Bring the blackreset SOHO/homelab infrastructure to a state where every
VM, network segment, service, and access path is documented, named per the
naming convention, integrated with Authentik SSO where appropriate,
edge-fronted by Traefik with HTTPS + security headers, and backed up at the
VM-image level via PBS — respecting the hard constraint that resilience
improvements must fit on the existing two physical hosts (no new hardware).
| Area | State |
|---|---|
| Sites | Home (Proxmox active), RZ (Hetzner ESXi active), Lager (off-site, passive) |
| Hypervisors | Proxmox VE 8.4 (Home, single host), VMware ESXi 7 (RZ, legacy) |
| Routers | pfSense 2.8.1 on each site, OpenVPN site-to-site 10.233.100.0/24 |
| Identity | Authentik 2025.8.4 with OIDC + per-app group claims |
| Edge | Traefik on RZ (file + docker providers, Let's Encrypt) |
| Backup | PBS as VM on Synology DS918+ — VM-image-level recovery + per-app dumps |
| Wiki | Wiki.js 2.5.307 — replaced BookStack on 2026-04-29 |
| Media stack | Plex + Immich + Tdarr (RTX-3060 NVENC node planned) |
.254 -> .1), FW-002 (~28 disabled rules)Aktueller Zustand seit 2026-05-03 night-shift:
vm-rz-svc-prod-01 (10.200.0.101).vm-rz-db-01 (10.100.0.111); MariaDB Container daneben.vm-hm-edge-01, vm-hm-svc-prod-01, vm-hm-app-prod-01, vm-hm-db-01, vm-hm-backup-01 LIVE.Phase-0-SSH-Discovery auf Home-VMs ist abgeschlossen. Aktuelle Restarbeiten: DC-Migration finalisieren, vm-sl-{00,03,04,05,06,21}+vm-sw-03+vm-db-01 finaler Shutdown nach Karenz.