Skip to main content

Interactive Nabla architecture

AI platform, homelab services, functional dependencies, and observable integrations.

The page starts with foundations and components with the largest blast radius before leaf applications. The detailed view then keeps the complete relationship graph declared in nabla-compose.

Operations and troubleshooting

One read-only snapshot of FastAPI runtime, dependency health, TrueNAS, pfSense and Cloudflare evidence. Start here to identify the failing layer before changing configuration.

Refreshing evidence…
Refreshing evidence…

Impact and root-cause inspector

Select a service to separate local health, observed blocked_by causes, and structural blast radius across required topology relations.

Architecture health and filters

Services stay first; filters use operator presentation roles while the complete topology remains the basis for dependency criticality and blast-radius calculations.

Refreshing…

72 declared services shown of 72

1 · Services & experimentsPrimary homelab outcomes: track service availability, errors, latency and traffic.RED49 components49 need attention
Garage

Garage

Unknown

Garage WebUI exposed through Cloudflare Tunnel directly to the LAN-bound :3909 origin without Traefik.

Nexus

Nexus

Unknown

Sonatype Nexus Repository

AdGuard Home

AdGuard Home

Unknown

Network-wide ad blocking

Affine

Affine

Unknown

Knowledge base and notes

AnythingLLM

AnythingLLM

Unknown

Private LLM workspace and RAG

AnythingLLM - albandrieu

AnythingLLM - albandrieu

Unknown

Private LLM workspace and RAG

ConvertX

ConvertX

Unknown

File conversion service

DDNS Updater

DDNS Updater

Unknown

Dynamic DNS updates

Domain Watchdog

Domain Watchdog

Unknown

Domain monitoring service

Heimdall

Heimdall

Unknown

Application dashboard

Hello

Hello

Unknown

Hello World NGINX service

Home

Home

Unknown

Gateway admin UI (home hostname)

IT Tools

IT Tools

Unknown

Developer utilities collection

KaraKeep

KaraKeep

Unknown

Karaoke management

Language Tool

Language Tool

Unknown

languagetool

Lidarr

Lidarr

Unknown

Music collection manager

LiteLLM - albandrieu

LiteLLM - albandrieu

Unknown

LLM proxy and gateway

LocalAI (GPU)

LocalAI (GPU)

Unknown

Local AI models (GPU instance)

NetAlertX

NetAlertX

Unknown

Network presence and alerts

Netbootxyz

Netbootxyz

Unknown

Network boot utility

Ollama (GPU)

Ollama (GPU)

Unknown

Large language models (GPU instance)

Open SpeedTest

Open SpeedTest

Unknown

Open SpeedTest - Network speed testing

Open WebUI

Open WebUI

Unknown

Web interface for chat models

OpenArchiver

OpenArchiver

Unknown

Archive management

Paperless AI

Paperless AI

Unknown

Document management with AI

Paperless-ngx

Paperless-ngx

Unknown

Document management system

pgAdmin

pgAdmin

Unknown

PostgreSQL administration

Plumber

Plumber

Unknown

GitLab Security check

Plumber API

Plumber API

Unknown

GitLab Security check

Portainer

Portainer

Unknown

Container management

PortTracker

PortTracker

Unknown

Port tracking service

PortTracker - albandrieu

PortTracker - albandrieu

Unknown

Port tracking service

Prometheus - albandrieu

Prometheus - albandrieu

Unknown

Prometheus

Radarr

Radarr

Unknown

Movie collection manager

Reactive Resume

Reactive Resume

Unknown

Reactive Resume

Reactive Resume - albandrieu

Reactive Resume - albandrieu

Unknown

Reactive Resume

Scrutiny Collector - albandrieu

Scrutiny Collector - albandrieu

Unknown

Workstation SMART collector posting disk telemetry to the Scrutiny Web/API hosted on TrueNAS.

