{"version":1,"name":"Nabla homelab declared topology","projection":"public-sanitized","nodes":[{"id":"2fauth","name":"2FAuth","kind":"security-app","category":"security","securityFunctions":["protect"],"icon":"🔐","runtime":{"provider":"truenas-app"}},{"id":"adguard-home","name":"AdGuard Home","kind":"native-truenas-dns-filter","category":"network","description":"Native TrueNAS App for network DNS filtering. It remains runtime-owned by TrueNAS until migration to repository-owned Compose.","lifecycle":{"phase":"foundation","priority":10},"runtime":{"provider":"truenas-app"}},{"id":"aistor","name":"AIStor","kind":"object-storage","category":"data","presentationRole":"service","criticality":"medium","description":"MinIO AIStor-compatible object storage service.","runtime":{"provider":"truenas-app"}},{"id":"akvorado-console","name":"Akvorado","kind":"network-observability","category":"observability","presentationRole":"service","criticality":"medium","status":"planned","securityFunctions":["identify","detect"],"runtime":{"provider":"truenas-app"}},{"id":"akvorado-inlet","name":"Akvorado Inlet","kind":"network-flow-collector","category":"observability","presentationRole":"support","criticality":"high","status":"planned","securityFunctions":["identify","detect"],"runtime":{"provider":"truenas-app"}},{"id":"akvorado-orchestrator","name":"Akvorado Orchestrator","kind":"network-flow-controller","category":"observability","presentationRole":"support","criticality":"high","status":"planned","securityFunctions":["identify","detect"],"runtime":{"provider":"truenas-app"}},{"id":"akvorado-outlet","name":"Akvorado Outlet","kind":"network-flow-processor","category":"observability","presentationRole":"support","criticality":"high","status":"planned","securityFunctions":["identify","detect"],"runtime":{"provider":"truenas-app"}},{"id":"alloy","name":"Grafana Alloy","kind":"telemetry-collector","category":"observability","icon":"🧬","runtime":{"provider":"truenas-app"}},{"id":"autokuma","name":"AutoKuma","kind":"monitoring-controller","category":"observability","description":"Declarative monitor reconciler for the existing Uptime Kuma instance.","lifecycle":{"phase":"platform-services","priority":40},"runtime":{"provider":"truenas-app"}},{"id":"autoxpose","name":"AutoXpose","kind":"exposure-automation","category":"operations","presentationRole":"support","criticality":"medium","description":"Reconciles Docker service exposure and DNS/proxy provider state.","runtime":{"provider":"truenas-app"}},{"id":"bichon","name":"Bichon","kind":"application","category":"productivity","runtime":{"provider":"truenas-app"}},{"id":"cartography","name":"Cartography","kind":"security-asset-graph-ingestor","category":"security","presentationRole":"support","criticality":"low","securityFunctions":["identify","detect"],"description":"Scheduled/manual security asset and relationship ingestion into Neo4j for attack-path and blast-radius analysis.","runtime":{"provider":"truenas-app"}},{"id":"clamav","name":"ClamAV","kind":"antivirus-engine","category":"security","presentationRole":"support","criticality":"high","securityFunctions":["protect","detect"],"description":"Internal ClamAV/clamd service. The .int URL is the private DNS identity; functional health remains a TCP/3310 probe."},{"id":"clickhouse","name":"ClickHouse","kind":"database","category":"data","icon":"⚡","lifecycle":{"phase":"secondary-data","priority":30},"runtime":{"provider":"truenas-app"}},{"id":"cloudflared","name":"Cloudflare Tunnel Connector","kind":"tunnel-connector","category":"network","presentationRole":"support","criticality":"high","description":"TrueNAS-hosted cloudflared connector for outbound-established Cloudflare Tunnel ingress that bypasses Traefik.","lifecycle":{"phase":"applications","priority":50},"runtime":{"provider":"truenas-app"}},{"id":"code-server","name":"Code Server","kind":"development-environment","category":"development","presentationRole":"service","criticality":"medium","description":"Browser-based development environment for homelab repositories.","runtime":{"provider":"truenas-app"}},{"id":"crowdsec","name":"CrowdSec","kind":"security-agent","category":"security","status":"planned","securityFunctions":["detect","respond"],"icon":"🛡️","runtime":{"provider":"truenas-app"}},{"id":"cyberbro","name":"Cyberbro","kind":"threat-intelligence-analysis","category":"security","presentationRole":"service","criticality":"medium","securityFunctions":["identify","detect"],"description":"Lightweight threat-intelligence workbench for extracting IoCs and checking reputation across OSINT, CTI, and EDR engines.","runtime":{"provider":"truenas-app"}},{"id":"defectdojo","name":"DefectDojo","kind":"vulnerability-management-platform","category":"security","presentationRole":"service","criticality":"medium","securityFunctions":["identify","detect","respond"],"description":"Central normalized security-finding aggregation, deduplication, triage and remediation workflow.","runtime":{"provider":"truenas-app"}},{"id":"defectdojo-api","name":"DefectDojo API","kind":"vulnerability-management-api","category":"security","presentationRole":"support","criticality":"medium","securityFunctions":["identify","detect","respond"],"runtime":{"provider":"truenas-app"}},{"id":"defectdojo-celerybeat","name":"DefectDojo Celery Beat","kind":"scheduler","category":"security","presentationRole":"support","criticality":"low","runtime":{"provider":"truenas-app"}},{"id":"defectdojo-initializer","name":"DefectDojo Initializer","kind":"database-initializer","category":"security","presentationRole":"support","criticality":"low","runtime":{"provider":"truenas-app"}},{"id":"defectdojo-worker","name":"DefectDojo Worker","kind":"background-worker","category":"security","presentationRole":"support","criticality":"low","runtime":{"provider":"truenas-app"}},{"id":"dependency-track","name":"Dependency-Track","kind":"software-supply-chain-platform","category":"security","presentationRole":"service","criticality":"medium","securityFunctions":["identify","detect"],"description":"CycloneDX SBOM component inventory and software supply-chain vulnerability analysis platform.","runtime":{"provider":"truenas-app"}},{"id":"dependency-track-api","name":"Dependency-Track API","kind":"software-supply-chain-api","category":"security","presentationRole":"support","criticality":"medium","securityFunctions":["identify","detect"],"runtime":{"provider":"truenas-app"}},{"id":"docker","name":"Docker","kind":"container-runtime","category":"infrastructure","presentationRole":"core","criticality":"critical","description":"Docker engine hosting the TrueNAS Compose workloads."},{"id":"docker-socket-proxy","name":"Docker Socket Proxy","kind":"security-proxy","category":"infrastructure","presentationRole":"support","criticality":"high","securityFunctions":["protect"],"description":"Restricted read-only Docker Engine API boundary for repository automation.","lifecycle":{"phase":"bootstrap-runtime","priority":0},"runtime":{"provider":"truenas-app"}},{"id":"dockhand","name":"Dockhand","kind":"container-management","category":"operations","presentationRole":"service","criticality":"medium","description":"Docker container management UI.","runtime":{"provider":"truenas-app"}},{"id":"docling","name":"Docling Serve","kind":"document-processing","category":"ai","presentationRole":"service","criticality":"medium","description":"CPU-backed document conversion API used by OpenRAG knowledge ingestion.","lifecycle":{"phase":"applications","priority":40},"runtime":{"provider":"truenas-app"}},{"id":"doco-cd","name":"Doco-CD","kind":"deployment-automation","category":"operations","presentationRole":"support","criticality":"medium","description":"Git-driven Compose deployment automation for the TrueNAS Docker runtime.","runtime":{"provider":"truenas-app"}},{"id":"dozzle","name":"Dozzle","kind":"log-viewer","category":"observability","presentationRole":"service","criticality":"medium","description":"Live Docker log viewer and MCP-enabled operations UI.","runtime":{"provider":"truenas-app"}},{"id":"drawio","name":"Draw.io","kind":"diagramming","category":"productivity","presentationRole":"service","criticality":"low","description":"Self-hosted diagrams.net editor.","runtime":{"provider":"truenas-app"}},{"id":"dsomm","name":"OWASP