Networking & Traffic Flow
Public Domain:
tskn.orgยท Wildcard:*.tskn.org
Local LAN:10.0.0.0/24ยท Host IP:10.0.0.172ยท Gateway:10.0.0.1
Tailscale Mesh:100.105.175.61(Node:latitude, Exit Node enabled)
Ingress Traffic Pipeline
All incoming external traffic passes through Cloudflare DNS, hits the router's forwarded ports, and is routed by Caddy on host latitude.
flowchart TD
Client["Client Browser"]
subgraph Edge ["Cloudflare Edge"]
CF_DNS["Cloudflare DNS<br/>tskn.org wildcard"]
ACME["ACME DNS-01 API<br/>TLS Certificates"]
end
subgraph Router ["Local Network Gateway"]
NAT["Home Router 10.0.0.1<br/>Ports 80 and 443 Forwarded"]
end
subgraph Host ["Host Server latitude"]
Caddy["Caddy Reverse Proxy<br/>Ports 80 and 443"]
subgraph HostNet ["Host Network"]
HA["Home Assistant<br/>Port 8123"]
Glance["Glance Dynacat<br/>Port 8080"]
end
subgraph AuthGate ["Identity Gate"]
Authelia["Authelia Forward-Auth<br/>Port 9091"]
end
subgraph Bridges ["Docker Bridge Networks"]
Apps["App Containers<br/>Immich, Paperless, etc."]
DBs["Isolated Databases<br/>Internal Only"]
end
end
Client --> CF_DNS
CF_DNS --> NAT
NAT --> Caddy
ACME -.->|"TLS Validation"| Caddy
Caddy -->|"Direct Proxy"| HostNet
Caddy -->|"Forward-Auth"| Authelia
Authelia -->|"Authorized"| Apps
Caddy -->|"Direct Proxy"| Apps
Apps --> DBs
1. Domain & DNS Architecture
Public DNS (Cloudflare)
- Authoritative DNS: Cloudflare manages
tskn.org. - Wildcard Record:
*.tskn.orgpoints to the home WAN IP. - Certificate Automation: Caddy communicates directly with the Cloudflare API via ACME DNS-01 challenge. Wildcard certificates are issued and renewed automatically without opening port 80 to ACME bots.
Local LAN DNS (Pi-hole)
- Container:
pihole/running on hostlatitude. - DNS Ports: Binds directly to
53:53/tcpand53:53/udp. - Web Admin: Mapped to
127.0.0.1:8070and reverse-proxied athttps://pihole.tskn.org. - LAN Function:
- Blocks ads, malware, and trackers network-wide.
- Resolves
*.tskn.orgqueries locally on the LAN to prevent NAT loopback hairpinning.
2. Reverse Proxy Ingress (Caddy)
Caddy runs as a native host binary (systemd service) managed by /home/tforkan/docker/Caddyfile.
Core Routing Capabilities
- Automatic HTTPS: Enforces HTTP โ HTTPS redirect globally.
- Compression: Zstandard (
zstd) andgzipenabled. - Security Headers: Injects standard security headers (
nosniff,SAMEORIGIN, hidden server header). - Admin API: Listens on
127.0.0.1:2019for local status queries by Glance.
