Infrastructure Self-Hosted
Production-grade self-hosted infrastructure with defense-in-depth security, SSO, automated vulnerability scanning, and full observability.
Note — Ce schéma est anonymisé : les sous-réseaux, noms de domaine et règles firewall ont été modifiés.
~50
CONTAINERS
6
VLANS
3
SERVEURS
8+
COUCHES SÉCU.
External Traffic — *.trashbread.fr
Internal Traffic — *.home.arpa
Authentication Flow — SSO / OIDC
UniFi Dream Machine Pro
Router / Firewall / VPN Gateway
Firewall Policy
Cloudflare
DNS Proxy / DDoS Protection
Fonctions
Domaines
Certificats
Servo
HP ProLiant ML350 Gen9 — VLAN 10
~40 containers — Docker Compose
Productivité
Outils & Dev
Monitoring
Sécurité
IA
OptiPlex
Dell OptiPlex — VLAN 10
Reverse Proxy & Auth — Gateway
Reverse Proxy
Stack Auth (SSO)
Traefik Plugins
Observabilité
Photo
TrueNAS
NAS — VLAN 20 (Management)
Immich Split Architecture
Photo management on OptiPlex, ML inference offloaded to Servo
Traefik Middleware Chain
Applied to every incoming request
+ ModSecurity WAF (OWASP CRS) available on-demand — GeoBlock restricts to Europe only
Authelia
SSO / 2FA / OIDC Provider
Single sign-on across all services. OIDC clients: Pangolin, Gitea (auto-login).
Falco
eBPF Runtime Security
Kernel-level syscall monitoring. Custom rules for container escape, privilege escalation.
Trivy
Automated Vulnerability Scanner
Daily scan of all Docker images. HIGH/CRITICAL CVEs reported via HTML email.
CrowdSec
Community Threat Intel
DefectDojo
Vulnerability Management
Dependency-Track
SCA / SBOM Analysis
Runtime Security Alerts
Vulnerability Reports
Container Updates
Immich Backup
cron 04:00 daily
PostgreSQL dump + library rsync from OptiPlex to Servo.
Kopia
Backup Agent
Backblaze B2
Offsite Cloud Backup