themagicalforest.net
Home Lab Infrastructure
THQlab Node
Docker Desktop & WSL2 Ubuntu host running Nginx Proxy Manager (80/443 ingress), Pi-hole DNS ad-blocking, and dedicated gaming containers (Palworld).
THAIA Rig (Main Workstation)
AMD Ryzen 7 5800X / 48GB DDR4 host running central Portainer UI and environment agents across private Twingate overlays.
TheOnePump Node
Entertainment & media node linked into Twingate zero-trust remote access overlay network.
Ingress & DNS Layer
Cloudflare DNS edge integration with Let's Encrypt wildcard SSL (*.themagicalforest.net) via Let's Encrypt DNS-01 verification challenges.
Network Architecture & Traffic Flow
flowchart TD
SubGraph1[Remote / Mobile Traffic] -->|Twingate VPN Tunnel| Router[Netgear Orbi Mesh Router]
Internet([Public Internet]) -->|Edge Proxy| CF[Cloudflare Edge DNS]
subgraph HomeLab [Home Lab Infrastructure]
Router --> Pihole[Pi-hole DNS Sinkhole]
Router --> NPM[Nginx Proxy Manager Ingress]
NPM -->|HTTP/443 Wildcard SSL| PortainerUI[Portainer UI @ THAIA]
NPM -->|Internal Forward| PiholeUI[Pi-hole Admin Web UI]
Router -->|Direct UDP Game Ports| Palworld[Palworld Server Container @ THQlab]
end
Project Case Study: Zero-Trust Remote Ingress & DNS Sinkholing
Problem Statement
Exposing home lab management web UIs (Portainer, Pi-hole) and custom game server instances directly to the public internet via port forwarding creates security vulnerabilities and exposes home IP addresses to scanning.
Solution & Implementation
Architected a hybrid ingress model combining Cloudflare API DNS-01 challenge automation in Nginx Proxy Manager for wildcard SSL termination (*.themagicalforest.net), combined with a network-wide Pi-hole DNS sinkhole and a Twingate zero-trust software overlay across all primary lab machines (THQlab, THAIA, TheOnePump).
Key Technical Takeaways
- Eliminated exposed administration ports to the outside internet.
- Automated trusted SSL certificate provisioning without open HTTP/80 validation ports.
- Achieved network-wide ad and domain filtering across both desktop and mobile clients.
Infrastructure Code Snippets
Nginx Proxy Manager Stack (Portainer Compose)
version: '3.8'
services:
app:
image: 'jc21/nginx-proxy-manager:latest'
container_name: nginx-proxy-manager
restart: unless-stopped
ports:
- '80:80' # HTTP Ingress
- '81:81' # Management Web UI
- '443:443' # HTTPS Ingress
volumes:
- npm_data:/data
- npm_letsencrypt:/etc/letsencrypt
volumes:
npm_data:
npm_letsencrypt:
Cloudflare DNS Challenge Credentials Verification
# Test Cloudflare Scoped API Token for DNS-01 SSL Automated Issuance
curl -X GET "https://api.cloudflare.com/client/v4/user/tokens/verify" \
-H "Authorization: Bearer YOUR_CLOUDFLARE_API_TOKEN" \
-H "Content-Type: application/json"