diff --git a/infrastructure/network.md b/infrastructure/network.md new file mode 100644 index 0000000..0461637 --- /dev/null +++ b/infrastructure/network.md @@ -0,0 +1,57 @@ +# Network Topology + +**Last updated:** 2026-08-11 + +## Overview + +The Daystrom Institute management network uses a flat `/24` subnet for all +infrastructure nodes. External traffic enters via Unifi and is routed to the +Traefik reverse proxy running on `impulse-controller`. + +## Subnets + +| Subnet | Purpose | +|--------|---------| +| 192.168.50.0/24 | Management / infrastructure | + +## Key Nodes + +| Hostname | IP | Role | +|----------|----|------| +| impulse-controller | 192.168.50.120 | Docker Swarm manager, Traefik ingress | + +## Ingress Architecture + +``` +Internet + │ + ▼ +Unifi (external ingress) + │ + ▼ +impulse-controller (192.168.50.120) + │ + ▼ +Traefik v3 (reverse proxy / TLS termination) + │ + ▼ +Swarm services (via master-proxy-overlay) +``` + +- **Reverse proxy:** Traefik v3 on `impulse-controller` +- **Overlay network:** `master-proxy-overlay` — Traefik and Swarm services only +- **Portainer UI:** https://192.168.50.120:9443 +- **External ingress handler:** Unifi → impulse-controller + +## TLS + +- Provider: Cloudflare DNS challenge +- Managed by: Traefik (automatic cert issuance and renewal) +- HTTP→HTTPS redirect enforced at the Traefik layer + +## Sharp Edges + +> **Docker NOT on `daystrom`** — `daystrom` is the Hermes host. Docker is not +> installed there. All containerised workloads run on Swarm nodes +> (`impulse-controller` and peers). Do not attempt to run `docker` commands +> from `daystrom`.