Homelab Infrastructure Wiki
Last updated 24 Aug 2026 — combines the live Portainer audit (13 environments, per-container detail) with the Home Lab Architecture document (hardware, virtualization, networking, storage), plus direct live checks against Proxmox, PBS, NPM, UniFi, Tailscale, Beszel, Home Assistant and AMP.
Network Overview
| Environment | IP | Role | Status |
|---|---|---|---|
| Game Manager Server | 192.168.1.114 | Board-game manager app (3 instances) | ONLINE |
| GetAMP Game Server | 192.168.2.10 | Game server host, 8 AMP instances (VLAN 2) | ONLINE |
| Home Assistant | 192.168.1.33 | Smart home automation (Raspberry Pi 4) | ONLINE |
| HP ProLiant MicroServer | 192.168.1.70 | Potential remote backup server (4 stacks) | DOWN |
| n8n Server | 192.168.1.160 | Workflow automation (VM on Proxmox-1) | ONLINE |
| Ollama Server | 192.168.1.249 | Local LLM inference (VM on Proxmox-1) | DOWN |
| Proxmox-1 Docker CT | 192.168.1.154 | Main utility box (Portainer host) | ONLINE |
| Proxmox-2 Docker CT | 192.168.1.63 | Docker agent on Proxmox-2 (future cluster node) | DOWN |
| Proxmox-3 Docker CT | 192.168.1.171 | Docker agent on Proxmox-3 (future cluster node) | DOWN |
| Proxmox Host Server | 192.168.1.218 | Proxmox-1 host — reverse proxy (NPM) | ONLINE |
| Sara-VM | 192.168.1.23 | Photo backup & publishing (VM on Proxmox-1) | ONLINE |
| Tipi Server | 192.168.1.66 | Runtipi app platform (VM on Proxmox-1) | ONLINE |
| Zaibatsui App Server | 192.168.1.56 | Custom full-stack apps | ONLINE |
| Zaibatsui Tower | 192.168.1.69 | Unraid NAS & media server | ONLINE |
This wiki itself is served from Proxmox-1 Docker CT at http://192.168.1.154:8090 (Portainer stack homelab-wiki). Status badges above are checked live from your browser (see note at the bottom of the page about accuracy & assumptions).
Hardware Inventory
Proxmox-1 — Minisforum MS-01 (primary server)
| Component | Spec |
|---|---|
| CPU | Intel Core i9-12900H |
| GPU | Intel Iris Xe Graphics (up to 1.5 GHz) |
| RAM | 96 GB dual-channel DDR5-5200 |
| Storage | 3× 2 TB M.2 2280 SSD |
| Connectivity | Dual USB4 (40 Gbps), dual 2.5G RJ45, WiFi 6, Bluetooth 5.2 |
| eGPU | Razer Core X enclosure · NVIDIA RTX 4080 · connected via USB4, PCI passthrough (0000:05:00) |
The eGPU is single-tenant. VMs 100 (Windows-11), 102 (SteamOS), 107 (Ollama), and 111 (Mint) all claim the same physical GPU — only one can hold it at a time. Ollama currently has it while running; switching to any of the other three means shutting Ollama down first.
Proxmox-2 — Minisforum MS-01 (secondary server)
| Component | Spec |
|---|---|
| CPU | Intel Core i9-13900H (14C/20T) — verified live 24 Aug 2026; the "same as Proxmox-1" assumption was wrong, Proxmox-1 is a 12900H |
| RAM | ~94 GiB usable (96 GB nominal DDR5-5200) — verified live 24 Aug 2026 |
| GPU | Iris Xe (integrated) — assumed from CPU family, not independently confirmed |
| Storage | 1× 2 TB M.2 2280 SSD |
| Connectivity | Dual USB4 (40 Gbps), dual 2.5G RJ45, WiFi 6, Bluetooth 5.2 |
Proxmox-3 — Framework board in CoolerMaster case
| Component | Spec |
|---|---|
| CPU | Intel Core i7-1280P |
| RAM | 32 GB DDR4-3200 (2× 16 GB) |
| Storage | 1 TB M.2 |
Zaibatsui Tower — LincPlus LincStation N2 (Unraid NAS)
| Component | Spec |
|---|---|
| CPU | Intel Alder Lake-N N100, 4C/4T, up to 3.4 GHz, 6 W TDP |
| OS | Unraid |
| RAM | 16 GB LPDDR5 (on-board) |
| Storage | 2× 4 TB SSD + 4× 2 TB M.2 |
| Network | 1× RJ45, 10 Gigabit Ethernet |
| Other I/O | USB-C (full function, 10G), USB 3.2 Gen2 Type-A, 2× USB 2.0, HDMI 2.0, 3.5mm audio |
HP ProLiant MicroServer
| Component | Spec |
|---|---|
| OS | Ubuntu 26.04 LTS |
| CPU | 2 vCPU (as seen by the OS) |
| RAM | 7.3 GiB |
| Asset tag | 5C7344P3MM |
| Network | LAN 192.168.1.70 · Tailscale 100.86.156.104 |
Role unconfirmed — not covered by the original architecture document. Likely a potential remote backup target (see Network Overview); currently runs Cockpit and its own FileBrowser Quantum instance. See environment section.