DevSecOps Maturity Model","kind":"security-maturity-assessment","category":"security","presentationRole":"service","criticality":"low","status":"planned","securityFunctions":["govern","identify"],"description":"OWASP DSOMM assessment UI. Assessment state is browser/YAML evidence; automated baseline results are supporting evidence, not an authoritative maturity verdict.","runtime":{"provider":"truenas-app"}},{"id":"dsomm-baseline","name":"DSOMM GitHub Baseline","kind":"security-maturity-evidence-scanner","category":"security","presentationRole":"support","criticality":"low","status":"planned","securityFunctions":["govern","identify"],"description":"Manual pinned Tweag dsomm-baseline runner that inventories automatable GitHub evidence and writes CSV reports for later human review in DSOMM.","runtime":{"provider":"truenas-app"}},{"id":"elasticsearch","name":"Elasticsearch","kind":"search","category":"data","icon":"🔎","runtime":{"provider":"truenas-app"}},{"id":"etcd","name":"etcd","kind":"control-plane-store","category":"infrastructure","presentationRole":"core","criticality":"critical","description":"Critical Kubernetes control-plane state store managed by Talos on control-plane nodes.","icon":"🗄️"},{"id":"fastapi-sample","name":"FastAPI Sample","kind":"api","category":"development","presentationRole":"support","criticality":"medium","description":"FastAPI Sample service with FastAPI Cloud production and TrueNAS staging environments.","environments":[{"name":"production"},{"name":"staging"}],"runtime":{"provider":"truenas-app"}},{"id":"garage","name":"Garage S3","kind":"object-storage","category":"data","description":"S3-compatible object storage exposed directly through pfSense HAProxy, TLS re-encryption and Traefik on TrueNAS.","icon":"🪣","runtime":{"provider":"truenas-app"}},{"id":"garage-admin","name":"Garage Admin","kind":"api","category":"data","presentationRole":"support","criticality":"high","description":"Garage Admin API exposed through Cloudflare Tunnel to the LAN-bound :3903 origin without Traefik."},{"id":"garage-webui","name":"Garage","kind":"application","category":"data","description":"Garage web administration UI exposed by Cloudflare Tunnel directly to the LAN-bound :3909 origin without Traefik.","icon":"🖥️","runtime":{"provider":"truenas-app"}},{"id":"gatus","name":"Gatus","kind":"status-monitor","category":"observability","description":"Declarative status monitoring generated from Nabla Compose services.","runtime":{"provider":"truenas-app"}},{"id":"grafana","name":"Grafana","kind":"observability-ui","category":"observability","icon":"📈","runtime":{"provider":"truenas-app"}},{"id":"graylog","name":"Graylog","kind":"log-management","category":"observability","icon":"🪵","lifecycle":{"phase":"platform-services","priority":40},"runtime":{"provider":"truenas-app"}},{"id":"haproxy-exporter","name":"pfSense HAProxy Exporter","kind":"metrics-exporter","category":"observability","icon":"⚖️","runtime":{"provider":"truenas-app"}},{"id":"heimdall","name":"Heimdall","kind":"dashboard","category":"operations","presentationRole":"support","criticality":"low","description":"Application dashboard retained from the legacy homelab inventory and classified canonically for topology consumers."},{"id":"hello-nginx","name":"Hello Nginx","kind":"web-server","category":"development","presentationRole":"support","criticality":"low","description":"Small internal Nginx service used for ingress and routing experiments.","runtime":{"provider":"truenas-app"}},{"id":"homarr","name":"Homarr","kind":"dashboard","category":"operations","presentationRole":"support","criticality":"medium","description":"Homelab application dashboard generated from the Nabla service inventory.","runtime":{"provider":"truenas-app"}},{"id":"homarr-sync","name":"Homarr Reconciler","kind":"configuration-reconciler","category":"operations","description":"Non-destructively reconciles generated Nabla applications through the Homarr API.","runtime":{"provider":"truenas-app"}},{"id":"homeassistant","name":"Home Assistant","kind":"home-automation","category":"automation","presentationRole":"service","criticality":"medium","description":"Home automation control plane exposed through the dedicated IoT network.","runtime":{"provider":"truenas-app"}},{"id":"influxdb","name":"InfluxDB","kind":"time-series-database","category":"data","description":"Shared InfluxDB 2.x time-series database for Scrutiny and future homelab consumers.","lifecycle":{"phase":"primary-data","priority":20},"runtime":{"provider":"truenas-app"}},{"id":"joplin","name":"Joplin Server","kind":"notes-sync","category":"productivity","presentationRole":"service","criticality":"medium","description":"Private Joplin synchronization server backed by the shared PostgreSQL service.","lifecycle":{"phase":"applications","priority":60},"runtime":{"provider":"truenas-app"}},{"id":"kafka","name":"Apache Kafka","kind":"message-broker","category":"data","lifecycle":{"phase":"primary-data","priority":20},"runtime":{"provider":"truenas-app"}},{"id":"kafka-exporter","name":"Kafka Exporter","kind":"metrics-exporter","category":"observability","runtime":{"provider":"truenas-app"}},{"id":"keycloak","name":"Keycloak","kind":"identity-provider","category":"security","presentationRole":"core","criticality":"critical","status":"planned","description":"Central OIDC/SAML identity provider backed by the shared PostgreSQL service.","runtime":{"provider":"truenas-app"}},{"id":"kibana","name":"Kibana","kind":"dashboard","category":"observability","icon":"📊","runtime":{"provider":"truenas-app"}},{"id":"kubernetes","name":"Kubernetes (Talos)","kind":"orchestrator","category":"infrastructure","presentationRole":"core","criticality":"critical","description":"Target Kubernetes cluster bootstrapped on Talos Linux VMs hosted by TrueNAS.","icon":"☸️"},{"id":"langflow","name":"Langflow","kind":"workflow","category":"ai","icon":"🔗","runtime":{"provider":"truenas-app"}},{"id":"langfuse","name":"Langfuse","kind":"observability","category":"ai","description":"Logical Langfuse v4 observability platform composed of web and worker workloads.","icon":"📈"},{"id":"langfuse-web","name":"Langfuse Web","kind":"application","category":"ai","icon":"🖥️","runtime":{"provider":"truenas-app"}},{"id":"langfuse-worker","name":"Langfuse Worker","kind":"worker","category":"ai","icon":"⚙️","runtime":{"provider":"truenas-app"}},{"id":"languagetool","name":"LanguageTool","kind":"language-service","category":"productivity","presentationRole":"service","criticality":"medium","description":"Self-hosted grammar and style checking API.","runtime":{"provider":"truenas-app"}},{"id":"litellm","name":"LiteLLM","kind":"gateway","category":"ai","icon":"🧠","runtime":{"provider":"truenas-app"}},{"id":"loki","name":"Loki","kind":"log-store","category":"observability","icon":"🧾","runtime":{"provider":"truenas-app"}},{"id":"mcp-cyberbro","name":"Cyberbro MCP","kind":"mcp-server","category":"security","presentationRole":"support","criticality":"low","securityFunctions":["identify","detect"],"description":"Model Context Protocol bridge exposing Cyberbro observable-analysis tools to MCP-capable clients such as LiteLLM.","runtime":{"provider":"truenas-app"}},{"id":"mimir","name":"Mimir","kind":"metrics-store","category":"observability","icon":"📐","runtime":{"provider":"truenas-app"}},{"id":"minio","name":"MinIO","kind":"object-storage","category":"data","icon":"🪣","runtime":{"provider":"truenas-app"}},{"id":"mongo","name":"MongoDB","kind":"database","category":"data","icon":"🍃","lifecycle":{"phase":"primary-data","priority":20},"runtime":{"provider":"truenas-app"}},{"id":"n8n","name":"n8n","kind":"workflow","category":"automation","status":"planned","icon":"⚙️","runtime":{"provider":"truenas-app"}},{"id":"neo4j-security","name":"Neo4j Security Graph","kind":"graph-database","category":"security","presentationRole":"support","criticality":"medium","securityFunctions":["identify","detect"],"description":"Analytical graph store for Cartography attack-path, privilege-chain and blast-radius queries; not an authoritative CMDB.","runtime":{"provider":"truenas-app"}},{"id":"netbox","name":"NetBox","kind":"infrastructure-source-of-truth","category":"infrastructure","presentationRole":"service","criticality":"medium","securityFunctions":["identify"],"description":"Network