🛡️
Tunnel-Protected
All CNAME subdomains use Cloudflare Tunnel — outbound QUIC survives ISP IP changes and router reboots entirely.
ha.harmjoy.us
homarr.harmjoy.us
n8n.harmjoy.us
auth.harmjoy.us
+25 more
🌍
VPS-Hosted
Hetzner VPS services use A records to 5.161.204.42 in Frankfurt — fully independent of home ISP. Survive complete home outage.
api.harmjoy.us
status.harmjoy.us
leadgen.harmjoy.us
vault.harmjoy.us
🔒
Tailscale Backup
CT203 on middy acts as a Tailscale subnet router — encrypted remote access to full LAN with no open ports required.
Full 192.168.1.x access
No port forwarding
ISP-IP agnostic
🔄
Auto-Recovery
pve-autostart-catchup timer on all 3 nodes starts missed VMs/CTs 5 minutes after boot. Handles Proxmox cluster autostart bugs after hard power-off.
All 3 nodes
5 min post-boot
Deployed 2026-02-25
✅
100% Tunnel Coverage
Every harmjoy.us subdomain now routes through Cloudflare Tunnel or a VPS A record. Zero direct home-IP A records remain.
stream.harmjoy.us ✓
Migrated 2026-02-21
No fragile records