Docker homelab architecture

Docker homelab architecture An architecture diagram generated by Archify. Clients · LAN and Internet · Architecture component Clients LAN and Internet Cloudflare Tunnel · Optional public ingress · Architecture component Cloudflare Tunnel Optional public ingress Remote access · Headscale / WireGuard / NetBird · Architecture component Remote access Headscale / WireGuard / NetBird Caddy · Reverse proxy :80 / :443 · Docker host › Ingress networks Caddy Reverse proxy :80 / :443 Application stacks · Isolated Compose projects · Docker host › Ingress networks Application stacks Isolated Compose projects Shared services · DNS / mail / storage / AI · Docker host Shared services DNS / mail / storage / AI Gluetun · Selected container egress · Docker host Gluetun Selected container egress Internet · Outbound providers · Architecture component Internet Outbound providers Observability · Prometheus / Loki / Grafana · Docker host Observability Prometheus / Loki / Grafana Operations · Portainer / updates / backup · Docker host Operations Portainer / updates / backup HTTPS tunnel local HTTP(S) VPN / mesh private access hostname routing DNS / SMTP / S3 / models selected egress VPN provider metrics / logs / probes manage / update / back up Docker host Ingress networks Legend Backend Cloud Security External

Ingress

  • • Caddy is the common HTTP(S) entry point
  • • Public tunnel and private network paths stay distinct

Isolation

  • • Each stack remains an independent Compose project
  • • Shared networks are opt-in contracts

Operations

  • • Telemetry observes workloads
  • • Management and backup tools act on selected stacks