BYTEGEIST / CONTROL PLANE
INFRASTRUCTURE NOMINAL
--:--:-- AMERICA / NEW YORK
OVERVIEW / LIVE UPDATED 00s AGO

SELF-HOSTED INFRASTRUCTURE ENVIRONMENT

Personal cloud.
Operational by design.

A working infrastructure lab for identity, observability, delivery, security, and recovery. Built and maintained as an evolving system—not a static demo.

SERVICES ONLINE 20/ 20
UPTIME 99.98%

30 DAY WINDOW

CONTAINERS 26

26 RUNNING / 0 DEGRADED

ACTIVE DOMAINS 11

TLS VALID / PROXIED

CPU LOAD 16.2%
MEMORY 61.6%
GRAFANA / BYTEGEIST OPERATIONS FULL RES ↗
Grafana operations dashboard showing ByteGeist infrastructure health
SYS.01

Infrastructure topology

Traffic, identity, workloads, telemetry, and recovery paths on the current host.

DOCUMENTED
EDGE Nginx Proxy Manager TLS termination / routing
IDENTITY Authentik OIDC / SSO / 2FA
COMPUTE Docker Compose 26 active containers
TELEMETRY Prometheus + Loki Metrics / logs / alerts
ByteGeist infrastructure architecture diagram
BYTEGEIST-CLOUD / REV 04 SELECT DIAGRAM TO INSPECT
OBS.02

Monitoring stack

Host metrics, container telemetry, centralized logs, and independent uptime checks.

COVERAGE ACTIVE
LOG PIPELINE Loki / Grafana Alloy Container output searchable by service and host
Centralized logs in Grafana
MONITORING COVERAGE6 / 6
  • Host metricsACTIVE
  • Container metricsACTIVE
  • Application logsACTIVE
  • Endpoint uptimeACTIVE
  • Resource alertsACTIVE
  • Security eventsACTIVE
GrafanaPrometheusLoki AlloyNode ExportercAdvisor
APP.03

Service inventory

Core applications currently exposed through the internal service portal.

20 ONLINE
ServiceRoleAccessState
GiteaSource controlSSOONLINE
Wiki.jsDocumentationSSOONLINE
DashyService portalSSOONLINE
VaultwardenSecretsDIRECTONLINE
Stirling PDFDocument toolsSSOONLINE
IT ToolsUtilitiesSSOONLINE
Uptime KumaAvailabilitySSOONLINE
SERVICE PORTAL Dashy / internal access layer
ByteGeist Dashy service portal
DEV.04

Delivery pipeline

Git-based workflows from repository change to automated deployment.

LAST RUN PASSED
01COMMITGitea repository
02BUILDWoodpecker runner
03VERIFYStatic checks
04DEPLOYDocker host
GITEA / REPOSITORIES
Gitea repositories dashboard
WOODPECKER / PIPELINE
Successful Woodpecker CI pipeline
SEC.05

Identity & perimeter

Central authentication, protected services, and automated hostile-traffic decisions.

ENFORCING
AUTHENTIK 11 protected applications / 2FA enforced
Applications protected by Authentik
ACCESS POSTURE HARDENED KEY-ONLY SSH / SSO / TLS
  • OIDC providers04
  • Forward-auth apps07
  • 2FA policyENFORCED
  • Public SSH passwordDISABLED
CROWDSEC / ACTIVE DECISIONS Automated hostile source blocking
CrowdSec active firewall decisions
DR.06

Recovery state

Configuration in Git, persistent data backups, and an explicit rebuild sequence.

RUNBOOK CURRENT
01Provision hostUbuntu / firewall / SSH
02Restore configGit / Compose / secrets
03Restore dataVolumes / databases
04Validate edgeDNS / TLS / identity
ByteGeist disaster recovery runbook