MENTIFABER BUILD LOG · 001

The Monstrosity

a bolted-together, beautifully chaotic homelab — first entry

NODE FEDORA-01
STATUS PRE-IGNITION
CLASS TINKERER'S UTILITY

Not a rented cloud tier. Not a black box you trust and forget. A stack built to be opened, understood, and grown — storage as one organ among many, routed through a proxy that thinks for itself, fronted by a door that doesn't need a thousand holes punched in it.

01
NETWORK FOUNDATION

The Private Line

  1. Cheap gigabit switch — all three machines share one private segment.
  2. Machine-to-machine traffic stays off the open internet entirely.
  3. Static local IPs or DHCP reservations, so nothing drifts on reboot.
02
MASTER NODE

Fedora & the Shared Source of Truth

  1. Fedora server stands as master node — already running, the natural anchor.
  2. Samba installed and configured on the master.
  3. Ten drives and three SSDs, scattered across boxes, pulled into one shared namespace.
  4. Naming convention decided before anything is mounted.
  5. Every share confirmed mountable from the other two machines before moving on.
Open thread — drive labeling scheme not yet fixed. Resolve before Phase 02 closes.
03
ORCHESTRATION

Docker, So Nothing Clashes

  1. Docker + Compose installed on the master node.
  2. Every service its own container — start, stop, kill independently.
  3. First tenants: NextCloud, and whatever Weaver / Muse currently expose as a WebUI.
  4. Shared or per-stack Docker networks — containers talk to each other without bleeding ports onto the host.
04
ROUTING

Traefik — Set It and Forget It

  1. Traefik Community Edition, deployed as its own container.
  2. Watches the Docker socket. New containers get routed the moment their labels appear.
  3. No manual proxy edits, ever, per new module.
  4. Internal-only services resolved via local DNS or hosts entries — never exposed further than they need to be.
05
EXTERNAL ACCESS

Cloudflare Tunnel — The Front Door

  1. Tunnel runs on the Fedora node. No inbound ports opened on the home firewall, full stop.
  2. Only services that need external reach are routed through it — everything else stays LAN-bound.
Trade-off — Cloudflare sits in the middle of that traffic. Fine for convenience now. Worth revisiting if fully independent external access ever outweighs the ease of it.

Troubleshooting the Monstrosity

A drive goes dark — Check dmesg / journalctl -k for disconnect errors first. Usually power or cable, before it's ever filesystem.
Samba share won't answer — Confirm smb is running, check the firewall isn't blocking the LAN subnet, recheck share permissions.
A container won't rise — docker logs before anything else. Then ask whether Traefik never saw it, or it crashed on its own.
Traefik ignores a new service — Confirm the container shares Traefik's network, and that every label is typed exactly right. They fail silently.
The tunnel drops — Check cloudflared's status and logs. Tunnels disconnect quietly on network blips.
General law — Isolate the layer before you debug it. Drive, share, container, proxy, tunnel — each keeps its own logs. Never guess across layers.

Ignition Sequence