Files
infrastructure/README.md
T
2026-07-19 15:07:30 +02:00

16 KiB

Infrastructure

Open source, decentralized and self-hosted infrastructure for many local services and authentication with Authelia.

Features

  • caddy 2 HTTP/S reverse proxy
  • Authelia (SSO / authentication middleware)
  • Open-WebUI + Ollama (Local chatGPT)
  • qbittorrent and transmission (Torrent client/server)
  • Docker / docker-compose
  • Homepage (Dashboard)
  • SearXNG (Self-hosted search engine)
  • Jellyfin (Eg Netflix, Disney+)
  • Forgejo (Git server, fork of Gitea)
  • Uptime Kuma (Monitoring)
  • Argus (Application update monitoring)
  • SyncThing (File synchronization)
  • Dufs (File server)
  • PsiTransfer, ProjectSend, Picoshare (File sharing)
  • it-tools, omni-tools and cyberchef (Tools for IT)
  • Privatebin
  • Memos (Note-taking)
  • Stirling PDF (PDF tools)
  • Wordpress (Via FASTCGI/caddy)
  • Dependency-Track (SBOM / vulnerability tracking)
  • Game (Satisfactory, Minecraft, 7 Days to Die, Team Fortress 2 etc...)

Architecture

Architecture

Screenshots

The homepage is a dashboard with many widgets and services.

Homepage

Installation and configuration

Requirements

List of ports used by the services in this infrastructure:

Port number Service Description
80 Caddy HTTP traffic
443 Caddy HTTPS traffic
22 Forgejo Git/SSH access
2222 OpenSSH Global SSH access
7777 Satisfactory Game server port
8888 Satisfactory Game server port
25565 Minecraft Game server port
8100 Bluemap Minecraft Web map port
26900 7 Days to Die Game server port
26901 7 Days to Die Game server port
26903 7 Days to Die Game server port
27015 Team Fortress 2 Game server port

To avoid get rate limit from letsencrypt (10 certificates per 3 hours), you need to disable some certificates in the caddyfiles and enable them 3h later...

Clone

Clone this repository to your local machine using:

git clone --recurse-submodules --remote-submodules https://github.com/bensuperpc/infrastructure.git

Go to the folder

cd infrastructure

Start the infrastructure

Start the website with:

make up

Stop the website with:

make stop

Remove containers with:

make down

Services are enabled via preset configuration files in the presets/ directory.

The active presets are declared in the Makefile via the CONFIGS variable, for example, CONFIGS := chatgpt loads presets/chatgpt.conf which activates the main_infrastructure, caddy, openssh, and openwebui profiles.

Configure the domain

For all bensuperpc.org, you need to replace it with your domain, example: mydomain.com, so the same for bensuperpc.com ect...

find . \( -type d -name .git -prune \) -o -type f -print0 | xargs -0 sed -i 's/bensuperpc.org/mydomain.com/g'

Check if all bensuperpc.* are replaced by your domain in Caddyfile

And then, caddy will generate the certificate for you and renew it automatically :D

Domain name Type Description
bensuperpc.org Main Redirect to www.bensuperpc.org
www.bensuperpc.org Main Homepage
openwebui.bensuperpc.org Sub For local chatGPT with ollama and openweb-ui
authelia.bensuperpc.org Sub Authelia for authentication
uptimekuma.bensuperpc.org Sub Uptime Kuma for monitoring
qbittorrent.bensuperpc.org Sub Torrent client/server
dozzle.bensuperpc.org Sub Dozzle for docker logs
transmission.bensuperpc.org Sub Torrent client/server
forgejo.bensuperpc.org Sub Fork of Gitea for git
git.bensuperpc.org Sub Fork of Gitea for git
jellyfin.bensuperpc.org Sub Jellyfin for media server
syncthing.bensuperpc.org Sub SyncThing for file synchronization
psitransfer.bensuperpc.org Sub PsiTransfer for file sharing
it-tools.bensuperpc.org Sub Tools for IT
omni-tools.bensuperpc.org Sub Tools for IT
privatebin.bensuperpc.org Sub Privatebin
projectsend.bensuperpc.org Sub ProjectSend for file sharing
picoshare.bensuperpc.org Sub Picoshare for file sharing
dufs.bensuperpc.org Sub Dufs for file sharing
memos.bensuperpc.org Sub Memos note-taking app
stirlingpdf.bensuperpc.org Sub Stirling PDF tools
argus.bensuperpc.org Sub Argus for monitoring application updates
searxng.bensuperpc.org Sub SearXNG self-hosted search engine
dependency-track.bensuperpc.org Sub SBOM / vulnerability analysis
litellm.bensuperpc.org Sub LiteLLM llm proxy for open-webui
localai.bensuperpc.org Sub For local chatGPT with multi-backend
wordpress.bensuperpc.org Sub Wordpress website
bentopdf.bensuperpc.org Sub BentoPDF

Configure the infrastructure

Every service ships a *.env.example file. Real *.env files are gitignored and never committed - generate them locally with:

make init

This copies every *.env.example*.env and fills in randomly generated passwords, keys and tokens (including shared values that must match across services, e.g. a service and its database). Existing .env files are never overwritten, so re-running it later is always safe.

