Global Architecture and Request Flow
Purpose
The Bytek homelab provides privately hosted identity, collaboration, documentation, monitoring, and project-management services.
The environment is hosted on Proxmox VE and follows these design principles:
- One major service per VM or LXC.
- Public services enter through a VPS instead of direct router port forwarding.
- WireGuard transports public traffic securely from the VPS to the home network.
- Traefik terminates HTTPS and routes requests by hostname.
- Authentik provides centralized authentication, MFA, and access policies.
- Pi-hole provides LAN DNS, split DNS, and DHCP reservations.
- Data-bearing applications use a separate LVM-thin storage pool.
- Proxmox backups are stored on a dedicated internal HDD.
- Management interfaces remain LAN or VPN only whenever practical.
- Each critical service retains an independent recovery method.
High-Level Architecture
Internet users
|
v
WHC public DNS
|
v
Public VPS
38.29.213.101
|
| WireGuard tunnel
v
Home WireGuard gateway
192.168.2.64
|
v
Traefik
192.168.2.182
|
+--> Authentik
| 192.168.2.162:9000
|
+--> Nextcloud AIO
| 192.168.2.100:11000
|
+--> Uptime Kuma
| 192.168.2.115:3001
|
+--> Vikunja
| 192.168.2.121:3456
|
+--> BookStack
<BOOKSTACK_IP>:6875