How it works

Four steps connect you to an application.

The homelab keeps public, private, and administrative access separate. Applications join only the networks they need.

  1. You request a service.

    You use a public hostname, a private network, or an administrator connection.

  2. The access layer checks the route.

    Cloudflare handles public entry. Private connections stay on the private network.

  3. Caddy sends the request to one application.

    Separate ingress networks limit which applications can receive each kind of request.

  4. Shared services support the application.

    Dedicated networks connect storage, databases, downloads, AI tools, and monitoring without exposing them publicly.

Explore the complete map

Use the interactive topology to trace relationships, search for a service, or isolate one part of the system.

Open the topology