Files
docs/infra/portmap.md
T
fkrebs 644ba72d77 ops: add Prometheus + Grafana monitoring stack on CT 104
- Prometheus :9090, Grafana :9091, node-exporter :9100
- LiteLLM /metrics/ enabled via prometheus callback
- Scrapes: litellm (bearer auth), node-ct104, prometheus self
- 14 litellm_* metrics confirmed flowing
- Stack: /opt/stacks/monitoring; migrate to CT 109 ops when built

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 03:35:22 +02:00

15 KiB
Raw Blame History

Port Map — NUC 14 Docker Stacks

Reverse proxy: Zoraxy v3.3.2 on 192.168.1.4:8000 (LXC 108) Wildcard cert *.nuclide.systems · source of truth: proxy/zoraxy/routes.json Manage routes: uv run scripts/zoraxy_sync.py [--apply|--prune|--list]

Port Scheme

Range Category
9090 Prometheus (monitoring)
9091 Grafana (monitoring)
9100 node-exporter (host metrics)
1000010999 Infrastructure
1100011999 Security & Auth
1200012999 Media Immich
1300013999 Media Downloads / Arr
1400014999 AI Stack
1500015999 Documents
1600016999 Automation
1700017999 Notes & Bookmarks
1800018999 DevOps / Image Gen
1900019999 Tracking
2000020999 Storage Admin
3000030999 VPN Control

Monitoring (9090 / 9091 / 9100)

Port Service Container Public URL Notes
9090 Prometheus prometheus LAN only; stack /opt/stacks/monitoring
9091 Grafana grafana grafana.nuclide.systems (Zoraxy route pending) admin pw in .env; OIDC pending PocketID client
9100 node-exporter node-exporter host-network mode; scrapes CT 104

Scrape targets: litellm (:14000/metrics/, bearer sk-tapirnase), node-ct104 (:9100), prometheus (:9090).
LiteLLM metrics enabled via litellm_settings.callbacks: ["prometheus"] in ai/litellm-config/config.yaml.


Infrastructure (1000010999)

Port Service Container Public URL Notes
10000 Homepage homepage Dashboard, LAN only
10001 Dozzle dozzle dozzle.nuclide.systems Log viewer
10002 Arcane arcane arcane.nuclide.systems Web IDE
10003 Gotify gotify gotify.nuclide.systems Push notifications
10004 Garage S3 API garage s3.nuclide.systems FIXED 2026-05-21: proxied by Zoraxy with ACME TLS. Garage API accessible at https://s3.nuclide.systems. Internal: http://garage:3900
10005 (127.0.0.1 only) Garage Admin garage localhost only

Security & Auth (1100011999)

Port Service Container Public URL Notes
11001 Vaultwarden vaultwarden vault.nuclide.systems Password manager · Pocket-ID OIDC client created 2026-05-21; auth flow not yet configured

Pocket-ID migrated from this CT to LXC 110 on 2026-05-20. See the External Services table below.


Media Immich (1200012999)

Port Service Container Public URL Notes
12000 Immich immich_server immich.nuclide.systems Photos/videos
Immich Power Tools immich_power_tools immich-tools.nuclide.systems Container-internal :3000, Zoraxy proxy

Media Downloads / Arr Stack (1300013999)

All arr-stack services run behind vpn_gluetun container network.

Port Service Container Public URL Notes
13001 RDTClient rdtclient LAN only
13002 Prowlarr prowlarr LAN only
13003 Audiobookshelf audiobookshelf abs.nuclide.systems
13004 ShelfArr shelfarr LAN only
13005 Flaresolverr flaresolverr Internal only
30000 Gluetun VPN control vpn_gluetun HTTP control API

AI Stack (1400014999)

