[main]: Add server-notes

This commit is contained in:
John Gatward committed 2026-10-06 16:33:29 +01:00
1 parent 68a3130159
commit 81b43de3f1
18 files changed
+1406 -1

No files matched your search

+75
View File
@@ -0,0 +1,75 @@
---
schema_version: 1
id: home-server.mercury
type: reference
scope: [mercury, vps, hosting, nginx, wireguard, firewall]
sensitivity: private-infrastructure
last_reviewed: "2026-10-06"
sources:
- kind: owner-report
reference: "Fasthosts plan, fastfetch, nginx sites, iptables and fail2ban output, 2026-10-06"
- kind: owner-report
reference: "nginx/WireGuard apt management and public IPv4/CGNAT rationale, 2026-10-06"
related: [home-server.reference, home-server.host, home-server.networking, home-server.operations]
update_triggers: [hosting-renewal, vps-resize, os-upgrade, proxy-change, firewall-change, certificate-change]
unknowns:
- renewal-price-and-renewal-date
- creation-timestamp-timezone
- certificate-renewal-method
- wireguard-allowedips-and-keepalive
- backup-and-restore-policy
---
# Mercury VPS
## Host / subscription
| Field | Configuration |
| --- | --- |
| Provider | [Fasthosts](https://www.fasthosts.co.uk/); UK data centre |
| Role / OS hostname | Mercury / `my-vps` |
| Plan | `1-1-10`; KVM virtual machine |
| CPU | 1 vCore; reported AMD EPYC-Milan @ 2.00 GHz |
| RAM | 1 GB plan; guest reports 864.37 MiB |
| Disk | 10 GB NVMe SSD plan; guest root ext4, 9.64 GiB |
| OS | Debian GNU/Linux 13 (trixie); x86_64 |
| Kernel | `6.12.85+deb13-amd64` |
| Swap | Disabled |
| Public interface | `ens6`; `185.230.217.66/32` |
| WireGuard | Server `10.0.0.1/24`; Jupiter peer `10.0.0.2/24` |
| Created | `2026-03-01 20:48:51`; timezone unconfirmed |
| Payment | GBP 10.00 prepaid for one year; renewal terms unconfirmed |
Capacities distinguish provider allocation from guest-visible values.
## Ingress
nginx runs directly in the VM, not in Docker; nginx and WireGuard are
apt-managed. Mercury provides static public IPv4 ingress because Jupiter's
home connection uses CGNAT. Residential-IP exposure is avoided by design.
| Hostname | Upstream |
| --- | --- |
| `umbra.mom`, `*.umbra.mom` | `https://10.0.0.2:443` over WireGuard |
| `gitea.umbra.mom` | Same; dedicated registry location `/v2/` |
| `john.gatward.dev`, `samstoreymusic.com` | `https://10.0.0.2:443` |
| `uptime.umbra.mom` | `http://127.0.0.1:3001` |
- HTTP -> HTTPS: `301`; unmatched default server: `418`.
- TLS terminates at nginx; upstream HTTPS terminates again at Jupiter Traefik.
- Upstream certificate verification disabled: `proxy_ssl_verify off`.
- Certificates: `/etc/letsencrypt/live/<domain>/{fullchain.pem,privkey.pem}`;
`umbra.mom` certificate also serves its subdomains.
- Preserves `Host`; sets `X-Real-IP`, `X-Forwarded-For`, `X-Forwarded-Proto`;
forwards WebSocket upgrade headers.
- Gitea `/v2/`: unlimited request body; proxy timeouts `900s`.
## Firewall / fail2ban
- UFW-managed iptables: INPUT/FORWARD `DROP`; OUTPUT `ACCEPT`.
- UFW allows TCP `22,80,443`; UDP `80,443,51820`.
- Docker forwarding has separate rules; INPUT policy alone does not define
container exposure.
- Fail2ban jails: `nginx-botsearch`, `nginx-http-auth`, `sshd`.
Rules and versions are supplied snapshots, not live inspection.