# Hosts

> The machines in the fleet, and what each of them is for.

---

LLMS index: [llms.txt](/llms.txt)

---

## Users

### Leyla

primary maintainer of the repository

### Eve

user of the repository

## Fleet

### Archipelago

primary fleet managed by this repository

## Host map

|  Hostname   |    Device Description    | Primary User |   Role   |     Fleet     | Provisioned | Using Nix |
| :---------: | :----------------------: | :----------: | :------: | :-----------: | :---------: | :-------: |
| `twilight`  |     Desktop Computer     |   `leyla`    | Desktop  | `archipelago` |     ✅      |    ✅     |
|  `horizon`  | 13 inch Framework Laptop |   `leyla`    |  Laptop  | `archipelago` |     ✅      |    ✅     |
|   `ceder`   |        A5 Tablet         |   `leyla`    |  Tablet  | `archipelago` |     ✅      |    ❌     |
|   `skate`   |        A6 Tablet         |   `leyla`    |  Tablet  | `archipelago` |     ❌      |    ❌     |
|   `coven`   |         Pixel 10         |   `leyla`    | Android  | `archipelago` |     ✅      |    ❌     |
|  `beacon`   |    Public VPS (blog)     |   `leyla`    |  Server  | `archipelago` |     ✅      |    ✅     |
|  `defiant`  |        NAS Server        |   `leyla`    |  Server  | `archipelago` |     ✅      |    ✅     |
|  `wolfram`  |        Steam Deck        |   `house`    | Handheld | `archipelago` |     ✅      |    ❌     |
| `hesperium` |           Mac            |   `house`    |   Mac    | `archipelago` |     ❌      |    ❌     |
| `emergent`  |     Desktop Computer     |    `eve`     | Desktop  | `archipelago` |     ✅      |    ✅     |
| `threshold` |          Laptop          |    `eve`     |  Laptop  | `archipelago` |     ❌      |    ❌     |
|   `shale`   |        A6 Tablet         |    `eve`     |  Tablet  | `archipelago` |     ✅      |    ❌     |

## Notes

### `beacon`

Beacon is a very small VPS intended to be used as a network gateway. It provides
outbound proxies to any publicly accessible services as well as acts as a
coordinator for a VPN able to connect other devices together behind a secure
proxy. It also hosts a few static services as well as provides public use
proxies for privacy preservation tools to help the public get fair access to
freedom to access information via tor (and soon i2p).

SSH answers on port 22222 instead of the standard 22 so that 22 can be bound to
a proxy to defiant so that there is no need to set a port when accessing the git
server's content.

`beacon` holds a tls certificate for each of the public names.`defiant` holds a wildcard certificate is a key for every name under the zone so that domains only reachable from inside the lan or the vpn don't have their domains exposed.

Beacon serves the dns zone that certificate challenges are answered from
(`_acme-challenge.jan-leila.com`), and lets defiant write its proof of identify into over the
vpn when it renews the wildcard. This would let `beacon` answer challenges on its own so the wildcard so the public zone is told who may be issued; see the certificates section of
[administration](../administration/README.md).

Also provides a ntfy server, but this should probably be moved to defiant and
simply proxied through this device.

A critical part of the design of this application is that all data that is on it
is considered to be somewhat accessible by rogue actors. This means that no
information in this device can be private, it must at most be secret. Any
information on this device that is allowed to be secret should be
interchangeable with any other word of information, whose exact makeup is not
relevant, as long as it represents a valid state.

### `defiant`

The server backbone of the household. Provides services used for things all
around the house such as tools, storage, compute, and other various services.