and infrastructure source of truth for IPAM, prefixes, VLANs, devices, VMs and interfaces; x-nabla remains authoritative for application/service identity.","runtime":{"provider":"truenas-app"}},{"id":"netbox-housekeeping","name":"NetBox Housekeeping","kind":"maintenance-worker","category":"infrastructure","presentationRole":"support","criticality":"low","runtime":{"provider":"truenas-app"}},{"id":"netbox-worker","name":"NetBox Worker","kind":"background-worker","category":"infrastructure","presentationRole":"support","criticality":"low","runtime":{"provider":"truenas-app"}},{"id":"nexus","name":"Nexus Repository","kind":"artifact-repository","category":"development","presentationRole":"service","criticality":"medium","description":"Repository manager for development artifacts and package proxies.","runtime":{"provider":"truenas-app"}},{"id":"nginx-proxy-manager","name":"Nginx Proxy Manager","kind":"reverse-proxy","category":"network","presentationRole":"support","criticality":"medium","description":"Legacy reverse-proxy administration service retained during NPMplus migration.","runtime":{"provider":"truenas-app"}},{"id":"npmplus","name":"NPMplus","kind":"reverse-proxy","category":"network","presentationRole":"support","criticality":"high","description":"Hardened Nginx Proxy Manager fork tracked as the repository migration target.","runtime":{"provider":"truenas-app"}},{"id":"ntopng","name":"ntopng","kind":"network-observability","category":"network","icon":"🌐","runtime":{"provider":"truenas-app"}},{"id":"obsidian","name":"Obsidian","kind":"application","category":"productivity","icon":"💎","runtime":{"provider":"truenas-app"}},{"id":"ollama","name":"Ollama","kind":"model-runtime","category":"ai","icon":"🦙","runtime":{"provider":"truenas-app"}},{"id":"op-connect-api","name":"1Password Connect API","kind":"secrets-api","category":"security","presentationRole":"support","criticality":"high","status":"disabled","securityFunctions":["protect"],"description":"1Password Connect API for machine-readable secret access.","runtime":{"provider":"truenas-app"}},{"id":"op-connect-sync","name":"1Password Connect Sync","kind":"secrets-sync","category":"security","presentationRole":"support","criticality":"high","status":"disabled","securityFunctions":["protect"],"description":"Synchronizes 1Password vault state for the Connect API.","runtime":{"provider":"truenas-app"}},{"id":"open-terminal","name":"Open Terminal","kind":"tool-service","category":"ai","description":"Optional agent terminal API consumed by Open WebUI tools.","icon":"⌨️"},{"id":"openclaw-sandbox","name":"OpenClaw Sandbox","kind":"automation-sandbox","category":"development","presentationRole":"support","criticality":"low","description":"Isolated sandbox for OpenClaw skills and local calendar tooling.","runtime":{"provider":"truenas-app"}},{"id":"opencre","name":"OWASP OpenCRE","kind":"security-standards-correlation","category":"security","presentationRole":"service","criticality":"low","status":"planned","securityFunctions":["govern","identify","protect"],"description":"Internal OWASP OpenCRE service for correlating common security requirements across standards. It complements DSOMM maturity assessment and does not replace the canonical Nabla service catalog.","runtime":{"provider":"truenas-app"}},{"id":"openhands","name":"OpenHands","kind":"ai-coding-agent","category":"ai","presentationRole":"service","criticality":"medium","description":"Self-hosted coding-agent environment with Docker-backed sandboxes.","runtime":{"provider":"truenas-app"}},{"id":"openrag-backend","name":"OpenRAG Backend","kind":"service","category":"ai","icon":"📚","runtime":{"provider":"truenas-app"}},{"id":"openrag-frontend","name":"OpenRAG Frontend","kind":"application","category":"ai","icon":"🔍","runtime":{"provider":"truenas-app"}},{"id":"opensearch","name":"OpenSearch","kind":"search","category":"data","icon":"🔎","lifecycle":{"phase":"secondary-data","priority":30},"runtime":{"provider":"truenas-app"}},{"id":"opensearch-dashboards","name":"OpenSearch Dashboards","kind":"application","category":"data","icon":"📊","lifecycle":{"phase":"secondary-data","priority":30},"runtime":{"provider":"truenas-app"}},{"id":"opensearch-exporter","name":"OpenSearch Exporter","kind":"metrics-exporter","category":"observability","icon":"📡","runtime":{"provider":"truenas-app"}},{"id":"opensearch-security","name":"OpenSearch Security","kind":"search","category":"security","icon":"🛡️","lifecycle":{"phase":"secondary-data","priority":30},"runtime":{"provider":"truenas-app"}},{"id":"opensearch-security-exporter","name":"OpenSearch Security Exporter","kind":"metrics-exporter","category":"observability","icon":"📡","runtime":{"provider":"truenas-app"}},{"id":"openssf-scorecard","name":"OpenSSF Scorecard","kind":"repository-security-posture-scanner","category":"security","presentationRole":"support","criticality":"low","securityFunctions":["identify","detect"],"description":"One-shot repository and upstream dependency security-posture scanner. Results are evidence, not a service criticality score.","runtime":{"provider":"truenas-app"}},{"id":"openwebui","name":"Open WebUI","kind":"application","category":"ai","icon":"💬","runtime":{"provider":"truenas-app"}},{"id":"openwebui-pipelines","name":"Open WebUI Pipelines","kind":"service","category":"ai","icon":"🔧","runtime":{"provider":"truenas-app"}},{"id":"pfsense","name":"pfSense","kind":"firewall","category":"network","presentationRole":"core","criticality":"critical","securityFunctions":["protect","respond"],"description":"External pfSense firewall running the lightweight CrowdSec remediation component.","icon":"🔥"},{"id":"pfsense-exporter","name":"pfSense Exporter","kind":"metrics-exporter","category":"observability","icon":"📡","runtime":{"provider":"truenas-app"}},{"id":"pfsense-haproxy","name":"pfSense HAProxy","kind":"reverse-proxy","category":"network","presentationRole":"core","criticality":"critical","description":"pfSense HAProxy terminates public TLS and re-encrypts direct *.int.albandrieu.com ingress to Traefik on TrueNAS.","icon":"⚖️"},{"id":"pfsense-unbound","name":"pfSense Unbound","kind":"dns-resolver","category":"network","presentationRole":"core","criticality":"critical","description":"Primary LAN recursive resolver at 172.17.0.1:53; delegates int.albandrieu.com to Pi-hole with Forwarding Mode disabled and outgoing interfaces set to All."},{"id":"pihole","name":"Pi-hole","kind":"dns","category":"network","presentationRole":"core","criticality":"critical","description":"LAN DNS filtering and private *.int.albandrieu.com record consumer.","lifecycle":{"phase":"foundation","priority":10},"runtime":{"provider":"truenas-app"}},{"id":"pihole-dns-sync","name":"Pi-hole DNS Sync","kind":"configuration-reconciler","category":"network","presentationRole":"support","criticality":"high","description":"Synchronizes repository-managed Docker/Traefik service names into Pi-hole private DNS.","runtime":{"provider":"truenas-app"}},{"id":"pihole-exporter","name":"Pi-hole Exporter","kind":"metrics-exporter","category":"observability","presentationRole":"support","criticality":"medium","description":"Prometheus-compatible metrics exporter for Pi-hole.","runtime":{"provider":"truenas-app"}},{"id":"plumber","name":"Plumber","kind":"developer-platform","category":"development","presentationRole":"service","criticality":"medium","securityFunctions":["identify","protect"],"description":"Repository-managed Plumber frontend replacing the legacy root plumber-platform submodule deployment model.","runtime":{"provider":"truenas-app"}},{"id":"plumber-api","name":"Plumber API","kind":"developer-platform-api","category":"development","presentationRole":"support","criticality":"medium","securityFunctions":["identify","protect"],"runtime":{"provider":"truenas-app"}},{"id":"plumber-worker","name":"Plumber Worker","kind":"background-worker","category":"development","presentationRole":"support","criticality":"low","runtime":{"provider":"truenas-app"}},{"id":"portracker","name":"Portracker","kind":"port-inventory","category":"operations","presentationRole":"support","criticality":"medium","description":"Host and Docker port inventory used to detect exposure and allocation