Web service
Sonarr

Sonarr

Unknown

TV series management

Speedtest Tracker

Speedtest Tracker

Unknown

Speedtest

Stirling PDF - albandrieu

Stirling PDF - albandrieu

Unknown

PDF toolkit

Transmission

Transmission

Unknown

BitTorrent client

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
2 · Critical core platformFoundations whose failure can remove a whole layer: track availability, quorum/readiness, pressure, capacity and errors.USE2 components2 need attention
TrueNAS

TrueNAS

Unknown

Storage management UI

pfSense

pfSense

Unknown

Firewall and router

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
3 · Security controlsControl availability and security posture stay separate dimensions.POSTURE4 components4 need attention
Keycloak

Keycloak

Unknown

Identity and access management

Vaultwarden

Vaultwarden

Unknown

Password manager

2FAuth

2FAuth

Unknown

Two-factor codes manager

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
4 · Shared platform & dataShared backends: track availability, latency, saturation and capacity without conflating impact with required dependency.RED + USE9 components9 need attention
PostgreSQL

PostgreSQL

Unknown

Database server (TCP — use a Postgres client, not a normal web browser tab)

Garage S3

Garage S3

Unknown

Garage S3-compatible object-storage API exposed through the direct HAProxy/TLS re-encryption/Traefik path.

Ollama

Ollama

Unknown

Large language models

LiteLLM

LiteLLM

Unknown

LLM proxy and gateway

Scrutiny

Scrutiny

Unknown

Hard drive health monitoring

Uptime Kuma

Uptime Kuma

Unknown

Uptime monitoring

Homarr

Homarr

Unknown

Homepage dashboard

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
5 · Observability & supportObservability and auxiliary tools: important for diagnosis without automatically marking monitored services unavailable.SUPPORT8 components8 need attention
Garage Admin

Garage Admin

Unknown

Garage Admin API exposed through Cloudflare Tunnel directly to the LAN-bound :3903 origin without Traefik.

SearXNG

SearXNG

Unknown

SearXNG service

Grafana

Grafana

Unknown

Analytics and monitoring

Graylog

Graylog

Unknown

Log management and analysis

ntopng

ntopng

Unknown

Network traffic visibility

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
Show critical dependency hierarchyRead required dependencies, blast radius, and the canonical Nabla Compose lifecycle order (phase + priority). Critical path

Critical dependency hierarchy

Foundational infrastructure and shared state are shown before applications, using declared required dependencies and their transitive blast radius.

Canonical Nabla Compose lifecycle order: required dependencies remain authoritative, then lifecycle phase and numeric priority determine operational order.

