Files
infra/sites/README.md
znetsixe 8ab9061983 scaffold: hub-and-spoke layout, 4-network topology, 13 stack stubs
Initial structure for R&D infrastructure:

- stacks/ — 13 reusable, runnable stack stubs (kebab-case)
  cloud-and-edge: node-red, influxdb, grafana, keycloak, portainer,
                  nginx-proxy, mqtt, postfix
  cloud-only:     wireguard-server, gitea, jenkins, sql (postgres stub)
  edge-only:      wireguard-client

- cloud/ — single central hub composition with 4 networks
           (edge, app, data internal, mgmt) and include: stubs
- sites/ — per-plant edge folders (template README only for now)
- docs/architecture.md — hub-and-spoke + ingress + segmentation rationale

Network model: only nginx-proxy (80/443/8883) and wireguard-server
(51820/udp) publish ports on the cloud host. Edge nginx publishes
80/443 on plant-LAN interface only. MQTT cloud-side via nginx stream
proxy; MQTT edge-side internal-only; Postfix outbound-only.

OT layer (OPCUA, PLCs) is out of scope for this repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-21 12:37:59 +02:00

45 lines
1.5 KiB
Markdown

# sites
Per-plant edge deployments. One folder per physical site.
## Convention
```
sites/<plant>/
├── compose.yml # include: ../../stacks/...
├── .env.example # committed; copy to .env locally
└── README.md # site-specific notes (IPs, LAN ranges, ops contact)
```
The folder name is **kebab-case** and matches the plant's short name (e.g. `nieuwveer`, `bath`, `waalwijk`).
## What runs at an edge
nginx-proxy, wireguard-client, keycloak, portainer, influxdb, grafana, node-red, mqtt, postfix. Cloud-only services (gitea, jenkins, sql, wireguard-server) are not deployed at edges.
## Networks (mirrors cloud, plant-LAN-facing)
| Network | Notes |
|---|---|
| `edge` | nginx-proxy, bound to the plant-LAN interface only |
| `app` | nginx-proxy, mqtt, postfix, node-red, grafana, keycloak, wireguard-client |
| `data` | influxdb, grafana (`internal: true`) |
| `mgmt` | portainer, keycloak, wireguard-client |
## Ingress at edge
| Port | Container | Bound to |
|---|---|---|
| tcp/80, 443 | nginx-proxy | plant-LAN interface only |
The wireguard-client publishes nothing — it dials out to the cloud server.
## Creating a new site
1. `cp -r <existing-site> sites/<new-plant>` (or scaffold by hand).
2. Edit `compose.yml` for any site-specific overrides.
3. Edit `.env.example` and copy to `.env` with real values.
4. Deploy: `cd sites/<new-plant> && docker compose up -d`.
See [`../docs/architecture.md`](../docs/architecture.md) for the full design rationale.