drift.","runtime":{"provider":"truenas-app"}},{"id":"postgres-exporter","name":"PostgreSQL Exporter","kind":"metrics-exporter","category":"observability","presentationRole":"support","criticality":"medium","description":"Prometheus exporter for the shared PostgreSQL service.","runtime":{"provider":"truenas-app"}},{"id":"postgresql","name":"PostgreSQL","kind":"native-truenas-database","category":"data","description":"Shared native TrueNAS PostgreSQL App used by repository-managed consumers. Keep it as a runtime-owned native service until migration to repository-owned Compose.","icon":"🐘","lifecycle":{"phase":"primary-data","priority":20},"runtime":{"provider":"truenas-app"}},{"id":"prometheus","name":"Prometheus","kind":"observability","category":"observability","icon":"📊","runtime":{"provider":"truenas-app"}},{"id":"prometheus-alertmanager","name":"Alertmanager","kind":"alerting","category":"observability","runtime":{"provider":"truenas-app"}},{"id":"pyroscope","name":"Grafana Pyroscope","kind":"continuous-profiler","category":"observability","presentationRole":"support","criticality":"medium","description":"Continuous profiling backend with persistent Pyroscope v2 metastore state.","runtime":{"provider":"truenas-app"}},{"id":"redis","name":"Redis","kind":"cache","category":"data","icon":"🔴","lifecycle":{"phase":"primary-data","priority":20},"runtime":{"provider":"truenas-app"}},{"id":"scanopy","name":"Scanopy","kind":"network-topology-management","category":"network","presentationRole":"service","criticality":"medium","securityFunctions":["identify","detect"],"description":"Agentless network discovery and continuously updated topology documentation backed by the shared PostgreSQL service.","runtime":{"provider":"truenas-app"}},{"id":"scanopy-daemon","name":"Scanopy Daemon","kind":"network-discovery-scanner","category":"network","presentationRole":"support","criticality":"medium","securityFunctions":["identify","detect"],"description":"Privileged agentless scanner used by Scanopy to discover hosts, ports, containers, and network topology.","runtime":{"provider":"truenas-app"}},{"id":"scrutiny","name":"Scrutiny","kind":"storage-monitoring","category":"observability","presentationRole":"support","criticality":"medium","description":"SMART disk health monitoring web/API backed by the shared InfluxDB service.","runtime":{"provider":"truenas-app"}},{"id":"scrutiny-collector","name":"Scrutiny Collector","kind":"metrics-collector","category":"observability","runtime":{"provider":"truenas-app"}},{"id":"searxng","name":"SearXNG","kind":"search","category":"ai","description":"Optional metasearch backend consumed by Open WebUI web-search tooling.","icon":"🌐"},{"id":"sentry","name":"Sentry","kind":"error-tracking","category":"observability","presentationRole":"service","criticality":"high","description":"Self-hosted Sentry 26.8 errors-only application service.","runtime":{"provider":"truenas-app"}},{"id":"sentry-clickhouse","name":"Sentry ClickHouse","kind":"database","category":"data","presentationRole":"support","criticality":"critical","lifecycle":{"phase":"secondary-data","priority":30},"runtime":{"provider":"truenas-app"}},{"id":"sentry-edge","name":"Sentry Edge","kind":"reverse-proxy","category":"network","presentationRole":"support","criticality":"high","runtime":{"provider":"truenas-app"}},{"id":"sentry-relay","name":"Sentry Relay","kind":"ingestion-relay","category":"observability","presentationRole":"support","criticality":"high","runtime":{"provider":"truenas-app"}},{"id":"sentry-snuba-api","name":"Sentry Snuba API","kind":"analytics-api","category":"observability","presentationRole":"support","criticality":"high","description":"Sentry query API backed by the dedicated temporary Sentry ClickHouse.","runtime":{"provider":"truenas-app"}},{"id":"sentry-taskbroker","name":"Sentry Taskbroker","kind":"task-broker","category":"observability","presentationRole":"support","criticality":"high","runtime":{"provider":"truenas-app"}},{"id":"sentry-taskworker","name":"Sentry Taskworker","kind":"worker","category":"observability","presentationRole":"support","criticality":"high","runtime":{"provider":"truenas-app"}},{"id":"sonarqube","name":"SonarQube","kind":"code-quality","category":"development","icon":"🧹","runtime":{"provider":"truenas-app"}},{"id":"squid","name":"Squid Proxy","kind":"forward-proxy","category":"network","presentationRole":"support","criticality":"medium","description":"Internal forward proxy for controlled HTTP(S) egress experiments.","runtime":{"provider":"truenas-app"}},{"id":"suricata","name":"Suricata","kind":"ids","category":"security","securityFunctions":["detect"],"icon":"🦈","lifecycle":{"phase":"platform-services","priority":40},"runtime":{"provider":"truenas-app"}},{"id":"sybase","name":"SAP Sybase ASE","kind":"database","category":"data","description":"External Sybase ASE database monitored through FreeTDS.","icon":"🗄️"},{"id":"sybase-exporter","name":"Sybase Exporter","kind":"metrics-exporter","category":"observability","icon":"📡","runtime":{"provider":"truenas-app"}},{"id":"talos","name":"Talos Linux","kind":"kubernetes-os","category":"infrastructure","presentationRole":"core","criticality":"critical","description":"Immutable Talos Linux platform for the Kubernetes control-plane and worker VMs on TrueNAS.","icon":"🔷","runtime":{"provider":"truenas-vm"}},{"id":"tempo","name":"Tempo","kind":"trace-store","category":"observability","icon":"⏱️","runtime":{"provider":"truenas-app"}},{"id":"traefik","name":"Traefik","kind":"edge","category":"network","presentationRole":"core","criticality":"critical","description":"Docker reverse proxy on TrueNAS for direct *.int.albandrieu.com services.","icon":"🚦","lifecycle":{"phase":"foundation","priority":10},"runtime":{"provider":"truenas-app"}},{"id":"truenas","name":"TrueNAS","kind":"storage-platform","category":"infrastructure","presentationRole":"core","criticality":"critical","description":"TrueNAS SCALE storage and application host."},{"id":"uptime-kuma","name":"Uptime Kuma","kind":"native-truenas-uptime-monitor","category":"observability","description":"Intended native TrueNAS Uptime Kuma target on host port 31050, reconciled by AutoKuma until the service is migrated to repository-owned Compose. Confirm the native App still exists before enabling AutoKuma.","lifecycle":{"phase":"platform-services","priority":40},"runtime":{"provider":"truenas-app"}},{"id":"vaultwarden","name":"Vaultwarden","kind":"password-manager","category":"security","presentationRole":"service","criticality":"high","securityFunctions":["protect"],"description":"Self-hosted Bitwarden-compatible password and secret vault.","lifecycle":{"phase":"foundation","priority":10,"blocksLaterWaves":false},"runtime":{"provider":"truenas-app"}},{"id":"vaultwarden-rest-api","name":"Vaultwarden REST API Adapter","kind":"compatibility-api","category":"security","presentationRole":"support","criticality":"medium","securityFunctions":["protect"],"description":"Legacy Doco-CD compatibility adapter for Vaultwarden secret retrieval.","runtime":{"provider":"truenas-app"}},{"id":"wazuh","name":"Wazuh","kind":"security-platform","category":"security","description":"Logical Wazuh security platform composed of manager, indexer, dashboard and forwarding workloads.","icon":"🛡️"},{"id":"wazuh-dashboard","name":"Wazuh Dashboard","kind":"application","category":"security","icon":"🖥️","runtime":{"provider":"truenas-app"}},{"id":"wazuh-forwarder","name":"Wazuh OpenSearch Forwarder","kind":"telemetry-forwarder","category":"security","icon":"🔁","runtime":{"provider":"truenas-app"}},{"id":"wazuh-indexer","name":"Wazuh Indexer","kind":"search","category":"security","icon":"🗂️","runtime":{"provider":"truenas-app"}},{"id":"wazuh-manager","name":"Wazuh Manager","kind":"security-manager","category":"security","securityFunctions":["detect"],"icon":"🛡️","runtime":{"provider":"truenas-app"}},{"id":"wordpress","name":"WordPress","kind":"cms","category":"development","presentationRole":"service","criticality":"low","description":"Lab WordPress deployment backed by PostgreSQL through PG4WP.","runtime":{"provider":"truenas-app"}}],"relations":[{"source":"2fauth","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"aistor","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"akvorado-console","target":"clickhouse","type":"dependsOn","strength":"required","description":"The Akvorado console queries flow history from the shared ClickHouse service."