1 · Infrastructure foundations

Docker97 dependents
container-runtimeP10 · Foundation · compatBlast radius: 2FAuth, AIStor, Akvorado, Akvorado Inlet +93 more
Inspect dependency impact
Direct dependents: 2FAuth, AIStor, Akvorado, Akvorado Inlet, Akvorado Orchestrator, Akvorado Outlet, Grafana Alloy, AutoKuma, AutoXpose, Bichon, ClickHouse, Code Server, CrowdSec, Docker Socket Proxy, Dockhand, Doco-CD, Dozzle, Draw.io, Elasticsearch, FastAPI Sample, Garage S3, Garage, Gatus, Grafana, Graylog, pfSense HAProxy Exporter, Hello Nginx, Homarr, Homarr Reconciler, Home Assistant, InfluxDB, Apache Kafka, Keycloak, Kibana, Langflow, Langfuse Web, Langfuse Worker, LanguageTool, LiteLLM, Loki, Mimir, MinIO, MongoDB, n8n, Nexus Repository, Nginx Proxy Manager, NPMplus, ntopng, Obsidian, Ollama, 1Password Connect API, 1Password Connect Sync, OpenClaw Sandbox, OpenHands, OpenRAG Backend, OpenRAG Frontend, OpenSearch, OpenSearch Dashboards, OpenSearch Exporter, OpenSearch Security, OpenSearch Security Exporter, Open WebUI, Open WebUI Pipelines, pfSense Exporter, Pi-hole, Pi-hole DNS Sync, Pi-hole Exporter, Portracker, PostgreSQL Exporter, Prometheus, Alertmanager, Grafana Pyroscope, Redis, Scrutiny, Scrutiny Collector, Sentry, Sentry ClickHouse, Sentry Edge, Sentry Relay, Sentry Snuba API, Sentry Taskbroker, Sentry Taskworker, SonarQube, Squid Proxy, Suricata, Sybase Exporter, Tempo, Traefik, Vaultwarden, Vaultwarden REST API Adapter, Wazuh Dashboard, Wazuh OpenSearch Forwarder, Wazuh Indexer, Wazuh Manager, WordPress
Indirect / transitive impact: Garage Admin, pfSense Unbound
Docker Socket Proxy3 dependents
security-proxyP0 · Bootstrap runtime · compatRequires: DockerBlast radius: AutoXpose, Doco-CD, Pi-hole DNS Sync
Inspect dependency impact
Required path: Docker Socket Proxy → Docker
Direct dependents: AutoXpose, Doco-CD, Pi-hole DNS Sync
TrueNAS101 dependents
storage-platformP10 · Foundation · compatBlast radius: 2FAuth, AIStor, Akvorado, Akvorado Inlet +97 more
Inspect dependency impact
Direct dependents: Docker, Talos Linux
Indirect / transitive impact: 2FAuth, AIStor, Akvorado, Akvorado Inlet, Akvorado Orchestrator, Akvorado Outlet, Grafana Alloy, AutoKuma, AutoXpose, Bichon, ClickHouse, Code Server, CrowdSec, Docker Socket Proxy, Dockhand, Doco-CD, Dozzle, Draw.io, Elasticsearch, etcd, FastAPI Sample, Garage S3, Garage Admin, Garage, Gatus, Grafana, Graylog, pfSense HAProxy Exporter, Hello Nginx, Homarr, Homarr Reconciler, Home Assistant, InfluxDB, Apache Kafka, Keycloak, Kibana, Kubernetes (Talos), Langflow, Langfuse Web, Langfuse Worker, LanguageTool, LiteLLM, Loki, Mimir, MinIO, MongoDB, n8n, Nexus Repository, Nginx Proxy Manager, NPMplus, ntopng, Obsidian, Ollama, 1Password Connect API, 1Password Connect Sync, OpenClaw Sandbox, OpenHands, OpenRAG Backend, OpenRAG Frontend, OpenSearch, OpenSearch Dashboards, OpenSearch Exporter, OpenSearch Security, OpenSearch Security Exporter, Open WebUI, Open WebUI Pipelines, pfSense Exporter, pfSense Unbound, Pi-hole, Pi-hole DNS Sync, Pi-hole Exporter, Portracker, PostgreSQL Exporter, Prometheus, Alertmanager, Grafana Pyroscope, Redis, Scrutiny, Scrutiny Collector, Sentry, Sentry ClickHouse, Sentry Edge, Sentry Relay, Sentry Snuba API, Sentry Taskbroker, Sentry Taskworker, SonarQube, Squid Proxy, Suricata, Sybase Exporter, Tempo, Traefik, Vaultwarden, Vaultwarden REST API Adapter, Wazuh Dashboard, Wazuh OpenSearch Forwarder, Wazuh Indexer, Wazuh Manager, WordPress
Pi-hole2 dependents
dnsP10 · Foundation · compatBlast radius: pfSense Unbound, Pi-hole Exporter
Inspect dependency impact
Direct dependents: pfSense Unbound, Pi-hole Exporter
Vaultwarden1 dependent
password-managerP10 · Foundation · compatBlast radius: Vaultwarden REST API Adapter
Inspect dependency impact
Direct dependents: Vaultwarden REST API Adapter
Nginx Proxy Managerleaf
reverse-proxyP10 · Foundation · compat
+5 lower-impact components

