Files
2026-10-06 16:33:29 +01:00

3.0 KiB

schema_version, id, type, scope, sensitivity, last_reviewed, sources, related, update_triggers, unknowns
schema_version id type scope sensitivity last_reviewed sources related update_triggers unknowns
1 home-server.mercury reference
mercury
vps
hosting
nginx
wireguard
firewall
private-infrastructure 2026-10-06
kind reference
owner-report Fasthosts plan, fastfetch, nginx sites, iptables and fail2ban output, 2026-10-06
kind reference
owner-report nginx/WireGuard apt management and public IPv4/CGNAT rationale, 2026-10-06
home-server.reference
home-server.host
home-server.networking
home-server.operations
hosting-renewal
vps-resize
os-upgrade
proxy-change
firewall-change
certificate-change
renewal-price-and-renewal-date
creation-timestamp-timezone
certificate-renewal-method
wireguard-allowedips-and-keepalive
backup-and-restore-policy

Mercury VPS

Host / subscription

Field Configuration
Provider Fasthosts; UK data centre
Role / OS hostname Mercury / my-vps
Plan 1-1-10; KVM virtual machine
CPU 1 vCore; reported AMD EPYC-Milan @ 2.00 GHz
RAM 1 GB plan; guest reports 864.37 MiB
Disk 10 GB NVMe SSD plan; guest root ext4, 9.64 GiB
OS Debian GNU/Linux 13 (trixie); x86_64
Kernel 6.12.85+deb13-amd64
Swap Disabled
Public interface ens6; 185.230.217.66/32
WireGuard Server 10.0.0.1/24; Jupiter peer 10.0.0.2/24
Created 2026-03-01 20:48:51; timezone unconfirmed
Payment GBP 10.00 prepaid for one year; renewal terms unconfirmed

Capacities distinguish provider allocation from guest-visible values.

Ingress

nginx runs directly in the VM, not in Docker; nginx and WireGuard are apt-managed. Mercury provides static public IPv4 ingress because Jupiter's home connection uses CGNAT. Residential-IP exposure is avoided by design.

Hostname Upstream
umbra.mom, *.umbra.mom https://10.0.0.2:443 over WireGuard
gitea.umbra.mom Same; dedicated registry location /v2/
john.gatward.dev, samstoreymusic.com https://10.0.0.2:443
uptime.umbra.mom http://127.0.0.1:3001
  • HTTP -> HTTPS: 301; unmatched default server: 418.
  • TLS terminates at nginx; upstream HTTPS terminates again at Jupiter Traefik.
  • Upstream certificate verification disabled: proxy_ssl_verify off.
  • Certificates: /etc/letsencrypt/live/<domain>/{fullchain.pem,privkey.pem}; umbra.mom certificate also serves its subdomains.
  • Preserves Host; sets X-Real-IP, X-Forwarded-For, X-Forwarded-Proto; forwards WebSocket upgrade headers.
  • Gitea /v2/: unlimited request body; proxy timeouts 900s.

Firewall / fail2ban

  • UFW-managed iptables: INPUT/FORWARD DROP; OUTPUT ACCEPT.
  • UFW allows TCP 22,80,443; UDP 80,443,51820.
  • Docker forwarding has separate rules; INPUT policy alone does not define container exposure.
  • Fail2ban jails: nginx-botsearch, nginx-http-auth, sshd.

Rules and versions are supplied snapshots, not live inspection.