},{"source":"akvorado-console","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"akvorado-inlet","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"akvorado-inlet","target":"kafka","type":"routesTo","strength":"required","description":"Decoded IPFIX/NetFlow records are published to the dedicated Akvorado Kafka topic."},{"source":"akvorado-orchestrator","target":"clickhouse","type":"storesIn","strength":"required","description":"Akvorado manages and queries its dedicated schema in the shared ClickHouse service."},{"source":"akvorado-orchestrator","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"akvorado-orchestrator","target":"kafka","type":"dependsOn","strength":"required","description":"Akvorado uses the shared Kafka broker for its dedicated flow topic."},{"source":"akvorado-outlet","target":"clickhouse","type":"storesIn","strength":"required","description":"Enriched network-flow records are persisted in the dedicated Akvorado ClickHouse database."},{"source":"akvorado-outlet","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"akvorado-outlet","target":"kafka","type":"dependsOn","strength":"required","description":"Akvorado Outlet consumes the dedicated flow topic from shared Kafka."},{"source":"alloy","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"alloy","target":"loki","type":"storesIn","strength":"required","description":"Alloy forwards collected security logs to Loki."},{"source":"alloy","target":"mimir","type":"storesIn","strength":"required","description":"Alloy remote-writes collected OTLP metrics to Mimir."},{"source":"alloy","target":"pfsense","type":"dependsOn","strength":"optional","description":"Alloy tails pfSense log files when they are mounted on the TrueNAS host."},{"source":"alloy","target":"suricata","type":"dependsOn","strength":"optional","description":"Alloy tails Suricata JSON logs when available."},{"source":"alloy","target":"tempo","type":"storesIn","strength":"required","description":"Alloy forwards collected OTLP traces to Tempo."},{"source":"autokuma","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"autokuma","target":"uptime-kuma","type":"consumesApi","strength":"required","description":"AutoKuma reconciles generated monitors into Uptime Kuma."},{"source":"autoxpose","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"autoxpose","target":"docker-socket-proxy","type":"consumesApi","strength":"required","description":"AutoXpose discovers containers through the restricted Docker API proxy."},{"source":"bichon","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"cartography","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"cartography","target":"neo4j-security","type":"storesIn","strength":"required"},{"source":"clickhouse","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"clickhouse","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes the native ClickHouse Prometheus endpoint."},{"source":"code-server","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"crowdsec","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"crowdsec","target":"pfsense","type":"providesApi","strength":"required","description":"CrowdSec provides the central LAPI consumed by the pfSense firewall bouncer in Small/remediation-only mode."},{"source":"crowdsec","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes CrowdSec metrics."},{"source":"crowdsec","target":"suricata","type":"dependsOn","strength":"optional","description":"CrowdSec can enrich decisions from Suricata event logs."},{"source":"cyberbro","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"defectdojo","target":"defectdojo-api","type":"consumesApi","strength":"required"},{"source":"defectdojo","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"defectdojo-api","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"defectdojo-api","target":"postgresql","type":"storesIn","strength":"required"},{"source":"defectdojo-api","target":"redis","type":"storesIn","strength":"required"},{"source":"defectdojo-celerybeat","target":"defectdojo-api","type":"partOf","strength":"required"},{"source":"defectdojo-celerybeat","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"defectdojo-initializer","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"defectdojo-initializer","target":"postgresql","type":"storesIn","strength":"required"},{"source":"defectdojo-worker","target":"defectdojo-api","type":"partOf","strength":"required"},{"source":"defectdojo-worker","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"dependency-track","target":"dependency-track-api","type":"consumesApi","strength":"required"},{"source":"dependency-track","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"dependency-track-api","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"dependency-track-api","target":"postgresql","type":"storesIn","strength":"required"},{"source":"docker","target":"truenas","type":"hostedBy","strength":"required","description":"Docker runtime is hosted on the TrueNAS platform."},{"source":"docker-socket-proxy","target":"docker","type":"consumesApi","strength":"required","description":"The proxy consumes the local Docker Engine API and exposes an allowlisted subset to trusted clients."},{"source":"docker-socket-proxy","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"dockhand","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"docling","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"docling","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes Docling Serve OpenTelemetry metrics from /metrics."},{"source":"docling","target":"traefik","type":"exposedBy","strength":"optional","description":"Traefik exposes Docling only on the private *.int.albandrieu.com namespace."},{"source":"doco-cd","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"doco-cd","target":"docker-socket-proxy","type":"consumesApi","strength":"required","description":"Doco-CD performs Docker discovery and deployments through the restricted proxy."},{"source":"dozzle","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"drawio","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"dsomm","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"dsomm-baseline","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"dsomm-baseline","target":"dsomm","type":"automates","strength":"optional","description":"Baseline output helps pre-fill evidence for the DSOMM assessment but cannot replace manual assessment activities."},{"source":"elasticsearch","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"etcd","target":"talos","type":"hostedBy","strength":"required","description":"Talos control-plane nodes host the etcd member(s) backing Kubernetes."},{"source":"fastapi-sample","target":"cloudflared","type":"exposedBy","strength":"optional","description":"The TrueNAS staging endpoint sample.albandrieu.com is exposed through Cloudflare Access and an outbound-established Cloudflare Tunnel; production FastAPI Cloud remains independent."},{"source":"fastapi-sample","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"fastapi-sample","target":"postgresql","type":"dependsOn","strength":"required","description":"TrueNAS staging uses the always-on shared PostgreSQL service; Supabase remains a separate cloud integration and must not overload the local POSTGRES_* identity."},{"source":"fastapi-sample","target":"redis","type":"dependsOn","strength":"optional","description":"FastAPI Sample uses the shared Redis service for L2 probe caches and runtime heartbeat aggregation."},{"source":"fastapi-sample","target":"traefik","type":"exposedBy","strength":"optional","description":"Traefik exposes the local FastAPI Sample endpoint on the trusted internal hostname."},{"source":"garage","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"garage","target":"traefik","type":"exposedBy","strength":"required","description":"Traefik routes the direct s3.int.albandrieu.com S3 ingress to Garage :3900 after pfSense HAProxy TLS re-encryption."},{"source":"garage-admin","target":"cloudflared","type":"exposedBy","strength":"required","description":"Cloudflare Tunnel forwards garage-admin.albandrieu.com through cloudflared directly to Garage Admin :3903."