# Infrastructure Topology
A visual map of the Kaburu MSP network. Designed for: - AI models parsing the wiki (Mermaid is plain text they can read) - Steve's network ops mate taking over cold if needed - Anyone needing to understand what connects where and why
—
## Network Diagram (Mermaid)
```mermaid graph TB
INTERNET[Internet] -->|PPPoE / Static IP 49.13.202.144| HZ[Hetzner VPS<br/>kaburusvr.uk<br/>Ubuntu 24 / CyberPanel<br/>49.13.202.144]
INTERNET -->|Virgin Media 1Gbps| OP[OPNsense Firewall<br/>192.168.0.1<br/>FreeBSD]
OP -->|Mullvad VPN<br/>WireGuard tunnel| INTERNET OP -->|LAN 192.168.0.0/24| Z840[kaburuaibox<br/>HP Z840 Workstation<br/>192.168.0.253] OP -->|LAN 192.168.0.0/24| UV[ubuntu-svr<br/>Mini PC<br/>192.168.0.252] OP -->|LAN 192.168.0.0/24| TN[TrueNAS SCALE<br/>HP MicroServer Gen8<br/>192.168.0.251]
subgraph TAILSCALE_MESH["Tailscale Mesh 100.x.x.x"]
HZ_TS[kaburusvr<br/>100.112.54.2]
Z840_TS[kaburuaibox<br/>100.120.18.44]
UV_TS[ubuntu-svr<br/>100.101.7.86]
OP_TS[OPNsense<br/>100.127.64.74]
end
HZ_TS <-->|Tailscale SSH + WP-CLI| Z840_TS HZ_TS ~~~|Tailscale blocked| TN
Z840_TS -.->|Tailscale SSH<br/>LAN preferred| UV_TS Z840_TS -.->|Tailscale SSH<br/>ACL blocked| TN
Z840 -->|SSH ~/.ssh/id_ed256| UV Z840 -->|SSH /opt/hermes/config/<br/>hetzner_id_ed25519| HZ Z840 -->|SSH ~/.ssh/id_ed256| TN UV -->|Coral TPU passthrough| TN
```
—
## Node Roles
| Node | IPs | Role | What runs here |
| —— | —– | —— | —————- |
| OPNsense | 192.168.0.1 / 100.127.64.74 | Firewall + Router + VPN | DHCP, DNS (dnsmasq), Mullvad VPN, Tailscale, SNMP traps |
| kaburuaibox (Z840) | 192.168.0.253 / 100.120.18.44 | AI + Automation | Hermes Agent, llama-server, Ollama, Immich, ComfyUI, Portainer |
| kaburusvr (Hetzner) | 49.13.202.144 / 100.112.54.2 | Web Hosting | CyberPanel, 22 WordPress sites, MainWP, Matomo, Fusion Invoice, Postfix, Docker |
| ubuntu-svr | 192.168.0.252 / 100.101.7.86 | Surveillance + Network | Frigate NVR, Omada Controller, Coral TPU |
| TrueNAS | 192.168.0.251 / 100.74.178.14 | Storage + Backups | ZFS pools, NFS/SMB shares, backup targets |
—
## Access Summary
| Target | Via LAN | Via Tailscale | Credentials |
| ——– | ——— | ————— | ————- |
| OPNsense | Web UI 192.168.0.1 | N/A (SSH disabled) | API: opnsense MCP tools |
| kaburuaibox | `ssh [email protected]` | `ssh [email protected]` | Local user - no key needed |
| kaburusvr (Hetzner) | N/A | `ssh [email protected]` with `hetzner_id_ed25519` | Key: /opt/hermes/config/ |
| ubuntu-svr | `ssh [email protected]` with `id_ed256` | `ssh [email protected]` with `id_ed256` | Key: ~/.ssh/id_ed256 |
| TrueNAS | `ssh [email protected]` with `id_ed256` | ❌ Tailscale ACL blocked | Key: ~/.ssh/id_ed256 |
⚠️ Critical rules: - OPNsense NEVER responds to ping — intentional - TrueNAS is LAN-only — Tailscale ACL blocks kaburuaibox → TrueNAS - Never SSH as root to ubuntu-svr or TrueNAS - SSH from LAN to internet is blocked by OPNsense — use Tailscale for external access
—
