Where martinwa.org subdomains point, and how they reach internal services.
How it works
Verified: All *.martinwa.org public hostnames are served by a single cloudflared daemon running on ct207 (webserver), tunnel name ct207-tunnel (ID 339a6757-5574-4723-a16c-da4769535caa), config at /etc/cloudflared/config.yml on ct207.
Verified:cloudflared is not installed on this host (ct460/hermes) — Hermes has no local tunnel process to manage or restart. Any tunnel-side incident (hostname down, wrong target) must be fixed on ct207, not here.
Two other Cloudflare tunnels exist in the same account (Cloudo, Ifttt-ssh-webhook, livinity-liv) but are unrelated to Hermes/ct207 and out of scope for this page.
Hostnames relevant to Hermes
Hostname
Target
Notes
hermes.martinwa.org
http://100.118.5.51:19119
Public Hermes dashboard — nginx on ct460 proxies 19119→127.0.0.1:9119
mcp-portal.martinwa.org is not present in the ct207 ingress list captured during this audit — it may be served by a different tunnel/host, or the ingress list may have moved since. Unknown, flagged for follow-up rather than guessed.
Full ct207 ingress list (context, not all Hermes-related)
The tunnel also fronts: pve.martinwa.org (Proxmox UI), docker.martinwa.org (Portainer), runtipi.martinwa.org, homar.martinwa.org, nextcloud.martinwa.org, readlater.martinwa.org, velvet.martinwa.org, overtchat.martinwa.org, freellmapi.martinwa.org, omnideb.martinwa.org, newstarter.martinwa.org, and SSH endpoints for debianvm/pve/webserver. These belong to the wider homelab, not Hermes specifically — recorded here only so an ingress diff is possible later.
History
ct207's /etc/cloudflared/ directory has ~25 dated config.yml.bak* files going back to 2026-06-18, including several during ct460's own setup (config.yml.before-hermes-ct460-20260717203530, ...before-hermes-desktop-20260718, ...before-hermesagent-20260718085557) — evidence the ingress list has been actively iterated on throughout Hermes's bring-up.