Archived
- Document bidirectional LAN ↔ Tailscale routing via tailscale-router (static route on router for 100.64.0.0/10, subnet advertisement into Tailnet) - Document DNS proxy chain: FreeIPA conditional forwarder for *.ts.net → tailscale-router → MagicDNS; reverse for *.sweet.home from Tailscale clients - Remove stale pihole.sweet.home from IP table (decommissioned) - Fix freeipa role: remove Pi-hole IP from ipa_dns_forwarder, document ts.net conditional forwarder as a post-install step - Fix inventory: remove Pi-hole forwarder IP, add ts.net forwarder note Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UvNjoxTWEDkhXsd1Dq2ETP
5.5 KiB
5.5 KiB
Architecture
Infrastructure layers
┌─────────────────────────────────────────────────────────┐
│ pve1.sweet.home (Proxmox VE — production hypervisor) │
│ │
│ ┌────────────┐ ┌──────────┐ ┌──────────────────────┐ │
│ │ server- │ │ docker │ │ nix-cache pxe-boot │ │
│ │ nixos VM │ │ LXC │ │ LXC LXC │ │
│ │ (baremetal │ │ 192.168 │ │ .224 .223 │ │
│ │ GUI host) │ │ .2.225 │ └──────────────────────┘ │
│ └────────────┘ └──────────┘ │
│ ┌────────────┐ ┌──────────┐ ┌──────────────────────┐ │
│ │ domain- │ │ pxe-boot │ │ ha-server-1 ha- │ │
│ │ controller │ │ LXC │ │ VM .2.228 server-2│ │
│ │ FreeIPA VM │ │ PXE DHCP │ │ VM .2.227│ │
│ │ .2.253 │ │ .2.223 │ └──────────────────────┘ │
│ └────────────┘ └──────────┘ │
└─────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────┐
│ pve-test.sweet.home (Proxmox VE — sandbox) │
│ WiFi-connected. Safe for scratch VMs/LXCs. │
└─────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────┐
│ raspberrypi.tail13f623.ts.net (Raspberry Pi 4) │
│ Edge monitoring via Tailscale. │
│ Traefik · Uptime Kuma · CrowdSec · Beszel agent │
└─────────────────────────────────────────────────────────┘
Configuration management matrix
| Host | Managed by | How |
|---|---|---|
| pve1, pve-test | Ansible (proxmox-hardening role) |
ansible/playbooks/proxmox.yml |
| domain-controller | Ansible (freeipa role) |
ansible/playbooks/freeipa.yml |
| pihole | Ansible (pihole role) |
ansible/playbooks/pihole.yml |
| raspberrypi | Ansible (raspberrypi role) |
ansible/playbooks/raspi.yml |
| docker LXC | NixOS flake | nixos/ — proxmox-docker target |
| nix-cache LXC | NixOS flake | nixos/ — proxmox-nix-cache target |
| pxe-boot LXC | NixOS flake | nixos/ — proxmox-pxe-boot target |
| ha-server-1/2 | NixOS flake | nixos/ — proxmox-ha-server-1/2 targets |
| baremetal workstation | NixOS flake | nixos/ — baremetal-gui target |
Authentication and DNS backbone
FreeIPA (SWEET.HOME realm) provides:
- Kerberos SSO for all IPA-enrolled hosts
- LDAP user/group directory (
admins,docker-accessgroups) - Authoritative DNS for the entire LAN (Pi-hole decommissioned; FreeIPA is the sole resolver)
- Conditional forwarder:
*.ts.net→tailscale-router(192.168.2.222) → Tailscale MagicDNS - Certificate authority for internal TLS
All hosts (Proxmox nodes, Raspberry Pi, Docker host) are IPA-enrolled via SSSD.
The admins group has passwordless sudo on all enrolled hosts.
The docker-access group (GID 50010) grants Docker socket access on Docker hosts.
DHCP is handled by the router. PXE-specific DHCP options are served by the pxe-boot LXC.
Tailscale ↔ LAN bridge
tailscale-router.sweet.home (192.168.2.222) is a NixOS LXC running the tailscale-router
build type. It provides full bidirectional connectivity between the LAN and the Tailnet:
- LAN → Tailscale: Router has a static route for
100.64.0.0/10(Tailscale CGNAT) → 192.168.2.222. DNS for*.ts.netflows through FreeIPA's conditional forwarder → tailscale-router → MagicDNS. - Tailscale → LAN: tailscale-router advertises
192.168.2.0/24as a subnet route. Tailscale clients use tailscale-router as a split-horizon DNS forwarder forsweet.home, which proxies those queries to FreeIPA.
This means any Tailscale-connected device can resolve and reach *.sweet.home hosts, and
any LAN host can resolve and reach *.ts.net hosts — without needing a Tailscale client installed.
Monitoring stack
Beszel agents (every host)
└─→ Beszel hub (stacks/docker — beszel.lan.ddnsgeek.com)
Uptime Kuma (stacks/docker — monitor-kuma.lan.ddnsgeek.com)
└─→ monitors all public endpoints
Gotify (stacks/docker)
└─→ receives: WUD alerts, Docker health checks, drift detection notifications
WUD (stacks/docker)
└─→ watches: local docker host + Raspberry Pi (via Tailscale)