Home Assistant
| Component | Spec |
|---|---|
| Model | Raspberry Pi 4 |
| OS | Home Assistant OS 18.1 (board rpi4-64) |
| Storage | 32 GB SD card (SC32G) |
| Radios | SkyConnect v1.0 (Zigbee) + Connect ZBT-2 (Thread) + TP-Link USB Bluetooth — see environment section |
| Network | LAN 192.168.1.33 (wired) · also Wi-Fi 192.168.1.120 |
Pi-hole
| Component | Spec |
|---|---|
| Model | Raspberry Pi 3B |
| Hostname | zaibatsui |
| OS | Raspberry Pi OS (Debian-based) — kernel 6.12.93+rpt-rpi-v8, aarch64 |
| CPU | 4 cores, ~1% typical load |
| RAM | 906 MB total (28% used) · 200 MB swap, 97% used — worth keeping an eye on |
| Pi-hole | Core v6.4.3 · FTL v6.7 · Web v6.6 (the UI still shows legacy "Pi-hole 5" branding text, but this is genuinely v6 — its API lives at /api, not the old /admin/api.php) |
| Network | 192.168.1.180 — admin UI at /admin |
Storage expansion (not currently connected)
SABRENT 4-bay hard drive dock (USB3 → Proxmox) — drives: 250 GB WD Black, 320 GB WD Black, 2× Samsung 1 TB. Intended for the OpenMediaVault NAS VM (also inactive).
Virtualization Map
How the Portainer environments map onto physical hosts. Proxmox-1 carries nearly all workloads; Proxmox-2 and Proxmox-3 are earmarked as future cluster nodes.
Proxmox-1 (MS-01) — VMs & CTs
Read live from the Proxmox API on 17 Jul 2026. VMIDs and status are authoritative here; several guests below appear nowhere else in this wiki.
| VMID | Guest | Type | Status | Purpose / notes |
|---|---|---|---|---|
104 | Docker-PX1 | LXC | RUNNING (29d) | Main Docker host 192.168.1.154 — see environment section |
115 | Sara-VM | VM | RUNNING (9d) | Immich + Ghost 192.168.1.23 — see environment section |
121 | Zaibatsui-App-Server | VM | RUNNING (29d) | Custom apps 192.168.1.56 — see environment section |
119 | Game-Manager-Server | VM | RUNNING (29d) | 192.168.1.114 — see environment section |
113 | n8n-docker | LXC | RUNNING (16d) | n8n 192.168.1.160 |
114 | Runtipi | LXC | RUNNING (29d) | Tipi Server 192.168.1.66 |
107 | Ollama | VM | RUNNING (4d) | Local LLM inference 192.168.1.249, 32 GB RAM, currently holds the eGPU — see environment section |
105 | GetAmp | LXC | RUNNING | Game servers via AMP 192.168.2.10 — VLAN tag 2, gateway 192.168.2.1 |
108 | Tailscale | LXC | RUNNING (29d) | Subnet router — LAN 192.168.1.25, Tailscale 100.96.43.79. See Tailscale |
110 | Beszel | LXC | RUNNING (29d) | Monitoring hub — DHCP, currently 192.168.1.174:8090 |
101 | CasaOS | LXC | RUNNING (29d) | CasaOS — DHCP, currently 192.168.1.88 (listed as "CASOS VM" in older notes; it is an LXC, not a VM) |
117 | FileBrowser-Quantum | LXC | RUNNING (1d) | File management — DHCP |
109 | NetBox | LXC | RUNNING | IPAM / DCIM — confirmed running via Proxmox API (21 Jul 2026), 5+ day uptime. Previously documented as stopped; check netbox.zaibatsui.co.uk and its Beszel status if still showing stale elsewhere |
126 | Moltbot | LXC | STOPPED | LAN 192.168.1.121, Tailscale 100.105.120.55 — last seen 22 Mar 2026 |
106 | OpenMediaVault | VM | STOPPED | NAS VM for the SABRENT dock — confirms "NOT ACTIVE", though omv.zaibatsui.co.uk still resolves |
100 | Windows-11 | VM | STOPPED | Desktop guest — Tailscale node last seen 18 Dec 2025. Shares the eGPU with 102/107/111; won't start while Ollama holds it |
102 | SteamOS | VM | STOPPED | Desktop guest — shares the eGPU with 100/107/111; won't start while Ollama holds it |
103 | Ubuntu-24 | VM | STOPPED | Desktop guest |
111 | Mint | VM | STOPPED | Desktop guest — shares the eGPU with 100/102/107; won't start while Ollama holds it |
112 | PopOS | VM | STOPPED | Desktop guest |
124 | CT-Template | LXC | STOPPED | Container template |
The node itself reports 94 GB RAM. A SaraBackup guest appears in older notes but does not exist here — the Proxmox Backup Server at 192.168.1.219 (pbs.zaibatsui.co.uk) is its likely successor.
Proxmox-2 / Proxmox-3
PVE 8→9 upgrade complete, 23 Aug 2026. All three nodes run pve-manager/9.2.11 on kernel 7.0.14-12-pve.
These two nodes are deliberately cycled on and off, not left running 24/7. They're scale-out capacity — brought online as needed rather than kept up permanently, since there's ample headroom on Proxmox-1 for day-to-day workloads. Don't treat either being offline as a fault; check current status live rather than assuming from this page. As of 24 Aug 2026: Proxmox-2 is up (CPU/RAM verified live, see Hardware Inventory), Proxmox-3 is down.
VMIDs 120 (Docker-PX2) and 116 (Docker-PX3) are the Docker CTs on each node; 122 (CT-Template-2) and 118 (CT-Template-3) are stopped templates. Each node runs Docker with a Portainer agent only when up. Full guest inventory for these two nodes hasn't been re-audited since the upgrade — worth a follow-up pass.
Zaibatsui Tower (Unraid)
NAS shares + Docker (media stack, Immich, agents — see environment section) + one VM: Proxmox Backup Server.