## Network Topology Details
### Internet Connectivity - Primary: Virgin Media 1Gbps → OPNsense PPPoE - Hetzner: Direct internet via 49.13.202.144 (routed through Cloudflare for HTTP/S) - VPN: Mullvad WireGuard tunnel on OPNsense for privacy/exit
### LAN (192.168.0.0/24) - OPNsense is DHCP server and local DNS (dnsmasq) - All local servers have static DHCP leases - No WiFi — everything wired - Outbound SSH to internet is blocked by firewall policy
### Tailscale (100.x.x.x) - Mesh VPN connecting all nodes - Primary use: secure access from kaburuaibox to Hetzner and off-LAN access - ACLs restrict TrueNAS access to SSH port 22 only
—
## Service Map
### kaburuaibox (Z840) — 192.168.0.253
| Service | Port | Notes |
| ——— | —— | ——- |
| llama-server (qwen36-reap, glm47-reap) | 11440, 8787 | LLM inference, OpenAI-compatible API |
| Ollama | 11434 | Additional models |
| Hermes Agent (NousResearch) | 8642 (API), 9119 (UI) | Infrastructure AI agent |
| Hermes Docker Agent | Docker stack | Monitoring + Telegram alerts |
| Immich | 2283 | Photo management |
| ComfyUI | 8188 | Image generation |
| Portainer CE | 9443 (HTTPS) | Docker management |
### kaburusvr.uk (Hetzner) — 49.13.202.144
| Service | Port | Notes |
| ——— | —— | ——- |
| CyberPanel (LiteSpeed) | 8090, 443, 80 | Web hosting control panel |
| 22 WordPress sites | 443 | Client sites, all behind Cloudflare |
| MainWP Dashboard | 443 | WordPress network management |
| Matomo Analytics | 443 | stats.kaburu.co — 18 sites tracked |
| Fusion Invoice | 443 | invoice.kaburu.co — billing |
| Postfix / Dovecot | 25, 587, 993 | Email — mail.kaburu.cc |
| RustDesk (Docker) | hbbs/hbbr | Remote desktop relay |
| MariaDB | 3306 (local) | All WordPress databases |
### ubuntu-svr — 192.168.0.252
| Service | Notes |
| ——— | ——- |
| Frigate NVR | Camera surveillance with Coral TPU |
| Omada Controller | TP-Link network management |
### TrueNAS — 192.168.0.251
| Service | Notes |
| ——— | ——- |
| ZFS pools | Main storage pool: kaburudata |
| SMB / NFS | Network shares for backups |
| Backup target | Wiki backups, system backups |
—
## Backup Flow ``` kaburuaibox → Hetzner (daily rsync of sites) Hetzner → TrueNAS (daily ZFS send) Wiki → git (local) + TrueNAS (nightly age-encrypted archive) kaburuaibox config → TrueNAS NFS share ```
—
## Emergency Contacts
| Service | Contact | Account |
| ——— | ——— | ——— |
| Hetzner | Hetzner Robot / Cloud Console | Email on file |
| Cloudflare | dashboard.cloudflare.com | [email protected] |
| Brevo (email) | smtp-relay.brevo.com | [email protected] |
| Virgin Media | Account holder | Steve |
| Namecheap (DNS exit pending) | namecheap.com | — |
| Chemicloud (exit Sept 2026) | dashboard.chemicloud.com | — |
—
## Single Points of Failure
| What | Risk | Mitigation |
| —— | —— | ———— |
| OPNsense | Entire LAN goes down if it fails | Keep spare config backup |
| Virgin Media | Internet down | Mullvad VPN exit (still need Virgin for transport) |
| kaburuaibox | Hermes + AI + Immich down | All in one box, no HA |
| TrueNAS | All backups lost | Wiki is git-pushed, configs are scattered |
—
## Related Pages
- kaburusvr — Hetzner server details - z840 — kaburuaibox specs and services - truenas — Storage pool layout - ubuntu-svr — Frigate/Omada details - opnsense — Firewall rules - tailscale — Mesh VPN config - credentials — API tokens and keys - hermes — Agent documentation - snmp — Monitoring traps