Oracle Cloud VPS
OCI ARMOracle Linux 9.8 • Hostname: haphazard-vps-oracle
Terminates all incoming public TLS traffic via Caddy (Let's Encrypt). Holds the control plane endpoint frps :7000 to receive outbound connections from home, bridging public HTTP subdomains to local & tunnelled containers.
iMac at Home
macOS SonomaUser: yjpecht • Zero Inbound Ports Open
Houses heavy workloads & media libraries. Initiates a single persistent outbound tunnel (frpc LaunchDaemon) to VPS. Home ISP block is transparently bypassed. Backup orchestrator (Backrest).
Traffic Routing Architecture & Outbound FRP Tunnel Logic
How external HTTPS requests cross CGNAT/Inbound blocks to reach home containers
Public Internet
*.haphazard.one
→ 82.70.253.152
Caddy Proxy & FRP Server
Terminates TLS (Let's Encrypt)
Single Outbound TCP
Initiated by iMac LaunchDaemon
frpc dials OUT to frps
Local Docker Apps
APFS DBs + External Media
Outbound-Only Tunnel
frpc dials out to VPS. Home IP can drift without breakage and no open router ports are required. Single point of failure if frpc dies.
Caddy Owns All TLS
Caddy handles Let's Encrypt for both local VPS and tunnelled iMac services. Zero containers deal with cert renewals or HTTPS listeners.
Plex Direct Exception
Bypasses Caddy entirely. Operates as raw TCP tunnel on port 32400 with dual-IP setting so home clients get gigabit LAN speed directly.
Parallel Admin Network
Headscale Tailnet handles all admin traffic (Dozzle, Beszel, SSH). Nothing sensitive gets a public hostname, replacing complex auth layers.