443 lines
5.4 KiB
Markdown
443 lines
5.4 KiB
Markdown
# Server Information
|
||
|
||
## Overview
|
||
|
||
SilverLinux is the primary self-hosted infrastructure server for Silver Solutions.
|
||
|
||
The server hosts source control, project management, collaboration, communication and supporting infrastructure services.
|
||
|
||
---
|
||
|
||
## Host Information
|
||
|
||
| Property | Value |
|
||
| ---------------- | ----------------------- |
|
||
| Hostname | silverlinux |
|
||
| Provider | OVH |
|
||
| Operating System | Ubuntu Server 24.04 LTS |
|
||
| Public IP | 51.255.83.140 |
|
||
|
||
---
|
||
|
||
## Hardware
|
||
|
||
| Resource | Value |
|
||
| -------- | -------------------- |
|
||
| CPU | Intel Xeon-D 1520 |
|
||
| Memory | 32 GB RAM |
|
||
| Storage | 2 × 480 GB SSD RAID1 |
|
||
|
||
---
|
||
|
||
## Installed Software
|
||
|
||
### Docker
|
||
|
||
Purpose:
|
||
|
||
* Container hosting
|
||
* Service isolation
|
||
* Deployment management
|
||
|
||
### Docker Compose
|
||
|
||
Purpose:
|
||
|
||
* Multi-container application deployment
|
||
* Service management
|
||
|
||
### PostgreSQL
|
||
|
||
Purpose:
|
||
|
||
* Primary PostgreSQL database platform
|
||
|
||
### Microsoft SQL Server Express
|
||
|
||
Purpose:
|
||
|
||
* Private SQL Server platform for compatible applications
|
||
|
||
### Fail2Ban
|
||
|
||
Purpose:
|
||
|
||
* SSH brute-force protection
|
||
|
||
### UFW
|
||
|
||
Purpose:
|
||
|
||
* Firewall management
|
||
|
||
### Monitoring Stack
|
||
|
||
Purpose:
|
||
|
||
* Metrics collection
|
||
* Monitoring dashboards
|
||
* Host metrics
|
||
* Docker container metrics
|
||
|
||
---
|
||
|
||
## Docker Networks
|
||
|
||
### internal
|
||
|
||
Purpose:
|
||
|
||
Private communication between services.
|
||
|
||
Examples:
|
||
|
||
* Gitea → PostgreSQL
|
||
* OpenProject → PostgreSQL
|
||
|
||
---
|
||
|
||
### proxy
|
||
|
||
Purpose:
|
||
|
||
Public-facing services behind Nginx Proxy Manager.
|
||
|
||
Examples:
|
||
|
||
* Gitea
|
||
* OpenProject
|
||
* Jitsi Meet
|
||
* Portainer
|
||
* DbGate
|
||
|
||
---
|
||
|
||
### jitsi-docker-jitsi-meet-aa76415_meet.jitsi
|
||
|
||
Purpose:
|
||
|
||
Isolated Jitsi communication cluster.
|
||
|
||
Examples:
|
||
|
||
* jitsi-web
|
||
* jitsi-jvb
|
||
* jitsi-jicofo
|
||
* jitsi-prosody
|
||
|
||
---
|
||
|
||
### xray_default
|
||
|
||
Purpose:
|
||
|
||
Compose-created tunneling and connectivity network for Xray.
|
||
|
||
Examples:
|
||
|
||
* No running containers were attached in the 2026-06-24 runtime snapshot
|
||
|
||
---
|
||
|
||
### gitea-runner_default
|
||
|
||
Purpose:
|
||
|
||
Default Compose network for the Gitea Actions runner stack.
|
||
|
||
Examples:
|
||
|
||
* gitea-runner
|
||
|
||
---
|
||
|
||
## Running Services
|
||
|
||
* PostgreSQL
|
||
* Gitea
|
||
* OpenProject
|
||
* Jitsi Meet
|
||
* Portainer
|
||
* Nginx Proxy Manager
|
||
* BaGet
|
||
* Gitea Actions Runner
|
||
* Microsoft SQL Server 2022 Express
|
||
* DbGate
|
||
* Xray
|
||
* Prometheus
|
||
* Grafana
|
||
* Node Exporter
|
||
* cAdvisor
|
||
|
||
---
|
||
|
||
## Directory Structure
|
||
|
||
### Docker Services
|
||
|
||
```text
|
||
/srv/docker
|
||
```
|
||
|
||
Contains:
|
||
|
||
```text
|
||
/srv/docker/gitea
|
||
/srv/docker/openproject
|
||
/srv/docker/postgres
|
||
/srv/docker/jitsi
|
||
/srv/docker/portainer
|
||
/srv/docker/nginx-proxy-manager
|
||
/srv/docker/baget
|
||
/srv/docker/gitea-runner
|
||
/srv/docker/mssql
|
||
/srv/docker/dbgate
|
||
/srv/docker/xray
|
||
/srv/docker/monitoring
|
||
```
|
||
|
||
---
|
||
|
||
### Shared Secrets
|
||
|
||
```text
|
||
/srv/secrets/company.env
|
||
```
|
||
|
||
Contains:
|
||
|
||
* SMTP credentials
|
||
* Database passwords
|
||
