Skip to main content

8 docs tagged with "networking"

View all tags

AdGuard Home

Network-wide DNS ad-blocker — every device on the home LAN points at it for resolution, ads and trackers never make it past the gateway.

app-network-policy (component)

Reusable Kustomize component that drops a baseline `NetworkPolicy` into every app's namespace — default-deny ingress + egress, with explicit allow-rules for what the app actually needs to talk to.

Cilium

eBPF-based CNI providing pod networking, kube-proxy replacement, network policy, WireGuard node-to-node encryption, L2 announcements for LoadBalancer IPs, and Hubble flow visibility.

ddclient

Dynamic DNS updater — keeps the public DNS records for the homelab in sync with the WAN IP, even when the ISP rotates it.

http-internal (resource)

Shared cluster resource that defines the internal `HTTPRoute` parent — the Gateway that internal-only apps attach to so their hostnames resolve on the home/mesh side without ever being routed publicly.

NetBird agent (Maresa)

NetBird peer running on the Maresa Synology host so the NAS is reachable over the mesh — Syncthing, AdGuard, and the Traefik dashboard all available to authenticated mesh members.

Traefik (Maresa)

Local reverse proxy + TLS terminator on the Maresa Synology host — exposes the host-local services (Syncthing UI, AdGuard UI, Traefik dashboard) on the internal *.maresa.int.kueber.eu zone with Let's Encrypt certs.