Architecture

Full Two-Site System Map

Interactive estate-wide diagram of every named host, switch, edge VM, service workload, and logical platform across both sites, with IPs, networks, purpose, placement, and connections.

The full estate map combines physical systems, hosted control-plane services, storage and application platforms, access equipment, and inter-site relationships. Search by hostname, IP, VLAN, role, or technology; selecting a node reveals its purpose, placement, addresses, networks, and direct dependencies.

Lifecycle State Is Part of the Diagram

“Current bootstrap” identifies the Site A UCG/XG6 path. “Approved target” describes the accepted Site A end state. “Retained design” identifies Site B equipment intentionally kept in its architecture. “Planned / parked” marks Site B and inter-site systems that are not yet deployed.

FULL ESTATE · PHYSICAL + LOGICAL · TARGET-AWARE

Explore Every System in Context

Search by hostname, IP, VLAN, platform, or purpose. Select a system to trace its direct relationships and inspect placement, addressing, and lifecycle state.

40systems shown
Site
Current bootstrapApproved targetPlanned / parkedRetained design
Site AManagement + durable services
10.10.0.0/16
01WAN + edge
02Layer 2 fabric
03Physical hosts
04Platform systems
05Service workloads
06Access + clients
Site BDistributed compute + storage
10.20.0.0/16
01WAN + edge
02Layer 2 fabric
03Physical hosts
04Platform systems
05Service workloads
06Access + clients
INTER-SITE

WireGuard

Routed inter-site transit

Planned / parked

Purpose and Placement

Routes approved traffic between the two OPNsense firewalls without stretching Layer 2, quorum, Ceph, or OpenBao Raft.

Placement
sa-fw-01 ↔ sb-fw-01
Design note
Planned after Site B comes online; routed packets only.

Addresses

Site A
10.255.0.1
Site B
10.255.0.2

Networks

  • Transit 10.255.0.0/24
  • Routes 10.10.0.0/16 ↔ 10.20.0.0/16

Direct Relationships

How to Use the Map

  • Search for an exact hostname such as sa-stor-01, an address fragment such as 10.20.65, a network such as VLAN 90, or a function such as “DNS” or “Ceph.”
  • Filter to one site or one architecture layer to reduce the estate to the systems relevant to a task.
  • Select a node to highlight direct relationships. The inspector lists those relationships as text and lets you follow them without relying on color.
  • Reset the filters from any relationship button to restore the complete two-site context.

The map groups logical systems such as sa-pve, Site B Ceph, and Kubernetes/OpenShift alongside the physical hosts that provide them. Logical nodes do not imply extra hardware or a new routing tier.

Scope and Next Detail

The map answers “what is this system, where does it live, which networks identify it, and what does it directly depend on?” It intentionally does not duplicate the 36-port Site A destination map or every Site B NIC-to-port assignment.

Use Physical & logical topology for traffic paths and failure behavior, IP tables for the full per-interface address record, and port tables for exact switch and NIC attachments.