Architecture

A high-level map of how the TekGarden platform connects on-prem infrastructure, the cloud edge, and remote access.

Network Overview

graph TB subgraph Internet["Internet"] USER["Users"] REMOTE["Laptops / Mobile
WireGuard road warrior"] end subgraph Cloud["Cloud Edge · Hetzner VPS"] PANGOLIN["Pangolin
Zero-trust tunnel gateway"] FORGEJO["Forgejo
Self-hosted Git + CI
private network only"] end subgraph OnPrem["On-Prem · Homelab"] PFSENSE["pfSense Router
Firewall rules + WireGuard road warrior
Only open: DNS, Traefik QNAP, Traefik k3s"] PROXMOX["Proxmox VE Cluster
2 nodes + QDevice"] K8S["Kubernetes (k3s)
2 HA clusters
prod + staging"] QNAP["QNAP NAS
Docker + Backrest backups
+ Traefik (Docker ingress)"] PBS["Proxmox PBS
Local backups → B2 sync"] SECRETS["Secrets
1Password + SOPS/age
+ Kyverno"] end subgraph External["External Services"] CF["Cloudflare
DNS + CDN"] B2["Backblaze B2
Off-site backups"] ONEPW["1Password
Secrets vault"] TG["Telegram
Alerts"] end subgraph Offline["Offline"] EXTDISK["External disk
Weekly offline copy"] end USER -->|HTTPS| CF CF -->|Tunnel| PANGOLIN PANGOLIN -->|Zero-trust| PFSENSE PFSENSE -->|DNS + Traefik only| QNAP PFSENSE -->|DNS + Traefik only| K8S PFSENSE --> PROXMOX PROXMOX --> K8S PROXMOX --> QNAP REMOTE -.->|WireGuard VPN| PFSENSE PFSENSE -.->|private network| FORGEJO PANGOLIN -.->|optional external access| FORGEJO FORGEJO -.->|GitOps pull| K8S FORGEJO -.->|CI deploy| QNAP PBS -.->|local backup| PROXMOX PBS -.->|sync| B2 QNAP -.->|Backrest local| QNAP QNAP -.->|Backrest → B2| B2 QNAP -.->|weekly| EXTDISK K8S --> SECRETS SECRETS -.->|op inject| ONEPW K8S -.->|alerts| TG

Flow Description

  1. Public access flows through Cloudflare → Pangolin (zero-trust tunnel gateway on the Hetzner VPS) → pfSense router. pfSense only allows traffic to DNS, the QNAP Traefik (Docker ingress), and the k3s Traefik (Kubernetes ingress): all protected by CrowdSec agents.
  2. Remote access: a WireGuard road warrior VPN on pfSense lets laptops and mobile connect from anywhere. Once connected, you have access to the entire TekGarden network and the Hetzner private network (including Forgejo), as if you were at home.
  3. Forgejo runs on a Hetzner private network: only reachable internally from TekGarden. If external access is needed, Pangolin can expose it on demand.
  4. GitOps runs from Forgejo: FluxCD pulls manifests into the Kubernetes clusters, and CI runners deploy Docker stacks to the QNAP and other Docker hosts.
  5. Proxmox VE (2 nodes + QDevice for quorum) provides the virtualization layer running both Kubernetes clusters and Docker hosts.
  6. Kubernetes runs two HA k3s clusters (production + staging, 12 nodes total).
  7. Docker runs 30+ services across 3 standalone hosts, including the QNAP NAS.
  8. Backups follow a 3-tier strategy:
    • Proxmox PBS: local backups of Proxmox guests, then synced to Backblaze B2.
    • Backrest (Docker on the QNAP): local backups of Docker data, then sent to B2.
    • Offline copy: weekly backup to an external disk.
  9. Observability (Grafana + Prometheus + Loki + Alertmanager) monitors everything and sends alerts to Telegram.
  10. Secrets are centralized in 1Password (injected via op inject), with SOPS/age for GitOps-encrypted manifests and Kyverno for runtime policies.

Tech Stack

LayerTechnology
Edge / TunnelPangolin, Cloudflare
VPNWireGuard (road warrior on pfSense)
Git / CIForgejo (Hetzner private network)
VirtualizationProxmox VE (2 nodes + QDevice)
Orchestrationk3s (2 HA clusters), Docker Compose (3 hosts)
GitOpsFluxCD
IngressTraefik (k3s + Docker), cert-manager, Let’s Encrypt, external-dns
Load BalancerMetalLB
ObservabilityGrafana, Prometheus, Loki, Alertmanager
Secrets1Password, SOPS/age, Kyverno
IaCOpenTofu, Ansible (pull mode)
NetworkpfSense, VLANs, Pi-hole, Cloudflare DNS
SecurityCrowdSec (on all Traefik instances), Kyverno policies, NetworkPolicies
BackupsProxmox PBS → B2, Backrest (QNAP) → B2, weekly offline disk
StorageNVMe local, iSCSI QNAP