Skip to main content

Global Architecture and Request Flow

Purpose

The Bytek homelab provides privately hosted identity, collaboration, documentation, monitoring, and project-management services.

The environment is hosted on Proxmox VE and follows these design principles:

    One major service per VM or LXC. Public services enter through a VPS instead of direct router port forwarding. WireGuard transports public traffic securely from the VPS to the home network. Traefik terminates HTTPS and routes requests by hostname. Authentik provides centralized authentication, MFA, and access policies. Pi-hole provides LAN DNS, split DNS, and DHCP reservations. Data-bearing applications use a separate LVM-thin storage pool. Proxmox backups are stored on a dedicated internal HDD. Management interfaces remain LAN or VPN only whenever practical. Each critical service retains an independent recovery method.

    High-Level Architecture

    Internet users
          |
          v
    WHC public DNS
          |
          v
    Public VPS
    38.29.213.101
          |
          | WireGuard tunnel
          v
    Home WireGuard gateway
    192.168.2.64
          |
          v
    Traefik
    192.168.2.182
          |
          +--> Authentik
          |    192.168.2.162:9000
          |
          +--> Nextcloud AIO
          |    192.168.2.100:11000
          |
          +--> Uptime Kuma
          |    192.168.2.115:3001
          |
          +--> Vikunja
          |    192.168.2.121:3456
          |
          +--> BookStack
               <BOOKSTACK_IP>:6875