Skip to main content

Interactive Nabla architecture

AI platform, homelab services, functional dependencies, and observable integrations.

The page starts with foundations and components with the largest blast radius before leaf applications. The detailed view then keeps the complete relationship graph declared in nabla-compose.

Operations and troubleshooting

One read-only snapshot of FastAPI runtime, dependency health, TrueNAS, pfSense and Cloudflare evidence. Start here to identify the failing layer before changing configuration.

Refreshing evidence…
Refreshing evidence…

Impact and root-cause inspector

Select a service to separate local health, observed blocked_by causes, and structural blast radius across required topology relations.

Architecture health and filters

Services stay first; filters use operator presentation roles while the complete topology remains the basis for dependency criticality and blast-radius calculations.

Refreshing…

70 declared services shown of 70

1 · Services & experimentsPrimary homelab outcomes: track service availability, errors, latency and traffic.RED52 components52 need attention
Vaultwarden

Vaultwarden

Unknown

Password manager

2FAuth

2FAuth

Unknown

Two-factor codes manager

Nexus

Nexus

Unknown

Sonatype Nexus Repository

AdGuard Home

AdGuard Home

Unknown

Network-wide ad blocking

Affine

Affine

Unknown

Knowledge base and notes

AnythingLLM

AnythingLLM

Unknown

Private LLM workspace and RAG

AnythingLLM - albandrieu

AnythingLLM - albandrieu

Unknown

Private LLM workspace and RAG

ConvertX

ConvertX

Unknown

File conversion service

DDNS Updater

DDNS Updater

Unknown

Dynamic DNS updates

Domain Watchdog

Domain Watchdog

Unknown

Domain monitoring service

Heimdall

Heimdall

Unknown

Application dashboard

Hello

Hello

Unknown

Hello World NGINX service

Home

Home

Unknown

Gateway admin UI (home hostname)

IT Tools

IT Tools

Unknown

Developer utilities collection

KaraKeep

KaraKeep

Unknown

Karaoke management

Keycloak

Keycloak

Unknown

Identity and access management

Language Tool

Language Tool

Unknown

languagetool

Lidarr

Lidarr

Unknown

Music collection manager

LiteLLM - albandrieu

LiteLLM - albandrieu

Unknown

LLM proxy and gateway

LocalAI (GPU)

LocalAI (GPU)

Unknown

Local AI models (GPU instance)

NetAlertX

NetAlertX

Unknown

Network presence and alerts

Netbootxyz

Netbootxyz

Unknown

Network boot utility

Ollama (GPU)

Ollama (GPU)

Unknown

Large language models (GPU instance)

Open SpeedTest

Open SpeedTest

Unknown

Open SpeedTest - Network speed testing

Open WebUI

Open WebUI

Unknown

Web interface for chat models

OpenArchiver

OpenArchiver

Unknown

Archive management

Paperless AI

Paperless AI

Unknown

Document management with AI

Paperless-ngx

Paperless-ngx

Unknown

Document management system

pgAdmin

pgAdmin

Unknown

PostgreSQL administration

Plumber

Plumber

Unknown

GitLab Security check

Plumber API

Plumber API

Unknown

GitLab Security check

Portainer

Portainer

Unknown

Container management

PortTracker

PortTracker

Unknown

Port tracking service

PortTracker - albandrieu

PortTracker - albandrieu

Unknown

Port tracking service

Prometheus - albandrieu

Prometheus - albandrieu

Unknown

Prometheus

Radarr

Radarr

Unknown

Movie collection manager

Reactive Resume

Reactive Resume

Unknown

Reactive Resume

Reactive Resume - albandrieu

Reactive Resume - albandrieu

Unknown

Reactive Resume

Scrutiny Collector - albandrieu

Scrutiny Collector - albandrieu

Unknown

Hard drive health monitoring

Sonarr

Sonarr

Unknown

TV series management

Speedtest Tracker

Speedtest Tracker

Unknown

Speedtest

Stirling PDF - albandrieu

Stirling PDF - albandrieu

Unknown

PDF toolkit

Transmission

Transmission

Unknown

BitTorrent client

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
2 · Critical core platformFoundations whose failure can remove a whole layer: track availability, quorum/readiness, pressure, capacity and errors.USE2 components2 need attention
TrueNAS

TrueNAS

Unknown

Storage management UI

pfSense

pfSense

Unknown

Firewall and router

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
4 · Shared platform & dataShared backends: track availability, latency, saturation and capacity without conflating impact with required dependency.RED + USE11 components11 need attention
PostgreSQL

PostgreSQL

Unknown

Database server (TCP — use a Postgres client, not a normal web browser tab)

Ollama

Ollama

Unknown

Large language models

Homarr

Homarr

Unknown

Homepage dashboard

LiteLLM

LiteLLM

Unknown

LLM proxy and gateway

Scrutiny

Scrutiny

Unknown

Hard drive health monitoring

Uptime Kuma

Uptime Kuma

Unknown

Uptime monitoring

SearXNG

SearXNG

Unknown

SearXNG service

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
5 · Observability & supportObservability and auxiliary tools: important for diagnosis without automatically marking monitored services unavailable.SUPPORT5 components5 need attention
Graylog

Graylog

Unknown

Log management and analysis

ntopng

ntopng

Unknown

Network traffic visibility

Grafana

Grafana

Unknown

Analytics and monitoring

TrueNAS application status: running / healthy transitional / degraded stopped / failed no current runtime status
Dependency health: The primary service/link color follows effective health; the runtime icon remains the local TrueNAS application state.
Show critical dependency hierarchy

Critical dependency hierarchy

Foundational infrastructure and shared state are shown before applications, using declared required dependencies and their transitive blast radius.

1 · Infrastructure foundations

TrueNAS98 dependents
storage-platformBlast radius: 2FAuth, AIStor, Akvorado, Akvorado Inlet +94 more
Inspect dependency impact
Direct dependents: Docker, Talos Linux
Indirect / transitive impact: 2FAuth, AIStor, Akvorado, Akvorado Inlet, Akvorado Orchestrator, Akvorado Outlet, Grafana Alloy, AutoKuma, AutoXpose, Bichon, ClickHouse, Code Server, CrowdSec, Docker Socket Proxy, Dockhand, Doco-CD, Dozzle, Draw.io, Elasticsearch, etcd, FastAPI Sample, Garage, Garage WebUI, Gatus, Grafana, Graylog, pfSense HAProxy Exporter, Hello Nginx, Homarr, Homarr Reconciler, Home Assistant, InfluxDB, Apache Kafka, Kibana, Kubernetes (Talos), Langflow, Langfuse Web, Langfuse Worker, LanguageTool, LiteLLM, Loki, Mimir, MinIO, MongoDB, n8n, Nexus Repository, Nginx Proxy Manager, NPMplus, ntopng, Obsidian, Ollama, 1Password Connect API, 1Password Connect Sync, OpenClaw Sandbox, OpenHands, OpenRAG Backend, OpenRAG Frontend, OpenSearch, OpenSearch Dashboards, OpenSearch Exporter, OpenSearch Security, OpenSearch Security Exporter, Open WebUI, Open WebUI Pipelines, pfSense Exporter, Pi-hole, Pi-hole DNS Sync, Pi-hole Exporter, Portracker, PostgreSQL Exporter, Prometheus, Alertmanager, Grafana Pyroscope, Redis, Scrutiny, Scrutiny Collector, Sentry, Sentry ClickHouse, Sentry Edge, Sentry Relay, Sentry Snuba API, Sentry Taskbroker, Sentry Taskworker, SonarQube, Squid Proxy, Suricata, Sybase Exporter, Tempo, Traefik, Vaultwarden, Vaultwarden REST API Adapter, Wazuh Dashboard, Wazuh OpenSearch Forwarder, Wazuh Indexer, Wazuh Manager, WordPress
Docker94 dependents
container-runtimeBlast radius: 2FAuth, AIStor, Akvorado, Akvorado Inlet +90 more
Inspect dependency impact
Direct dependents: 2FAuth, AIStor, Akvorado, Akvorado Inlet, Akvorado Orchestrator, Akvorado Outlet, Grafana Alloy, AutoKuma, AutoXpose, Bichon, ClickHouse, Code Server, CrowdSec, Docker Socket Proxy, Dockhand, Doco-CD, Dozzle, Draw.io, Elasticsearch, FastAPI Sample, Garage, Garage WebUI, Gatus, Grafana, Graylog, pfSense HAProxy Exporter, Hello Nginx, Homarr, Homarr Reconciler, Home Assistant, InfluxDB, Apache Kafka, Kibana, Langflow, Langfuse Web, Langfuse Worker, LanguageTool, LiteLLM, Loki, Mimir, MinIO, MongoDB, n8n, Nexus Repository, Nginx Proxy Manager, NPMplus, ntopng, Obsidian, Ollama, 1Password Connect API, 1Password Connect Sync, OpenClaw Sandbox, OpenHands, OpenRAG Backend, OpenRAG Frontend, OpenSearch, OpenSearch Dashboards, OpenSearch Exporter, OpenSearch Security, OpenSearch Security Exporter, Open WebUI, Open WebUI Pipelines, pfSense Exporter, Pi-hole, Pi-hole DNS Sync, Pi-hole Exporter, Portracker, PostgreSQL Exporter, Prometheus, Alertmanager, Grafana Pyroscope, Redis, Scrutiny, Scrutiny Collector, Sentry, Sentry ClickHouse, Sentry Edge, Sentry Relay, Sentry Snuba API, Sentry Taskbroker, Sentry Taskworker, SonarQube, Squid Proxy, Suricata, Sybase Exporter, Tempo, Traefik, Vaultwarden, Vaultwarden REST API Adapter, Wazuh Dashboard, Wazuh OpenSearch Forwarder, Wazuh Indexer, Wazuh Manager, WordPress
🔥 pfSense2 dependents
firewallBlast radius: pfSense HAProxy Exporter, pfSense Exporter
Inspect dependency impact
Direct dependents: pfSense HAProxy Exporter, pfSense Exporter
Nginx Proxy Managerleaf
reverse-proxy
NPMplusleaf
reverse-proxy
⚖️ pfSense HAProxyleaf
reverse-proxy
+2 lower-impact components