Game Manager Server
Each instance is its own stack: static frontend + Python/FastAPI backend (uvicorn) + MongoDB. The primary instance's backend authenticates to the BoardGameGeek (BGG) API, confirming the app pulls game data from BGG for collection/session management.
| Instance | Ports | Status | Likely purpose |
|---|---|---|---|
| game-manager-1 | 7550 / 7551 | RUNNING | Production (primary — BGG API auth) |
| game-manager-500 | 7565 / 7566 | RUNNING | Friend / group copy |
| game-manager-999 | — | STOPPED | Test build |
Plus a Portainer agent for remote management.
GetAMP Game Server
This is the reason the homelab exists in its current form — a Debian 12 box (16 GB RAM allocated, i9-12900H) running eight AMP-managed game server instances. Only one runs at a time in practice.
| Instance | Game | Game port | Status |
|---|---|---|---|
| Zaibatsui Server | Core Keeper | 27015 | RUNNING |
| James Server | Minecraft (Bedrock) | 19132 | OFFLINE |
| Zaibatsui Server | Satisfactory | 7777 | OFFLINE — flagged "Replace Instance" in AMP |
| Zaibatsui Experimental Server | Satisfactory (experimental branch) | 7760 | OFFLINE |
| Zaibatsui Server | Factorio | 34197 | OFFLINE |
| Zaibatsui Server | Valheim | 2456 | OFFLINE |
| Zaibatsui Server | Enshrouded | 15637 | OFFLINE |
| Zaibatsui Server | OpenTTD | 3979 | OFFLINE |
Port forwards (UniFi, all forwarded to 192.168.2.10)
| Game | Ports | Purpose |
|---|---|---|
| Core Keeper | 27015 UDP, 27016 UDP, 2231 TCP | Game, query, SFTP |
| Minecraft (Bedrock) | 19132 UDP, 2230 TCP | Game, SFTP |
| Satisfactory | 7777, 15777, 15000, 8888 (all TCP+UDP) | Game, query, beacon, reliable messaging |
| Satisfactory (experimental) | 7760 TCP+UDP, 2228 TCP+UDP | Game, SFTP — shares port 8888 with the main Satisfactory instance, see note below |
| Factorio | 34197, 7778 (game+RCON, TCP+UDP), 2225 TCP+UDP | Game, RCON, SFTP |
| Valheim | 2456, 2457 (TCP+UDP), 2226 TCP+UDP | Game, Steam query, SFTP |
| Enshrouded | 15637 TCP+UDP, 2227 TCP+UDP | Game, SFTP |
| OpenTTD | 3979 TCP+UDP, 2229 TCP+UDP | Game, SFTP |
All 29 UniFi port-forward rules for this VLAN were cross-checked directly against AMP's own instance ports and match exactly.
The main and experimental Satisfactory instances share UniFi's Satisfactory Reliable Messaging forward (8888) — if both were ever started together, whichever isn't bound first would lose that port. In practice this hasn't mattered since only one instance runs at a time. Also note there is no separate SFTP forward for the main Satisfactory instance; only the experimental one (2228) is defined.
GetAMP gained a Portainer agent in July 2026 (environment “GetAMP”) and is now managed alongside the other Docker hosts. It is not covered by the original architecture document beyond its existence.
Home Assistant
Runs as a dedicated HAOS appliance, not a Docker container — separate from the Proxmox/Portainer estate. 1,769 entities across 782 devices, spanning 8 areas: Bedroom, Entrance, Front Door Sensor, Kitchen, Limbo, Living Room, Loft, Office.
Access control
| Device | Details |
|---|---|
| Nuki Smart Lock Ultra | Front door, via Matter · battery 93% · paired with a door sensor (motion, light, opening, battery 60%) |
| NFC tag unlock | An NFC tag (tag.front_door_unlock) triggers an automation to unlock on scan |
Automations: an Alexa alarm if the front door is left open, with a sensor-button press to silence it.
Flic buttons
A Flic Hub LR bridges six Flic buttons (flicktwist, office green, office red, bedroom, living room, computer) plus a separate Flic IR Blaster, all over the local MQTT broker below. The office pair does the most work — single/double/hold click combinations toggle the office lamp and strip, switch the screens and PC via IR, and control the main lights.
Radios
| Dongle | Purpose |
|---|---|
| Home Assistant SkyConnect v1.0 | Zigbee, via ZHA |
| Home Assistant Connect ZBT-2 | Thread border router, via OTBR — also paired with Matter |
| TP-Link USB Bluetooth adapter | External BLE (onboard Pi Bluetooth also present) |
Integration ecosystem (77 config entries, 50 domains)
| Category | Integrations |
|---|---|
| Smart home platforms | SwitchBot (heaviest — sensors, Bots, 2× K10+ vacuums), Tuya, Nest, Govee, LIFX, Matter, Thread, ZHA |
| Apple & voice | HomeKit bridge (exposes 5 devices out to Apple Home) and HomeKit Controller (consumes 3 accessories in — Aqara Hub M2, FP2 presence sensor, an MSS smart plug), Alexa Media Player, Google Cast, Google Translate TTS |
| Media & TV | Samsung TV, Sony Bravia, Android TV, DLNA (2 renderers + 1 media server), go2rtc |
| Cloud & extensibility | Home Assistant Cloud (Nabu Casa), HACS, IFTTT webhook |
| Local services (migrated off cloud) | Mosquitto MQTT broker (HAOS add-on, backs the Flic Hub) · tuya_local for the Office Fan · govee_lan for network-local Govee control, alongside the existing cloud/Bluetooth integrations |
| Climate & sensors | Airzone Cloud, SensorPush, Met (weather) |
| Network presence | Bluetooth (2 adapters), iBeacon tracker — together responsible for a very large device_tracker count (620 entities); likely worth pruning stale entries at some point |
Not fully working: Sony Bravia TV and 3 Oral-B toothbrushes show as not_loaded; 2 generic LED-BLE strips are not_loaded; the EPSON XP-8600 printer integration is in setup_retry. None of these are critical, but worth a look if those devices matter day to day.
