| .. | ||
| technical | ||
| user-facing | ||
| context.txt | ||
| README.md | ||
The Nest — Documentation
Welcome to the documentation for The Nest: one bird's homelab, shared from me to you! This documentation is split into two audiences:
For Users (Accessible via mynest.love)
These guides explain what each service does, how to reach it, and how to get started. No technical background required.
- Getting Started — First-time setup, accounts, and passkeys
- Requesting Service Access — How to ask an admin for access to services beyond your default set
- Media & Entertainment
- Jellyfin — Stream movies and TV shows
- Audiobookshelf — Audiobooks and podcasts
- DroppedNeedle — Music discovery and streaming
- Calibre-Web — E-book library
- Media Request
- Seerr — Request movies, TV shows, and anime for Jellyfin
- Shelfmark — Request ebooks and audiobooks for Calibre and Audiobookshelf
- DroppedNeedle — Discover and request music
- Productivity & Creation
- Forgejo — Git hosting and code collaboration
- Foundry VTT — Virtual tabletop for TTRPGs
- Storage & Files
- Nextcloud — File sync, sharing, cloud storage, office suite, and more!
- Communication & Security
- Matrix — Chat, voice/video calls, and federation
- Vaultwarden — Password manager (Bitwarden-compatible)
- Your Account (Keycloak) — Manage your identity and passkeys
For Operators (Technical)
These documents cover architecture, networking, security, backups, and internal services. Intended for administrators and technically inclined users.
- Architecture Overview
- Networking — HAProxy, Traefik, MetalLB, ingress routing
- Security & Identity — Keycloak, passkeys, OIDC, group policies
- Backups & Recovery — Longhorn snapshots, Restic, schedules
- MetalLB — Layer 2 load balancing for internal services
- Vault & Keykeeper — HashiCorp Vault HA cluster and transit sealing
- External Secrets Operator — Syncing secrets from Vault into Kubernetes
- Longhorn Storage — Distributed block storage across the cluster
- Keel & Auto-Updates — Automated image updates for deployments
- System Upgrade Controller — Rolling K3s upgrades
- Monitoring Stack — Prometheus, Grafana, Alertmanager
- Matrix Architecture — Synapse, MAS, LiveKit, and RTC internals
- Forgejo (Technical) — Deployment, SSH, package registry, OIDC integration
- Media Automation Pipeline — Sonarr, Radarr, Bazarr, Prowlarr, SABnzbd, Deluge
- slskd (Soulseek) — Peer-to-peer music sharing
- flaresolverr — Cloudflare bypass for indexers
- Tadarr Transcoding — Automatic h.264 to HEVC transcoding
Quick Reference: Service URLs
| Service | URL | Audience |
|---|---|---|
| Jellyfin | https://beak.mynest.love | User |
| Audiobookshelf | https://lyrebird.mynest.love | User |
| DroppedNeedle | https://heron.mynest.love | User |
| Calibre-Web | https://rookery.mynest.love | User |
| Shelfmark | https://magpie.mynest.love | User |
| Seerr | https://stork.mynest.love | User |
| Nextcloud | https://cloud.mynest.love | User |
| Vaultwarden | https://vault.mynest.love | User |
| Forgejo | https://weaver.mynest.love | User |
| Matrix (Synapse) | https://starling.mynest.love | User |
| Matrix RTC | https://matrix-rtc.mynest.love | User |
| Keycloak (SSO) | https://sso.mynest.love | User |
| Foundry VTT | https://foundry.mynest.love | User |
Conventions
- All user-facing services use TLS certificates issued by Let's Encrypt via cert-manager.
- Internal-only services (media automation, Soulseek, etc.) are reachable only within the home network at
*.k3s.home.nest. - Non-critical services auto-update daily around 03:00 EST. Brief disruptions may occur.
- Nest host OSes update weekly on Sundays at 05:00 EST in a rolling fashion.
This documentation is maintained as code. If you spot an error or have a suggestion, open an issue or reach out via Matrix.