="UTF-8">
curl -k> for local testing." }
]
},
pihole: {
title: "Pi-hole DNS",
tags: ["lan"],
sections: [
{ heading: "Hardware", body: "Raspberry Pi Zero (separate from both servers, no SSH access)" },
{ heading: "Role", body: "Local DNS resolver and ad blocker for the home network. New plonito.at subdomains must be added manually via Pi-hole web admin — without this, local requests are intercepted and never reach the proxy chain." }
]
},
wireguard: {
title: "WireGuard VPN",
tags: ["lan"],
sections: [
{ heading: "Network", body: "10.10.10.0/24 on UDP 51820 (amore-server at 10.10.10.1)" },
{ heading: "Purpose", body: "Secure remote access to all LAN-only services (Grafana, Dozzle, Zigbee2MQTT, pgAdmin, MQTT, databases, etc.) when outside the home network." }
]
},
amore: {
title: "amore-server",
tags: ["public", "lan"],
sections: [
{ heading: "Host", body: "Debian 13 (trixie), kernel 6.12.111, Ryzen 5 7640HS, ~29 GiB RAM" },
{ heading: "Network", body: "192.168.68.131/24 (LAN), 10.10.10.1/24 (WireGuard)" },
{ heading: "Storage", body: "908 GB root NVMe, 1.8 TB LUKS /mnt/data (45% used), 1.8 TB /mnt/backups (40% used, unencrypted)" },
{ heading: "Role", body: "Central home server and public ingress point. Runs Docker 29.8.2 with 18 active Compose projects." }
]
},
edge_proxy: {
title: "Edge Proxy (nginx-proxy)",
tags: ["tls", "public"],
sections: [
{ heading: "Stack", body: "/mnt/data/amore-server/projects/proxy/" },
{ heading: "Components", body: "proxy-web-autocode> (nginx:1.29-alpine) owns :80/:443 · docker-gen-auto auto-generates config · letsencrypt-auto manages certs" },
{ heading: "Routing", body: "Services advertise routes via VIRTUAL_HOST environment variables. Must be on the proxycode> Docker network." },
{ heading: "TLS", body: "Let's Encrypt via HTTP-01. SSL policy: Mozilla-Intermediate (TLSv1.2 + TLSv1.3)." }
]
},
ai_forwarder: {
title: "AI Server Forwarder",
tags: ["tls", "public"],
sections: [
{ heading: "Location", body: "/mnt/data/amore-server/projects/ai-server/" },
{ heading: "Image", body: "nginx:1.29-alpine (pinned)" },
{ heading: "Purpose", body: "Edge forwarder for ai-server services. Uses VIRTUAL_HOST + LETSENCRYPT_HOST so acme-companion handles certs while pointing to remote host." },
{ heading: "Config", body: "Forwards to http://192.168.68.56:80 (ai-server Caddy). WebSocket support + 300s timeouts for LLM streaming." },
{ heading: "Current Domains", body: "ai.plonito.at (Open WebUI), diagram.plonito.at (Infrastructure Diagram)" }
]
},
ddns: {
title: "Hetzner DDNS",
tags: ["public"],
sections: [
{ heading: "Location", body: "/mnt/data/amore-server/projects/hetzner-ddns/stefan_hetzner_ddns.json" },
{ heading: "Role", body: "Keeps plonito.at subdomains pointing to current Hetzner public IP. Container: hetzner-ddns-stefan" },
{ heading: "Current Records", body: "Includes ai (for ai.plonito.at), diagram (for diagram.plonito.at) plus all main service domains." }
]
},
nextcloud: {
title: "Nextcloud AIO",
tags: ["public"],
sections: [
{ heading: "Domain", body: "cloud.plonito.at" },
{ heading: "Backend", body: "via nginx-nc intermediate proxy → nextcloud-aio-apache:11000" },
{ heading: "Legacy", body: "chaoticbits.soon.it → 301 redirect · chaoticcloud.soon.it → proxies to master container" }
]
},