KH3 infrastructure handbook
This handbook enables a system administrator or support engineer to understand, operate, validate, troubleshoot, back up, restore, and safely change the KH3 environment without undocumented local knowledge.
Start here
- New administrator: Getting started
- Understand the system: Current architecture
- Find a host or guest: Current inventory
- Find a service: Service catalog
- Follow a task: Operational runbooks
- Diagnose relationships: Dependency map
- Recover the environment: Backup and recovery
- Maintain this handbook: Documentation workflow
- Understand past systems: History
- Understand why: Architecture decisions
Scope and authority
The handbook covers physical equipment, Proxmox guests, OPNsense, network and DNS, ingress, rootless Podman, remote access, application services, documentation publication, backup evidence, and historical recovery material.
Current pages state the evidence date and confidence. Historical pages preserve recovery value but are not instructions for the live environment. Secrets are excluded; use the approved password manager and follow security and secrets handling.
Current platform summary
As of 2026-07-17, a single Proxmox host runs OPNsense VM 100 and LXCs for
rootless Podman applications, Technitium DNS, Caddy ingress, a website,
Headscale subnet routing, and RustDesk. A public VPS hosts Headscale,
Headplane, and Caddy. The exact inventory and confidence are maintained in the
current inventory.