Files
agent-estate-wiki/infrastructure/network-map.md
T

66 lines
2.7 KiB
Markdown

---
title: Network Map
type: infrastructure
status: active
created: 2026-07-22
updated: 2026-07-22
verified_on: 2026-07-22
confidence: high
tags: [infrastructure, network]
sources: [raw/configs/hermes-config-sanitized.txt]
---
# Network Map
## Purpose
Where Hermes and its dependencies run, and how traffic reaches them.
## Zones
### LAN
- **Cluster host (pve):** `192.168.178.39` (Proxmox VE, kernel 6.17.4-1-pve)
- **This container (hermes, ct460):** `192.168.178.129` (DHCP, eth0)
### Tailscale (`kangaroo-eel.ts.net`)
- **pve:** `100.96.100.82`
- **hermes (ct460):** `100.118.5.51`
- **hermesagent (ct450, the original/legacy Hermes agent dashboard):** `100.98.205.112`
- **omniroute (ct600):** resolves via `omniroute.kangaroo-eel.ts.net``100.88.81.19`
- **nanobot (ct333, "clawtest"):** `100.122.189.81`
- **webserver (ct207, runs the Cloudflare Tunnel):** `100.82.40.23`
- **debianvm (VM 101):** `100.98.95.65`
- **docker host (ct200):** `100.96.150.69`
- **openweb (ct245):** `100.69.230.13`
- **nextcloud (ct270):** `100.90.102.19`
### Public (Cloudflare Tunnel)
- Origin daemon runs on **ct207 (webserver)**, not on this host. See [[systems/cloudflare-tunnel]] and [[infrastructure/domains-and-tunnels]] for the full ingress list.
- This host is reached publicly via two routes defined in that tunnel: `hermes.martinwa.org``100.118.5.51:19119` (nginx-fronted webui) and `hermes-desktop.martinwa.org``100.118.5.51:5174` (desktop companion).
## Local ports on this host (ct460)
| Port | Bind | Process | Purpose |
|---|---|---|---|
| 22 | `*` | sshd | SSH |
| 80 / [::]:80 | `*` | nginx | reverse proxy, default vhost |
| 19119 | `*` | nginx → 127.0.0.1:9119 | public Hermes webui path (tunneled) |
| 9119 | `0.0.0.0` | hermes (webui) | Hermes Web UI backend |
| 8644 / 8642 | `*` | hermes | additional Hermes agent ports |
| 5174 | `*` | node | Hermes desktop companion (tunneled as hermes-desktop.martinwa.org) |
| 9377 | `*` | node | Stratos — AI Command Centre |
| 8787 | `127.0.0.1`* | python | Hermes gateway health endpoint (see [[runbooks/update-hermes-safely]]) |
| 9099 / 8790 | `*` | python3 | auxiliary Hermes processes (unverified purpose) |
| 5901 / [::]:5901 | `*` | x11vnc | VNC on Xvfb `:99`, see [[systems/headless-server]] |
| 6080 / 6081 | `127.0.0.1` | websockify | noVNC web bridges for two VNC displays |
| 25 | `127.0.0.1` / `[::1]` | postfix | local mail transport |
\* `curl` target used in [[runbooks/update-hermes-safely]] health check; binding not independently re-verified in this pass.
## Relevant runbooks
- [[runbooks/diagnose-docker]]
- [[runbooks/recover-docker-service]]
## Related
- [[infrastructure/hosts]]
- [[infrastructure/domains-and-tunnels]]
- [[systems/cloudflare-tunnel]]