INFRASTRUCTURE

The systems behind CastleRock.

A practical environment spanning routing, switching, wireless access, virtualization, container services, network storage, and secure remote access.

NETWORK ARCHITECTURE

UniFi routing, switching, and wireless

The network supports a three-floor home environment while separating trusted clients from IoT devices and keeping remote administration behind VPN access.

GATEWAY

UniFi Dream Machine (UDM)

Routing, firewall policy, DHCP, VPN access, and VLAN control.

SWITCHING

UniFi USW 24 non-PoE switch

Central wired connectivity for endpoints and access-point uplinks.

WIRELESS

Multi-floor access points

U6 Lite and U7 Lite access points provide distributed coverage, with wireless expansion planned as needs change.

SEGMENTATION

Trusted and IoT networks

Separate VLANs reduce unnecessary access between personal systems and connected devices; mDNS is enabled only where discovery is required.

Sanitized UniFi topology showing the UDM Pro, USW 24 switch, and wireless access points
Live infrastructure evidence: Sanitized UniFi topology showing the UDM Pro gateway, USW 24 non-PoE switch, and wireless access points.

PROXMOX

CastleRock compute platform

Proxmox VE hosts Linux container infrastructure and centralizes compute, networking, storage mounts, maintenance, and recovery.

Host CastleRock
Platform Proxmox VE
Workloads Linux LXC and Docker services
Operations Updates, mounts, networking, lifecycle management, and incident recovery
Sanitized Proxmox console showing a Docker Compose application stack restarting successfully
Operational evidence: A sanitized Proxmox console view showing a Docker Compose stack recreated and returned to service. Internal addressing and storage paths are excluded.

STORAGE

NAS-backed application data

Synology and QNAP systems provide centralized storage for media, backups, photo libraries, and application data.

Synology NAS

SMB/CIFS shares support music, media services, home directories, and Sims backup workflows.

PhotoVault QNAP

Dedicated storage for the Virginia photo environment with separate users, groups, and capacity planning.

Dependency management

Persistent mounts, permissions, reachability, and startup dependencies are documented because storage availability directly affects hosted services.

DOCKER

Containerized service operations

Application stacks are managed through Docker and Portainer, with supporting proxy, database, cache, media, monitoring, and file-management services.

Immich Nginx Proxy Manager Plex Portainer FileBrowser PostgreSQL Valkey/Redis Machine Learning WUD Pushover

SECURITY

Access is narrow by design.

The public portfolio describes the lab; it is not hosted inside the lab and cannot reach internal management systems.

01

Firewall separation

Traffic between network zones is limited according to device and service needs.

02

Private administration

Hypervisor, NAS, network management, and dashboards are not exposed publicly.

03

Controlled publishing

Approved applications use HTTPS through a reverse proxy rather than direct management access.

04

Documentation hygiene

Public diagrams omit real addressing, credentials, serial numbers, and sensitive rules.