HP ProLiant MicroServer
| Service | Address | Notes |
|---|---|---|
| Cockpit | :9090 (LAN, Tailscale IP, or the .ts.net hostname) | Web system console for the box itself. Self-signed certificate — expect a browser SSL warning on the LAN/IP addresses; the Tailscale hostname has a valid cert via Tailscale, so no warning there |
| FileBrowser Quantum | :8080 | Serves this box's own /srv storage (586 GB). Distinct from the FileBrowser Quantum on CT 117 (Proxmox-1) — same software and port, different host and data; see Issues |
| Watchtower, Beszel Agent, Portainer Agent | — | Standard support containers, all healthy |
Not covered by the original architecture document, so its intended role is unclear beyond file storage — worth deciding what this box is actually for.
n8n Server
| Service | Purpose | Notes |
|---|---|---|
| n8n | Workflow-automation platform (self-hosted Zapier alternative) | Basic-auth login; public webhook URL at n8n.zaibatsui.co.uk; workflows / credentials / executions persist in a bind-mounted host folder |
| Watchtower | Auto image updates | — |
| Portainer Agent | Remote management | — |
Ollama Server
Currently holds the passed-through RTX 4080 (Razer Core X eGPU via USB4). It's exclusive to one VM at a time — Windows-11 (100), SteamOS (102) and Mint (111) all claim the same PCI device, so this VM must be shut down before starting any of the others. See Hardware Inventory.
| Service | Purpose | Notes |
|---|---|---|
| Open WebUI | Chat front-end for local models | ghcr.io/open-webui/open-webui:latest on port 8080 — healthy |
| Beszel Agent | Host metrics | Polled by the Beszel hub at 192.168.1.174:8090; agent v0.17.0 while most others report v0.18.7 |
| Portainer Agent | Remote management | Port 9001 |
All three run as standalone containers — there are no stacks on this environment. Note there is no ollama container present, so the model runtime itself appears to run natively on the VM rather than in Docker; Open WebUI is only the front-end.
Proxmox Host Server
| Service | Purpose | Notes |
|---|---|---|
| Nginx Proxy Manager | Reverse proxy with UI for domains & SSL certs | Ports 80, 81 (admin), 443; config and Let's Encrypt certs bind-mounted to host |
| Portainer Agent | Remote management | — |
The ~101 GB RAM Portainer reports here reflects the Proxmox-1 host itself (96 GB MS-01), which also runs all the VMs listed in the Virtualization Map — not just NPM.
Proxmox-1 Docker CT
Stacks
| Service | Purpose | Ports / dependencies / notes |
|---|---|---|
| Blinko | Self-hosted note / bookmark app | Built from its GitHub repo; own PostgreSQL |
| ConvertX | Web file-format converter | Port 3000 |
| Fileshaper | Custom Python file-handling tool | Port 5000 |
| game-picker | Custom random game picker (Node.js) | STOPPED — static files + small data folder |
| game-picker-fury | Custom random game picker (Node.js) | STOPPED — static files + small data folder |
| Joplin Server | Sync backend for Joplin notes | Port 22300; own PostgreSQL |
| Mealie | Recipe manager & meal planner | Port 9925 |
| Tesseract / OCRmyPDF | Long-running OCR helper | Idle; pointed at Nextcloud "recipes" folder |
| FlareSolverr | Cloudflare-challenge bypass proxy | Part of a small externally-deployed compose project |
| Nextcloud | File sync & sharing | Port 8765; cron container for thumbnail pre-generation; MariaDB + Redis; bind-mounted under /mnt/nextcloud_* |
| homelab-wiki | This wiki (nginx:alpine) | Port 8090; page embedded in stack definition |
Standalone containers
| Service | Purpose | Notes |
|---|---|---|
| Portainer | Container management UI for all environments | Data volume + Docker socket access |
| Watchtower | Automatic image updates | Runs daily |
| Homarr | Dashboard / launcher | SQLite-backed; Docker socket access for container status |
| Stirling-PDF | Full PDF toolkit | — |
| Uptime Kuma | Uptime / status monitoring | — |
| IT-Tools | Small developer utilities | — |
Penpot was deliberately removed (the architecture doc is stale); its old domain now points at a dead target — see Domains.
Sara-VM
| Service | Purpose | Notes |
|---|---|---|
| Immich | Google-Photos-style backup with AI photo search | Vector-enabled PostgreSQL + Redis; uploads on dedicated /mnt/SaraImages mount; CORS configured for sara-image.zaibatsui.co.uk |
| Ghost | Blogging platform | Runs agirlandherappetite.com (AGAHA); own MySQL; Gmail SMTP for outgoing mail (notifications / newsletters) |
| Homarr | Dashboard | STOPPED |
| Portainer Agent | Remote management | — |
Tipi Server
| Service | Purpose | Notes |
|---|---|---|
| Runtipi | Self-hosted "app store" homeserver platform | Wired with generated internal passwords |
| Traefik | Reverse proxy backing Runtipi | Routes a configured domain plus local tipi.local |
| RabbitMQ | Message queue backing Runtipi | — |
| PostgreSQL | Database backing Runtipi | — |
| code-server | VS Code in the browser | Installed through Runtipi's app store (runtipi.managed label), not a separate deployment |
| Beszel Agent | Resource monitoring — reports to the Beszel hub on Proxmox-1 | — |
| Portainer Agent | Remote management | — |
Zaibatsui App Server
Standard pattern: frontend + FastAPI backend + MongoDB (exceptions noted).
