Current dependency map
Last verified: 2026-07-17.
flowchart TD
Power --> PVE["Proxmox pve"]
Network["Switching / WAN"] --> PVE
PVE --> FW["OPNsense VM 100"]
FW --> DNS["CT 102 Technitium"]
FW --> Ingress["CT 103 Caddy"]
FW --> Apps["CT 101 Podman"]
FW --> TS["CT 105 ts-router"]
VPS["ovps-me Headscale"] --> TS
DNS --> Apps
DNS --> Ingress
Apps --> PG["PostgreSQL"]
PG --> Forgejo
PG --> Vaultwarden
Forgejo --> Runner
Runner --> Publish["runner-data publish directory"]
Publish --> Static["docs-static :30084"]
Ingress --> Static
Failure domains and recovery priority
| Priority | Dependency | Consumers | Failure effect |
|---|---|---|---|
| 1 | Power, switching, WAN | All systems | Broad outage |
| 2 | Proxmox and local storage | OPNsense and all on-premises LXCs | Broad on-premises outage |
| 3 | OPNsense | LAN/DMZ routing and policy | Routed access and internet failure |
| 4 | Technitium | Client and service name resolution | Name-based access and package operations fail |
| 4 | Headscale/CT 105 |
Remote subnet access | Tailnet route unavailable |
| 5 | Caddy ingress | Published HTTP services | HTTPS routes fail; direct backends may remain healthy |
| 6 | CT 101 / PostgreSQL |
Hosted applications | Application/data outage |
| 7 | Forgejo runner/publish volume | CI publication | New builds stop; existing static content remains |
Documentation publishing flow
Forgejo Actions depends on the runner, rootless Podman job execution, external
DNS for package installation, and a valid bind mount for runner-data. Serving
depends only on the last published artifact, docs-static, CT 101
reachability, and CT 103 ingress. This is why a failed build can coexist with
a healthy but stale website.
Use publishing architecture for exact paths and publishing troubleshooting for ordered checks.