66 lines
2.7 KiB
Markdown
66 lines
2.7 KiB
Markdown
---
|
|
title: Network Map
|
|
type: infrastructure
|
|
status: active
|
|
created: 2026-07-22
|
|
updated: 2026-07-22
|
|
verified_on: 2026-07-22
|
|
confidence: high
|
|
tags: [infrastructure, network]
|
|
sources: [raw/configs/hermes-config-sanitized.txt]
|
|
---
|
|
|
|
# Network Map
|
|
|
|
## Purpose
|
|
Where Hermes and its dependencies run, and how traffic reaches them.
|
|
|
|
## Zones
|
|
|
|
### LAN
|
|
- **Cluster host (pve):** `192.168.178.39` (Proxmox VE, kernel 6.17.4-1-pve)
|
|
- **This container (hermes, ct460):** `192.168.178.129` (DHCP, eth0)
|
|
|
|
### Tailscale (`kangaroo-eel.ts.net`)
|
|
- **pve:** `100.96.100.82`
|
|
- **hermes (ct460):** `100.118.5.51`
|
|
- **hermesagent (ct450, the original/legacy Hermes agent dashboard):** `100.98.205.112`
|
|
- **omniroute (ct600):** resolves via `omniroute.kangaroo-eel.ts.net` → `100.88.81.19`
|
|
- **nanobot (ct333, "clawtest"):** `100.122.189.81`
|
|
- **webserver (ct207, runs the Cloudflare Tunnel):** `100.82.40.23`
|
|
- **debianvm (VM 101):** `100.98.95.65`
|
|
- **docker host (ct200):** `100.96.150.69`
|
|
- **openweb (ct245):** `100.69.230.13`
|
|
- **nextcloud (ct270):** `100.90.102.19`
|
|
|
|
### Public (Cloudflare Tunnel)
|
|
- Origin daemon runs on **ct207 (webserver)**, not on this host. See [[systems/cloudflare-tunnel]] and [[infrastructure/domains-and-tunnels]] for the full ingress list.
|
|
- This host is reached publicly via two routes defined in that tunnel: `hermes.martinwa.org` → `100.118.5.51:19119` (nginx-fronted webui) and `hermes-desktop.martinwa.org` → `100.118.5.51:5174` (desktop companion).
|
|
|
|
## Local ports on this host (ct460)
|
|
| Port | Bind | Process | Purpose |
|
|
|---|---|---|---|
|
|
| 22 | `*` | sshd | SSH |
|
|
| 80 / [::]:80 | `*` | nginx | reverse proxy, default vhost |
|
|
| 19119 | `*` | nginx → 127.0.0.1:9119 | public Hermes webui path (tunneled) |
|
|
| 9119 | `0.0.0.0` | hermes (webui) | Hermes Web UI backend |
|
|
| 8644 / 8642 | `*` | hermes | additional Hermes agent ports |
|
|
| 5174 | `*` | node | Hermes desktop companion (tunneled as hermes-desktop.martinwa.org) |
|
|
| 9377 | `*` | node | Stratos — AI Command Centre |
|
|
| 8787 | `127.0.0.1`* | python | Hermes gateway health endpoint (see [[runbooks/update-hermes-safely]]) |
|
|
| 9099 / 8790 | `*` | python3 | auxiliary Hermes processes (unverified purpose) |
|
|
| 5901 / [::]:5901 | `*` | x11vnc | VNC on Xvfb `:99`, see [[systems/headless-server]] |
|
|
| 6080 / 6081 | `127.0.0.1` | websockify | noVNC web bridges for two VNC displays |
|
|
| 25 | `127.0.0.1` / `[::1]` | postfix | local mail transport |
|
|
|
|
\* `curl` target used in [[runbooks/update-hermes-safely]] health check; binding not independently re-verified in this pass.
|
|
|
|
## Relevant runbooks
|
|
- [[runbooks/diagnose-docker]]
|
|
- [[runbooks/recover-docker-service]]
|
|
|
|
## Related
|
|
- [[infrastructure/hosts]]
|
|
- [[infrastructure/domains-and-tunnels]]
|
|
- [[systems/cloudflare-tunnel]]
|