Backlog : Fédération Multi-Stack avec VPN
Date : 16-01-2026
Priorité : MOYENNE
Status : À FAIRE
Vision
Connecter plusieurs stacks (33800 Boulogne, 86000 Poitiers) via un réseau privé avec O2switch comme hub central.
┌─────────────────────────────────────────────────────────────────────────────┐
│ FÉDÉRATION STACKS │
│ │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ 33800 │◄────────►│ O2SWITCH │◄────────►│ 86000 │ │
│ │ (Bordeaux) │ WireGuard│ (Hub) │ WireGuard│ (Poitiers) │ │
│ │ Gouroubleu │ │ nowhere84 │ │ Ami │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
│ │
│ IP: 10.33.0.0/24 IP: 10.0.0.0/24 IP: 10.86.0.0/24 │
│ *.33800.nowhere84.com *.nowhere84.com *.86000.nowhere84.com │
└─────────────────────────────────────────────────────────────────────────────┘
Composants
1. Réseau VPN (WireGuard)
| Peer |
IP VPN |
Rôle |
| O2switch |
10.0.0.1 |
Hub central |
| 33800-PVE |
10.33.0.1 |
Stack Boulogne |
| 86000-PVE |
10.86.0.1 |
Stack Poitiers |
2. Services partagés via O2switch
| Service |
URL |
Description |
| Dashboard fédéré |
dashboard.nowhere84.com |
Vue unifiée toutes stacks |
| Status page |
status.nowhere84.com |
Santé de toutes les stacks |
| Logs centralisés |
logs.nowhere84.com |
Viewer logs multi-stack |
| Backups croisés |
- |
Backup 33800 → 86000 et vice-versa |
3. DNS wildcard par stack
| Stack |
Wildcard |
Certificat |
| 33800 |
*.33800.nowhere84.com |
Let's Encrypt wildcard |
| 86000 |
*.86000.nowhere84.com |
Let's Encrypt wildcard |
| Racine |
*.nowhere84.com |
Let's Encrypt wildcard |
Prérequis
Stack 86000 (Poitiers)
- [ ] PVE installé
- [ ] ZFS configuré
- [ ] Docker/Portainer déployé
- [ ] Promtail → Loki local
- [ ] Nginx + certificat wildcard
O2switch
- [ ] WireGuard installable ? (vérifier)
- [ ] Alternative : Tailscale ou ZeroTier
Phases d'implémentation
Phase 1 : Préparation
- [ ] Vérifier si WireGuard possible sur O2switch (mutualisé)
- [ ] Si non, évaluer alternatives (Tailscale, ZeroTier, SSH tunnels)
- [ ] Définir plan d'adressage IP VPN
Phase 2 : Stack 86000
- [ ] Ami installe Proxmox
- [ ] Copier scripts/configs depuis 33800
- [ ] Adapter pour 86000.nowhere84.com
- [ ] Générer certificat wildcard 86000
Phase 3 : Connexion VPN
- [ ] Installer WireGuard/alternative sur O2switch
- [ ] Configurer peers 33800 et 86000
- [ ] Tester connectivité inter-stack
Phase 4 : Services fédérés
- [ ] Dashboard multi-stack sur O2switch
- [ ] Agrégation logs (Loki fédéré ou viewer PHP)
- [ ] Backup croisés (rsync via VPN)
Avantages
- Résilience : Si une stack tombe, l'autre peut reprendre
- Backups croisés : Données en sécurité sur 2 sites géographiques
- Monitoring unifié : Vue globale de toute l'infrastructure
- Partage ressources : GPU 33800 accessible depuis 86000, etc.
Notes
- Code postal Poitiers : 86000
- WireGuard préféré (léger, rapide, moderne)
- O2switch = hébergement mutualisé (limitations possibles)
- Alternative si WireGuard impossible : tunnels SSH persistants