| App | Purpose | Notes |
|---|---|---|
| Smart Cooking Sync | Recipe / meal-sync API | HEALTHY (previously flagged unhealthy, confirmed resolved) |
| ServerDash | Network / uptime monitoring — internally "Netset Server Dashboard" | Checks endpoints ~every minute; email alerts via IONOS SMTP; Google OAuth login — likely used for a client/business named Netset |
| Proxmox AI Assistant | AI-assisted Proxmox host management | JWT-secured admin tool; OpenAI API key slot currently empty |
| Gaming Rota | Gaming-session scheduler with Discord bot | File-backed data folder rather than a database |
| Design Workshop | Design / page-building tool — internally "modular-pages" | Runs Playwright (headless browser automation, likely for rendering / exporting pages); Google OAuth login |
| Portainer Agent | Remote management | — |
| ZaibatsuAI | Discord ops agent for the whole estate | Container zaibatsu-agent; excluded from its own actions by policy — see Services > Cross-cutting deployments |
Zaibatsui Tower
The *arr stack runs in host-networking mode; all media tools read from and write to Unraid's /mnt/user share.
*arr stack & downloaders
| Service | Purpose | Notes |
|---|---|---|
| Sonarr | TV show automation | — |
| Radarr | Movie automation | — |
| Readarr | Books & audiobooks automation | — |
| Prowlarr | Shared indexer manager for all three | — |
| SABnzbd | Usenet downloader | — |
| qBittorrent | Torrent client | Download folder pointed at the shared media library |
Media & other services
| Service | Purpose | Notes |
|---|---|---|
| Plex | Media streaming server | — |
| Calibre | Ebook library / server | GPU-accelerated remote-desktop-style web UI |
| Immich (2nd instance) | Photo backup | Port 8085; server + machine-learning + own PostgreSQL + Redis — independent of the Sara-VM instance |
| Beszel Agent | Server monitoring | — |
| Watchtower | Auto image updates | — |
| Portainer Agent | Remote management | — |
VMs
| VM | Status | Resources | Notes |
|---|---|---|---|
| Proxmox Backup Server | RUNNING (autostart) | 2 vCPU · 4 GB · 32 GB vdisk | 192.168.1.219:8007 / pbs.zaibatsui.co.uk — backup target for the Proxmox nodes; datastore lives on the Unraid array. See Storage & Backup |
| Quorum | STOPPED (autostart on) | 2 vCPU · 2 GB · 32 GB vdisk | Proxmox cluster quorum tiebreaker for when one node is down — presumably to be started once Proxmox-2/-3 join the cluster |
NAS shares
backups, config, domains, downloads, isos, media, PBS (NFS & SMB), SaraVM (NFS & SMB), scratch, system, Z-Drive (NFS & SMB).
Offline Environments
HP MicroServer, Proxmox-2 Docker CT, and Proxmox-3 Docker CT are currently offline — deliberate, not a fault. The MicroServer is staged as a future remote NAS, waiting on cheap drives, no timeline. The two Proxmox Docker CTs are pre-configured standby capacity held offline until Proxmox-1 runs out of headroom. Observa Server (CT 125) was reviewed and deleted on 22 Jul 2026 — a self-monitoring Prometheus/Grafana stack superseded by Beszel + Uptime Kuma. See Virtualization Map for the full cluster status.
Networking
| Element | Detail |
|---|---|
| Core router | Ubiquiti Cloud Gateway Max (UCGMAX, firmware 5.1.19) — dual WAN (Internet 1 + Internet 2) |
| Wireless | Two U6 Mesh APs — 192.168.1.8 (24 clients) and 192.168.1.169 (8 clients) — plus a non-UniFi ASUS AP (homelab only). SSIDs: Zaibatsui 5GHz, Zaibatsui 2.4GHz, Zaibatsui Guest; a "Zaibatsui IoT" SSID exists but is disabled |
| Switches | USW Flex XG (10GbE, 192.168.1.35) · USW-Lite-16-PoE (192.168.1.34) — neither previously documented |
| Clients | 51 online at last check — 19 wired, 32 wireless; all but one on the main LAN |
| Networks (from UniFi, 17 Jul 2026) | Zaibatsui Network — untagged, 192.168.1.0/24, DHCP .6–.254 · Zaibatsui Game Network — VLAN 2, 192.168.2.0/24 (GetAmp lives here) · Zaibatsui VPN — remote-user VPN on 192.168.3.0/24 · Zaibatsui IoT — VLAN 3, 192.168.4.0/24, built but disabled. The old "LAN / IoT / Lab (planned)" note is superseded: LAN and Game are live, IoT is one toggle away |
| Reverse proxy | Nginx Proxy Manager on the Proxmox-1 host (192.168.1.218) |
| DNS filtering | Pi-hole on Raspberry Pi 3B |
| Remote access | Tailscale — subnet router VM on Proxmox-1 advertising 192.168.1.0/24; tailnet tailee040d.ts.net. See Tailscale. |
Key IPs
| Host | IP | Notes |
|---|---|---|
| Proxmox-1 host / NPM | 192.168.1.218 | — |
| Docker VM (Proxmox-1 Docker CT) | 192.168.1.154 | — |
| Pi-hole (RPi 3B) | 192.168.1.180 | Admin UI at /admin |
| Home Assistant (RPi 4) | 192.168.1.33 | Web UI :8123 — also homeassistant.local via mDNS |
| CasaOS CT | 192.168.1.88 | DHCP lease — Vault app :10380 |
| OMV NAS VM | 192.168.1.150 | NOT ACTIVE |
| getAMP VM | 192.168.2.10 | Note: on the 192.168.2.x subnet |
Tailscale
Remote access runs through a single subnet router — the tailscale VM on Proxmox-1 — advertising 192.168.1.0/24 (approved). No exit node is enabled and no routes are awaiting approval. MagicDNS is on at 100.100.100.100.