2 · Shared data and state

🐘 PostgreSQL10 dependents
databaseP20 · Primary data · compatBlast radius: Keycloak, Langfuse Web, Langfuse Worker, n8n +6 more
Inspect dependency impact
Direct dependents: Keycloak, Langfuse Web, Langfuse Worker, n8n, PostgreSQL Exporter, Sentry, SonarQube, WordPress
Indirect / transitive impact: Sentry Edge, Sentry Relay
Apache Kafka9 dependents
message-brokerP20 · Primary data · compatBlast radius: Akvorado Inlet, Akvorado Orchestrator, Akvorado Outlet, Sentry +5 more
Inspect dependency impact
Direct dependents: Akvorado Inlet, Akvorado Orchestrator, Akvorado Outlet, Sentry, Sentry Relay, Sentry Snuba API, Sentry Taskbroker
Indirect / transitive impact: Sentry Edge, Sentry Taskworker
🔴 Redis6 dependents
cacheP20 · Primary data · compatBlast radius: Langfuse Web, Langfuse Worker, Sentry, Sentry Edge +2 more
Inspect dependency impact
Direct dependents: Langfuse Web, Langfuse Worker, Sentry, Sentry Relay, Sentry Snuba API
Indirect / transitive impact: Sentry Edge
InfluxDB2 dependents
time-series-databaseP20 · Primary data · compatBlast radius: Scrutiny, Scrutiny Collector
Inspect dependency impact
Direct dependents: Scrutiny
Indirect / transitive impact: Scrutiny Collector
🍃 MongoDB1 dependent
databaseP20 · Primary data · compatBlast radius: Graylog
Inspect dependency impact
Direct dependents: Graylog
ClickHouse6 dependents
databaseP30 · Secondary data · compatBlast radius: Akvorado, Akvorado Orchestrator, Akvorado Outlet, Langfuse Web +2 more
Inspect dependency impact
Direct dependents: Akvorado, Akvorado Orchestrator, Akvorado Outlet, Langfuse Web, Langfuse Worker, ntopng
+16 lower-impact components

3 · Shared platform services

🛡️ Wazuh4 dependents
security-platformP40 · Platform services · compatBlast radius: Wazuh Dashboard, Wazuh OpenSearch Forwarder, Wazuh Indexer, Wazuh Manager
Inspect dependency impact
Direct dependents: Wazuh Dashboard, Wazuh OpenSearch Forwarder, Wazuh Indexer, Wazuh Manager
Sentry Snuba API3 dependents
analytics-apiP40 · Platform services · compatRequires: Apache Kafka · Redis · Sentry ClickHouseBlast radius: Sentry, Sentry Edge, Sentry Relay
Inspect dependency impact
Required path: Sentry Snuba API → Apache Kafka
Direct dependents: Sentry
Indirect / transitive impact: Sentry Edge, Sentry Relay
🔗 Langflow2 dependents
workflowP40 · Platform services · compatRequires: OpenSearchBlast radius: OpenRAG Backend, OpenRAG Frontend
Inspect dependency impact
Required path: Langflow → OpenSearch
Direct dependents: OpenRAG Backend, OpenRAG Frontend
📈 Langfuse2 dependents
observabilityP40 · Platform services · compatBlast radius: Langfuse Web, Langfuse Worker
Inspect dependency impact
Direct dependents: Langfuse Web, Langfuse Worker
Sentry2 dependents
error-trackingP40 · Platform services · compatRequires: Apache Kafka · PostgreSQL · Redis · Sentry Snuba APIBlast radius: Sentry Edge, Sentry Relay
Inspect dependency impact
Required path: Sentry → Sentry Snuba API → Apache Kafka
Direct dependents: Sentry Edge, Sentry Relay
🛡️ Wazuh Manager2 dependents
security-managerP40 · Platform services · compatRequires: Wazuh · Wazuh IndexerBlast radius: Wazuh Dashboard, Wazuh OpenSearch Forwarder
Inspect dependency impact
Required path: Wazuh Manager → Wazuh Indexer → Wazuh
Direct dependents: Wazuh Dashboard, Wazuh OpenSearch Forwarder
+41 lower-impact components

