ONYXNET // INFRASTRUCTURE

Real infrastructure.
Continuous improvement.

OnyxNet is an actively operated homelab focused on network engineering, infrastructure administration, automation, and reliability.

Its architecture includes six operational VLANs, a pfSense firewall, managed switching, UniFi wireless, virtualization, storage, and essential network services.

Existing infrastructure — operational

PHYSICAL ARCHITECTURE

High-Level Network Topology

A simplified view of the deployed environment. More detailed physical and logical diagrams will be added as the documentation develops.

InternetSpectrum Broadband
↓
Router / FirewallpfSense
↓
Managed Switching3 × Zyxel GS1200-8HPv3
↓
UniFi Wireless
Proxmox Clusters
TrueNAS Storage
Networked Devices

LOGICAL ARCHITECTURE

Network Segmentation

6 deployed VLANs separate infrastructure management, IoT, security equipment, guest access, trusted clients, and servers.

A seventh VLAN was proposed during offsite backup planning, but was superseded before implementation. It remains documented as part of the network's design history.

VLAN 10Operational

Valhalla

Management

Network infrastructure management.

VLAN 25Operational

Jotunheim

IoT

Smart devices and home automation.

VLAN 50Operational

Helheim

Security

Cameras and security equipment.

VLAN 99Operational

Vanaheim

Guest

Guest network and untrusted clients.

VLAN 100Operational

Midgard

Trusted

Personal and trusted devices.

VLAN 1000Operational

Asgard

Server / Data

Servers, storage, and hosted services.

VLAN 700Superseded

Ginnungagap

Proposed Offsite Transit

Historical VLAN and 10.0.10.0/31 transit proposal, superseded by a Tailscale-based approach before implementation.

ARCHITECTURE DECISION

Why wasn't VLAN 700 implemented?

Ginnungagap originally proposed a dedicated cross-site transit network for offsite backups. After reviewing the cost, complexity, and actual connectivity requirements, a Tailscale overlay was selected instead.

The original VLAN design was never deployed, and the replacement backup project remains deferred due to budget constraints.

Read ADR-001: Offsite Backup Connectivity →

INFRASTRUCTURE SERVICES

Systems & Technologies

Network & Security

pfSense firewall, three Zyxel managed switches, and two UniFi access points.

pfSense · VLANs · UniFi · Zyxel

Virtualization

Three-node Aesir production cluster and single-node Vanir experimental Proxmox environment.

Proxmox VE · ZFS · LXC · VMs

Storage & Backups

TrueNAS storage and Proxmox Backup Server supporting local backup and recovery operations.

TrueNAS · PBS · ZFS

Network Services

Raspberry Pi systems providing DNS and supporting infrastructure services.

Linux · Pi-hole · Docker

Automation

Ansible-based configuration management and repeatable infrastructure maintenance.

Ansible · YAML · Git

Observability

Infrastructure monitoring with Grafana, Prometheus, Blackbox Exporter, and UniFi telemetry.

Grafana · Prometheus · PromQL

ARCHITECTURE EVOLUTION

Engineering Roadmap

OnyxNet continues to evolve around existing infrastructure and available resources. Roadmap items are distinct from completed implementations.

UNDER REVIEW

Firewall Policy Refinement

Review operational inter-VLAN firewall policies and validate the intended security boundaries.

UNDER REVIEW

Network Architecture Refinement

Evaluate infrastructure access, management security, physical topology, and reliability improvements.

ONGOING

Monitoring Improvements

Expand operational visibility using existing monitoring tools and available hardware.

FUTURE

Higher-Speed Networking

Evaluate future 2.5/10 GbE upgrades while continuing to operate the existing 1 GbE infrastructure.

DEFERRED

Ginnungagap — Offsite Disaster Recovery

Future TrueNAS SCALE appliance connected through Tailscale, intended to protect NAS datasets and Proxmox VM/LXC backups.

Explore the Engineering Work

Discover the projects, documentation, design decisions, and lessons learned behind OnyxNet.