Files
infra/sites/README.md
znetsixe 8ab9061983 scaffold: hub-and-spoke layout, 4-network topology, 13 stack stubs
Initial structure for R&D infrastructure:

- stacks/ — 13 reusable, runnable stack stubs (kebab-case)
  cloud-and-edge: node-red, influxdb, grafana, keycloak, portainer,
                  nginx-proxy, mqtt, postfix
  cloud-only:     wireguard-server, gitea, jenkins, sql (postgres stub)
  edge-only:      wireguard-client

- cloud/ — single central hub composition with 4 networks
           (edge, app, data internal, mgmt) and include: stubs
- sites/ — per-plant edge folders (template README only for now)
- docs/architecture.md — hub-and-spoke + ingress + segmentation rationale

Network model: only nginx-proxy (80/443/8883) and wireguard-server
(51820/udp) publish ports on the cloud host. Edge nginx publishes
80/443 on plant-LAN interface only. MQTT cloud-side via nginx stream
proxy; MQTT edge-side internal-only; Postfix outbound-only.

OT layer (OPCUA, PLCs) is out of scope for this repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-21 12:37:59 +02:00

1.5 KiB

sites

Per-plant edge deployments. One folder per physical site.

Convention

sites/<plant>/
├── compose.yml      # include: ../../stacks/...
├── .env.example     # committed; copy to .env locally
└── README.md        # site-specific notes (IPs, LAN ranges, ops contact)

The folder name is kebab-case and matches the plant's short name (e.g. nieuwveer, bath, waalwijk).

What runs at an edge

nginx-proxy, wireguard-client, keycloak, portainer, influxdb, grafana, node-red, mqtt, postfix. Cloud-only services (gitea, jenkins, sql, wireguard-server) are not deployed at edges.

Networks (mirrors cloud, plant-LAN-facing)

Network Notes
edge nginx-proxy, bound to the plant-LAN interface only
app nginx-proxy, mqtt, postfix, node-red, grafana, keycloak, wireguard-client
data influxdb, grafana (internal: true)
mgmt portainer, keycloak, wireguard-client

Ingress at edge

Port Container Bound to
tcp/80, 443 nginx-proxy plant-LAN interface only

The wireguard-client publishes nothing — it dials out to the cloud server.

Creating a new site

  1. cp -r <existing-site> sites/<new-plant> (or scaffold by hand).
  2. Edit compose.yml for any site-specific overrides.
  3. Edit .env.example and copy to .env with real values.
  4. Deploy: cd sites/<new-plant> && docker compose up -d.

See ../docs/architecture.md for the full design rationale.