Network

How it fits together.

One flat network, deliberately. Click any box for detail — or tab through them if you'd rather use the keyboard.

Topology

The map

LAN — single flat subnet Internet ISP uplink UniFi Cloud Gateway Router · Firewall · DHCP Proxmox — obbo Main node 6 guests Proxmox — shion Second node Spare capacity NAS Shared storage 2-bay LAN services DNS · Automation · Remote access 4 services Docker service stack 18 containers · one host on node obbo Management · Monitoring · Media · Productivity · Data
  • Network link
  • Storage mount
  • Connections of the selected node

Select a node

Click any box in the diagram to see what it does.

Design

Why it's shaped like this

One flat subnet, no VLANs. That's a deliberate trade — segmentation would be more correct, but it also means more to debug at 1am when something stops resolving. For a lab this size the simplicity wins.

The two rules that do get enforced: storage stays off the compute boxes, and nothing is exposed by opening a port. Remote access runs over Tailscale and Twingate, so the attack surface from the internet stays effectively zero.

Principles
  • SegmentationFlat, on purpose
  • Inbound portsNone
  • Remote accessMesh VPN
  • DNSFiltered at source
  • StorageSeparate from compute
This map is the public version. It shows the shape without the addresses. The detailed map — with subnets, hosts, and ports — sits behind the login.