Files

2052 lines
37 KiB
HTML

<!doctype html>
<html lang="en" class="no-js">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<meta name="description" content="Single source of truth for the homelab">
<link rel="canonical" href="http://192.168.1.8:13080/docker-internal-inventory/">
<link rel="icon" href="../assets/images/favicon.png">
<meta name="generator" content="mkdocs-1.6.1, mkdocs-material-9.7.6">
<title>Docker-internal inventory - nuclide.systems docs</title>
<link rel="stylesheet" href="../assets/stylesheets/main.484c7ddc.min.css">
<link rel="stylesheet" href="../assets/stylesheets/palette.ab4e12ef.min.css">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:300,300i,400,400i,700,700i%7CRoboto+Mono:400,400i,700,700i&display=fallback">
<style>:root{--md-text-font:"Roboto";--md-code-font:"Roboto Mono"}</style>
<script>__md_scope=new URL("..",location),__md_hash=e=>[...e].reduce(((e,_)=>(e<<5)-e+_.charCodeAt(0)),0),__md_get=(e,_=localStorage,t=__md_scope)=>JSON.parse(_.getItem(t.pathname+"."+e)),__md_set=(e,_,t=localStorage,a=__md_scope)=>{try{t.setItem(a.pathname+"."+e,JSON.stringify(_))}catch(e){}}</script>
</head>
<body dir="ltr" data-md-color-scheme="slate" data-md-color-primary="black" data-md-color-accent="blue">
<input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
<input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
<label class="md-overlay" for="__drawer"></label>
<div data-md-component="skip">
<a href="#docker-internal-inventory" class="md-skip">
Skip to content
</a>
</div>
<div data-md-component="announce">
</div>
<header class="md-header" data-md-component="header">
<nav class="md-header__inner md-grid" aria-label="Header">
<a href=".." title="nuclide.systems docs" class="md-header__button md-logo" aria-label="nuclide.systems docs" data-md-component="logo">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 8a3 3 0 0 0 3-3 3 3 0 0 0-3-3 3 3 0 0 0-3 3 3 3 0 0 0 3 3m0 3.54C9.64 9.35 6.5 8 3 8v11c3.5 0 6.64 1.35 9 3.54 2.36-2.19 5.5-3.54 9-3.54V8c-3.5 0-6.64 1.35-9 3.54"/></svg>
</a>
<label class="md-header__button md-icon" for="__drawer">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3zm0 5h18v2H3zm0 5h18v2H3z"/></svg>
</label>
<div class="md-header__title" data-md-component="header-title">
<div class="md-header__ellipsis">
<div class="md-header__topic">
<span class="md-ellipsis">
nuclide.systems docs
</span>
</div>
<div class="md-header__topic" data-md-component="header-topic">
<span class="md-ellipsis">
Docker-internal inventory
</span>
</div>
</div>
</div>
<form class="md-header__option" data-md-component="palette">
<input class="md-option" data-md-color-media="(prefers-color-scheme: dark)" data-md-color-scheme="slate" data-md-color-primary="black" data-md-color-accent="blue" aria-hidden="true" type="radio" name="__palette" id="__palette_0">
<input class="md-option" data-md-color-media="(prefers-color-scheme: light)" data-md-color-scheme="default" data-md-color-primary="black" data-md-color-accent="blue" aria-hidden="true" type="radio" name="__palette" id="__palette_1">
</form>
<script>var palette=__md_get("__palette");if(palette&&palette.color){if("(prefers-color-scheme)"===palette.color.media){var media=matchMedia("(prefers-color-scheme: light)"),input=document.querySelector(media.matches?"[data-md-color-media='(prefers-color-scheme: light)']":"[data-md-color-media='(prefers-color-scheme: dark)']");palette.color.media=input.getAttribute("data-md-color-media"),palette.color.scheme=input.getAttribute("data-md-color-scheme"),palette.color.primary=input.getAttribute("data-md-color-primary"),palette.color.accent=input.getAttribute("data-md-color-accent")}for(var[key,value]of Object.entries(palette.color))document.body.setAttribute("data-md-color-"+key,value)}</script>
<label class="md-header__button md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"/></svg>
</label>
<div class="md-search" data-md-component="search" role="dialog">
<label class="md-search__overlay" for="__search"></label>
<div class="md-search__inner" role="search">
<form class="md-search__form" name="search">
<input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" required>
<label class="md-search__icon md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"/></svg>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11z"/></svg>
</label>
<nav class="md-search__options" aria-label="Search">
<button type="reset" class="md-search__icon md-icon" title="Clear" aria-label="Clear" tabindex="-1">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12z"/></svg>
