Global Architecture and Request Flow
Purpose
The Bytek homelab provides privately hosted identity, collaboration, documentation, monitoring, project-management, and infrastructure services.
The environment is hosted on Proxmox VE and follows these design principles:
Main Components
38.29.213.101
Public HTTPS entry point
WireGuard gateway
192.168.2.64
VPS-to-home tunnel gateway
Pi-hole
192.168.2.65
DNS, split DNS, and DHCP reservations
Nextcloud AIO
192.168.2.100
File storage and collaboration
Uptime Kuma
192.168.2.115
Service monitoring
Vikunja
192.168.2.121
Project and task management
Authentik
192.168.2.162
Identity, authorization, and MFA
Traefik
192.168.2.182
HTTPS reverse proxy
Proxmox VE
192.168.2.254
Hypervisor
BookStack
Confirm current IP
Infrastructure documentation
Core Infrastructure Roles
Proxmox VE
Proxmox VE hosts the Bytek VMs and LXCs.
Proxmox provides:
Proxmox management address:
Proxmox is intended for LAN or trusted VPN access only.
Public VPS
The VPS is the public entry point for applications hosted at home.
The VPS receives public HTTPS traffic at 38.29.213.101 and forwards permitted traffic through WireGuard.
The VPS prevents each home service from requiring its own public router port forwarding rule.
WireGuard Gateway
The home WireGuard gateway connects the VPS tunnel to the home LAN.
The gateway performs:
Pi-hole
Pi-hole provides:
Pi-hole allows the same application hostname to work both inside and outside the home network.
Traefik
Traefik is the central HTTPS reverse proxy.
Traefik provides:
Authentik
Authentik is the central identity provider.
Authentik provides:
External Application Traffic
When an external user opens an application, traffic moves through the following components:
cloud.bytek.ca.
WHC public DNS resolves the hostname to the VPS at 38.29.213.101.
The VPS accepts the HTTPS connection on TCP port 443.
The VPS forwards the traffic through the WireGuard tunnel.
The home WireGuard gateway receives the tunneled traffic.
The gateway forwards the request to Traefik at 192.168.2.182.
Traefik examines the requested hostname.
Traefik forwards the request to the correct internal application.
Nextcloud Example
A public Nextcloud request follows this path:
cloud.bytek.ca.
WHC DNS returns 38.29.213.101.
The VPS receives the connection.
The VPS forwards the connection through WireGuard.
The home gateway forwards the request to Traefik.
Traefik forwards the request to Nextcloud at 192.168.2.100 on TCP port 11000.
BookStack Example
A public BookStack request follows this path:
docs.bytek.ca.
WHC DNS returns 38.29.213.101.
The VPS receives the connection.
The VPS forwards the connection through WireGuard.
The home gateway forwards the request to Traefik.
Traefik forwards the request to the BookStack VM on TCP port 6875.
Vikunja Example
A public Vikunja request follows this path:
projects.bytek.ca.
WHC DNS returns 38.29.213.101.
The VPS receives the connection.
The VPS forwards the connection through WireGuard.
The home gateway forwards the request to Traefik.
Traefik forwards the request to Vikunja at 192.168.2.121 on TCP port 3456.
Internal Application Traffic
LAN devices do not need to leave the home network and return through the VPS.
Pi-hole resolves public application hostnames directly to Traefik.
cloud.bytek.ca
192.168.2.182
docs.bytek.ca
192.168.2.182
portal.bytek.ca
192.168.2.182
projects.bytek.ca
192.168.2.182
proxy.bytek.ca
192.168.2.182
status.bytek.ca
192.168.2.182
An internal request follows this path:
192.168.2.182.
The client connects directly to Traefik.
Traefik routes the request to the private application backend.
This internal route provides:
Proxmox Private Access
Proxmox does not sit behind Traefik.
Pi-hole resolves:
pve.bytek.ca to 192.168.2.254.
The administrative path is:
192.168.2.254.
The workstation connects to Proxmox on TCP port 8006.
The Proxmox host itself uses Quad9 at 9.9.9.9 rather than Pi-hole.
This prevents the hypervisor from depending on Pi-hole for its own DNS resolution.
Native OIDC Authentication
The following services use native Authentik OpenID Connect:
The authentication sequence is:
portal.bytek.ca.
Authentik requests credentials and MFA.
Authentik evaluates application group and policy bindings.
Authentik redirects the browser to the application callback.
The application validates the returned token.
The application creates or matches the local user.
The application applies its own internal permissions.
OIDC Callback Reference
https://cloud.bytek.ca/apps/user_oidc/code
Vikunja
https://projects.bytek.ca/auth/openid/authentik
BookStack
https://docs.bytek.ca/oidc/callback
Proxmox VE
https://pve.bytek.ca:8006
Proxy Authentication
Some services do not support native OIDC.
Authentik Proxy Providers or ForwardAuth are used for:
Traefik Dashboard
The dashboard request follows this sequence:
proxy.bytek.ca.
Traefik invokes the Authentik ForwardAuth middleware.
The embedded Authentik outpost validates the user.
Authentik requires membership in bytek-admin.
The authenticated request returns to the Traefik dashboard.
Uptime Kuma
The Uptime Kuma request follows this sequence:
status.bytek.ca.
Traefik forwards the request to the Authentik embedded outpost.
Authentik validates the user and policies.
The outpost forwards the request to Uptime Kuma.
Selected public status-page paths may bypass authentication when intentionally configured.
Standard User Access
The Authentik group bytek-users grants access to:
These applications also apply the Allow bytek.ca users policy.
Policy engine mode is set to ALL.
A user must therefore:
bytek-users.
Pass the Allow bytek.ca users policy.
Administrator Access
The Authentik group bytek-admin grants access to:
Administrative applications also apply the Allow bytek.ca users policy.
An administrator may belong to both bytek-admin and bytek-users.
Application Access Matrix
bytek-users
Vikunja
Native Authentik OIDC
bytek-users
BookStack
Native Authentik OIDC
bytek-users
Proxmox VE
Native Authentik OIDC
bytek-admin
Traefik dashboard
Authentik ForwardAuth
bytek-admin
Uptime Kuma dashboard
Authentik Proxy Provider
bytek-admin
Pi-hole
Local authentication
Administrators on LAN
Nextcloud AIO
AIO local authentication
Administrators on LAN
WireGuard gateway
SSH key authentication
Administrators
VPS
SSH key authentication
Administrators
Service URLs
https://192.168.2.100:8080/
LAN or VPN only
Break-Glass Access
Central authentication must not be the only recovery path.
Proxmox VE
root@pam
Access methods: Private hostname, private IP, or Proxmox console
Authentik
Nextcloud
/login?direct=1
BookStack
AUTH_METHOD from oidc to standard
Uptime Kuma
Traefik
Pi-hole
Critical Dependencies
Failure Impact
Security Boundaries
The following services must not be exposed directly to the public internet: