Security Layer

Network Topology & DNS Security

Internal network infrastructure relies on strict DNS filtering and recursive query processing to eliminate outbound tracking headers and safeguard local client nodes.

DNS Path: Local client queries target Pi-hole running inside container 100. Unresolved external lookups are passed securely via recursive local validation through Unbound over encrypted channels, completely circumventing upstream ISP telemetry collection.

Tunneling & Access Control

• WireGuard Gateway deployed for encrypted remote management tunnels.
• Local firewall rule sets restricting inter-VLAN guest traffic.
• Real-time alert dispatch configured through Uptime Kuma webhooks.