Pangolin Edge
Public front door: TLS, login, route-by-name, site-mesh endpoint. All public traffic passes through here.
Every box in the lab — role, software, data, failure mode, backup role. Hardware specs TBD until sized.
Identity, TLS, routing, and the public-internet devices that reach the lab through the edge.
Public front door: TLS, login, route-by-name, site-mesh endpoint. All public traffic passes through here.
Public-internet devices (phones, laptops). Untrusted endpoints — access only via authenticated sessions at the edge; the edge is the trust boundary.
Workloads. Their data lives on storage — see the “stores on” line on each card.
Deploy platform for public side projects: git-deploy, databases, built-in backups.
Google Photos alternative — single primary instance, family sync, ML search. Public URL gated by Google OAuth2 SSO at the edge; data stored on NAS 1.
ZFS pools. Passive units run nothing but SSH (restic targets). NAS 1 shares hardware with compute under Option A.
The active storage unit in Istanbul — the ZFS pool holding the live photo library, databases, and app volumes. Shares hardware with the compute services under Option A.
Local mirror for fast recovery — LAN-speed restores in hours.
First offsite copy — the disaster-recovery leg, at brother’s place in Tallinn.
Second offsite copy, synced locally in Tallinn — zero Istanbul upload bandwidth.
The router, the site mesh, and the single inbound path.
The only inbound path into the lab: forwards 443 + WireGuard UDP to the Pangolin edge. Nothing else exposed.
Site-to-site link Istanbul ⇄ Tallinn. One tool covers edge + mesh (no Headscale).