Revise Ced's HomeLab Diagrams documentation

Updated the document to enhance clarity and organization, including new headings and improved diagram descriptions.
This commit is contained in:
Chase Dumphord
2026-04-02 18:25:39 -05:00
committed by GitHub
parent 607f15c93c
commit 7236e75be5
+85 -133
View File
@@ -1,177 +1,129 @@
# Ced's HomeLab Network & Cloud Architecture Diagrams # 🧠 Ced's HomeLab - Architecture & Network Diagrams
This file contains **Mermaid diagrams** for: This document provides visual representations of the Ced's HomeLab environment, including:
- Cloud & homelab architecture - 🌐 Cloud and homelab architecture
- VLAN segmentation - 🧩 VLAN segmentation
- Request flows (Proxmox, Home Assistant) - 🔄 Request flow through Cloudflare, reverse proxy, and internal services
You can view or edit them with: These diagrams explain how infrastructure components interact and how services are exposed.
- Mermaid Live Editor: https://mermaid.live
- Draw.io (Arrange → Insert → Advanced → Mermaid)
- GitHub / Obsidian / VS Code (Mermaid support)
--- ---
## 1. High-Level Cloud & Homelab Architecture ## 🛠️ Viewing & Editing
You can view or edit these diagrams using:
- Mermaid Live Editor: https://mermaid.live
- Draw.io → Arrange → Insert → Advanced → Mermaid
- GitHub / VS Code with Mermaid support
---
## 🌐 1. High-Level Cloud & Homelab Architecture
```mermaid ```mermaid
graph TD graph TD
subgraph Internet["🌐 Internet"] User[User Browser] --> CFDNS[Cloudflare DNS and SSL]
User[User Browser] CFDNS --> CFZT[Cloudflare Zero Trust Planned]
end CFZT --> CFTUN[Cloudflare Tunnel]
CFTUN --> NPM[Nginx Proxy Manager 10.10.30.210]
subgraph Cloudflare["Cloudflare Edge"] NPM --> PVE[Proxmox VE Host 10.10.30.250]
CF_DNS[DNS & SSL] NPM --> TRUENAS[TrueNAS Storage 10.10.30.143]
CF_ZT[Zero Trust (future)] NPM --> HA[Home Assistant 10.10.30.104]
end NPM --> GRAF[Grafana]
NPM --> PROM[Prometheus]
NPM --> UPTK[Uptime Kuma]
NPM --> JF[Jellyfin]
NPM --> ARR[Arr Suite]
subgraph Tunnel["Cloudflare Tunnel"] PVE -.-> K3S[K3s Cluster 12 Nodes]
CF_Tunnel[cloudflared<br/>NPM LXC] PVE -.-> OBS[Observability Stack]
end PVE -.-> MEDIA[Media Services]
subgraph HomeLab_VLAN["HomeLab VLAN 10.10.30.0/24"]
NPM[Nginx Proxy Manager<br/>10.10.30.210]
PVE[Proxmox VE Host<br/>10.10.30.250]
TRUENAS[TrueNAS & Media<br/>10.10.30.143]
HA[Home Assistant<br/>10.10.30.104]
subgraph K3S["Raspberry Pi K3s Cluster<br/>12 nodes"]
K3S_M[Masters]
K3S_W[Workers]
end
subgraph OBS["Observability Stack"]
GRAF[Grafana]
PROM[Prometheus]
UPTK[Uptime Kuma]
end
subgraph MEDIA["Media & Arr Suite"]
ARR[Sonarr/Radarr/etc.]
JF[Jellyfin]
end
end
User -->|"https://*.cedshomelab.com"| CF_DNS --> CF_ZT
CF_ZT --> CF_Tunnel --> NPM
NPM -->|"dashy.cedshomelab.com"| NPM
NPM -->|"pve.cedshomelab.com"| PVE
NPM -->|"truenas.cedshomelab.com"| TRUENAS
NPM -->|"ha.cedshomelab.com"| HA
NPM -->|"jellyfin.cedshomelab.com"| JF
NPM -->|"grafana.cedshomelab.com"| GRAF
NPM -->|"prometheus.cedshomelab.com"| PROM
NPM -->|"uptime.cedshomelab.com"| UPTK
NPM -->|"arr.cedshomelab.com"| ARR
PVE -.-> OBS
PVE -.-> MEDIA
PVE -.-> K3S
TRUENAS -. Storage .- PVE TRUENAS -. Storage .- PVE
TRUENAS -. Media Storage .- JF TRUENAS -. Media Storage .- JF
``` ```
--- ---
## 2. VLAN & Network Segmentation Diagram ## 🧩 2. VLAN & Network Segmentation
```mermaid ```mermaid
flowchart LR graph TD
subgraph UDR["UniFi Dream Router (UDR)"] UDR[UniFi Dream Router]
GW_MAIN["VLAN Main 10.10.10.1"]
GW_IOT["VLAN IoT 10.10.20.1"]
GW_LAB["VLAN HomeLab 10.10.30.1"]
GW_GUEST["VLAN Guest 10.10.99.1"]
end
subgraph VLAN_MAIN["Main Network 10.10.10.0/24"] MAIN[Main 10.10.10.0/24]
DEV1[Phones / Laptops / PCs] IOT[MyHomeIOT 10.10.20.0/24]
