Central infrastructure documentation and public ingress points routed securely via Cosmos Cloud reverse proxy.
| Service | Public URL | Security Profile | Description |
|---|---|---|---|
| Authentik | auth.uno308.com | mTLS / HTTPS | Central Identity Provider & SSO gateway. |
| Omada Controller | omada.uno308.com | SSO Protected | SDN Infrastructure Control Plane. |
| KeyHelp | panel.uno308.com | SSO Protected | Web hosting and domain administration. |
| DDNS | ddns.uno308.com | Proxy Internal | Dynamic DNS continuous sync client. |
| Service | Public URL | Security Profile |
|---|---|---|
| Synology DSM | dsm.goonersnas.com | SSO / Encrypted |
| Synology Drive | drive.goonersnas.com | SSO Protected |
| Synology Photos | photos.goonersnas.com | SSO Protected |
| Surveillance Station | cam.goonersnas.com | Encrypted Ingress |
| Active Backup | abb.goonersnas.com | Proxy Tunnel |
| DS File | files.goonersnas.com | SSO Protected |
| Synology Contacts | contacts.goonersnas.com | SSO Protected |
| Service | Public URL | Security Profile | Description |
|---|---|---|---|
| Wiki.JS | wiki.uno308.com | Public Ingress | Primary operational knowledge base. |
| Bookstack | bookstack.uno308.com | SSO Protected | Legacy repository reference. |
| Vaultwarden | vault.uno308.com | HTTPS Enforced | Self-hosted credential vault engine. |
| HomeAssistant | ha.uno308.com | SSO Protected | Core home automation environment. |
| Jellyfin | video.goonersnas.com | Public Ingress | Hardware-transcoded streaming media. |
| Service | Public URL | Security Profile | Description |
|---|---|---|---|
| Wazuh | wazuh.uno308.com | SSO Protected | Endpoint security and log intelligence. |
| Beszel | beszel.uno308.com | SSO Protected | Lightweight host metrics telemetry. |
| Matomo | matomo.uno308.com | SSO Protected | Infrastructure analytics monitoring. |
| Gotify | gotify.uno308.com | Token Enforced | Internal push notification endpoint. |
| Peanut | peanut.uno308.com | SSO Protected | UPS monitoring status indicators. |
Before launching a container block within CasaOS, cross-verify host bindings inside the core infrastructure configuration dashboard to prevent port collisions on the physical node.
New Service Ingress Template: 1. Deploy container via CasaOS/Docker, assigning a static host port (Verify against existing internal schema matrix). 2. Create URL configuration entry in Cosmos Cloud. 3. Map proxy target to container destination via internal host context loop. 4. Assign Subdomain: [app].uno308.com OR [app].goonersnas.com 5. Security Settings: Apply global Authentik SSO forward-auth headers for all applications lacking native authentication controls.