},{"source":"garage-admin","target":"garage","type":"partOf","strength":"required","description":"Garage Admin :3903 is the administration API of the Garage object-storage service."},{"source":"garage-webui","target":"cloudflared","type":"exposedBy","strength":"required","description":"Cloudflare Tunnel forwards garage.albandrieu.com through cloudflared directly to the Garage WebUI :3909 origin."},{"source":"garage-webui","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"garage-webui","target":"garage","type":"consumesApi","strength":"required","description":"Garage WebUI uses the Garage Admin API and S3 API."},{"source":"gatus","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"grafana","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"grafana","target":"loki","type":"consumesApi","strength":"optional","description":"Grafana queries Loki for logs."},{"source":"grafana","target":"mimir","type":"consumesApi","strength":"optional","description":"Grafana queries Mimir for metrics."},{"source":"grafana","target":"tempo","type":"consumesApi","strength":"optional","description":"Grafana queries Tempo for distributed traces."},{"source":"graylog","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"graylog","target":"mongo","type":"dependsOn","strength":"required","description":"Graylog stores application configuration and metadata in the shared MongoDB service."},{"source":"graylog","target":"opensearch-security","type":"storesIn","strength":"required","description":"Graylog stores log indices in the shared OpenSearch 2.x security cluster."},{"source":"haproxy-exporter","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"haproxy-exporter","target":"pfsense","type":"consumesApi","strength":"required","description":"The exporter scrapes the HAProxy statistics endpoint exposed by pfSense."},{"source":"haproxy-exporter","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes HAProxy metrics from this exporter."},{"source":"hello-nginx","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"homarr","target":"docker","type":"consumesApi","strength":"optional","description":"Homarr discovers and manages containers through the read-only Docker socket proxy."},{"source":"homarr","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"homarr-sync","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"homarr-sync","target":"homarr","type":"consumesApi","strength":"required","description":"Reconciles generated application desired state through the Homarr OpenAPI endpoints."},{"source":"homeassistant","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"influxdb","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"joplin","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"joplin","target":"postgresql","type":"dependsOn","strength":"required","description":"Joplin persists notes, users and synchronization state in the shared PostgreSQL service."},{"source":"joplin","target":"traefik","type":"exposedBy","strength":"required","description":"Traefik exposes Joplin only through the private joplin.int.albandrieu.com hostname."},{"source":"kafka","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"kafka-exporter","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"kafka-exporter","target":"kafka","type":"dependsOn","strength":"required","description":"Exporter queries broker/topic and consumer-group state from the co-located Kafka App."},{"source":"kafka-exporter","target":"prometheus","type":"observedBy","strength":"required","description":"Prometheus scrapes Kafka topic/group lag and membership metrics."},{"source":"keycloak","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"keycloak","target":"postgresql","type":"dependsOn","strength":"required","description":"Keycloak stores realm, client and identity state in the shared PostgreSQL service."},{"source":"keycloak","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes Keycloak metrics from the private management interface."},{"source":"kibana","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"kibana","target":"elasticsearch","type":"dependsOn","strength":"required","description":"Kibana queries Elasticsearch for indexed data and saved objects."},{"source":"kubernetes","target":"etcd","type":"dependsOn","strength":"required","description":"Kubernetes control-plane availability depends on a healthy etcd state store."},{"source":"kubernetes","target":"talos","type":"hostedBy","strength":"required","description":"The Kubernetes cluster runs on Talos Linux control-plane and worker nodes."},{"source":"langflow","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"langflow","target":"opensearch","type":"dependsOn","strength":"required","description":"The OpenRAG Langflow runtime accesses the shared OpenSearch service."},{"source":"langfuse-web","target":"clickhouse","type":"dependsOn","strength":"required","description":"Langfuse Web reads and writes analytical event data in ClickHouse."},{"source":"langfuse-web","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"langfuse-web","target":"langfuse","type":"partOf","strength":"required","description":"The web application is a runtime workload of the logical Langfuse platform."},{"source":"langfuse-web","target":"minio","type":"storesIn","strength":"required","description":"Langfuse Web uses S3-compatible object storage for media and exports."},{"source":"langfuse-web","target":"postgresql","type":"dependsOn","strength":"required","description":"Langfuse Web stores transactional application data in PostgreSQL."},{"source":"langfuse-web","target":"redis","type":"dependsOn","strength":"required","description":"Langfuse Web uses Redis-backed queues and shared asynchronous state."},{"source":"langfuse-worker","target":"clickhouse","type":"dependsOn","strength":"required","description":"Langfuse Worker stores analytical event data in ClickHouse."},{"source":"langfuse-worker","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"langfuse-worker","target":"langfuse","type":"partOf","strength":"required","description":"The worker is a runtime workload of the logical Langfuse platform."},{"source":"langfuse-worker","target":"minio","type":"storesIn","strength":"required","description":"Langfuse Worker uses S3-compatible object storage for event, media and export data."},{"source":"langfuse-worker","target":"postgresql","type":"dependsOn","strength":"required","description":"Langfuse Worker stores transactional application data in PostgreSQL."},{"source":"langfuse-worker","target":"redis","type":"dependsOn","strength":"required","description":"Langfuse Worker uses Redis for queues and asynchronous processing."},{"source":"languagetool","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"litellm","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"litellm","target":"langfuse","type":"observedBy","strength":"optional","description":"LiteLLM exports LLM telemetry to Langfuse through its OpenTelemetry callback."},{"source":"litellm","target":"mcp-cyberbro","type":"routesTo","strength":"optional","description":"LiteLLM exposes Cyberbro threat-intelligence tools through its MCP gateway."},{"source":"litellm","target":"ollama","type":"routesTo","strength":"required","description":"LiteLLM routes local model and embedding requests to Ollama runtimes."},{"source":"litellm","target":"prometheus","type":"observedBy","strength":"optional","description":"LiteLLM enables its Prometheus callback and budget metrics."},{"source":"litellm","target":"redis","type":"dependsOn","strength":"optional","description":"LiteLLM can use Redis for its response cache."},{"source":"loki","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"mcp-cyberbro","target":"cyberbro","type":"consumesApi","strength":"required","description":"Cyberbro MCP submits observables to the Cyberbro HTTP API and retrieves analysis results."},{"source":"mcp-cyberbro","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"mcp-cyberbro","target":"litellm","type":"providesApi","strength":"optional","description":"LiteLLM can consume this streamable HTTP MCP endpoint as an upstream MCP server."