Port Map — NUC 14 Docker Stacks
Reverse proxy: Zoraxy v3.3.2 on 192.168.1.4:8000 (LXC 108)
Wildcard cert *.nuclide.systems · source of truth: proxy/zoraxy/routes.json
Manage routes: uv run scripts/zoraxy_sync.py [--apply|--prune|--list]
Port Scheme
| Range |
Category |
| 3100 |
Loki (log aggregation) |
| 9090 |
Prometheus (monitoring) |
| 9091 |
Grafana (monitoring) |
| 9100 |
node-exporter (host metrics) |
| 12345 |
Alloy (log agent UI) |
| 10000–10999 |
Infrastructure |
| 11000–11999 |
Security & Auth |
| 12000–12999 |
Media – Immich |
| 13000–13999 |
Media – Downloads / Arr |
| 14000–14999 |
AI Stack |
| 15000–15999 |
Documents |
| 16000–16999 |
Automation |
| 17000–17999 |
Notes & Bookmarks |
| 18000–18999 |
DevOps / Image Gen |
| 19000–19999 |
Tracking |
| 20000–20999 |
Storage Admin |
| 30000–30999 |
VPN Control |
Monitoring — CT 109 ops (192.168.1.8)
| Port |
Host |
Service |
Notes |
| 9090 |
CT 109 |
Prometheus |
LAN only; 90d retention |
| 3000 |
CT 109 |
Grafana |
LAN only; admin/tapirnase |
| 3100 |
CT 109 |
Loki |
LAN only; 30d retention; log aggregation |
| 9221 |
CT 109 |
pve-exporter |
Proxmox VE metrics; auth: monitor@pve!prometheus |
| 12345 |
CT 109 |
Alloy (self) |
agent UI; also runs on all other hosts at :12345 |
| 4090 |
CT 109 |
Wetty |
LAN only (127.0.0.1); web SSH → jump-menu.sh on nuc |
| 3010 |
CT 109 |
Homepage |
LAN only (ops.nuclide.lan:3010); service dashboard; remote Docker via socket-proxy :2375 on CT 110/111/112/113, direct TCP on CT 104 |
| 10001 |
CT 109 |
Dozzle |
LAN only; live log viewer; agents on all 7 Docker hosts |
10002 |
CT 109 |
Arcane |
DECOMMISSIONED 2026-05-26 — replaced by Portainer |
| 13080 |
CT 109 |
docs-server |
LAN only; mkdocs Material; auto-rebuilds from fkrebs/docs every 5 min — migrated from CT 111 2026-05-23 |
| 9100 |
CT 109 |
node-exporter |
host-network, self-scrape |
| 9100 |
CT 104 |
node-exporter |
standalone stack /opt/stacks/monitoring/; scraped by CT 109 |
Scrape targets (CT 109 Prometheus): litellm CT104:14000/metrics/ (SUNSET 2026-05-26), node-ct104 :9100, node-ct109 :9100, home-assistant 192.168.1.60:8123/api/prometheus (HA token), prometheus self, walg CT113:9100/textfile (WAL-G backup freshness, added 2026-05-23).
Alloy (log agent): deployed on all 12 hosts → ships to Loki at CT 109:3100.
- Docker hosts (CT 101/104/105/109/110/111/112/113): container at
/opt/stacks/alloy/; reads Docker socket + journald
- Binary/systemd (CT 102/103/108 + nuc):
/etc/alloy/config.alloy; reads journald only
- HA VM 100: Grafana Alloy add-on (wymangr/hassos-addons v0.0.8) — pushes metrics to CT 109 Prometheus remote_write + logs to Loki.
Infrastructure (10000–10999)
| Port |
Service |
Container |
Public URL |
Notes |
| 10000 |
Homepage |
homepage |
— |
DECOMMISSIONED 2026-05-23 — compose renamed .DECOMMISSIONED |
| 10001 |
Dozzle |
dozzle |
— |
DECOMMISSIONED — moved to CT 109 2026-05-23 |
| 10002 |
Arcane |
arcane |
— |
DECOMMISSIONED — moved to CT 109 2026-05-23 |
| 10003 |
Gotify |
gotify |
gotify.nuclide.systems |
Push notifications |
| 10004 |
Garage S3 API |
garage |
s3.nuclide.systems |
FIXED 2026-05-21: proxied by Zoraxy with ACME TLS. Garage API accessible at https://s3.nuclide.systems. Internal: http://garage:3900 |
| 10005 (127.0.0.1 only) |
Garage Admin |
garage |
— |
localhost only |
Security & Auth (11000–11999)
| Port |
Service |
Container |
Public URL |
Notes |
| 11001 |
Vaultwarden |
vaultwarden |
vault.nuclide.systems |
Password manager · Pocket-ID OIDC client created 2026-05-21; auth flow not yet configured |
Pocket-ID migrated from this CT to LXC 110 on 2026-05-20. See the External Services table below.