</button>
</nav>
<div class="md-search__suggest" data-md-component="search-suggest"></div>
</form>
<div class="md-search__output">
<div class="md-search__scrollwrap" tabindex="0" data-md-scrollfix>
<div class="md-search-result" data-md-component="search-result">
<div class="md-search-result__meta">
Initializing search
</div>
<ol class="md-search-result__list" role="presentation"></ol>
</div>
</div>
</div>
</div>
</div>
</nav>
</header>
<div class="md-container" data-md-component="container">
<nav class="md-tabs" aria-label="Tabs" data-md-component="tabs">
<div class="md-grid">
<ul class="md-tabs__list">
<li class="md-tabs__item">
<a href=".." class="md-tabs__link">
Home
</a>
</li>
<li class="md-tabs__item">
<a href="../CHANGELOG/" class="md-tabs__link">
Changelog
</a>
</li>
<li class="md-tabs__item">
<a href="../RESUME/" class="md-tabs__link">
Resume
</a>
</li>
<li class="md-tabs__item">
<a href="../ct-inventory/" class="md-tabs__link">
CT inventory
</a>
</li>
<li class="md-tabs__item">
<a href="../infra/proxmox-state/" class="md-tabs__link">
Infra
</a>
</li>
<li class="md-tabs__item">
<a href="../services/homelab-architecture/" class="md-tabs__link">
Services
</a>
</li>
<li class="md-tabs__item">
<a href="../security/data-leak-audit-comparison/" class="md-tabs__link">
Security & audits
</a>
</li>
<li class="md-tabs__item">
<a href="../ideas/stack-ideas/" class="md-tabs__link">
Ideas
</a>
</li>
<li class="md-tabs__item">
<a href="../history/traefik-migration/" class="md-tabs__link">
History
</a>
</li>
</ul>
</div>
</nav>
<main class="md-main" data-md-component="main">
<div class="md-main__inner md-grid">
<div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--primary md-nav--lifted" aria-label="Navigation" data-md-level="0">
<label class="md-nav__title" for="__drawer">
<a href=".." title="nuclide.systems docs" class="md-nav__button md-logo" aria-label="nuclide.systems docs" data-md-component="logo">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 8a3 3 0 0 0 3-3 3 3 0 0 0-3-3 3 3 0 0 0-3 3 3 3 0 0 0 3 3m0 3.54C9.64 9.35 6.5 8 3 8v11c3.5 0 6.64 1.35 9 3.54 2.36-2.19 5.5-3.54 9-3.54V8c-3.5 0-6.64 1.35-9 3.54"/></svg>
</a>
nuclide.systems docs
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href=".." class="md-nav__link">
<span class="md-ellipsis">
Home
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../CHANGELOG/" class="md-nav__link">
<span class="md-ellipsis">
Changelog
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../RESUME/" class="md-nav__link">
<span class="md-ellipsis">
Resume
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../ct-inventory/" class="md-nav__link">
<span class="md-ellipsis">
CT inventory
</span>
</a>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_5" >
<label class="md-nav__link" for="__nav_5" id="__nav_5_label" tabindex="0">
<span class="md-ellipsis">
Infra
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_5_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_5">
<span class="md-nav__icon md-icon"></span>
Infra
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../infra/proxmox-state/" class="md-nav__link">
<span class="md-ellipsis">
Proxmox state
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../infra/portmap/" class="md-nav__link">
<span class="md-ellipsis">
Port map
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../infra/storage/" class="md-nav__link">
<span class="md-ellipsis">
Storage
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../infra/volumes/" class="md-nav__link">
<span class="md-ellipsis">
Volumes
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../infra/docker-networks/" class="md-nav__link">
<span class="md-ellipsis">
Docker networks
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../infra/connection-hosts/" class="md-nav__link">
<span class="md-ellipsis">
Connection hosts
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../infra/proxmox-memory-audit/" class="md-nav__link">
<span class="md-ellipsis">
Memory audit
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6" >
<label class="md-nav__link" for="__nav_6" id="__nav_6_label" tabindex="0">
<span class="md-ellipsis">
Services
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_6_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_6">
<span class="md-nav__icon md-icon"></span>
Services
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../services/homelab-architecture/" class="md-nav__link">
<span class="md-ellipsis">
