Homelab Edge And Split DNS
The Contabo-side contract for public homelab ingress, NetBird, Yui, Pi-hole split DNS, and LAN TLS.
Homelab Edge And Split DNS
Contabo remains the public edge and certificate authority for the homelab hostnames. Pi-hole changes only the answer seen by clients on the home LAN; they do not replace public DNS, change the VPS routes, or expose an administration service to the Internet.
Ownership and current endpoints
| Boundary | Current endpoint | Responsibility |
|---|---|---|
| Public IPv4 | 161.97.83.142 | Namecheap public records and Contabo Traefik |
| Contabo NetBird peer | 100.83.72.162 | Private NetBird DNS target for the Pi-hole dashboard |
| Homelab NetBird peer | 100.83.117.37 | NetBird hop from Contabo to the Inspiron 5567 |
| Yui Home Assistant | 100.83.117.37:8123 | NetBird-only backend; no public or LAN listener |
| Homelab LAN edge | 192.168.1.135 | Pi-hole DNS and the local Traefik HTTPS edge |
| Home LAN | 192.168.1.0/24 | PTCL F1611A LAN; the Archer AX10 is an access point on this LAN |
The public homelab routes are declared in swarm/configs/traefik/dynamic/homelab.yml. The file provider is installed and checked with operations/traefik/install-dynamic-config.sh.
Request paths
Remote and public clients continue to use the existing path:
Client
-> Namecheap public DNS
-> Contabo 161.97.83.142:443
-> Contabo Traefik
-> NetBird
-> homelab 100.83.117.37
-> local service portThe Yui router is installed at the canonical hostname assistant.home.perspective-v.com. NetBird DNS maps the name to Contabo's NetBird address 100.83.72.162; Namecheap publishes an explicit A record to 161.97.83.142. The trusted certificate is issued, the public edge returns 403 without NetBird, and existing wildcard and sibling records remain unchanged:
Authorized NetBird client
-> private NetBird DNS: assistant.home.perspective-v.com -> 100.83.72.162
-> Contabo Traefik (netbird-only)
-> NetBird
-> Home Assistant at 100.83.117.37:8123Clients on the home LAN use the short path after the router advertises the homelab Pi-hole address as DNS:
LAN client
-> PTCL F1611A or Archer AX10 access point
-> Pi-hole at 192.168.1.135:53
-> LAN override for the service hostname
-> homelab local edge at 192.168.1.135:443
-> local serviceThe same HTTPS hostname and Host header are used on both paths. This preserves Traefik host routing, browser bookmarks, application callbacks, and certificate validation while avoiding the Germany round trip on the LAN.
DNS contract
Namecheap remains the public source of truth. The public application records
images.home, media.home, and next.home explicitly point public clients at
161.97.83.142. In the Namecheap Host field they are entered as relative
labels (images.home, media.home, next.home), not as full FQDNs. Do not add
LAN or NetBird addresses to Namecheap and do not use a public DNS record as a
substitute for the Pi-hole overrides.
Pi-hole on the homelab should override only hostnames that have a local edge router. The current application set is:
| Hostname | LAN answer | Public answer |
|---|---|---|
| home.perspective-v.com | 192.168.1.135 | 161.97.83.142 |
| next.home.perspective-v.com | 192.168.1.135 | 161.97.83.142 |
| images.home.perspective-v.com | 192.168.1.135 | 161.97.83.142 |
| media.home.perspective-v.com | 192.168.1.135 | 161.97.83.142 |
The Pi-hole dashboard name, pihole.home.perspective-v.com, is a different
case: its private NetBird DNS record points to Contabo's NetBird address
100.83.72.162 and the Contabo router applies netbird-only. It must not become a
public or unrestricted LAN administration route. Portainer follows the same
NetBird-only policy. The private NetBird DNS record for Home Assistant is
assistant.home.perspective-v.com -> 100.83.72.162. Do not add a Pi-hole
override because no local Yui TLS route is configured.
