NixIO serves as the cluster’s primary ingress and network gateway.
It handles all external traffic routing, VPN tunnelling, DNS filtering, and dashboard aggregation for the server fleet.
This host is expected to have stable upstream network access plus reachability to the cluster LAN and tailnet, because ingress, DNS, and tunnel traffic all terminate here.
Caddy terminates public TLS for cluster services, while some backends also use separate internal TLS or mTLS; certificate trust and backend server names must stay aligned with those upstream services.
Reverse-proxied services remain individually responsible for their own authn/authz. Publishing a route here does not replace service-level access controls.