← Back to SRE lab SRE lab / 002

A small system,
deliberately drawn.

A map of how this website moves from a public request to private services, and where the boundaries are designed to hold.

Network topology / 10 nodes · 4 zones
probed livestatic layer
HTTPS · TLS 1.3 · DNS proxied
Outbound QUIC tunnel · no inbound ports
Published loopback · 127.0.0.1:8000
Selected layer / browser

Visitor browser

Any client on the internet. Requests are ordinary HTTPS with no secrets at the edge; the public surface is assumed hostile and stays behind Cloudflare.

connectionsDNS + TLS
protocolHTTPS
port443
tlsTLS 1.3
static layer · not probed
zonePublic internet
Operating principlesDesigned boundaries
01

Public by choice

The frontend is public. Backend health is deliberately reduced to a small, sanitized contract.

02

Private by default

Immich and homelab services stay on the private network; the dashboard does not become an application gateway.

03

Recoverable

Services are independently managed by systemd, with persistent data isolated from disposable containers.