end LAB[HomeLab 10.10.30.0/24]
GUEST[Guest 10.10.99.0/24]
subgraph VLAN_IOT["MyHomeIOT 10.10.20.0/24"] DEV[User Devices]
IOT1[IoT Devices] IOTDEV[IoT Devices and TVs]
TV[Smart TVs / Consoles] LABDEV[Servers and Services]
end GDEV[Guest Devices]
subgraph VLAN_LAB["Ced's HomeLab 10.10.30.0/24"] UDR --> MAIN
PVE[Proxmox Host(s)] UDR --> IOT
NPM[Nginx Proxy Manager<br/>+ cloudflared] UDR --> LAB
TRUENAS[TrueNAS] UDR --> GUEST
HA[Home Assistant]
K3S["K3s Pi Cluster"]
OBS[Grafana / Prometheus / Uptime Kuma]
MEDIA[Arr Suite / Jellyfin]
end
subgraph VLAN_GUEST["Guest Network 10.10.99.0/24"] MAIN --> DEV
GUEST_DEV[Guest Devices] IOT --> IOTDEV
end LAB --> LABDEV
GUEST --> GDEV
UDR --- VLAN_MAIN
UDR --- VLAN_IOT
UDR --- VLAN_LAB
UDR --- VLAN_GUEST
VLAN_MAIN -->|Restricted Access| VLAN_LAB
VLAN_IOT -->|HA API Only| HA
VLAN_GUEST -->|Internet Only| UDR
VLAN_LAB -->|Cloudflare Tunnel<br/>Outbound Only| NPM
``` ```
--- ---
## 3. Request Flow Proxmox via `pve.cedshomelab.com` ## 🔄 3. Request Flow - Proxmox Access
```mermaid ```mermaid
sequenceDiagram sequenceDiagram
participant User as User Browser participant User
participant CF as Cloudflare Edge participant CF as Cloudflare
participant Tunnel as cloudflared (NPM LXC) participant Tunnel
participant NPM as Nginx Proxy Manager participant NPM
participant PVE as Proxmox (10.10.30.250:8006) participant PVE as Proxmox
User->>CF: HTTPS GET pve.cedshomelab.com User->>CF: HTTPS request for pve.cedshomelab.com
CF->>CF: DNS resolve / SSL terminate / (Zero Trust auth) CF->>Tunnel: Encrypted tunnel
CF-->>Tunnel: Encrypted Tunnel Connection Tunnel->>NPM: Forward request
Tunnel-->>NPM: HTTP request (Host: pve.cedshomelab.com) NPM->>PVE: Proxy to port 8006
NPM->>PVE: HTTPS to 10.10.30.250:8006<br/>proxy headers PVE-->>NPM: UI response
PVE-->>NPM: Proxmox login HTML NPM-->>Tunnel: Return response
NPM-->>Tunnel: Response Tunnel-->>CF: Return response
Tunnel-->>CF: Encrypted tunnel response CF-->>User: Proxmox UI
CF-->>User: HTTPS response (Proxmox UI)
``` ```
--- ---
## 4. Request Flow Home Assistant via `ha.cedshomelab.com` ## 🔄 4. Request Flow - Home Assistant
```mermaid ```mermaid
sequenceDiagram sequenceDiagram
participant User as User (Phone/Laptop) participant User
participant CF as Cloudflare Edge participant CF as Cloudflare
participant Tunnel as cloudflared (NPM LXC) participant Tunnel
participant NPM as Nginx Proxy Manager participant NPM
participant HA as Home Assistant (10.10.30.104:8123) participant HA as Home Assistant
User->>CF: HTTPS GET ha.cedshomelab.com User->>CF: HTTPS request for ha.cedshomelab.com
CF->>CF: DNS / SSL / (Zero Trust future) CF->>Tunnel: Encrypted tunnel
CF-->>Tunnel: Encrypted tunnel connection Tunnel->>NPM: Forward request
Tunnel-->>NPM: HTTP request with X-Forwarded-For NPM->>HA: Proxy to port 8123
NPM->>HA: HTTP to 10.10.30.104:8123 HA-->>NPM: UI or API response
HA->>HA: Check trusted_proxies & use_x_forwarded_for NPM-->>Tunnel: Return response
HA-->>NPM: HA UI / API response Tunnel-->>CF: Return response
NPM-->>Tunnel: Response CF-->>User: Home Assistant UI
Tunnel-->>CF: Response
CF-->>User: HTTPS response (HA UI)
``` ```
--- ---
## 5. Notes ## 🧠 Notes
- Cloudflare Zero Trust can be layered in front of any critical service. - 🌐 All external access is routed through Cloudflare Tunnel
- External entrypoint is always `*.cedshomelab.com`. - 🚫 No inbound port forwarding is required
- Only outbound traffic from the HomeLab VLAN is required. - 🔗 Services are exposed via subdomains under `cedshomelab.com`
- 🧩 VLAN segmentation reduces unnecessary lateral movement
- 🔐 Cloudflare Zero Trust can be layered on sensitive services