},{"source":"mimir","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"minio","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"mongo","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"n8n","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"n8n","target":"postgresql","type":"dependsOn","strength":"required","description":"n8n is configured with PostgreSQL credentials for workflow persistence."},{"source":"n8n","target":"prometheus","type":"observedBy","strength":"optional","description":"n8n exposes metrics for Prometheus scraping."},{"source":"n8n","target":"redis","type":"dependsOn","strength":"optional","description":"n8n is configured with Redis credentials for queue-backed execution."},{"source":"n8n","target":"traefik","type":"exposedBy","strength":"optional","description":"Traefik routes HTTPS traffic to n8n."},{"source":"neo4j-security","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"netbox","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"netbox","target":"postgresql","type":"storesIn","strength":"required"},{"source":"netbox","target":"redis","type":"storesIn","strength":"required"},{"source":"netbox-housekeeping","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"netbox-housekeeping","target":"netbox","type":"partOf","strength":"required"},{"source":"netbox-worker","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"netbox-worker","target":"netbox","type":"partOf","strength":"required"},{"source":"nexus","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"nginx-proxy-manager","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"npmplus","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"ntopng","target":"clickhouse","type":"storesIn","strength":"required","description":"ntopng stores historical flow data in the existing ClickHouse service."},{"source":"ntopng","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"obsidian","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"ollama","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"ollama","target":"prometheus","type":"observedBy","strength":"optional","description":"Ollama is marked for Prometheus scraping."},{"source":"ollama","target":"traefik","type":"exposedBy","strength":"optional","description":"Traefik routes the internal Ollama endpoint."},{"source":"op-connect-api","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"op-connect-sync","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"op-connect-sync","target":"op-connect-api","type":"partOf","strength":"required","description":"Sync and API form the 1Password Connect deployment."},{"source":"openclaw-sandbox","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"opencre","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"openhands","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"openrag-backend","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"openrag-backend","target":"docling","type":"consumesApi","strength":"required","description":"OpenRAG sends document conversion requests to the repository-managed Docling Serve API."},{"source":"openrag-backend","target":"langflow","type":"dependsOn","strength":"required","description":"OpenRAG backend invokes the shared Langflow service."},{"source":"openrag-backend","target":"opensearch","type":"dependsOn","strength":"required","description":"OpenRAG backend stores and retrieves indexed content through OpenSearch."},{"source":"openrag-frontend","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"openrag-frontend","target":"langflow","type":"dependsOn","strength":"required","description":"Frontend collective health checks the shared global Langflow service."},{"source":"openrag-frontend","target":"openrag-backend","type":"consumesApi","strength":"required","description":"The OpenRAG frontend talks to the OpenRAG backend."},{"source":"opensearch","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"opensearch-dashboards","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"opensearch-dashboards","target":"opensearch","type":"dependsOn","strength":"required","description":"OpenSearch Dashboards queries the OpenRAG OpenSearch cluster."},{"source":"opensearch-exporter","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"opensearch-exporter","target":"opensearch","type":"consumesApi","strength":"required","description":"The exporter collects metrics from the OpenRAG OpenSearch service."},{"source":"opensearch-exporter","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes metrics from the OpenSearch exporter."},{"source":"opensearch-security","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"opensearch-security-exporter","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"opensearch-security-exporter","target":"opensearch-security","type":"consumesApi","strength":"required","description":"The exporter collects metrics from the shared OpenSearch 2.x security cluster."},{"source":"opensearch-security-exporter","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes metrics from the OpenSearch Security exporter."},{"source":"openssf-scorecard","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"openwebui","target":"cloudflared","type":"exposedBy","strength":"required","description":"Cloudflare Tunnel forwards open-webui.albandrieu.com through cloudflared directly to the published :31028 origin; Traefik is not in this path."},{"source":"openwebui","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"openwebui","target":"litellm","type":"consumesApi","strength":"required","description":"Open WebUI sends chat and RAG OpenAI-compatible requests through LiteLLM."},{"source":"openwebui","target":"open-terminal","type":"consumesApi","strength":"optional","description":"Open WebUI agents can invoke the Open Terminal tool API."},{"source":"openwebui","target":"searxng","type":"consumesApi","strength":"optional","description":"Open WebUI can delegate web search to the SearXNG integration."},{"source":"openwebui-pipelines","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"pfsense-exporter","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"pfsense-exporter","target":"pfsense","type":"consumesApi","strength":"required","description":"The exporter queries pfSense for firewall and system metrics."},{"source":"pfsense-exporter","target":"prometheus","type":"observedBy","strength":"required","description":"Prometheus scrapes the pfSense exporter."},{"source":"pfsense-unbound","target":"pihole","type":"dependsOn","strength":"required","description":"Private int.albandrieu.com resolution through pfSense/Unbound depends on the Pi-hole authority at 172.17.0.24:53; public recursion remains independent."},{"source":"pihole","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"pihole-dns-sync","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"pihole-dns-sync","target":"docker-socket-proxy","type":"consumesApi","strength":"required","description":"DNS Sync discovers services through the restricted Docker socket proxy."},{"source":"pihole-dns-sync","target":"pihole","type":"automates","strength":"required","description":"DNS Sync reconciles private service records through the Pi-hole API."},{"source":"pihole-exporter","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"pihole-exporter","target":"pihole","type":"dependsOn","strength":"required","description":"The exporter reads Pi-hole runtime statistics."},{"source":"plumber","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"plumber","target":"plumber-api","type":"consumesApi","strength":"required"},{"source":"plumber-api","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"plumber-api","target":"postgresql","type":"storesIn","strength":"required"},{"source":"plumber-api","target":"redis","type":"storesIn","strength":"required"},{"source":"plumber-worker","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"plumber-worker","target":"plumber-api","type":"partOf","strength":"required"},{"source":"portracker","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"postgres-exporter","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"postgres-exporter","target":"postgresql","type":"dependsOn","strength":"required","description":"The exporter queries the shared PostgreSQL service."},{"source":"prometheus","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"prometheus","target":"mimir","type":"storesIn","strength":"required","description":"Prometheus remote-writes collected metrics to Mimir for durable storage."