After make init, a few things still need manual attention:

Caddy

Edit caddy.env to set your domain and mail address:

MAIN_DOMAIN=bensuperpc.org
MAIL_DOMAIN=bensuperpc@gmail.com
SCHEME=https
AUTO_HTTPS_OPTIONS=ignore_loaded_certs

Authelia - user database

make init generates all Authelia secrets automatically. users_database.yml ships with a placeholder example user (bensuperpc) - replace it with your own before starting the stack, don't just add a user next to it. Generate an argon2 hash for your password:

docker run --rm authelia/authelia:latest authelia crypto hash generate argon2 --password 'MyPassword'

Then edit the username, displayname, password hash and email fields to match.

Dozzle - user account

Generate a user entry for users.yml:

docker run -it --rm amir20/dozzle generate bensuperpc --password mypassword --email bensuperpc@gmail.com --name "bensuperpc"

OpenSSH - public key

Replace id_ed25519.pub with your own public SSH key.

Open-WebUI - Ollama model

After starting the stack, pull a model via the Open-WebUI GUI or with:

docker exec -it ollama ollama run deepseek-r1:8b

Team Fortress 2 - Steam GSLT

make init will remind you: set SRCDS_TOKEN in teamfortress2.env with your token from steamcommunity.com/dev/managegameservers.

Dependency-Track - first login

Default credentials are admin / admin - change them on first login.

Forgejo - installation lock

After the first-run installation wizard completes, set in forgejo.env:

FORGEJO__security__INSTALL_LOCK=true

Homepage

You can change the homepage config in these files:

Forgejo Runner (Out of date)

docker exec -it forgejo_runner /bin/bash
forgejo-runner generate-config > /data/config.yml

Now update the config.yml file to support docker-in-docker:

  envs:
    DOCKER_TLS_VERIFY: 1
    DOCKER_CERT_PATH: /certs/client
    DOCKER_HOST: tcp://docker:2376
  labels: ["ubuntu-latest:docker://node:20-bookworm", "ubuntu-22.04:docker://node:20-bookworm"]
  network: host
  options: -v /certs/client:/certs/client
  valid_volumes:
     - /certs/client

Register the runner with your Forgejo instance:

forgejo-runner register

You will need to provide the following information:

https://forgejo.bensuperpc.org/
<Your Registration Token, in https://forgejo.bensuperpc.org/admin/actions/runners>
ubuntu-22.04:docker://ghcr.io/catthehacker/ubuntu:act-24.04
main

Docker volumes

This infrastructure uses docker volumes to store data, all configuration/data for each service are not shared between services for security and maintenance reasons, but public_data and private_data are shared between all services to store your data.

Volume name Description
public_data Public data reachable on internet via dufs.bensuperpc.org, can be disabled.
private_data Private data

SSH access

The default port for SSH/rsync is 2222.

You can access to the server with:

ssh -p 2222 admin@bensuperpc.org

Qbittorrent

To activate the alternative webui theme (VueTorrent), you need to go in the qbittorrent settings, then in the webui section, check the Use alternative webui and add /vuetorrent to text field.

Local testing

If you want to test the infrastructure locally, you can add these lines in your /etc/hosts file:

127.0.0.1 openwebui.bensuperpc.org
127.0.0.1 authelia.bensuperpc.org
127.0.0.1 memos.bensuperpc.org
127.0.0.1 stirlingpdf.bensuperpc.org
127.0.0.1 public.bensuperpc.org
127.0.0.1 private.bensuperpc.org
127.0.0.1 jellyfin.bensuperpc.org
127.0.0.1 syncthing.bensuperpc.org
127.0.0.1 psitransfer.bensuperpc.org
127.0.0.1 projectsend.bensuperpc.org
127.0.0.1 picoshare.bensuperpc.org
127.0.0.1 dufs.bensuperpc.org
127.0.0.1 it-tools.bensuperpc.org
127.0.0.1 omni-tools.bensuperpc.org
127.0.0.1 privatebin.bensuperpc.org
127.0.0.1 forgejo.bensuperpc.org
127.0.0.1 git.bensuperpc.org
127.0.0.1 qbittorrent.bensuperpc.org
127.0.0.1 transmission.bensuperpc.org
127.0.0.1 uptimekuma.bensuperpc.org
127.0.0.1 wordpress.bensuperpc.org
127.0.0.1 searxng.bensuperpc.org
127.0.0.1 dependency-track.bensuperpc.org
127.0.0.1 homepage.bensuperpc.org

Then update the caddy.env file with your local domain to disable the letsencrypt certificate generation and auto redirect to https:

MAIN_DOMAIN=bensuperpc.org
# Scheme
SCHEME=https
# ignore_loaded_certs off
AUTO_HTTPS_OPTIONS=ignore_loaded_certs

And remove all the import authelia_middleware in the caddyfiles, authelia need https to work.

Sources

License

License