2 · Shared data and state

Apache Kafka9 dependents
message-brokerBlast radius: Akvorado Inlet, Akvorado Orchestrator, Akvorado Outlet, Sentry +5 more
Inspect dependency impact
Direct dependents: Akvorado Inlet, Akvorado Orchestrator, Akvorado Outlet, Sentry, Sentry Relay, Sentry Snuba API, Sentry Taskbroker
Indirect / transitive impact: Sentry Edge, Sentry Taskworker
🐘 PostgreSQL9 dependents
databaseBlast radius: Langfuse Web, Langfuse Worker, n8n, PostgreSQL Exporter +5 more
Inspect dependency impact
Direct dependents: Langfuse Web, Langfuse Worker, n8n, PostgreSQL Exporter, Sentry, SonarQube, WordPress
Indirect / transitive impact: Sentry Edge, Sentry Relay
ClickHouse6 dependents
databaseBlast radius: Akvorado, Akvorado Orchestrator, Akvorado Outlet, Langfuse Web +2 more
Inspect dependency impact
Direct dependents: Akvorado, Akvorado Orchestrator, Akvorado Outlet, Langfuse Web, Langfuse Worker, ntopng
🔴 Redis6 dependents
cacheBlast radius: Langfuse Web, Langfuse Worker, Sentry, Sentry Edge +2 more
Inspect dependency impact
Direct dependents: Langfuse Web, Langfuse Worker, Sentry, Sentry Relay, Sentry Snuba API
Indirect / transitive impact: Sentry Edge
🔎 OpenSearch5 dependents
searchBlast radius: Langflow, OpenRAG Backend, OpenRAG Frontend, OpenSearch Dashboards +1 more
Inspect dependency impact
Direct dependents: Langflow, OpenRAG Backend, OpenSearch Dashboards, OpenSearch Exporter
Indirect / transitive impact: OpenRAG Frontend
Sentry ClickHouse4 dependents
databaseBlast radius: Sentry, Sentry Edge, Sentry Relay, Sentry Snuba API
Inspect dependency impact
Direct dependents: Sentry Snuba API
Indirect / transitive impact: Sentry, Sentry Edge, Sentry Relay
+11 lower-impact components

3 · Shared platform services

🛡️ Wazuh4 dependents
security-platformBlast radius: Wazuh Dashboard, Wazuh OpenSearch Forwarder, Wazuh Indexer, Wazuh Manager
Inspect dependency impact
Direct dependents: Wazuh Dashboard, Wazuh OpenSearch Forwarder, Wazuh Indexer, Wazuh Manager
Docker Socket Proxy3 dependents
security-proxyRequires: DockerBlast radius: AutoXpose, Doco-CD, Pi-hole DNS Sync
Inspect dependency impact
Required path: Docker Socket Proxy → Docker
Direct dependents: AutoXpose, Doco-CD, Pi-hole DNS Sync
Sentry Snuba API3 dependents
analytics-apiRequires: Apache Kafka · Redis · Sentry ClickHouseBlast radius: Sentry, Sentry Edge, Sentry Relay
Inspect dependency impact
Required path: Sentry Snuba API → Apache Kafka
Direct dependents: Sentry
Indirect / transitive impact: Sentry Edge, Sentry Relay
📈 Langfuse2 dependents
observabilityBlast radius: Langfuse Web, Langfuse Worker
Inspect dependency impact
Direct dependents: Langfuse Web, Langfuse Worker
Sentry2 dependents
error-trackingRequires: Apache Kafka · PostgreSQL · Redis · Sentry Snuba APIBlast radius: Sentry Edge, Sentry Relay
Inspect dependency impact
Required path: Sentry → Sentry Snuba API → Apache Kafka
Direct dependents: Sentry Edge, Sentry Relay
🔷 Talos Linux2 dependents
kubernetes-osBlast radius: etcd, Kubernetes (Talos)
Inspect dependency impact
Direct dependents: etcd, Kubernetes (Talos)
+14 lower-impact components

4 · Applications and consumers

Akvoradoleaf
network-observabilityRequires: ClickHouse
Inspect dependency impact
Required path: Akvorado → ClickHouse
Akvorado Inletleaf
network-flow-collectorRequires: Apache Kafka
Inspect dependency impact
Required path: Akvorado Inlet → Apache Kafka
Akvorado Orchestratorleaf
network-flow-controllerRequires: ClickHouse · Apache Kafka
Inspect dependency impact
Required path: Akvorado Orchestrator → ClickHouse
Akvorado Outletleaf
network-flow-processorRequires: ClickHouse · Apache Kafka
Inspect dependency impact
Required path: Akvorado Outlet → ClickHouse
🧬 Grafana Alloyleaf
telemetry-collectorRequires: Loki · Mimir · TempoOptional: pfSense, Suricata
Inspect dependency impact
Required path: Grafana Alloy → Loki
AutoKumaleaf
monitoring-controllerRequires: Uptime Kuma
Inspect dependency impact
Required path: AutoKuma → Uptime Kuma
+31 lower-impact components

5 · Support and low-impact components

🔐 2FAuthleaf
security-app
AIStorleaf
object-storage
Bichonleaf
application
Code Serverleaf
development-environment
🛡️ CrowdSecleaf
security-agentOptional: Suricata
Dockhandleaf
container-management
+20 lower-impact components

Criticality is derived from blocking required relations (dependsOn, consumesApi, routesTo, storesIn, authenticatesVia and structural partOf). Databases, caches and storage kinds are treated as shared state when they have required dependents. Observability and exposure links do not artificially increase startup criticality.

Compact hierarchy

Mobile view of criticality tiers, effective health, and direct relations. The complete interactive graph remains available below.

Infrastructure foundations2 servicesunknown
TrueNASfoundation · blast 98
unknown
No direct relations shown.
pfSensefoundation · blast 2
unknown
No direct relations shown.
Shared data and state4 servicesunknown
PostgreSQLshared-data · blast 9
unknown
No direct relations shown.
Clickhouseshared-data · blast 6
unknown
  • Dockerrequired · hostedBy
Minioshared-data · blast 2
unknown
  • Dockerrequired · hostedBy
Garageshared-data · blast 1
unknown
  • Dockerrequired · hostedBy
Shared platform services7 servicesunknown
Scrutinyshared-platform · blast 1
unknown
  • Dockerrequired · hostedBy
  • InfluxDBrequired · storesIn
Uptime Kumashared-platform · blast 1
unknown
No direct relations shown.
Vaultwardenshared-platform · blast 1
unknown
  • Dockerrequired · hostedBy
Ollamashared-platform · blast 2
unknown
  • Dockerrequired · hostedBy
Homarrshared-platform · blast 1
unknown
  • Dockerrequired · hostedBy
LiteLLMshared-platform · blast 1
unknown
  • Dockerrequired · hostedBy
  • Ollamarequired · routesTo
Langfuseshared-platform · blast 2
unknown
No direct relations shown.
Applications and consumers4 servicesunknown
Prometheusapplication · blast 0
unknown
  • Dockerrequired · hostedBy
  • Mimirrequired · storesIn
n8napplication · blast 0
unknown
  • Dockerrequired · hostedBy
  • PostgreSQLrequired · dependsOn
Graylogapplication · blast 0
unknown
  • Dockerrequired · hostedBy
  • MongoDBrequired · dependsOn
  • OpenSearch Securityrequired · storesIn
ntopngapplication · blast 0
unknown
  • ClickHouserequired · storesIn
  • Dockerrequired · hostedBy

Interactive service topology

Use the graph search and controls to switch between the AI platform, services, critical path, full catalog, and optional relations. On mobile, the compact hierarchy above provides a more direct view before the complete graph.

20 nodes · 6 groups · 20 relations
Edge semantics
DependencyAPI / data flowExposurePlacementObservationAutomation
Color and line pattern identify relation purpose; required/optional separately identifies functional strength. A required edge may temporarily inherit red/orange health without changing its semantic category.

