76 lines
3.0 KiB
Markdown
76 lines
3.0 KiB
Markdown
---
|
|
schema_version: 1
|
|
id: home-server.mercury
|
|
type: reference
|
|
scope: [mercury, vps, hosting, nginx, wireguard, firewall]
|
|
sensitivity: private-infrastructure
|
|
last_reviewed: "2026-10-06"
|
|
sources:
|
|
- kind: owner-report
|
|
reference: "Fasthosts plan, fastfetch, nginx sites, iptables and fail2ban output, 2026-10-06"
|
|
- kind: owner-report
|
|
reference: "nginx/WireGuard apt management and public IPv4/CGNAT rationale, 2026-10-06"
|
|
related: [home-server.reference, home-server.host, home-server.networking, home-server.operations]
|
|
update_triggers: [hosting-renewal, vps-resize, os-upgrade, proxy-change, firewall-change, certificate-change]
|
|
unknowns:
|
|
- renewal-price-and-renewal-date
|
|
- creation-timestamp-timezone
|
|
- certificate-renewal-method
|
|
- wireguard-allowedips-and-keepalive
|
|
- backup-and-restore-policy
|
|
---
|
|
|
|
# Mercury VPS
|
|
|
|
## Host / subscription
|
|
|
|
| Field | Configuration |
|
|
| --- | --- |
|
|
| Provider | [Fasthosts](https://www.fasthosts.co.uk/); UK data centre |
|
|
| Role / OS hostname | Mercury / `my-vps` |
|
|
| Plan | `1-1-10`; KVM virtual machine |
|
|
| CPU | 1 vCore; reported AMD EPYC-Milan @ 2.00 GHz |
|
|
| RAM | 1 GB plan; guest reports 864.37 MiB |
|
|
| Disk | 10 GB NVMe SSD plan; guest root ext4, 9.64 GiB |
|
|
| OS | Debian GNU/Linux 13 (trixie); x86_64 |
|
|
| Kernel | `6.12.85+deb13-amd64` |
|
|
| Swap | Disabled |
|
|
| Public interface | `ens6`; `185.230.217.66/32` |
|
|
| WireGuard | Server `10.0.0.1/24`; Jupiter peer `10.0.0.2/24` |
|
|
| Created | `2026-03-01 20:48:51`; timezone unconfirmed |
|
|
| Payment | GBP 10.00 prepaid for one year; renewal terms unconfirmed |
|
|
|
|
Capacities distinguish provider allocation from guest-visible values.
|
|
|
|
## Ingress
|
|
|
|
nginx runs directly in the VM, not in Docker; nginx and WireGuard are
|
|
apt-managed. Mercury provides static public IPv4 ingress because Jupiter's
|
|
home connection uses CGNAT. Residential-IP exposure is avoided by design.
|
|
|
|
| Hostname | Upstream |
|
|
| --- | --- |
|
|
| `umbra.mom`, `*.umbra.mom` | `https://10.0.0.2:443` over WireGuard |
|
|
| `gitea.umbra.mom` | Same; dedicated registry location `/v2/` |
|
|
| `john.gatward.dev`, `samstoreymusic.com` | `https://10.0.0.2:443` |
|
|
| `uptime.umbra.mom` | `http://127.0.0.1:3001` |
|
|
|
|
- HTTP -> HTTPS: `301`; unmatched default server: `418`.
|
|
- TLS terminates at nginx; upstream HTTPS terminates again at Jupiter Traefik.
|
|
- Upstream certificate verification disabled: `proxy_ssl_verify off`.
|
|
- Certificates: `/etc/letsencrypt/live/<domain>/{fullchain.pem,privkey.pem}`;
|
|
`umbra.mom` certificate also serves its subdomains.
|
|
- Preserves `Host`; sets `X-Real-IP`, `X-Forwarded-For`, `X-Forwarded-Proto`;
|
|
forwards WebSocket upgrade headers.
|
|
- Gitea `/v2/`: unlimited request body; proxy timeouts `900s`.
|
|
|
|
## Firewall / fail2ban
|
|
|
|
- UFW-managed iptables: INPUT/FORWARD `DROP`; OUTPUT `ACCEPT`.
|
|
- UFW allows TCP `22,80,443`; UDP `80,443,51820`.
|
|
- Docker forwarding has separate rules; INPUT policy alone does not define
|
|
container exposure.
|
|
- Fail2ban jails: `nginx-botsearch`, `nginx-http-auth`, `sshd`.
|
|
|
|
Rules and versions are supplied snapshots, not live inspection.
|