--- schema_version: 1 id: home-server.mercury type: reference scope: [mercury, vps, hosting, nginx, wireguard, firewall] sensitivity: private-infrastructure last_reviewed: "2026-10-06" sources: - kind: owner-report reference: "Fasthosts plan, fastfetch, nginx sites, iptables and fail2ban output, 2026-10-06" - kind: owner-report reference: "nginx/WireGuard apt management and public IPv4/CGNAT rationale, 2026-10-06" related: [home-server.reference, home-server.host, home-server.networking, home-server.operations] update_triggers: [hosting-renewal, vps-resize, os-upgrade, proxy-change, firewall-change, certificate-change] unknowns: - renewal-price-and-renewal-date - creation-timestamp-timezone - certificate-renewal-method - wireguard-allowedips-and-keepalive - backup-and-restore-policy --- # Mercury VPS ## Host / subscription | Field | Configuration | | --- | --- | | Provider | [Fasthosts](https://www.fasthosts.co.uk/); UK data centre | | Role / OS hostname | Mercury / `my-vps` | | Plan | `1-1-10`; KVM virtual machine | | CPU | 1 vCore; reported AMD EPYC-Milan @ 2.00 GHz | | RAM | 1 GB plan; guest reports 864.37 MiB | | Disk | 10 GB NVMe SSD plan; guest root ext4, 9.64 GiB | | OS | Debian GNU/Linux 13 (trixie); x86_64 | | Kernel | `6.12.85+deb13-amd64` | | Swap | Disabled | | Public interface | `ens6`; `185.230.217.66/32` | | WireGuard | Server `10.0.0.1/24`; Jupiter peer `10.0.0.2/24` | | Created | `2026-03-01 20:48:51`; timezone unconfirmed | | Payment | GBP 10.00 prepaid for one year; renewal terms unconfirmed | Capacities distinguish provider allocation from guest-visible values. ## Ingress nginx runs directly in the VM, not in Docker; nginx and WireGuard are apt-managed. Mercury provides static public IPv4 ingress because Jupiter's home connection uses CGNAT. Residential-IP exposure is avoided by design. | Hostname | Upstream | | --- | --- | | `umbra.mom`, `*.umbra.mom` | `https://10.0.0.2:443` over WireGuard | | `gitea.umbra.mom` | Same; dedicated registry location `/v2/` | | `john.gatward.dev`, `samstoreymusic.com` | `https://10.0.0.2:443` | | `uptime.umbra.mom` | `http://127.0.0.1:3001` | - HTTP -> HTTPS: `301`; unmatched default server: `418`. - TLS terminates at nginx; upstream HTTPS terminates again at Jupiter Traefik. - Upstream certificate verification disabled: `proxy_ssl_verify off`. - Certificates: `/etc/letsencrypt/live//{fullchain.pem,privkey.pem}`; `umbra.mom` certificate also serves its subdomains. - Preserves `Host`; sets `X-Real-IP`, `X-Forwarded-For`, `X-Forwarded-Proto`; forwards WebSocket upgrade headers. - Gitea `/v2/`: unlimited request body; proxy timeouts `900s`. ## Firewall / fail2ban - UFW-managed iptables: INPUT/FORWARD `DROP`; OUTPUT `ACCEPT`. - UFW allows TCP `22,80,443`; UDP `80,443,51820`. - Docker forwarding has separate rules; INPUT policy alone does not define container exposure. - Fail2ban jails: `nginx-botsearch`, `nginx-http-auth`, `sshd`. Rules and versions are supplied snapshots, not live inspection.