Public VPS Ingress
Purpose
The public VPS is the internet-facing entry point for applications hosted on the Bytek home network.
The VPS prevents individual home services from being exposed directly through the Bell router. Public HTTPS traffic reaches the VPS first, then travels through an encrypted WireGuard tunnel to the home network.
The VPS provides:
Service Information
38.29.213.101
Primary purpose
Public HTTPS ingress
Public application port
TCP 443
Home-network transport
WireGuard
Administration
SSH key authentication
SSH port
Confirm current hardened SSH port
Operating system
Confirm current Linux distribution
Hosting provider
Confirm current VPS provider
Public DNS provider
WHC cPanel
Monitoring
Uptime Kuma
Architecture Role
The VPS does not host the main Bytek applications.
The VPS forwards approved traffic to the home network.
The primary traffic path is:
38.29.213.101.
The client establishes HTTPS to the VPS on TCP port 443.
The VPS forwards the permitted connection through WireGuard.
The home WireGuard gateway receives the traffic.
The gateway forwards the request to Traefik at 192.168.2.182.
Traefik selects the correct application backend.
The VPS must not have direct access to all home-LAN services unless a specific rule requires it.
Public Hostnames
The following public DNS records point to the VPS:
cloud.bytek.ca
38.29.213.101
BookStack
docs.bytek.ca
38.29.213.101
Authentik
portal.bytek.ca
38.29.213.101
Vikunja
projects.bytek.ca
38.29.213.101
Traefik dashboard
proxy.bytek.ca
38.29.213.101
Uptime Kuma
status.bytek.ca
38.29.213.101
The public hostname pve.bytek.ca must not point to the VPS.
Proxmox remains available only through the LAN or a trusted remote-access method.
Public HTTPS Flow
External HTTPS requests follow this sequence:
38.29.213.101.
The incoming connection reaches the VPS on TCP port 443.
VPS firewall rules verify that the connection targets an approved public entry point.
The VPS forwards the traffic through the WireGuard tunnel.
The home WireGuard gateway forwards the connection to Traefik.
Traefik terminates HTTPS or processes the forwarded connection according to the configured design.
Traefik routes the request by hostname.
The VPS does not need separate public ports for every HTTPS application because Traefik distinguishes applications by hostname.
WireGuard Connection
The VPS maintains a WireGuard peer relationship with the home WireGuard gateway.
The tunnel is used for:
The existing VPS tunnel must remain separate from any future laptop or phone VPN.
Do not reuse:
WireGuard Health
Review the tunnel using:
sudo wg show
Verify:
A recent handshake confirms peer connectivity but does not prove that application forwarding works.
Test the complete application path separately.
VPS Firewall Policy
The VPS firewall should allow only required public and administrative traffic.
Required Public Access
Traffic That Must Remain Private
Do not expose the following home ports through the VPS:
New public ports must be documented before being added.
SSH Administration
VPS management uses SSH key authentication.
Recommended SSH controls include:
Confirm the current SSH listener using:
ss -lntp
Confirm SSH service health using:
systemctl is-active ssh
Expected result:
active
Do not place the private SSH key in BookStack.
Public DNS Management
Public DNS records are managed through WHC cPanel.
When adding a new public application:
38.29.213.101.
Use a short TTL during the initial deployment.
Create the matching Pi-hole split-DNS record.
Create the Traefik router and service.
Confirm the application backend is reachable from Traefik.
Confirm certificate issuance.
Test internally.
Test externally using cellular data or another external network.
Add Uptime Kuma monitoring.
Update BookStack documentation.
Do not point public DNS directly to:
Public Application Onboarding Checklist
Before exposing a new application through the VPS, confirm:
38.29.213.101.
Pi-hole points the hostname to 192.168.2.182.
A Traefik route exists.
The Traefik backend uses the correct current IP.
A valid HTTPS certificate is issued.
Authentik is configured if the application requires SSO.
The application does not expose an administrative backend unintentionally.
Uptime Kuma monitors the routed service.
The VM is covered by the Proxmox backup job.
Service Validation
Confirm the VPS Public Address
Verify that public DNS resolves application hostnames to:
38.29.213.101
Confirm the WireGuard Tunnel
Use:
sudo wg show
Expected:
Confirm Public Port 443
Use:
ss -lntp
Confirm that the intended ingress service or forwarding mechanism is listening on TCP port 443.
Confirm Routing to the Home Network
Test the intended WireGuard peer or private tunnel address.
A successful tunnel ping confirms network reachability but not application-level routing.
Confirm an Application Through the VPS
From an external connection, open a public application such as:
The request should reach Authentik without exposing the private backend port.
External Testing
External testing must use a network outside the home LAN.
Suitable test methods include:
Testing from the home LAN may use Pi-hole split DNS and therefore bypass the VPS.
To validate public ingress, confirm the client resolves the hostname to 38.29.213.101.
Monitoring
Recommended Uptime Kuma monitors include:
portal.bytek.ca
Nextcloud external route
cloud.bytek.ca
BookStack external route
docs.bytek.ca
Vikunja external route
projects.bytek.ca
Monitoring should distinguish:
A successful ping does not prove HTTPS or WireGuard forwarding is functioning.
Logging
Review logs for:
Useful sources may include:
Do not copy active tokens, private keys, or full authentication headers into BookStack.
Failure Impact
The VPS is therefore critical for external access but not for normal LAN access.
Common Failure Scenarios
Public DNS Resolves Incorrectly
Symptoms:
Check:
WireGuard Handshake Is Missing
Symptoms:
Check:
Tunnel Works but Application Fails
Symptoms:
Check:
Internal Access Works but External Access Fails
This usually indicates a problem with:
Internal split DNS bypasses those components.
External Access Works but Internal Access Fails
This usually indicates a problem with:
Recovery Procedure
If all public applications become unavailable:
38.29.213.101.
Confirm SSH access.
Confirm the WireGuard interface.
Confirm the latest home-peer handshake.
Confirm transfer counters.
Confirm IP forwarding and firewall rules.
Confirm TCP 443 is listening.
Confirm the home WireGuard gateway is running.
Confirm Traefik is running.
Test one application directly from Traefik.
Test the public hostname from an external network.
Review logs before changing configuration.
Backup and Recovery Data
Preserve the following VPS information:
Private keys must remain in a password manager or encrypted backup.
BookStack should record the location of secrets, not the secret values.
Security Review Checklist
Document Control
38.29.213.101
Primary role: Public HTTPS ingress
Home transport: WireGuard
Public DNS provider: WHC cPanel
Last verified: YYYY-MM-DD
Last external-access test: YYYY-MM-DD
Last WireGuard recovery test: YYYY-MM-DD
SSH recovery tested: Yes / No
Known limitations: External application access depends on one VPS and one WireGuard tunnel