A map of how this website moves from a public request to private services, and where the boundaries are designed to hold.
Network topology / 10 nodes · 4 zones
probed livestatic layer
HTTPS · TLS 1.3 · DNS proxied
Outbound QUIC tunnel · no inbound ports
Published loopback · 127.0.0.1:8000
Selected layer / browser
Visitor browser
Any client on the internet. Requests are ordinary HTTPS with no secrets at the edge; the public surface is assumed hostile and stays behind Cloudflare.
connectionsDNS + TLS
protocolHTTPS
port443
tlsTLS 1.3
static layer · not probed
zonePublic internet
Operating principlesDesigned boundaries
01
Public by choice
The frontend is public. Backend health is deliberately reduced to a small, sanitized contract.
02
Private by default
Immich and homelab services stay on the private network; the dashboard does not become an application gateway.
03
Recoverable
Services are independently managed by systemd, with persistent data isolated from disposable containers.