TLS and certificate handoff
Contabo's ACME store and the existing TLS-ALPN-01 resolver remain authoritative for the public certificates. The split-DNS rollout therefore does not require Cloudflare, a Namecheap API credential, DNS-01, or a second public certificate authority.
operations/traefik/export-homelab-certs.py reads the root-only ACME store and exports only the six selected certificate/key pairs required by the private homelab edge:
- home.perspective-v.com
- next.home.perspective-v.com
- images.home.perspective-v.com
- media.home.perspective-v.com
- pihole.home.perspective-v.com
- portainer.home.perspective-v.com
The exporter writes a tar.gz stream, fails closed when a certificate is missing or malformed, and never prints key material. Keep the generated archive root-only and outside Git. If a later sync fails, retain the last known-good homelab files and investigate before changing the Contabo ACME design.
Pi-hole administration route
The repo-managed homelab-pihole router is intentionally separate from the LAN application overrides:
- public hostname: pihole.home.perspective-v.com
- backend: http://100.83.117.37:8053 over NetBird
- access control: netbird-only and security-headers
- backend Host header: pi.hole, required by Pi-hole v6
- expected public result: HTTP 403
- expected authorized NetBird result: Pi-hole login page over trusted HTTPS
The route and policy are maintained in swarm/configs/traefik/dynamic/homelab.yml and the existing contabo-homelab-server-link NetBird policy. Do not publish port 8053 on the public interface.
Home Assistant route
The repo-managed homelab-yui router serves
assistant.home.perspective-v.com, forwards to
http://100.83.117.37:8123, and applies netbird-only plus
security-headers-allow-sameorigin. Keep TCP 8123 scoped to the existing
Contabo-to-homelab peer policy; do not publish the backend port.
The private DNS record maps the canonical hostname to Contabo's NetBird IP
100.83.72.162; public DNS maps it to 161.97.83.142 for TLS issuance.
Traefik has issued a trusted certificate, and the public edge returns 403
without NetBird. Home Assistant currently returns 400 through the proxy because
its UI-managed HTTP settings have not promoted the imported trusted-proxy
configuration. Complete first-owner onboarding, then enable Trust
X-Forwarded-For and trust 100.83.72.162 in Settings > System > Network.
Validation
From a public or remote client, confirm that the public edge remains healthy:
dig @1.1.1.1 +short next.home.perspective-v.com A
dig @1.1.1.1 +short images.home.perspective-v.com A
dig @1.1.1.1 +short media.home.perspective-v.com A
curl -I https://next.home.perspective-v.com
# After trusted HTTPS is configured, test from an authorized NetBird peer.
curl -sS -o /dev/null -w '%{http_code}\n' https://assistant.home.perspective-v.com/ # after confirming HA HTTP settings
# A non-NetBird client must receive 403 from netbird-only.Each public A answer should be 161.97.83.142. From a LAN client, confirm that
Pi-hole returns the homelab address and that HTTPS still uses the same hostname:
Resolve-DnsName next.home.perspective-v.com -Type A -DnsOnly
curl.exe -I --resolve next.home.perspective-v.com:443:192.168.1.135 https://next.home.perspective-v.comThe LAN answer should be 192.168.1.135, while the public test should continue to traverse Contabo. For the dashboard, test from an authorized NetBird peer and confirm that an ordinary public request is denied. When investigating an edge failure, use the Traefik file-provider drift check and access log before changing the public route.
Change boundaries and rollback
- Keep the explicit public application records pointed at Contabo; never publish
192.168.1.135or a100.83.x.xNetBird address in Namecheap. - Do not expose Pi-hole DNS, the Pi-hole dashboard, Portainer, or other admin services on the public interface.
- Do not replace the Contabo ACME store or public Traefik routers as part of split DNS.
- Storage and backup layout are outside this change.
To roll back the LAN optimization, remove the Pi-hole local overrides or restore the router's prior DHCP DNS advertisement. The Contabo public path remains unchanged, so remote access and public HTTPS continue to work while the LAN configuration is repaired.