| Machine | Tailscale IP | OS & client | Last seen |
|---|---|---|---|
| tailscale — subnet router | 100.96.43.79 | Linux 6.8.12-16-pve · v1.98.3 | Connected |
| ollama | 100.103.14.90 | Linux 6.17.0-35-generic · v1.98.8 | Connected |
| zaibatsui-11 | 100.102.97.83 | Windows 11 25H2 · v1.98.4 | Connected |
| zaibatsui-pc | 100.102.123.96 | Windows 10 22H2 · v1.98.2 | 16 Jul 2026 |
| sara-hp-laptop | 100.103.83.45 | Windows 11 25H2 · v1.98.4 | 15 Jul 2026 |
| zaib-framework | 100.118.126.95 | Windows 11 25H2 · v1.98.8 | 8 Jul 2026 |
| hpproliantmicroserver | 100.86.156.104 | Linux 7.0.0-22-generic · v1.98.4 | Connected |
| anthonys-s24-ultra | 100.77.154.112 | Android 16 · v1.98.2 | 1 Jun 2026 |
| moltbot | 100.105.120.55 | Linux 6.8.12-16-pve · v1.94.1 | 22 Mar 2026 |
| windows-11-vm | 100.64.49.55 | Windows 11 25H2 · v1.90.6 | 18 Dec 2025 |
Two users share the tailnet: zaibatsui@hotmail.com owns nine machines; sara.gibson.1988@gmail.com owns sara-hp-laptop. Key expiry is disabled on every machine except anthonys-s24-ultra. Both tailscale and moltbot run a Proxmox kernel, so both are guests on Proxmox-1.
getAMP is not reachable over Tailscale. The subnet router advertises only 192.168.1.0/24, but the getAMP VM lives on 192.168.2.10 and has no Tailscale node of its own — so it falls outside the tunnel entirely. Add a second advertised route or install a client there if remote access is wanted.
Domains & External Endpoints
Read directly from Nginx Proxy Manager on 17 Jul 2026 — 41 proxy hosts, all Let's Encrypt and all public. NPM's "Online" means the proxy host is enabled, not that the upstream answers; four of these point at targets that are currently stopped.
| Domain | Upstream | Service | Notes |
|---|---|---|---|
zaibatsui.co.uk | https://192.168.2.10:443 | GetAMP | Apex domain — GetAmp CT 105, VLAN 2 |
wiki.zaibatsui.co.uk | 192.168.1.154:8090 | Homelab Wiki | This page |
homelab.zaibatsui.co.uk | 192.168.1.154:7575 | Homarr | The dashboard |
proxmox.zaibatsui.co.uk | https://192.168.1.218:8006 | Proxmox VE | Node proxmox |
proxmox-2.zaibatsui.co.uk | https://192.168.1.200:8006 | Proxmox-2 VE | Node IP 192.168.1.200 — distinct from the Proxmox-2 Docker CT on .63; node currently offline |
pbs.zaibatsui.co.uk | https://192.168.1.219:8007 | Proxmox Backup Server | Undocumented host at 192.168.1.219 — possibly the "SaraBackup" from older notes |
npm.zaibatsui.co.uk | 192.168.1.218:81 | Nginx Proxy Manager | The proxy itself |
tower.zaibatsui.co.uk | 192.168.1.69:80 | Unraid | Zaibatsui Tower |
tipi.zaibatsui.co.uk | 192.168.1.66:80 | Runtipi | Tipi Server (CT 114) |
code.zaibatsui.co.uk | 192.168.1.66:63437 | code-server | On Tipi Server |
uptime.zaibatsui.co.uk | 192.168.1.154:3001 | Uptime Kuma | Proxmox-1 |
ollama.zaibatsui.co.uk | 192.168.1.249:8080 | Open WebUI | Ollama VM 107 |
n8n.zaibatsui.co.uk | 192.168.1.160:5678 | n8n | CT 113 |
files.zaibatsui.co.uk | 192.168.1.26:8080 | FileBrowser Quantum | CT 117 — DHCP lease .26, hard-coded here |
vault.zaibatsui.co.uk | 192.168.1.88:10380 | Vault app on CasaOS | This is what CasaOS (CT 101) serves |
nextcloud.zaibatsui.co.uk | 192.168.1.154:8765 | NextCloud | Proxmox-1 |
joplin.zaibatsui.co.uk | 192.168.1.154:22300 | Joplin | Proxmox-1 |
blinko.zaibatsui.co.uk | 192.168.1.154:9080 | Blinko | Proxmox-1 |
it-tools.zaibatsui.co.uk | 192.168.1.154:8086 | IT Tools | Proxmox-1 |
pdf.zaibatsui.co.uk | 192.168.1.154:8088 | Stirling PDF | Proxmox-1 |
convertx.zaibatsui.co.uk | 192.168.1.154:3000 | ConvertX | Proxmox-1 |
fileshaper.zaibatsui.co.uk | 192.168.1.154:5000 | FileShaper | Proxmox-1 |
shop.zaibatsui.co.uk | 192.168.1.154:9925 | Mealie | Proxmox-1 |
cook.zaibatsui.co.uk | 192.168.1.56:3001 | Smart Cooking Sync | App Server |
designworkshop.zaibatsui.co.uk | 192.168.1.56:8080 | Design Workshop | App Server |
netsetdash.zaibatsui.co.uk | 192.168.1.56:80 | Server Dash / Netset | App Server |
killsquadbot.zaibatsui.co.uk | 192.168.1.56:3002 | KillSquadBot | Same port as "Gaming Rota" — the rota app and its Discord bot are one and the same |
api-killsquadbot.zaibatsui.co.uk | 192.168.1.56:8003 | KillSquadBot API | App Server — not previously documented |
gamemanager.zaibatsui.co.uk | 192.168.1.114:7551 | Game Manager | Primary instance |
furey.zaibatsui.co.uk | 192.168.1.114:7566 | Game Manager 500 | The "friend / group copy" instance |
plex.zaibatsui.co.uk | 192.168.1.69:32400 | Plex | Zaibatsui Tower |
images.zaibatsui.co.uk | 192.168.1.69:8085 | Immich (Tower) | Zaibatsui Tower |
calibre.zaibatsui.co.uk | 192.168.1.69:8180 | Calibre | Zaibatsui Tower |
readarr.zaibatsui.co.uk | 192.168.1.69:8787 | Readarr | Zaibatsui Tower |
sara-image.zaibatsui.co.uk | 192.168.1.23:2283 | Immich (Sara) | Sara-VM |
agirlandherappetite.com | 192.168.1.23:2368 | Ghost blog | Sara-VM |
sara.blog.zaibatsui.co.uk | 192.168.1.23:2368 | Ghost blog | Second hostname for the same Ghost instance |
netbox.zaibatsui.co.uk | https://192.168.1.239:443 | NetBox | Dead target — NetBox CT 109 is stopped |
omv.zaibatsui.co.uk | 192.168.1.150:80 | OpenMediaVault | Dead target — OMV VM 106 is stopped |
penpot.zaibatsui.co.uk | 192.168.1.154:9001 | Penpot | Dead target — Penpot was removed; this now points at a Portainer agent port |
gamepicker.zaibatsui.co.uk | 192.168.1.154:3159 | Game Picker | Dead target — the game-picker container is stopped |
Public routing terminates at Nginx Proxy Manager on the Proxmox-1 host (192.168.1.218), which holds the Let's Encrypt certificates.