Homelab architecture
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/dev-environment/" class="md-nav__link">
<span class="md-ellipsis">
Dev environment (Coder + Gitea)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/mcp-gateway/" class="md-nav__link">
<span class="md-ellipsis">
MCP gateway
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/mcp-servers/" class="md-nav__link">
<span class="md-ellipsis">
MCP servers
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/pocket-id/" class="md-nav__link">
<span class="md-ellipsis">
Pocket-ID (OIDC)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/backrest/" class="md-nav__link">
<span class="md-ellipsis">
Backrest (backups)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/databases/" class="md-nav__link">
<span class="md-ellipsis">
Databases
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/secrets-manager/" class="md-nav__link">
<span class="md-ellipsis">
Secrets manager
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/comfyui/" class="md-nav__link">
<span class="md-ellipsis">
ComfyUI
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/zoraxy/" class="md-nav__link">
<span class="md-ellipsis">
Zoraxy
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/adguard-dns/" class="md-nav__link">
<span class="md-ellipsis">
AdGuard DNS
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/cloud-gpu/" class="md-nav__link">
<span class="md-ellipsis">
Cloud GPU
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/arcane/" class="md-nav__link">
<span class="md-ellipsis">
Arcane
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/doc-ingestion/" class="md-nav__link">
<span class="md-ellipsis">
Doc ingestion pipeline
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../services/llm-benchmark/" class="md-nav__link">
<span class="md-ellipsis">
LLM benchmark
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_7" >
<label class="md-nav__link" for="__nav_7" id="__nav_7_label" tabindex="0">
<span class="md-ellipsis">
Security & audits
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_7_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_7">
<span class="md-nav__icon md-icon"></span>
Security & audits
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../security/data-leak-audit-comparison/" class="md-nav__link">
<span class="md-ellipsis">
Comparison
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../security/data-leak-audit-2026-05-20-tr004-cloud-sandbox/" class="md-nav__link">
<span class="md-ellipsis">
2026-05-20 · cloud-sandbox breach
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../security/data-leak-audit-2026-05-21-tr004-artifacts/" class="md-nav__link">
<span class="md-ellipsis">
2026-05-21 · artifacts (clean)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../security/audit-claude-code-meta/" class="md-nav__link">
<span class="md-ellipsis">
Self-audit (Claude Code)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../security/transcripts/audit-chat-2026-05-21/" class="md-nav__link">
<span class="md-ellipsis">
Transcript (audit session)
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_8" >
<label class="md-nav__link" for="__nav_8" id="__nav_8_label" tabindex="0">
<span class="md-ellipsis">
Ideas
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_8_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_8">
<span class="md-nav__icon md-icon"></span>
Ideas
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../ideas/stack-ideas/" class="md-nav__link">
<span class="md-ellipsis">
Stack ideas
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_9" >
<label class="md-nav__link" for="__nav_9" id="__nav_9_label" tabindex="0">
<span class="md-ellipsis">
History
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_9_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_9">
<span class="md-nav__icon md-icon"></span>
History
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../history/traefik-migration/" class="md-nav__link">
<span class="md-ellipsis">
Traefik (abandoned 2026-05-16)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../history/traefik-migration-docker-labels/" class="md-nav__link">
<span class="md-ellipsis">
Traefik labels (abandoned)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../history/mcp-gateway-requirements/" class="md-nav__link">
<span class="md-ellipsis">
MCP gateway requirements (superseded)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../history/scrubbing-list-2026-05-17/" class="md-nav__link">