4 · Applications and consumers

🔷 Talos Linux2 dependents
kubernetes-osP50 · Applications · compatBlast radius: etcd, Kubernetes (Talos)
Inspect dependency impact
Direct dependents: etcd, Kubernetes (Talos)
🗄️ etcd1 dependent
control-plane-storeP50 · Applications · compatBlast radius: Kubernetes (Talos)
Inspect dependency impact
Direct dependents: Kubernetes (Talos)
Homarr1 dependent
dashboardP50 · Applications · compatOptional: DockerBlast radius: Homarr Reconciler
Inspect dependency impact
Direct dependents: Homarr Reconciler
📚 OpenRAG Backend1 dependent
serviceP50 · Applications · compatRequires: Langflow · OpenSearchBlast radius: OpenRAG Frontend
Inspect dependency impact
Required path: OpenRAG Backend → Langflow → OpenSearch
Direct dependents: OpenRAG Frontend
Homarr Reconcilerleaf
configuration-reconcilerP50 · Applications · compatRequires: Homarr
Inspect dependency impact
Required path: Homarr Reconciler → Homarr
☸️ Kubernetes (Talos)leaf
orchestratorP50 · Applications · compatRequires: etcd
Inspect dependency impact
Required path: Kubernetes (Talos) → etcd
+8 lower-impact components

5 · Support and low-impact components

AutoXposeleaf
exposure-automationP50 · Applications · compatRequires: Docker Socket Proxy
Inspect dependency impact
Required path: AutoXpose → Docker Socket Proxy → Docker
Bichonleaf
applicationP50 · Applications · compat
Cloudflare Tunnel Connectorleaf
tunnel-connectorP50 · Applications · compat
Code Serverleaf
development-environmentP50 · Applications · compat
Dockhandleaf
container-managementP50 · Applications · compat
Doco-CDleaf
deployment-automationP50 · Applications · compatRequires: Docker Socket Proxy
Inspect dependency impact
Required path: Doco-CD → Docker Socket Proxy → Docker
+13 lower-impact components

Criticality is derived from blocking required relations (dependsOn, consumesApi, routesTo, storesIn, authenticatesVia and structural partOf). Databases, caches and storage kinds are treated as shared state when they have required dependents. Observability and exposure links do not artificially increase startup criticality.

Compact hierarchy

Mobile view of criticality tiers, effective health, and direct relations. The complete interactive graph remains available below.

Infrastructure foundations3 servicesunknown
TrueNASfoundation · blast 101
unknown
No direct relations shown.
pfSensefoundation · blast 2
unknown
No direct relations shown.
Vaultwardenfoundation · blast 1
unknown
  • Dockerrequired · hostedBy
Shared data and state7 servicesunknown
PostgreSQLshared-data · blast 10
unknown
No direct relations shown.
SearXNGshared-data · blast 0
unknown
No direct relations shown.
Clickhouseshared-data · blast 6
unknown
  • Dockerrequired · hostedBy
Minioshared-data · blast 2
unknown
  • Dockerrequired · hostedBy
Garage S3shared-data · blast 2
unknown
  • Dockerrequired · hostedBy
  • Traefikrequired · exposedBy
Garageshared-data · blast 0
unknown
  • Dockerrequired · hostedBy
  • Garage S3required · consumesApi
  • Cloudflare Tunnel Connectorrequired · exposedBy
Garage Adminshared-data · blast 0
unknown
  • Garage S3required · partOf
  • Cloudflare Tunnel Connectorrequired · exposedBy
Shared platform services13 servicesunknown
Prometheusshared-platform · blast 0
unknown
  • Dockerrequired · hostedBy
  • Mimirrequired · storesIn
Scrutinyshared-platform · blast 1
unknown
  • Dockerrequired · hostedBy
  • InfluxDBrequired · storesIn
Uptime Kumashared-platform · blast 1
unknown
No direct relations shown.
2FAuthshared-platform · blast 0
unknown
  • Dockerrequired · hostedBy
Ollamashared-platform · blast 2
unknown
  • Dockerrequired · hostedBy
n8nshared-platform · blast 0
unknown
  • Dockerrequired · hostedBy
  • PostgreSQLrequired · dependsOn
Grafanashared-platform · blast 0
unknown
  • Dockerrequired · hostedBy
Keycloakshared-platform · blast 0
unknown
  • Dockerrequired · hostedBy
  • PostgreSQLrequired · dependsOn
ClamAVshared-platform · blast 0
unknown
No direct relations shown.
Gatusshared-platform · blast 0
unknown
  • Dockerrequired · hostedBy
Graylogshared-platform · blast 0
unknown
  • Dockerrequired · hostedBy
  • MongoDBrequired · dependsOn
  • OpenSearch Securityrequired · storesIn
LiteLLMshared-platform · blast 1
unknown
  • Dockerrequired · hostedBy
  • Ollamarequired · routesTo
Langfuseshared-platform · blast 2
unknown
No direct relations shown.
Applications and consumers2 servicesunknown
Homarrapplication · blast 1
unknown
  • Dockerrequired · hostedBy
ntopngapplication · blast 0
unknown
  • ClickHouserequired · storesIn
  • Dockerrequired · hostedBy

