[main]: Add server-notes
This commit is contained in:
18 files changed
+1406
-1
No files matched your search
@@ -0,0 +1,75 @@
|
||||
---
|
||||
schema_version: 1
|
||||
id: home-server.mercury
|
||||
type: reference
|
||||
scope: [mercury, vps, hosting, nginx, wireguard, firewall]
|
||||
sensitivity: private-infrastructure
|
||||
last_reviewed: "2026-10-06"
|
||||
sources:
|
||||
- kind: owner-report
|
||||
reference: "Fasthosts plan, fastfetch, nginx sites, iptables and fail2ban output, 2026-10-06"
|
||||
- kind: owner-report
|
||||
reference: "nginx/WireGuard apt management and public IPv4/CGNAT rationale, 2026-10-06"
|
||||
related: [home-server.reference, home-server.host, home-server.networking, home-server.operations]
|
||||
update_triggers: [hosting-renewal, vps-resize, os-upgrade, proxy-change, firewall-change, certificate-change]
|
||||
unknowns:
|
||||
- renewal-price-and-renewal-date
|
||||
- creation-timestamp-timezone
|
||||
- certificate-renewal-method
|
||||
- wireguard-allowedips-and-keepalive
|
||||
- backup-and-restore-policy
|
||||
---
|
||||
|
||||
# Mercury VPS
|
||||
|
||||
## Host / subscription
|
||||
|
||||
| Field | Configuration |
|
||||
| --- | --- |
|
||||
| Provider | [Fasthosts](https://www.fasthosts.co.uk/); UK data centre |
|
||||
| Role / OS hostname | Mercury / `my-vps` |
|
||||
| Plan | `1-1-10`; KVM virtual machine |
|
||||
| CPU | 1 vCore; reported AMD EPYC-Milan @ 2.00 GHz |
|
||||
| RAM | 1 GB plan; guest reports 864.37 MiB |
|
||||
| Disk | 10 GB NVMe SSD plan; guest root ext4, 9.64 GiB |
|
||||
| OS | Debian GNU/Linux 13 (trixie); x86_64 |
|
||||
| Kernel | `6.12.85+deb13-amd64` |
|
||||
| Swap | Disabled |
|
||||
| Public interface | `ens6`; `185.230.217.66/32` |
|
||||
| WireGuard | Server `10.0.0.1/24`; Jupiter peer `10.0.0.2/24` |
|
||||
| Created | `2026-03-01 20:48:51`; timezone unconfirmed |
|
||||
| Payment | GBP 10.00 prepaid for one year; renewal terms unconfirmed |
|
||||
|
||||
Capacities distinguish provider allocation from guest-visible values.
|
||||
|
||||
## Ingress
|
||||
|
||||
nginx runs directly in the VM, not in Docker; nginx and WireGuard are
|
||||
apt-managed. Mercury provides static public IPv4 ingress because Jupiter's
|
||||
home connection uses CGNAT. Residential-IP exposure is avoided by design.
|
||||
|
||||
| Hostname | Upstream |
|
||||
| --- | --- |
|
||||
| `umbra.mom`, `*.umbra.mom` | `https://10.0.0.2:443` over WireGuard |
|
||||
| `gitea.umbra.mom` | Same; dedicated registry location `/v2/` |
|
||||
| `john.gatward.dev`, `samstoreymusic.com` | `https://10.0.0.2:443` |
|
||||
| `uptime.umbra.mom` | `http://127.0.0.1:3001` |
|
||||
|
||||
- HTTP -> HTTPS: `301`; unmatched default server: `418`.
|
||||
- TLS terminates at nginx; upstream HTTPS terminates again at Jupiter Traefik.
|
||||
- Upstream certificate verification disabled: `proxy_ssl_verify off`.
|
||||
- Certificates: `/etc/letsencrypt/live/<domain>/{fullchain.pem,privkey.pem}`;
|
||||
`umbra.mom` certificate also serves its subdomains.
|
||||
- Preserves `Host`; sets `X-Real-IP`, `X-Forwarded-For`, `X-Forwarded-Proto`;
|
||||
forwards WebSocket upgrade headers.
|
||||
- Gitea `/v2/`: unlimited request body; proxy timeouts `900s`.
|
||||
|
||||
## Firewall / fail2ban
|
||||
|
||||
- UFW-managed iptables: INPUT/FORWARD `DROP`; OUTPUT `ACCEPT`.
|
||||
- UFW allows TCP `22,80,443`; UDP `80,443,51820`.
|
||||
- Docker forwarding has separate rules; INPUT policy alone does not define
|
||||
container exposure.
|
||||
- Fail2ban jails: `nginx-botsearch`, `nginx-http-auth`, `sshd`.
|
||||
|
||||
Rules and versions are supplied snapshots, not live inspection.
|
||||
Reference in new issue
Block a user