Media – Immich (12000–12999)
Media – Downloads / Arr Stack (13000–13999)
All arr-stack services run behind vpn_gluetun container network.
| Port |
Service |
Container |
Public URL |
Notes |
| 13001 |
RDTClient |
rdtclient |
— |
LAN only |
| 13002 |
Prowlarr |
prowlarr |
— |
LAN only |
| 13003 |
Audiobookshelf |
audiobookshelf |
abs.nuclide.systems |
|
| 13004 |
ShelfArr |
shelfarr |
— |
LAN only |
| 13005 |
Flaresolverr |
flaresolverr |
— |
Internal only |
| 30000 |
Gluetun VPN control |
vpn_gluetun |
— |
HTTP control API |
AI Stack (14000–14999)
| Port |
Service |
Container |
Public URL |
Notes |
14000 |
LiteLLM |
litellm |
— |
SUNSET 2026-05-26 — service block commented out in ai/docker-compose.yml; replaced entirely by Bifrost |
14001 |
LobeHub |
lobehub |
— |
DECOMMISSIONED 2026-05-26 — compose renamed .DECOMMISSIONED-lobehub-2026-05-26.yml; replaced by Open WebUI |
| 14002 |
Open WebUI |
open-webui |
chat.nuclide.systems |
Chat UI; stack ai/open-webui.yml; uses Qdrant + TEI for RAG |
| 14003 |
Bifrost |
bifrost |
ai.nuclide.systems |
LLM gateway + MCP at /mcp; auth via sk-bf- VKs; stack ai/bifrost/ |
8080 |
MCP Gateway |
mcp-gateway |
— |
DECOMMISSIONED 2026-05-26 — compose renamed .DECOMMISSIONED-2026-05-26; MCP now at https://ai.nuclide.systems/mcp (Bifrost) |
| 18002 |
ComfyUI |
comfyui |
— |
LAN only (Intel Arc iGPU, FLUX.1-schnell GGUF) |
| 18003 |
ComfyUI MCP |
comfyui-mcp |
— |
FastMCP; reachable via gateway at mcp.nuclide.systems/comfyui/mcp |
| 18005 |
Docling MCP |
docling-mcp |
— |
SAIA Docling PDF→Markdown; reachable via gateway |
| 18007 |
Kroki MCP |
kroki-mcp |
— |
Diagram rendering; reachable via gateway |
| 18009 |
Speaches |
speaches |
— |
TTS/STT; LAN only |
18010 |
Shepard MCP |
shepard-mcp |
— |
DECOMMISSIONED 2026-05-21 — replaced by native https://shepard.nuclide.systems/v2/mcp (streamable HTTP; gateway entry: shepard, auth via ${SHEPARD_API_KEY}) |
| 18011 |
Upload-artifact MCP |
upload-artifact-mcp |
— |
S3 chat-artifacts upload; reachable via gateway |
| — |
SearXNG |
searxng |
— |
Internal, shared_backend, used by LobeHub |
Documents (15000–15999)
Automation (16000–16999)
Notes & Bookmarks (17000–17999)
DevOps (18000–18999)
| Port |
Service |
Container |
Public URL |
Notes |
| — | MCP servers (Gitea repos) | See AI Stack §18000 | — | mcp-comfyui, mcp-docling, mcp-upload-artifact at git.nuclide.systems/fkrebs/ (mcp-shepard decommissioned) |
Tracking (19000–19999)
Traccar moved to 15000–15001 (Documents range). 19000–19001 now free.
Storage Admin (20000–20999)
| Port |
Service |
Container |
Public URL |
Notes |
| 20010 (127.0.0.1 only) |
pgAdmin |
pgadmin |
— |
shared-db pgAdmin, localhost only (CT 104) |
LXC 112 — secrets (192.168.1.7)
CT 112 hosts Infisical. LAN-only — no Zoraxy route; secrets must not be internet-exposed.
| Port |
Service |
Container |
Notes |
| 8200 |
Infisical |
infisical |
LAN: http://192.168.1.7:8200 — admin UI + API |
| (internal) |
Postgres 16 |
infisical-db |
DB for Infisical only; no external port |
| (internal) |
Redis 7 |
infisical-redis |
Session/queue backing; no external port |
Stack at /opt/stacks/infisical/ on CT 112. Deployed 2026-05-22.