Interactive service topology

Use the graph search and controls to switch between the AI platform, services, critical path, full catalog, and optional relations. On mobile, the compact hierarchy above provides a more direct view before the complete graph.

20 nodes · 6 groups · 20 relations
Edge semantics
DependencyAPI / data flowExposurePlacementObservationAutomation
Color and line pattern identify relation purpose; required/optional separately identifies functional strength. FastAPI evidence for a required dependency may override its color without changing its semantic category.

The wheel scrolls the page. Use Ctrl/Cmd + wheel or the +/− controls to zoom the diagram.

Mini Map

AI Platform is grouped by functional layers. The main flow moves from interfaces through control plane, inference, tools, orchestration and observability; edge semantics remain distinct from required/optional strength.

Homelab network and ingress paths

This React Flow diagram is the exact same component used on the TrueNAS page. Direct HAProxy/Traefik ingress and Cloudflare Tunnel now both show their WAN transit before pfSense, with tunnel traffic then crossing the LAN switch to TrueNAS/cloudflared. OpenWebUI illustrates a direct tunnel origin on :31028 that never traverses Traefik. The DNS filter separates name resolution from HTTP routing: LAN clients use pfSense/Unbound 172.17.0.1:53; public names recurse externally with Quad9/Cloudflare as public-only fallbacks, while the int.albandrieu.com Domain Override delegates to Pi-hole 172.17.0.24:53, fed by pihole-dns-sync from eligible Traefik labels. The graph also captures the previous failure mode where WAN-only Unbound outgoing interfaces made the Pi-hole forwarder expire; the validated setting is Outgoing Network Interfaces = All with Forwarding Mode disabled. Garage keeps three surfaces: s3.int.albandrieu.com through HAProxy → TLS re-encryption → Traefik → :3900, garage.albandrieu.com through Tunnel → cloudflared → :3909, and garage-admin.albandrieu.com through Tunnel → cloudflared → :3903.

The wheel scrolls the page. Use Ctrl/Cmd + wheel to zoom the diagram.

Focus pathFrames are failure domains, not just visual categories.
WAN transportLAN / hostingWi-FiDirect reverse proxy (HAProxy / Traefik)Cloudflare TunnelDNS resolution / split DNS

Declared configuration, observed runtime, and health

The architecture deliberately separates what should exist, what is actually running, and what is operationally usable. This makes configuration drift visible without turning the website or the TrueNAS API into the configuration source of truth.

1. nabla-compose

Declarative source: x-nabla services, stable identity, runtime binding, and topology relationships. services.json and service-topology.json are generated from code.

2. TrueNAS API

Observed runtime source: the official truenas_api_client queries app.query for Apps, containers, states, and versions. It never decides that a service should exist or be public.

3. fastapi-sample

Reconciliation layer: joins declared bindings to TrueNAS workloads, classifies drift (in_sync, declared_only, observed_only, conflict), and keeps health checks separate.

4. albanandrieu.com

Presentation layer: visualizes topology, runtime status, and health without becoming a backend data source.

Declared ≠ Observed ≠ Healthy