Architecture Overview
Running a modern developer portal requires combining low-latency edge delivery with extensive storage capabilities. Rather than paying exorbitant egress and storage fees on monolithic cloud providers, DenverNerd couples a hardened public Debian VPS at the edge with an internal NVMe ZFS storage cluster in the homelab.
Edge Ingress: Caddy Server
All traffic enters through Caddy, terminating TLS with automated ACME certificates:
denvernerd.com {
encode zstd gzip
reverse_proxy 127.0.0.1:5000 {
header_up X-Real-IP {remote_host}
}
}
Secure Tunneling with WireGuard
The VPS communicates with the home lab over a dedicated point-to-point WireGuard tunnel (wg0).
[Interface]
Address = 10.100.0.1/24
PrivateKey = <VPS_PRIVATE_KEY>
ListenPort = 51820
[Peer]
PublicKey = <HOMELAB_PUBLIC_KEY>
Endpoint = home.denvernerd.com:51820
AllowedIPs = 10.100.0.2/32
PersistentKeepalive = 25
Performance Benchmarks
- Tunnel Handshake Time: < 5ms
- Average Throughput: 940 Mbps over symmetric fiber
- Encrypted Round-Trip Latency: 11ms
Discussion (0)
Community Guidelines EnforcedNo community comments yet. Be the first to share your thoughts!
Join the Community Discussion
Sign in or create an account to share observations, tuning setups, and connect with other makers.