Storage & Backup
| Element | Detail |
|---|---|
| Z-Drive | CIFS share from Unraid, mounted on Proxmox at /mnt/pve/Z-Drive; a reset script handles CIFS remounting |
| Local pools | SSD / NVMe pools on each Proxmox node |
| Backup target | Proxmox Backup Server (VM on Unraid Tower, PBS datastore share) — PBS → Unraid strategy |
| Unraid array | 12 TB xfs across 4 SSDs (2×4 TB 870 EVO + 2×2 TB 990 PRO) — 7.17 TB used · btrfs cache pool 2×2 TB 990 PRO · 4 GB flash boot |
| Z-Drive_Backup | Unassigned 5 TB WD drive on Tower (xfs, 1.4 TB used) — local backup of the Z-Drive share |
| SABRENT 4-bay dock | Via the OMV NAS VM — NOT ACTIVE |
| Photo storage | Sara-VM Immich uploads on dedicated /mnt/SaraImages; SaraVM share on Unraid (NFS & SMB) |
Maintenance approach: regular Proxmox/VM updates; container updates via Watchtower; monitoring via Beszel (CT 110, agents on all 13 systems) and Uptime Kuma (agent-port checks on the same fleet). The Observa CT — a self-contained Prometheus/Grafana/Netdata stack that only monitored itself, and whose cAdvisor had never successfully started (invalid launch flag) — was reviewed and deleted 22 Jul 2026.
Proxmox Backup Server — audit (9 Aug 2026)
Backups run weekly — last run Sun 9 Aug 2026, CTs from 00:00–00:10 and VMs from 05:00–05:04. Sixteen guests are covered:
| Coverage | Guests (VMID) |
|---|---|
| Fresh (9 Aug) | CTs: CasaOS 101, Docker-PX1 104, GetAmp 105, Tailscale 108, NetBox 109, Beszel 110, n8n 113, Runtipi 114, FileBrowser-Quantum 117 · VMs: Ubuntu-24 103, Ollama 107, PopOS 112, Sara-VM 115, Game-Manager 119, App-Server 121 |
| Stale | SteamOS 102 — last backup 19 Oct 2025, unchanged |
| Never backed up | Windows-11 100, OpenMediaVault 106, Mint 111, Observa 125, Moltbot 126 |
Hygiene has improved since the last audit: Ollama (107) is fresh again after missing four runs, and FileBrowser-Quantum (117) is finally covered. A daily prune job now runs (keep-last 3, keep-weekly 4, keep-monthly 3, last run OK) and a weekly verify job runs Sundays at 22:00 (30-day outdated threshold, last run OK) — so backups are now both pruned to a sane retention policy and periodically integrity-checked, which they weren't before. No sync job exists, so there is still no second copy of the datastore outside Zaibatsui Tower itself.