* Application secrets
|
||
* MSSQL SA password
|
||
* Future DbGate password
|
||
* Future OAuth credentials
|
||
|
||
---
|
||
|
||
### Backups
|
||
|
||
```text
|
||
/srv/backups
|
||
```
|
||
|
||
Suggested structure:
|
||
|
||
```text
|
||
/srv/backups/daily
|
||
/srv/backups/weekly
|
||
/srv/backups/monthly
|
||
```
|
||
|
||
---
|
||
|
||
## Service Data Locations
|
||
|
||
### Gitea
|
||
|
||
```text
|
||
/srv/docker/gitea/data
|
||
```
|
||
|
||
---
|
||
|
||
### OpenProject
|
||
|
||
```text
|
||
/srv/docker/openproject/assets
|
||
```
|
||
|
||
---
|
||
|
||
### PostgreSQL
|
||
|
||
```text
|
||
/srv/docker/postgres/data
|
||
```
|
||
|
||
---
|
||
|
||
### Microsoft SQL Server Express
|
||
|
||
```text
|
||
/srv/docker/mssql/data
|
||
```
|
||
|
||
---
|
||
|
||
### DbGate
|
||
|
||
```text
|
||
/srv/docker/dbgate/data
|
||
```
|
||
|
||
---
|
||
|
||
### Nginx Proxy Manager
|
||
|
||
```text
|
||
/srv/docker/nginx-proxy-manager/data
|
||
/srv/docker/nginx-proxy-manager/letsencrypt
|
||
```
|
||
|
||
---
|
||
|
||
### Jitsi
|
||
|
||
```text
|
||
/srv/docker/jitsi
|
||
```
|
||
|
||
---
|
||
|
||
### BaGet
|
||
|
||
```text
|
||
/srv/docker/baget/data
|
||
```
|
||
|
||
---
|
||
|
||
### Gitea Actions Runner
|
||
|
||
```text
|
||
/srv/docker/gitea-runner
|
||
```
|
||
|
||
Runner:
|
||
|
||
```text
|
||
silverlinux-runner
|
||
```
|
||
|
||
---
|
||
|
||
### Xray
|
||
|
||
```text
|
||
/srv/docker/xray
|
||
```
|
||
|
||
Network:
|
||
|
||
```text
|
||
proxy
|
||
```
|
||
|
||
Published port:
|
||
|
||
```text
|
||
0.0.0.0:32443 -> 8080/tcp
|
||
```
|
||
|
||
Image:
|
||
|
||
```text
|
||
ghcr.io/xtls/xray-core:latest
|
||
```
|
||
|
||
Runtime note:
|
||
|
||
The `xray_default` network exists, but the running `xray` container was attached only to `proxy` in the 2026-06-24 runtime snapshot.
|
||
|
||
---
|
||
|
||
### Monitoring Stack
|
||
|
||
```text
|
||
/srv/docker/monitoring
|
||
```
|
||
|
||
Components:
|
||
|
||
* Prometheus
|
||
* Grafana
|
||
* Node Exporter
|
||
* cAdvisor
|
||
|
||
Validated:
|
||
|
||
* Prometheus targets
|
||
* Grafana Prometheus datasource
|
||
* Backup metrics
|
||
* Host metrics
|
||
* Docker metrics
|
||
|
||
---
|
||
|
||
## SSH Access
|
||
|
||
Primary user:
|
||
|
||
```text
|
||
ubuntu
|
||
```
|
||
|
||
Authentication:
|
||
|
||
* SSH key authentication
|
||
* Root login disabled
|
||
|
||
---
|
||
|
||
## Security
|
||
|
||
Implemented:
|
||
|
||
* UFW enabled
|
||
* Fail2Ban enabled
|
||
* Shared secrets stored outside Git repositories
|
||
* SSL certificates managed through Nginx Proxy Manager
|
||
* PostgreSQL not exposed publicly
|
||
* MSSQL port 1433 not exposed publicly
|
||
* Database administration is available only through authenticated HTTPS access to DbGate
|
||
* Xray is not attached to the private database network and is monitored as a tunneling endpoint
|
||
* OpenID disabled in Gitea
|
||
|
||
---
|
||
|
||
## Email
|
||
|
||
Sender address:
|
||
|
||
```text
|
||
noreply@silveressence.net
|
||
```
|
||
|
||
SMTP credentials are stored in:
|
||
|
||
```text
|
||
/srv/secrets/company.env
|
||
```
|
||
|
||
Used by:
|
||
|
||
* Gitea
|
||
* OpenProject
|
||
|
||
---
|
||
|
||
## Disaster Recovery
|
||
|
||
This repository should contain enough information to rebuild the SilverLinux environment from scratch.
|
||
|
||
Recovery priorities:
|
||
|
||
1. Restore secrets
|
||
2. Restore PostgreSQL
|
||
3. Restore Nginx Proxy Manager
|
||
4. Restore Gitea
|
||
5. Restore OpenProject
|
||
6. Restore remaining services
|
||
|
||
---
|
||
|
||
## Related Documentation
|
||
|
||
* docs/secrets.md
|
||
* docs/security.md
|
||
* docs/backups.md
|
||
* docs/services.md
|
||
* docs/network.md
|
||
* docs/domains.md
|