||||
- `internal` assignment (name `spoder-ctr`) on the host's `ctrs` bridge, MTU 1420.
|
||||
|
||||
## Notable config files
|
||||
|
||||
- [`nixos/boxes/kelder/containers/spoder/default.nix`](../../../../nixos/boxes/kelder/containers/spoder/default.nix) — Nextcloud + ACME.
|
||||
- [`nixos/boxes/kelder/containers/spoder/nginx.nix`](../../../../nixos/boxes/kelder/containers/spoder/nginx.nix) — reverse proxy vhosts.
|
||||
Reference in New Issue
Block a user