Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

nixio - Ingress Host

Purpose

NixIO serves as the cluster’s primary ingress and network gateway. It handles all external traffic routing, VPN tunnelling, DNS filtering, and dashboard aggregation for the server fleet.

Entry Point

Architecture / Services / Scope

Services

ServiceModule / PathRole
Caddyhosts/server/nixio/proxy.nixReverse-proxy and TLS termination for all cluster services
Tailscale Tunnelhosts/server/nixio/tunnel/Mesh VPN connectivity, subnet routing, and ingress via Tailscale tags
Dashy Dashboardhosts/server/nixio/dashboard.nixAggregated service dashboard displayed on the IO Coordinator
AdGuard Homehosts/server/nixio/adguard.nixLocal DNS filtering and ad-blocking for the home network
Network Configdefault.nixSubnet declarations, IP forwarding (IPv4 + IPv6)

Secrets

Declared secrets

Secret keyPurpose
CLOUDFLARE/EMAILACME DNS challenge account email
CLOUDFLARE/ZONE_API_TOKENACME DNS challenge zone token
CLOUDFLARE/DNS_API_TOKENACME DNS challenge API token

Operational Notes / Assumptions

  • This host is expected to have stable upstream network access plus reachability to the cluster LAN and tailnet, because ingress, DNS, and tunnel traffic all terminate here.
  • Caddy terminates public TLS for cluster services, while some backends also use separate internal TLS or mTLS; certificate trust and backend server names must stay aligned with those upstream services.
  • Reverse-proxied services remain individually responsible for their own authn/authz. Publishing a route here does not replace service-level access controls.

References