External Devices
| Device | Role |
|---|---|
| Raspberry Pi 4 | Home Assistant (smart home automation) |
| Raspberry Pi 3B | Pi-hole (DNS filtering) |
| Raspberry Pi 3B | OctoPi (3D printer control) |
| UniFi Dream Machine Max | Core router / gateway |
| ASUS WiFi AP | Homelab-only wireless |
| Ubiquiti U6 Mesh | Main network wireless |
Services
Apps
| Service | Address | Host | Status |
|---|---|---|---|
| Plex | 192.168.1.69:32400 | Zaibatsui Tower | CHECKING |
| Immich (Tower) | 192.168.1.69:8085 | Zaibatsui Tower | CHECKING |
| Design Workshop (DW) | 192.168.1.56:8080 | Zaibatsui App Server | CHECKING |
| Server Dash | 192.168.1.56:80 | Zaibatsui App Server | CHECKING |
| FileShaper | 192.168.1.154:5000 | Proxmox-1 | CHECKING |
| Game Manager | 192.168.1.114:7551 | Game Manager Server | CHECKING |
| Smart Cooking | 192.168.1.56:3001 | Zaibatsui App Server | CHECKING |
| Proxmox AI Assistant | 192.168.1.56:3000 | Zaibatsui App Server | CHECKING |
| Gaming Rota | 192.168.1.56:3002 | Zaibatsui App Server | CHECKING |
Network & infrastructure
| Service | Address | Host | Status |
|---|---|---|---|
| Homarr (this dashboard) | 192.168.1.154:7575 | Proxmox-1 | CHECKING |
| Uptime Kuma | 192.168.1.154:3001 | Proxmox-1 | CHECKING |
| Beszel | 192.168.1.174:8090 | Proxmox-1 CT 110 (no Portainer agent) | CHECKING |
| Homelab Wiki | 192.168.1.154:8090 | Proxmox-1 | CHECKING |
| Nginx Proxy Manager | 192.168.1.218:81 | Proxmox Host Server | CHECKING |
| Portainer | 192.168.1.154:9000 | Proxmox-1 | CHECKING |
| Unraid | 192.168.1.69:80 | Zaibatsui Tower | CHECKING |
| Runtipi | 192.168.1.66:80 | Tipi Server | CHECKING |
| Open WebUI (Ollama) | 192.168.1.249:8080 | Ollama Server | CHECKING |
| Proxmox | 192.168.1.218:8006 | Proxmox Host Server | NOT CHECKED |
| n8n | 192.168.1.160:5678 | n8n Server | NOT CHECKED |
Proxmox and n8n are deliberately not live-checked. Proxmox serves a self-signed certificate that fetch() rejects, and n8n's proxied endpoint returns a false-negative 503 to programmatic requests. Both are fine when browsed directly — a red badge here would be a lie.
*arr stack & downloaders
| Service | Address | Host | Status |
|---|---|---|---|
| Sonarr (TV) | 192.168.1.69:8989 | Zaibatsui Tower | CHECKING |
| Radarr (Film) | 192.168.1.69:7878 | Zaibatsui Tower | CHECKING |
| Readarr | 192.168.1.69:8787 | Zaibatsui Tower | CHECKING |
| Prowlarr (Indexers) | 192.168.1.69:9696 | Zaibatsui Tower | CHECKING |
| qBittorrent | 192.168.1.69:8080 | Zaibatsui Tower | CHECKING |
| SABnzbd | 192.168.1.69:8081 | Zaibatsui Tower | CHECKING |
| Calibre | 192.168.1.69:8180 | Zaibatsui Tower | CHECKING |
SABnzbd is on 8081, not its usual 8080 — qBittorrent already holds 8080 on this host's network, so they would otherwise collide. Verified by probe.
Household & media
| Service | Address | Host | Status |
|---|---|---|---|
| Immich (Sara) | 192.168.1.23:2283 | Sara-VM | CHECKING |
| Mealie | 192.168.1.154:9925 | Proxmox-1 | CHECKING |
| A Girl & Her Appetite (Ghost) | 192.168.1.23:2368 | Sara-VM | NOT CHECKED |
The Ghost blog only answers on its configured domain, so a direct IP probe fails even though the site is up — same class of false negative as n8n.
Utilities (Proxmox-1)
| Service | Address | Host | Status |
|---|---|---|---|
| NextCloud | 192.168.1.154:8765 | Proxmox-1 | CHECKING |
| Blinko | 192.168.1.154:9080 | Proxmox-1 | CHECKING |
| Joplin | 192.168.1.154:22300 | Proxmox-1 | CHECKING |
| Stirling PDF | 192.168.1.154:8088 | Proxmox-1 | CHECKING |
| IT-Tools | 192.168.1.154:8086 | Proxmox-1 | CHECKING |
| ConvertX | 192.168.1.154:3000 | Proxmox-1 | CHECKING |
Cross-cutting deployments
| Service | Deployed on |
|---|---|
| Portainer Agent | All remote environments (managed from Proxmox-1) |
| Watchtower | Proxmox-1 (daily), Zaibatsui Tower — n8n Server's instance is crash-looping (see Issues) |
| Beszel | Hub at 192.168.1.174:8090 — runs as CT 110 on Proxmox-1, without a Portainer agent. Monitors 8 systems. Agents listen on :45876 (host network) and are polled by the hub, so agents hold no hub address. |
| Homarr | Proxmox-1 (running), Sara-VM (stopped) |
| Immich | Sara-VM, Zaibatsui Tower — two independent instances, each with own Postgres + Redis. By design: one per user, not a duplication to consolidate. |
| MongoDB | Game Manager Server (×3), Zaibatsui App Server (per-app) |
| FastAPI backends | Game Manager Server, Zaibatsui App Server (standard custom-app pattern) |
| ZaibatsuAI | Discord-based ops agent (not a container listed here by design). Reads and acts across all Portainer environments, Proxmox and NetBox for the operator; state changes and NetBox writes need operator approval, and its own container is excluded from any action by policy. |
Known Issues / To-Do
Check items off as you handle them — state is saved in this browser (via localStorage), so it'll still be checked next time you load the page on this device.
Future plans (from architecture doc)
About the Live Status Checks
The status badges and nav dots are checked directly from your browser, not from a background service — this page has no backend beyond the nginx container serving it. On load (and every 60 seconds after, or on demand via "Recheck now"), it attempts a lightweight connection to one known address per environment. A successful connection marks it ONLINE; a timeout or refused connection marks it DOWN. The sidebar's "Environments (online)" / "Environments (offline)" groups are rebuilt after every check, so an environment moves group automatically as its real status changes.
Caveats: checks run from your browser, so they only reflect reachability from this device on this network (VPN/off-LAN will differ, and mixed-content rules apply on HTTPS). Some services cannot be probed reliably — Portainer agent ports expect mutual-TLS, Proxmox serves a self-signed certificate, and n8n and Ghost answer only on their configured domains — so those show as NOT CHECKED rather than guessed.