<span class="md-ellipsis">
Scrubbing list (2026-05-17)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../history/case-study/" class="md-nav__link">
<span class="md-ellipsis">
Case study
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" >
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--secondary" aria-label="Table of contents">
<label class="md-nav__title" for="__toc">
<span class="md-nav__icon md-icon"></span>
Table of contents
</label>
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
<li class="md-nav__item">
<a href="#recommendation-legend" class="md-nav__link">
<span class="md-ellipsis">
Recommendation legend
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#ct-104-docker-host-43-internal-only" class="md-nav__link">
<span class="md-ellipsis">
CT 104 (docker host) — 43 internal-only
</span>
</a>
<nav class="md-nav" aria-label="CT 104 (docker host) — 43 internal-only">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#ai-mcp-plumbing-all-keep-internal" class="md-nav__link">
<span class="md-ellipsis">
AI / MCP plumbing — all 🟢 keep internal
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#backends-for-exposed-services-keep-internal" class="md-nav__link">
<span class="md-ellipsis">
Backends for exposed services — 🟢 keep internal
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#diagrams-keep-internal" class="md-nav__link">
<span class="md-ellipsis">
Diagrams — 🟢 keep internal
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#monitoring-agents-keep-internal" class="md-nav__link">
<span class="md-ellipsis">
Monitoring agents — 🟢 keep internal
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="#ct-105-nextcloud-8-internal-only" class="md-nav__link">
<span class="md-ellipsis">
CT 105 (nextcloud) — 8 internal-only
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#ct-109-ops-1-internal-only" class="md-nav__link">
<span class="md-ellipsis">
CT 109 (ops) — 1 internal-only
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#ct-110-111-112-113-arcane-agent-only" class="md-nav__link">
<span class="md-ellipsis">
CT 110 / 111 / 112 / 113 — arcane-agent only
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#cross-tier-issues-spotted" class="md-nav__link">
<span class="md-ellipsis">
Cross-tier issues spotted
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#candidate-lan-bind-if-you-want-them" class="md-nav__link">
<span class="md-ellipsis">
Candidate LAN-bind, if you want them
</span>
</a>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-content" data-md-component="content">
<article class="md-content__inner md-typeset">
<h1 id="docker-internal-inventory">Docker-internal inventory<a class="headerlink" href="#docker-internal-inventory" title="Permanent link">&para;</a></h1>
<p>Live at <a href="http://192.168.1.8:13080/docker-internal-inventory/">http://192.168.1.8:13080/docker-internal-inventory/</a>.</p>
<p>Containers that have <strong>no LAN-published port</strong> — reachable only on their Docker bridge network. This is the third tier of our access model:</p>
<ol>
<li><strong>public</strong> — Zoraxy-routed via <code>*.nuclide.systems</code> (internet-reachable)</li>
<li><strong>LAN</strong><code>192.168.1.0/24</code> direct (host port mapping)</li>
<li><strong>docker-internal</strong> — only via container-to-container bridge (this doc)</li>
</ol>
<p>Default per [[feedback_internal_only]]: keep new things at tier 2 or 3 unless there's a real external-access reason. <strong>Most of what is on tier 3 should stay there</strong> — that's the point of having three tiers.</p>
<h2 id="recommendation-legend">Recommendation legend<a class="headerlink" href="#recommendation-legend" title="Permanent link">&para;</a></h2>
<ul>
<li>🟢 <strong>Keep internal</strong> — sidecar / backend / engine, must not be exposed</li>
<li>🟡 <strong>Maybe</strong> — admin UI exists; could be useful to reach directly but low value</li>
<li>🔴 <strong>Expose to LAN</strong> — broken access pattern, fix recommended</li>
</ul>
<h2 id="ct-104-docker-host-43-internal-only">CT 104 (docker host) — 43 internal-only<a class="headerlink" href="#ct-104-docker-host-43-internal-only" title="Permanent link">&para;</a></h2>
<h3 id="ai-mcp-plumbing-all-keep-internal">AI / MCP plumbing — all 🟢 keep internal<a class="headerlink" href="#ai-mcp-plumbing-all-keep-internal" title="Permanent link">&para;</a></h3>
<p>Backend MCP servers consumed only by the MCP gateway. Exposing them would bypass auth + audit.
