Service Startup Order
Purpose
This page documents the preferred startup and validation order after:
Starting services in dependency order reduces DNS, OIDC, proxy, and monitoring failures.
Preferred Startup Order
1. Proxmox VE
Confirm that the hypervisor completed booting.
Validate:
192.168.2.254.
Network bridge is active.
Storage pools are active.
pveproxy is active.
TCP port 8006 is listening.
Backup HDD is mounted.
Useful checks:
systemctl is-active pveproxy
ss -lntp | grep ':8006'
pvesm status
findmnt /mnt/pve/pve-backup
Do not start troubleshooting application guests until required Proxmox storage is active.
2. Pi-hole
Pi-hole should start before services that require split DNS.
Validate:
192.168.2.65.
TCP port 53 responds.
UDP port 53 responds.
Internal records resolve.
Public records resolve.
Test:
nslookup portal.bytek.ca 192.168.2.65
Expected result:
192.168.2.182
Test:
nslookup google.com 192.168.2.65
Expected result:
Containers that started before Pi-hole may need to be restarted after Pi-hole becomes healthy.
3. WireGuard Gateway
Validate:
192.168.2.64.
WireGuard interface exists.
VPS peer appears.
Recent handshake exists.
Transfer counters increase.
IPv4 forwarding is enabled.
Firewall and NAT rules loaded.
Useful checks:
sudo wg show
sysctl net.ipv4.ip_forward
ip route
sudo ufw status numbered
The WireGuard tunnel must be working before external application access can recover.
4. Authentik Database and Redis
Authentik depends on PostgreSQL and Redis.
Validate the Authentik Compose stack using:
sudo docker compose ps
Confirm:
Do not treat Authentik as ready merely because the server container has started.
5. Authentik Server and Worker
After PostgreSQL and Redis are healthy, validate:
Direct readiness should return HTTP 200.
The outpost ping should return HTTP 204.
OIDC-dependent applications should not be treated as healthy until Authentik is ready.
6. Traefik
Traefik depends on:
Validate:
192.168.2.182.
Docker is active.
Traefik container is running.
TCP port 443 is listening.
Pi-hole DNS works inside the container.
Dynamic routers loaded.
Certificates are available.
Authentik route works.
Useful checks:
sudo docker compose ps
sudo docker inspect --format='DNS={{json .HostConfig.Dns}}' traefik
sudo tail -n 100 /opt/traefik/logs/traefik.log
If Traefik started before Pi-hole and DNS remains broken, recreate the Traefik container after Pi-hole is healthy.
7. Uptime Kuma
Start monitoring after DNS, identity, and routing are operational.
Validate:
192.168.2.115.
Docker is active.
Container is running.
Container health is healthy.
Embedded database is available.
Container DNS resolves internal hostnames.
Dashboard route works.
Monitors begin recovering.
Do not immediately modify every failed monitor after a reboot. Allow dependencies to recover first.
8. Nextcloud AIO
Before starting the Nextcloud application stack, validate:
192.168.2.100.
500 GB data disk is attached.
/mnt/nextcloud-data is mounted.
/mnt/nextcloud-data/ncdata exists.
Docker is active.
AIO management is reachable.
Then confirm:
Test:
cloud.bytek.ca.
Authentik login.
File access.
Do not run Nextcloud normally if the data disk is not mounted.
9. Vikunja
Validate:
192.168.2.121.
Docker is active.
PostgreSQL is healthy.
Vikunja container is running.
/health returns HTTP 200.
Authentik login works.
If the container cannot reach Authentik, confirm DNS before changing OIDC credentials.
10. BookStack
Validate:
docs.bytek.ca works.
Authentik login works.
Existing pages open.
If OIDC fails, temporarily restore standard authentication rather than rebuilding BookStack.
Future Plex Startup
When Plex is deployed, validate:
nvidia-smi works.
Docker has GPU access.
Plex configuration storage is mounted.
Media storage is mounted.
Plex web interface responds.
Hardware transcoding is available.
Do not start Plex if expected media storage is missing.
Future Game-Server Startup
When a game server is deployed, validate:
Do not expose RCON or management ports publicly without additional protection.
Docker DNS Recovery
A recurring risk after a full power loss is that containers start before Pi-hole is ready.
Symptoms include:
Recovery process:
Do not regenerate application secrets because of a DNS-only failure.