Client cloudflared transports SSH through Cloudflare; Jupiter's connector opens
the outbound tunnel. Origins still perform SSH authentication. No Mercury,
WireGuard, or Traefik hop on this path; no home-router port forwarding.
Ingress hostname
Origin
Client SSH user
ssh.umbra.mom
ssh://192.168.1.56:22
jay
git.umbra.mom
ssh://192.168.1.56:2222
git
Unmatched
http_status:404
N/A
Both client configurations use IdentityFile ~/.ssh/id_ed25519.
Host jupiter
User jay
IdentityFile ~/.ssh/id_ed25519
ProxyCommand cloudflared access ssh --hostname ssh.umbra.mom
Host git.umbra.mom
User git
IdentityFile ~/.ssh/id_ed25519
ProxyCommand cloudflared access ssh --hostname %h
Local tunnel configuration is separate from Cloudflare Access applications.
Access login/provider/allow rules remain unconfirmed; ProxyCommand alone
does not establish enforcement.
Ingress source: host /data/cloudflared/config.yaml, mounted at
/etc/cloudflared/config.yaml.
DNS / routes
DNS / route
Destination
Public service ingress
Mercury 185.230.217.66
jellyfin.local.umbra.mom
Jupiter 192.168.1.56
bookshelf.local.umbra.mom
Jupiter 192.168.1.56
ssh.umbra.mom, git.umbra.mom
Cloudflare Tunnel
uptime.umbra.mom
Mercury nginx -> http://127.0.0.1:3001
Mercury
Mercury VPS: native nginx; WireGuard server 10.0.0.1/24;
Jupiter client 10.0.0.2/24. Hosting, TLS, firewall and fail2ban details are
maintained on that page.
Home ISP uses CGNAT. Mercury supplies a static public IPv4 and forwards over
WireGuard; owner preference is to avoid public ingress via the residential IP.
Observed Docker networks
Snapshot from supplied inspection, not fixed-address configuration. Container
IPs may change; use Docker service names.
Network
IPv4 subnet
Internal
Observed role
traefik
172.18.0.0/16
No
Reverse proxy and application ingress
gitea_network
172.23.0.0/16
No
Gitea, runner, notes builder, Havox sync
cloudflared_cloudflare
172.26.0.0/16
No
Tunnel connector
gitea_data
192.168.96.0/20
Yes
Gitea and PostgreSQL
paperless_data
192.168.112.0/20
Yes
Paperless, PostgreSQL, Redis
dozzle_dozzle
172.27.0.0/16
Yes
Dozzle and socket proxy
Cloudflared's observed 172.26.0.2 matches the supplied proxied SSH login source.
An internal network alone does not isolate a multi-network container from
egress through its other networks. Empty network entries do not establish
whether they are obsolete or safe to remove.
Jupiter: repository configuration
Traefik publishes TCP 80,443; HTTP redirects to HTTPS.