Port Service Container Public URL Notes
14000 LiteLLM litellm ai.nuclide.systems LLM proxy gateway
14001 LobeHub lobehub chat.nuclide.systems Chat UI
14002 Qdrant qdrant_scientific Vector DB, internal only
8080 MCP Gateway mcp-gateway mcp.nuclide.systems Pocket ID gated; spawns MCP servers on ai-internal
18002 ComfyUI comfyui LAN only (Intel Arc iGPU, FLUX.1-schnell GGUF)
18003 ComfyUI MCP comfyui-mcp FastMCP; reachable via gateway at mcp.nuclide.systems/comfyui/mcp
18005 Docling MCP docling-mcp SAIA Docling PDF→Markdown; reachable via gateway
18007 Kroki MCP kroki-mcp Diagram rendering; reachable via gateway
18009 Speaches speaches TTS/STT; LAN only
18010 Shepard MCP shepard-mcp DECOMMISSIONED 2026-05-21 — replaced by native https://shepard.nuclide.systems/v2/mcp (streamable HTTP; gateway entry: shepard, auth via ${SHEPARD_API_KEY})
18011 Upload-artifact MCP upload-artifact-mcp S3 chat-artifacts upload; reachable via gateway
SearXNG searxng Internal, shared_backend, used by LobeHub

Documents (1500015999)

Port Service Container Public URL Notes
15000 Traccar HTTP traccar traccar.nuclide.systems GPS tracking UI
15001 Traccar GPS traccar TCP+UDP watch protocol
15002 Paperless AI paperless-ai paperless-ai.nuclide.systems Internal-only Zoraxy policy
15003 Paperless-ngx paperless-ngx-webserver-1 paperless.nuclide.systems Internal-only Zoraxy policy

Automation (1600016999)

Port Service Container Public URL Notes
16000 n8n n8n n8n.nuclide.systems Workflow automation

Notes & Bookmarks (1700017999)

Port Service Container Public URL Notes
17000 Memos memos memos.nuclide.systems Notes
17001 Karakeep karakeep hoarder.nuclide.systems Bookmarks

DevOps (1800018999)

Port Service Container Public URL Notes

| — | MCP servers (Gitea repos) | See AI Stack §18000 | — | mcp-comfyui, mcp-docling, mcp-upload-artifact at git.nuclide.systems/fkrebs/ (mcp-shepard decommissioned) |


Tracking (1900019999)

Traccar moved to 1500015001 (Documents range). 1900019001 now free.


Storage Admin (2000020999)

Port Service Container Public URL Notes
20010 (127.0.0.1 only) pgAdmin pgadmin shared-db pgAdmin, localhost only (CT 104)

LXC 112 — secrets (192.168.1.7)

CT 112 hosts Infisical. LAN-only — no Zoraxy route; secrets must not be internet-exposed.

Port Service Container Notes
8200 Infisical infisical LAN: http://192.168.1.7:8200 — admin UI + API
(internal) Postgres 16 infisical-db DB for Infisical only; no external port
(internal) Redis 7 infisical-redis Session/queue backing; no external port

Stack at /opt/stacks/infisical/ on CT 112. Deployed 2026-05-22.


LXC 113 — db (192.168.1.6)

CT 113 is the dedicated postgres LXC. No public proxy routes — LAN access only.

Port Service Container Notes
5432 Postgres 17 postgres LAN: 192.168.1.6:5432 — accepts app connections from all CTs
5050 pgAdmin 4 pgadmin LAN only: http://192.168.1.6:5050 — no Zoraxy route

LXC 111 — Dev (192.168.1.42)

CT 111 hosts the self-hosted dev platform. Same Pocket-ID SSO as the rest.

Port Service Container Public URL Notes
7080 Coder coder dev.nuclide.systems Workspace orchestrator; OIDC via Pocket-ID; password auth disabled
3000 Gitea gitea git.nuclide.systems Self-hosted Git; OIDC; password form disabled
222 Gitea SSH gitea ssh -p 222 git@git.nuclide.systems
5432 (internal) coder-db coder-db Postgres 16 for Coder
5432 (internal) gitea-db gitea-db Postgres 16 for Gitea
13080 docs site docs-server — (LAN-only) mkdocs Material; auto-rebuilds from fkrebs/docs every 5 min
(no port) coder-fkrebs-dev (workspace) (Coder app proxy) Active Coder workspace
(no port) act-runner act-runner Gitea Actions runner (ct111-runner)

QNAP TS-251D (192.168.1.189)

Celeron J4025, 2-core. Hosts Klipper natively (not Docker).

Port Service Notes
80 Mainsail 3D printer web UI
7125 Moonraker Klipper API

Config backed up daily to git.nuclide.systems/fkrebs/klipper-config via cron at 03:00 → covered offsite by Backrest services/gitea path.


