3.0 KiB
3.0 KiB
schema_version, id, type, scope, sensitivity, last_reviewed, sources, related, update_triggers, unknowns
| schema_version | id | type | scope | sensitivity | last_reviewed | sources | related | update_triggers | unknowns | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | home-server.mercury | reference |
|
private-infrastructure | 2026-10-06 |
|
|
|
|
Mercury VPS
Host / subscription
| Field | Configuration |
|---|---|
| Provider | Fasthosts; UK data centre |
| Role / OS hostname | Mercury / my-vps |
| Plan | 1-1-10; KVM virtual machine |
| CPU | 1 vCore; reported AMD EPYC-Milan @ 2.00 GHz |
| RAM | 1 GB plan; guest reports 864.37 MiB |
| Disk | 10 GB NVMe SSD plan; guest root ext4, 9.64 GiB |
| OS | Debian GNU/Linux 13 (trixie); x86_64 |
| Kernel | 6.12.85+deb13-amd64 |
| Swap | Disabled |
| Public interface | ens6; 185.230.217.66/32 |
| WireGuard | Server 10.0.0.1/24; Jupiter peer 10.0.0.2/24 |
| Created | 2026-03-01 20:48:51; timezone unconfirmed |
| Payment | GBP 10.00 prepaid for one year; renewal terms unconfirmed |
Capacities distinguish provider allocation from guest-visible values.
Ingress
nginx runs directly in the VM, not in Docker; nginx and WireGuard are apt-managed. Mercury provides static public IPv4 ingress because Jupiter's home connection uses CGNAT. Residential-IP exposure is avoided by design.
| Hostname | Upstream |
|---|---|
umbra.mom, *.umbra.mom |
https://10.0.0.2:443 over WireGuard |
gitea.umbra.mom |
Same; dedicated registry location /v2/ |
john.gatward.dev, samstoreymusic.com |
https://10.0.0.2:443 |
uptime.umbra.mom |
http://127.0.0.1:3001 |
- HTTP -> HTTPS:
301; unmatched default server:418. - TLS terminates at nginx; upstream HTTPS terminates again at Jupiter Traefik.
- Upstream certificate verification disabled:
proxy_ssl_verify off. - Certificates:
/etc/letsencrypt/live/<domain>/{fullchain.pem,privkey.pem};umbra.momcertificate also serves its subdomains. - Preserves
Host; setsX-Real-IP,X-Forwarded-For,X-Forwarded-Proto; forwards WebSocket upgrade headers. - Gitea
/v2/: unlimited request body; proxy timeouts900s.
Firewall / fail2ban
- UFW-managed iptables: INPUT/FORWARD
DROP; OUTPUTACCEPT. - UFW allows TCP
22,80,443; UDP80,443,51820. - Docker forwarding has separate rules; INPUT policy alone does not define container exposure.
- Fail2ban jails:
nginx-botsearch,nginx-http-auth,sshd.
Rules and versions are supplied snapshots, not live inspection.