# Infrastructure — cross-cutting systems The homelab's shared infrastructure: systems that span multiple nodes and are documented in their own pages. Each system below links to its full doc. ## Network - **[Network](network.md)** — physical topology, subnets, routing, DHCP. Homelab `192.168.8.0/24` isolated from household `192.168.178.0/24`. Proxmox hubris acts as subnet router. - **[DNS — split-horizon](dns.md)** — Technitium DNS on LXC 107, `192.168.8.2:53`. `*.hubris.network` resolves to LAN IPs on the homelab network and to mesh addresses off-LAN. ## Connectivity / mesh - **[Mesh — Tailscale → Netbird migration](mesh.md)** — overlay networking. Netbird is the preferred path; Tailscale is legacy. - **[SSH access](ssh-access.md)** — dual-server SSH (OpenSSH + Netbird SSH) on hubris, key distribution. ## Public ingress - **[Public ingress — VPS traefik + cert mirror](ingress.md)** — how home services reach the open internet. Two-stage: VPS traefik (IONOS) terminates TLS, proxies over Netbird to home Caddy. - **[Caddy reverse proxy](../containers/121-caddy.md)** — LAN endpoint. Terminates TLS for every `*.hubris.network` hostname, forwards to backends. ## Storage - **[Media permissions — GID 10000 standard](media-permissions.md)** — shared group permission model across all LXCs that read/write the media library. - **[Backups — rclone → Proton Drive](backups.md)** — off-host backup strategy. LXC 132 handles rclone to Proton Drive; restic-on-USB deprecated. ## Identity & access - **[Authentik SSO](../containers/106-auth-outpost.md)** — identity provider. Core server runs on the VPS; LAN forward-auth outpost at LXC 106. OIDC providers configured for Jellyfin, Jellyseerr, Sabnzbd, qBittorrent, Yuvomi, and more. ## Management & automation - **[Homelab context distribution](homelab-context.md)** — `/opt/homelab-context` clone, MCP server, secrets issuance, cross-client sync. - **[Auto-deploy — gitea-webhook pipelines](auto-deploy.md)** — push-to-deploy for Caddy config, mule-image, and other tracked repos. - **[Monitoring](monitoring.md)** — health checks, watchdogs, alerting (migrated from claudio-bot to Hermes cron). - **[VPS hardening](vps-hardening.md)** — IONOS netbird VPS: fail2ban, nftables, OIDC SSH, security posture. ## Topology - **[Topology diagram (generated)](topology.md)** — Mermaid graph of compute, ingress routing, and storage mounts. Auto-generated from `inventory.yaml` by `oikos/gen-topology.py`. ## Related - [README](../../../README.md) — entry point - [Containers index](../containers/index.md) - [Operations cheatsheet](../../../.agents/operations/commands.md) - [OIKOS operating model](../../../.agents/OIKOS.md)