alfheim¶
alfheim is an Oracle Cloud Infrastructure ARM VM (aarch64-linux). It is the
homelab's cloud application node and runs jamye-plz.
Responsibilities¶
- Validate NixOS operation on OCI with a real service
- Run the jamye-plz full-stack PWA from its upstream flake module
- Provide a small remote node with the shared operator baseline
Public traffic still enters through yggdrasil. Caddy on yggdrasil proxies
jamye-plz.ridewithmin.com to alfheim.tail6fc192.ts.net:8080 over the
tailnet.
Loaded host-specific modules¶
modules/podman.nix
services/jamye-plz.nix
Service ports¶
| Port | Service | Public URL |
|---|---|---|
8080 |
jamye-plz full-stack PWA entrypoint | https://jamye-plz.ridewithmin.com |
9429 |
vlagent | No public exposure (tailnet-reachable via trusted interface); buffers journald logs to VictoriaLogs |
45876 |
beszel-agent | Not exposed; the agent dials the Beszel hub over the tailnet |
jamye-plz notes¶
- Upstream application code comes from the
jamye-plzflake input, currently pinned inflake.lock. services/jamye-plz.niximports the upstream NixOS module and enablesservices.jamye-plz.- The upstream module runs the frontend, backend API, local PostgreSQL database, and alfheim-local Caddy for the service.
- Secrets live in
secrets/jamye-plz.yamland are rendered intojamye-plz.envwithsops.templates. - OAuth redirect URIs and
FRONTEND_ORIGINusehttps://jamye-plz.ridewithmin.com.
Access¶
SSH is intentionally exposed only through the tailnet. The public OCI address does not accept SSH.
SSH for deploys
GitHub Actions CD uses the repository deploy key secret. A local break-glass
deploy relies on the operator's SSH client config: just and
nixos-rebuild pass the bare host name (alfheim), and an alias in
~/.ssh/config resolves it to alfheim.tail6fc192.ts.net with the right
key, the same way the other hosts are reached. The Justfile itself sets no
SSH identity or hostname.
Health checks¶
The jamye-plz-backend systemd unit runs the application backend. Caddy serves
the complete public PWA, backed by the local PostgreSQL database.
systemctl is-active jamye-plz-backend caddy postgresql
journalctl -u jamye-plz-backend -f
curl -fsS https://jamye-plz.ridewithmin.com/