Proof of concept · built in ~12 hours

NetRunner Infra

A multi-region, zero-trust, self-hosted stack: end-to-end encrypted notes on geo-distributed object storage, reachable only over a private WireGuard mesh.

ssh hub.mesh "docker compose ps" — 9 services healthy

3VPS nodes, 2 continents
0public ports on the app stack
E2EEserver stores ciphertext only
~$3per month for the edge nodes

Architecture

topology.txt
   [ laptop ]          [ phone ]                    public DNS
   desktop app       mobile app                   SPF · DKIM · DMARC
       │   (via SD-WAN     │   (via cellular CGNAT)
       │    exit node)     │
       └──── WireGuard ───┴──────────────┐
                                        ▼
 ╔══════════════════════════════════════════════════════════════════╗
 ║  HUB  · Ubuntu · default-deny firewall · IPS · auto-patching     ║
 ║                                                                  ║
 ║   mesh interface ── routes peer ↔ peer                           ║
 ║        │                                                         ║
 ║        ▼   the only listener, bound to the mesh IP               ║
 ║   ┌──────────── Caddy · TLS from a private ACME CA ───────────┐  ║
 ║   └───┬────────────┬────────────┬────────────┬────────────┬──┘   ║
 ║       ▼            ▼            ▼            ▼            ▼      ║
 ║    sync API      identity     events      publish     Garage S3  ║
 ║       │         (auth + 2FA)   (SSE)                  attachments║
 ║       ▼            │                                             ║
 ║    MongoDB         │ SMTP AUTH                                   ║
 ║   (ciphertext)     ▼                                             ║
 ║              Postfix send-only + OpenDKIM ──► TLS 1.3 out        ║
 ╚══════════════════════════════════════════════════════════════════╝
              │  mesh tunnels (edge nodes dial out · no NAT ports)
        ┌─────┴──────────────────────────┐
        ▼                                ▼
 ╔══════════════════════╗        ╔══════════════════════╗
 ║ EDGE · US  Alpine    ║        ║ EDGE · NL  Alpine    ║
 ║ iptables DROP v4+v6  ║        ║ iptables DROP v4+v6  ║
 ║ SSH via mesh only    ║        ║ SSH via mesh only    ║
 ║ IPv6 · weekly patch  ║        ║ IPv6 · weekly patch  ║
 ╚══════════════════════╝        ╚══════════════════════╝

What it does

01Zero-knowledge notes

  • Notes are encrypted on-device (XChaCha20-Poly1305, Argon2 key derivation) before sync.
  • The server only ever holds an IV and ciphertext: no titles, no content.
  • Verified client builds: release checksum matched across three sources.

02Distributed object storage

  • Garage S3 replaces MinIO (archived 2026).
  • CRDT-based metadata, built for geo-distributed commodity nodes.
  • Single node today; designed to grow to 3 zones with replication factor 3.

03Software-defined mesh

  • WireGuard hub-and-spoke across regions, with peer-to-peer routing.
  • NAT traversal from cellular CGNAT and nested inside another SD-WAN.
  • Zero-trust: services are invisible to the internet.

04Hardened hosts

  • Default-deny firewalls on IPv4 and IPv6; key-only SSH, no root login.
  • Crowd-sourced IPS on the hub; unattended security updates everywhere.
  • Idempotent provisioning script with an auto-rollback firewall.

05Own the mail path

  • Send-only Postfix with SASL login and DKIM signing.
  • SPF, DKIM and DMARC aligned; delivered over TLS 1.3.
  • Notifications go to a privacy alias, never a real address.

06Private PKI

  • Caddy runs an internal ACME CA with short-lived certificates.
  • One root trusted per device; nothing is exposed publicly.
  • Docker ports bound to the mesh IP, because Docker bypasses host firewalls.

Defense in depth

LayerControlProtects against
deviceE2EE before upload · encrypted ZFS at reststolen laptop, compromised server
transportTLS (private CA) inside WireGuardinterception, network snooping
networkmesh-only services · default-deny firewallsscanning, exposed attack surface
hostkey-only SSH · IPS · auto-patchingbrute force, known CVEs
server dataciphertext only · scoped S3 keysdatabase theft, insider access
supply chainchecksum-verified client buildstampered app binaries

Stack

WireGuardDocker ComposeCaddy NotesnookGarage S3MongoDB PostfixOpenDKIMCyrus SASL CrowdSecUFW / iptablesUbuntuAlpine IPv6ZFSrclone

Lessons from the trenches

Background

Started out on an enterprise storage team running a three-site distributed file system with Kerberos ACLs and replicated databases. This project rebuilds the same ideas with modern open-source tools: geo-distributed storage, identity-based access and a private network between sites, with end-to-end encryption on top.

Next up: multi-node Garage across all three sites, a hash-chained append-only audit ledger, and immutable snapshots.