- <code>mcp-proxmox</code>, <code>gitea-mcp</code>, <code>mcp-immich</code>, <code>mcp-fetch</code>, <code>mcp-time</code>, <code>mcp-git</code>, <code>mcp-gotify</code>, <code>mcp-unifi</code>, <code>mcp-ntfy</code>, <code>mcp-markitdown</code>, <code>mcp-context7</code>, <code>mcp-youtube-transcript</code>, <code>mcp-sequential-thinking</code>, <code>mcp-wikipedia-mcp</code>, <code>mcp-gitlab</code>, <code>mcp-crawl4ai</code>, <code>coder-mcp</code>, <code>ariel-mcp</code>, <code>paperless-mcp</code>, <code>claude-max-bridge</code>
- Plus the ephemeral <code>crazy_colden</code>/<code>stoic_kirch</code>/etc. (auto-spawned MCP one-shots — Docker name collisions, no static port).</p>
<h3 id="backends-for-exposed-services-keep-internal">Backends for exposed services — 🟢 keep internal<a class="headerlink" href="#backends-for-exposed-services-keep-internal" title="Permanent link">&para;</a></h3>
<ul>
<li><code>karakeep_meilisearch</code>, <code>karakeep_chrome</code> (Karakeep search + headless browser)</li>
<li><code>immich_postgres</code>, <code>immich_redis</code>, <code>immich_machine_learning</code> (Immich backends)</li>
<li><code>immich_power_tools</code> — 🟡 <strong>maybe</strong>. Power-user UI for Immich. Bind to LAN if you ever want to use it directly.</li>
<li><code>paperless-ngx-tika-1</code>, <code>paperless-ngx-gotenberg-1</code>, <code>paperless-ngx-broker-1</code> (Paperless OCR/PDF/redis)</li>
<li><code>redis-searxng</code>, <code>rdtclient</code> (auxiliary)</li>
</ul>
<h3 id="diagrams-keep-internal">Diagrams — 🟢 keep internal<a class="headerlink" href="#diagrams-keep-internal" title="Permanent link">&para;</a></h3>
<ul>
<li><code>kroki</code>, <code>kroki-mermaid</code>, <code>kroki-excalidraw</code> — rendered via MCP, no UI to expose.</li>
</ul>
<h3 id="monitoring-agents-keep-internal">Monitoring agents — 🟢 keep internal<a class="headerlink" href="#monitoring-agents-keep-internal" title="Permanent link">&para;</a></h3>
<ul>
<li><code>node-exporter</code> (scraped by Prometheus on <code>:9100</code> over container network; LAN exposure not needed since Prometheus is on the same LAN already)</li>
<li><code>arcane-agent</code> (talks back to Arcane server on CT 109)</li>
</ul>
<h2 id="ct-105-nextcloud-8-internal-only">CT 105 (nextcloud) — 8 internal-only<a class="headerlink" href="#ct-105-nextcloud-8-internal-only" title="Permanent link">&para;</a></h2>
<p>🟢 <strong>All keep internal</strong> — Nextcloud AIO architecture.