Compact mobile view: expand a layer, then a service, to inspect its visible relations.

Interfaces & agentsHuman-facing clients and coding/agent entry points.5 nodes · main flow ↓
  • Codexinterfaces · coding-agent
    1 relation
    • required · API/data flow · model requestsLiteLLM
  • Cursorinterfaces · coding-agent
    1 relation
    • required · API/data flow · model requestsLiteLLM
  • Open WebUIinterfaces · interface
    application · blast radius 0
    3 relations
    • required · API/data flow · model requestsLiteLLM
    • optional · API/data flow · tool callsFastAPI MCP
    • optional · API/data flow · RAGOpenRAG
  • OpenClawinterfaces · agent
    1 relation
    • required · API/data flow · model requestsLiteLLM
  • OpenCodeinterfaces · coding-agent
    1 relation
    • required · API/data flow · model requestsLiteLLM
Control planeShared model gateway, routing policy and hot state.2 nodes · main flow ↓
  • LiteLLMcontrol-plane · model-gateway
    shared platform · blast radius 1
    5 relations
    • optional · dependency · cacheRedis
    • required · API/data flow · routesToOllama
    • optional · API/data flow · routesToOpenAI API
    • optional · observation · telemetryLangfuse
    • optional · observation · metricsPrometheus
  • Rediscontrol-plane · cache
    shared data · blast radius 6
InferenceLocal and remote model execution targets.2 nodes · main flow ↓
  • Ollamainference · local-inference
    shared platform · blast radius 2
  • OpenAI APIinference · remote-inference
    Open
Tools & knowledgeMCP tools, search, RAG and document knowledge boundaries.5 nodes · main flow ↓
  • FastAPI MCPtools · mcp-server
    2 relations
    • optional · API/data flow · tool boundaryOpen Terminal
    • optional · API/data flow · searchSearXNG
    Open
  • Open Terminaltools · agent-tool
    support · blast radius 0
  • OpenRAGtools · rag
    2 relations
    • optional · observation · tracesLangfuse
    • optional · observation · evaluationOpik
    Open
  • Paperless-ngxtools · knowledge
    1 relation
    • optional · API/data flow · knowledge flowOpenRAG
    Open
  • SearXNGtools · search
    support · blast radius 0
OrchestrationWorkflow engines coordinating long-running and automated work.3 nodes · main flow ↓
  • Langfloworchestration · workflow
    shared platform · blast radius 2
    1 relation
    • required · API/data flow · workflowOpenRAG
  • n8norchestration · workflow
    application · blast radius 0
    1 relation
    • optional · automation · automatesFastAPI MCP
  • Temporalorchestration · workflow
    1 relation
    • optional · automation · document workflowPaperless-ngx
    Open
Observability & evaluationTracing, metrics, quality and evaluation feedback loops.3 nodes · main flow ↓
  • Langfuseobservability · llm-observability
    shared platform · blast radius 2
  • Opikobservability · evaluation
    Open
  • Prometheusobservability · metrics
    application · blast radius 0
Mini Map

AI Platform is grouped by functional layers. The main flow moves from interfaces through control plane, inference, tools, orchestration and observability; edge semantics remain distinct from required/optional strength.

Homelab network and ingress paths

This React Flow diagram is the exact same component used on the TrueNAS page. For Garage, client HTTPS terminates at HAProxy on pfSense, HAProxy re-encrypts the backend connection with TLS to Traefik :443 on TrueNAS, and Traefik then routes to Garage. Cloudflare provides DNS only for Garage, while OpenWebUI uses a Cloudflare Tunnel terminated by the cloudflared Docker container.

Focus pathFrames are failure domains, not just visual categories.
WANLAN / hostingWi-FiDirect reverse proxy (HAProxy / Traefik)Cloudflare TunnelCloudflare DNS only

Declared configuration, observed runtime, and health

The architecture deliberately separates what should exist, what is actually running, and what is operationally usable. This makes configuration drift visible without turning the website or the TrueNAS API into the configuration source of truth.

1. nabla-compose

Declarative source: x-nabla services, stable identity, runtime binding, and topology relationships. services.json and service-topology.json are generated from code.

2. TrueNAS API

Observed runtime source: the official truenas_api_client queries app.query for Apps, containers, states, and versions. It never decides that a service should exist or be public.

3. fastapi-sample

Reconciliation layer: joins declared bindings to TrueNAS workloads, classifies drift (in_sync, declared_only, observed_only, conflict), and keeps health checks separate.

4. albanandrieu.com

Presentation layer: visualizes topology, runtime status, and health without becoming a backend data source.

Declared ≠ Observed ≠ Healthy