External Services (Not on NUC Docker)

Zoraxy routes to these external backends:

Domain Target Host Service
ha.nuclide.systems 192.168.1.60:8123 Home Assistant VM 100 Home automation
nc.nuclide.systems 192.168.1.41:11000 Nextcloud LXC 105 Cloud storage
ocpp.nuclide.systems 192.168.1.60:8887 Home Assistant VM 100 EV charger OCPP
shepard.nuclide.systems 192.168.1.49:80 Shepard LXC 101 Shepard
shepard-api.nuclide.systems 192.168.1.49:8080 Shepard LXC 101 Shepard API
id.nuclide.systems 192.168.1.5:11000 Pocket-ID LXC 110 OIDC IdP (migrated 2026-05-20)
git.nuclide.systems 192.168.1.42:3000 Dev LXC 111 Gitea (self-hosted Git)
dev.nuclide.systems 192.168.1.42:7080 Dev LXC 111 Coder (workspace orchestrator)
Gitea SSH 192.168.1.42:222 Dev LXC 111 ssh -p 222 git@git.nuclide.systems

Zoraxy Public Routes (proxied via 192.168.1.4)

Domain Backend (NUC 192.168.1.40) Port
ai.nuclide.systems litellm 14000
chat.nuclide.systems lobehub 14001
mcp.nuclide.systems mcp-gateway 8080
arcane.nuclide.systems arcane 10002
gotify.nuclide.systems gotify 10003
vault.nuclide.systems vaultwarden 11001
immich.nuclide.systems immich_server 12000
immich-tools.nuclide.systems immich_power_tools (container-internal)
abs.nuclide.systems audiobookshelf 13003
n8n.nuclide.systems n8n 16000
memos.nuclide.systems memos 17000
hoarder.nuclide.systems karakeep 17001
traccar.nuclide.systems traccar 15000
dozzle.nuclide.systems dozzle 10001
s3.nuclide.systems garage 10004

Not publicly proxied (LAN / localhost only): pgadmin, paperless, paperless-ai, comfyui, comfyui-mcp, rdtclient, prowlarr, shelfarr, qdrant.


Known Issues

  • lobe-postgres / lobe-redis: host-port exposed (0.0.0.0:5432/6379) — firewall blocks external access but ideally restricted to localhost.

OIDC Client Registry (Pocket ID — id.nuclide.systems)

Client ID Name Redirect URIs
e73bb7b9 litellm (empty = accept all) — used by LiteLLM UI + MCP Gateway
26f3c26b lobehub https://chat.nuclide.systems/api/auth/callback/generic-oidc
81cf4ed0 arcane https://arcane.nuclide.systems/auth/oidc/callback
33135ad4 n8n https://n8n.nuclide.systems/auth/oidc/callback
9c91c18b immich https://immich.nuclide.systems/auth/login + mobile
62bf4e0d memos https://memos.nuclide.systems/auth/callback
d92f82b0 karakeep https://hoarder.nuclide.systems/api/auth/callback/custom
a14b8076 nextcloud https://nc.nuclide.systems/apps/user_oidc/code
0aee4280 Coder https://dev.nuclide.systems/api/v2/users/oidc/callback
9444609e Gitea https://git.nuclide.systems/user/oauth2/pocket-id/callback
38469e7e Proxmox VE https://192.168.1.20:8006
798a367f daytona DECOMMISSIONED — remove from Pocket-ID
cbbf20d5 Audiobookshelf https://abs.nuclide.systems/… + *
d8733fcc shelfarr *
78c78998 Claude MCP https://claude.ai/api/mcp/auth_callback + https://mcp.nuclide.systems/mcp/auth/callback
82ca2d53 nuc-ai (empty) — used by spawned MCP servers
7fe1a14b zoraxy (empty)
af2f837b mcp-auth (empty) — legacy, unused
(new) vaultwarden https://vault.nuclide.systems/auth/callback

OIDC Endpoints (corrected 2026-05-17 — previously used wrong /api/v1/oauth2/ path):

  • Authorization: https://id.nuclide.systems/authorize
  • Token: https://id.nuclide.systems/api/oidc/token
  • Userinfo: https://id.nuclide.systems/api/oidc/userinfo
  • Discovery: https://id.nuclide.systems/.well-known/openid-configuration