LXC 113 — db (192.168.1.6)
CT 113 is the dedicated postgres LXC. No public proxy routes — LAN access only.
| Port |
Service |
Container |
Notes |
| 5432 |
Postgres 17 |
postgres |
LAN: 192.168.1.6:5432 — accepts app connections from all CTs |
| 5050 |
pgAdmin 4 |
pgadmin |
LAN only: http://192.168.1.6:5050 — no Zoraxy route |
LXC 111 — Dev (192.168.1.42)
CT 111 hosts the self-hosted dev platform. Same Pocket-ID SSO as the rest.
| Port |
Service |
Container |
Public URL |
Notes |
| 7080 |
Coder |
coder |
dev.nuclide.systems |
Workspace orchestrator; OIDC via Pocket-ID; password auth disabled |
| 3000 |
Gitea |
gitea |
git.nuclide.systems |
Self-hosted Git; OIDC; password form disabled |
| 222 |
Gitea SSH |
gitea |
— |
ssh -p 222 git@git.nuclide.systems |
| 5432 (internal) |
coder-db |
coder-db |
— |
Postgres 16 for Coder |
| 5432 (internal) |
gitea-db |
gitea-db |
— |
Postgres 16 for Gitea |
| (no port) |
coder-fkrebs-dev |
(workspace) |
(Coder app proxy) |
Active Coder workspace |
| (no port) |
act-runner |
act-runner |
— |
Gitea Actions runner (ct111-runner) |
QNAP TS-251D (192.168.1.189)
Celeron J4025, 2-core. Hosts Klipper natively (not Docker).
| Port |
Service |
Notes |
| 80 |
Mainsail |
3D printer web UI |
| 7125 |
Moonraker |
Klipper API |
Config backed up daily to git.nuclide.systems/fkrebs/klipper-config via cron at 03:00 → covered offsite by Backrest services/gitea path.
External Services (Not on NUC Docker)
Zoraxy routes to these external backends:
Zoraxy Public Routes (proxied via 192.168.1.4)
Not publicly proxied (LAN / localhost only): pgadmin, paperless, paperless-ai, comfyui, comfyui-mcp, rdtclient, prowlarr, shelfarr, qdrant.
Known Issues
lobe-postgres / lobe-redis: host-port exposed (0.0.0.0:5432/6379) — firewall blocks external access but ideally restricted to localhost.
OIDC Client Registry (Pocket ID — id.nuclide.systems)
| Client ID |
Name |
Redirect URIs |
e73bb7b9 |
litellm |
DELETED 2026-05-26 — LiteLLM sunset; Pocket-ID client removed from CT 110 DB |
26f3c26b |
lobehub |
DECOMMISSIONED 2026-05-26 — LobeChat removed; Open WebUI OIDC not yet wired |
81cf4ed0 |
arcane |
https://arcane.nuclide.systems/auth/oidc/callback |
33135ad4 |
n8n |
https://n8n.nuclide.systems/auth/oidc/callback |
9c91c18b |
immich |
https://immich.nuclide.systems/auth/login + mobile |
62bf4e0d |
memos |
https://memos.nuclide.systems/auth/callback |
d92f82b0 |
karakeep |
https://hoarder.nuclide.systems/api/auth/callback/custom |
a14b8076 |
nextcloud |
https://nc.nuclide.systems/apps/user_oidc/code |
0aee4280 |
Coder |
https://dev.nuclide.systems/api/v2/users/oidc/callback |
9444609e |
Gitea |
https://git.nuclide.systems/user/oauth2/pocket-id/callback |
38469e7e |
Proxmox VE |
https://192.168.1.20:8006 |
798a367f |
daytona |
DECOMMISSIONED — remove from Pocket-ID |
cbbf20d5 |
Audiobookshelf |
https://abs.nuclide.systems/… + * |
d8733fcc |
shelfarr |
* |
78c78998 |
Claude MCP |
https://claude.ai/api/mcp/auth_callback + https://mcp.nuclide.systems/mcp/auth/callback |
82ca2d53 |
nuc-ai |
(empty) — used by spawned MCP servers |
7fe1a14b |
zoraxy |
(empty) |
af2f837b |
mcp-auth |
(empty) — legacy, unused |
| (new) |
vaultwarden |
https://vault.nuclide.systems/auth/callback |
OIDC Endpoints (corrected 2026-05-17 — previously used wrong /api/v1/oauth2/ path):
- Authorization:
https://id.nuclide.systems/authorize
- Token:
https://id.nuclide.systems/api/oidc/token
- Userinfo:
https://id.nuclide.systems/api/oidc/userinfo
- Discovery:
https://id.nuclide.systems/.well-known/openid-configuration