- <code>nextcloud-aio-nextcloud</code> (fronted by AIO apache proxy on <code>:11000</code>)
- <code>nextcloud-aio-database</code> (Postgres), <code>nextcloud-aio-redis</code>, <code>nextcloud-aio-imaginary</code>, <code>nextcloud-aio-notify-push</code>, <code>nextcloud-aio-collabora</code>, <code>nextcloud-aio-docker-socket-proxy</code>
- <code>arcane-agent</code></p>
<p>Exposing the AIO backends directly would break Nextcloud's auth model and crash backups.</p>
<h2 id="ct-109-ops-1-internal-only">CT 109 (ops) — 1 internal-only<a class="headerlink" href="#ct-109-ops-1-internal-only" title="Permanent link">&para;</a></h2>
<ul>
<li><code>node-exporter</code> — 🟢 keep internal. Scraped via <code>host.docker.internal</code> from Prometheus on the same host.</li>
</ul>
<h2 id="ct-110-111-112-113-arcane-agent-only">CT 110 / 111 / 112 / 113 — <code>arcane-agent</code> only<a class="headerlink" href="#ct-110-111-112-113-arcane-agent-only" title="Permanent link">&para;</a></h2>
<p>🟢 <strong>All keep internal</strong>. The Arcane agent on each Docker host calls back to the Arcane server on <code>192.168.1.8:10002</code>; no inbound LAN traffic needed.</p>
<p>Plus:
- CT 111: <code>act-runner</code> 🟢 (Gitea Actions runner — outbound to Gitea API; never needs inbound)
- CT 112: <code>infisical-db</code>, <code>infisical-redis</code> 🟢 (Infisical app on <code>:8200</code> is the only intended entry)</p>
<h2 id="cross-tier-issues-spotted">Cross-tier issues spotted<a class="headerlink" href="#cross-tier-issues-spotted" title="Permanent link">&para;</a></h2>
<p>None. The 3-tier model is clean across the fleet:
- No backend Postgres/Redis is accidentally LAN-bound
- No MCP server is double-exposed
- No admin UI is bound to LAN when it shouldn't be</p>
<h2 id="candidate-lan-bind-if-you-want-them">Candidate LAN-bind, if you want them<a class="headerlink" href="#candidate-lan-bind-if-you-want-them" title="Permanent link">&para;</a></h2>
<p>If you ever want direct LAN access to one of the 🟡 services, the pattern is to add a <code>ports:</code> line to its compose entry:</p>
<table>
<thead>
<tr>
<th>Service</th>
<th>Suggested port</th>
<th>Why you might</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>immich_power_tools</code></td>
<td><code>:3001</code> on CT 104</td>
<td>Bulk Immich operations (album merge, dedup) the main UI doesn't expose</td>
</tr>
</tbody>
</table>
<p>Everything else: leave at tier 3.</p>
</article>
</div>
<script>var target=document.getElementById(location.hash.slice(1));target&&target.name&&(target.checked=target.name.startsWith("__tabbed_"))</script>
</div>
<button type="button" class="md-top md-icon" data-md-component="top" hidden>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M13 20h-2V8l-5.5 5.5-1.42-1.42L12 4.16l7.92 7.92-1.42 1.42L13 8z"/></svg>
Back to top
</button>
</main>
<footer class="md-footer">
<div class="md-footer-meta md-typeset">
<div class="md-footer-meta__inner md-grid">
<div class="md-copyright">
Made with
<a href="https://squidfunk.github.io/mkdocs-material/" target="_blank" rel="noopener">
Material for MkDocs
</a>
</div>
</div>
</div>
</footer>
</div>
<div class="md-dialog" data-md-component="dialog">
<div class="md-dialog__inner md-typeset"></div>
</div>
<script id="__config" type="application/json">{"annotate": null, "base": "..", "features": ["navigation.tabs", "navigation.sections", "navigation.expand", "navigation.top", "search.highlight", "search.suggest", "content.code.copy"], "search": "../assets/javascripts/workers/search.2c215733.min.js", "tags": null, "translations": {"clipboard.copied": "Copied to clipboard", "clipboard.copy": "Copy to clipboard", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.placeholder": "Type to start searching", "search.result.term.missing": "Missing", "select.version": "Select version"}, "version": null}</script>
<script src="../assets/javascripts/bundle.79ae519e.min.js"></script>
</body>
</html>