},{"source":"prometheus-alertmanager","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"pyroscope","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"pyroscope","target":"grafana","type":"observedBy","strength":"optional","description":"Grafana queries Pyroscope as a profiling data source."},{"source":"pyroscope","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes Pyroscope self-metrics from /metrics."},{"source":"redis","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"scanopy","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"scanopy","target":"postgresql","type":"storesIn","strength":"required","description":"Scanopy stores topology, inventory, and discovery history in its dedicated scanopy database on the shared PostgreSQL service."},{"source":"scanopy","target":"scanopy-daemon","type":"consumesApi","strength":"required","description":"Scanopy consumes discovery data from its integrated daemon."},{"source":"scanopy-daemon","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"scrutiny","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"scrutiny","target":"influxdb","type":"storesIn","strength":"required","description":"Scrutiny stores SMART history in the shared InfluxDB service."},{"source":"scrutiny-collector","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"scrutiny-collector","target":"scrutiny","type":"consumesApi","strength":"required","description":"The collector posts SMART inventory and metrics to the Scrutiny web/API service."},{"source":"sentry","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sentry","target":"kafka","type":"dependsOn","strength":"required","description":"Sentry publishes and consumes event streams through shared Kafka."},{"source":"sentry","target":"postgresql","type":"dependsOn","strength":"required","description":"Sentry application metadata is stored in the dedicated sentry PostgreSQL database."},{"source":"sentry","target":"redis","type":"dependsOn","strength":"required","description":"Sentry uses the shared Redis database 3."},{"source":"sentry","target":"sentry-snuba-api","type":"dependsOn","strength":"required","description":"Sentry queries event data through Snuba."},{"source":"sentry-clickhouse","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sentry-edge","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sentry-edge","target":"sentry","type":"routesTo","strength":"required","description":"The Sentry edge routes application traffic to Sentry web."},{"source":"sentry-edge","target":"sentry-relay","type":"routesTo","strength":"required","description":"The Sentry edge routes ingestion traffic through Relay."},{"source":"sentry-relay","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sentry-relay","target":"kafka","type":"dependsOn","strength":"required","description":"Relay publishes processing traffic to shared Kafka."},{"source":"sentry-relay","target":"redis","type":"dependsOn","strength":"required","description":"Relay uses the shared Redis service."},{"source":"sentry-relay","target":"sentry","type":"routesTo","strength":"required","description":"Relay forwards accepted traffic to Sentry web."},{"source":"sentry-snuba-api","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sentry-snuba-api","target":"kafka","type":"dependsOn","strength":"required","description":"Snuba consumes Sentry event streams from shared Kafka."},{"source":"sentry-snuba-api","target":"redis","type":"dependsOn","strength":"required","description":"Snuba uses the shared Redis service for runtime state."},{"source":"sentry-snuba-api","target":"sentry-clickhouse","type":"dependsOn","strength":"required","description":"Snuba reads and writes Sentry analytical state in ClickHouse."},{"source":"sentry-taskbroker","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sentry-taskbroker","target":"kafka","type":"dependsOn","strength":"required","description":"Taskbroker persists task streams through shared Kafka."},{"source":"sentry-taskworker","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sentry-taskworker","target":"sentry-taskbroker","type":"dependsOn","strength":"required","description":"Taskworker receives RPC work from Taskbroker."},{"source":"sonarqube","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sonarqube","target":"postgresql","type":"dependsOn","strength":"required","description":"SonarQube persists application state in the existing PostgreSQL service."},{"source":"squid","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"suricata","target":"alloy","type":"observedBy","strength":"optional","description":"Grafana Alloy tails Suricata JSON logs for Loki ingestion."},{"source":"suricata","target":"crowdsec","type":"observedBy","strength":"optional","description":"CrowdSec consumes Suricata event logs for behavioral decisions."},{"source":"suricata","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sybase-exporter","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"sybase-exporter","target":"prometheus","type":"observedBy","strength":"optional","description":"Prometheus scrapes Sybase database metrics from this exporter."},{"source":"sybase-exporter","target":"sybase","type":"consumesApi","strength":"required","description":"The exporter queries Sybase ASE through the FreeTDS driver."},{"source":"talos","target":"truenas","type":"hostedBy","strength":"required","description":"Talos control-plane and worker nodes are provisioned as VMs on TrueNAS."},{"source":"tempo","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"traefik","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"traefik","target":"pfsense-haproxy","type":"exposedBy","strength":"required","description":"pfSense HAProxy terminates WAN TLS and opens a new TLS connection to Traefik on 172.17.0.24:443 while preserving the HTTP Host used by Traefik routers."},{"source":"vaultwarden","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"vaultwarden-rest-api","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"vaultwarden-rest-api","target":"vaultwarden","type":"consumesApi","strength":"required","description":"The compatibility adapter authenticates against Vaultwarden."},{"source":"wazuh-dashboard","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"wazuh-dashboard","target":"wazuh","type":"partOf","strength":"required","description":"Wazuh Dashboard is a runtime workload of the Wazuh security platform."},{"source":"wazuh-dashboard","target":"wazuh-indexer","type":"dependsOn","strength":"required","description":"Wazuh Dashboard queries security data from Wazuh Indexer."},{"source":"wazuh-dashboard","target":"wazuh-manager","type":"consumesApi","strength":"required","description":"Wazuh Dashboard consumes the Wazuh Manager API."},{"source":"wazuh-forwarder","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"wazuh-forwarder","target":"opensearch-security","type":"storesIn","strength":"required","description":"The forwarder replicates Wazuh alerts into the shared OpenSearch 2.x security cluster."},{"source":"wazuh-forwarder","target":"wazuh","type":"partOf","strength":"required","description":"The forwarder is an integration workload of the Wazuh security platform."},{"source":"wazuh-forwarder","target":"wazuh-manager","type":"dependsOn","strength":"required","description":"The forwarder reads Wazuh alert files produced by Wazuh Manager."},{"source":"wazuh-indexer","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"wazuh-indexer","target":"wazuh","type":"partOf","strength":"required","description":"Wazuh Indexer is a runtime workload of the Wazuh security platform."},{"source":"wazuh-manager","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"wazuh-manager","target":"wazuh","type":"partOf","strength":"required","description":"Wazuh Manager is a runtime workload of the Wazuh security platform."},{"source":"wazuh-manager","target":"wazuh-indexer","type":"dependsOn","strength":"required","description":"Wazuh Manager indexes security events in the Wazuh Indexer."},{"source":"wordpress","target":"docker","type":"hostedBy","strength":"required","description":"Compose workload is hosted by the Docker runtime on TrueNAS."},{"source":"wordpress","target":"postgresql","type":"dependsOn","strength":"required","description":"WordPress stores application state in PostgreSQL through PG4WP."}]}