Routing & Port Table
| Hostname | Destination | Auth Policy | Special Routing |
|---|---|---|---|
tskn.org |
localhost:8080 |
Public startpage, Authelia on dashboard/editor | Root Glance |
auth.tskn.org |
localhost:9091 |
Direct proxy (Authelia portal) | Auth engine |
pihole.tskn.org |
localhost:8070 |
Built-in login | Admin mapped from :80 |
homeassistant.tskn.org |
localhost:8123 |
Built-in login | Host network |
jellyfin.tskn.org |
localhost:8096 |
Built-in login | Direct host binding |
immich.tskn.org |
localhost:2283 |
Built-in / OIDC | CORS whitelist, flush -1 |
seerr.tskn.org |
localhost:5055 |
Built-in login | Media discovery |
paperless.tskn.org |
localhost:8000 |
Built-in / OIDC | Documents |
adventurelog.tskn.org |
localhost:8015 |
Built-in / OIDC | Trips tracking |
dawarich.tskn.org |
localhost:3000 |
Built-in / OIDC | GPS tracking |
homebox.tskn.org |
localhost:3100 |
Built-in / OIDC | Container port :7745 |
yamtrack.tskn.org |
localhost:8111 |
Built-in / OIDC | Container port :8000 |
sparkyfitness.tskn.org |
localhost:3004 |
Built-in / OIDC | Container port :80 |
sure.tskn.org |
localhost:3334 |
Built-in login | Finance tracker |
dispatcharr.tskn.org |
localhost:9191 |
Built-in login | IPTV manager |
syncthing.tskn.org |
localhost:8384 |
Built-in login | File sync |
ntfy.tskn.org |
localhost:8085 |
Built-in / Token | Container port :80 |
it-tools.tskn.org |
localhost:8082 |
Public (no auth) | Container port :8080 |
wud.tskn.org |
localhost:3005 |
Public (no auth) | Container port :3000 |
beszel.tskn.org |
localhost:8090 |
Built-in / OIDC | Hub metrics |
kopia.tskn.org |
localhost:51515 |
Authelia Forward-Auth | Backup Web UI |
dozzle.tskn.org |
127.0.0.1:3030 |
Authelia Forward-Auth | Container logs |
megadown.tskn.org |
localhost:8091 |
Authelia Forward-Auth | Downloader |
snapcap.tskn.org |
localhost:5151 |
Authelia Forward-Auth | OCR tool |
webapps.tskn.org |
Static / localhost:3088 |
Authelia Forward-Auth | Webapps root + Shuffle API |
3. Remote Mesh Network (Tailscale)
Tailscale provides an encrypted WireGuard peer-to-peer overlay for secure remote management from outside the home without exposing management ports to the public internet.
flowchart TD
subgraph RemoteClients ["Remote Clients"]
Laptop["spectre (Linux Laptop)<br/>100.66.187.82"]
Phone["taskins-s25 (Phone)<br/>100.64.118.26"]
Desktop["skytech (Windows PC)<br/>100.109.164.33"]
end
subgraph Tailnet ["Tailscale Encrypted Mesh"]
Tunnel["WireGuard P2P Tunnels"]
end
subgraph ServerNode ["Host Node latitude"]
TS_Daemon["tailscaled (100.105.175.61)"]
ExitNode["Exit Node Service<br/>Route remote traffic through home"]
Services["Local Stacks and Admin Tools"]
end
Laptop --> Tunnel
Phone --> Tunnel
Desktop --> Tunnel
Tunnel --> TS_Daemon
TS_Daemon --> ExitNode
TS_Daemon --> Services
Tailnet Configuration
- Node IP:
100.105.175.61(latitude) - Exit Node: Enabled on
latitude. When connected from public Wi-Fi or cellular, personal devices can route all web traffic through the home fiber/broadband connection. - MagicDNS: Resolves node hostnames (
http://latitude:8080,http://latitude:3001). - Direct Connections: Tailscale establishes direct UDP hole-punched connections where possible (e.g.
10.0.0.181:41641on LAN), falling back to DERP relays when behind strict symmetric NAT.
4. Docker Network Segregation
Docker containers are segmented into distinct network modes:
- Host Network (
network_mode: host): - Containers share the host's network namespace directly with no NAT overhead.
- Used strictly where required:
- Home Assistant: Needed for LAN device discovery (mDNS, SSDP, Zigbee, Bluetooth).
- Glance / Dynacat: High-performance dashboard and API polling.
- Beszel Agent: System hardware and interface metrics collection.
- Localhost-Bound Bridge Ports (
127.0.0.1:<host_port>:<container_port>): - Services published strictly to loopback so they can only be reached through Caddy.
- Internal Bridge Networks:
- Multi-container compose stacks (Immich, Paperless, AdventureLog) run isolated bridges. Backend databases (
postgres,redis) have no published ports and can only be reached by sibling containers on that bridge.
๐ Network Diagnostic Commands
# Check Caddy reverse proxy syntax and active state
sudo caddy validate --config /home/tforkan/docker/Caddyfile
sudo systemctl status caddy
# Verify listening ports on the host
ss -tulpn | grep -E "LISTEN.*(80|443|53|8080|8123|9091)"
# Check Tailscale status and active peer connections
tailscale status
# Test local DNS resolution via Pi-hole
dig @127.0.0.1 jellyfin.tskn.org +short
# Check Docker network bridges
docker network ls