Proof of concept · built in ~12 hours
NetRunner Infra
A multi-region, zero-trust, self-hosted stack: end-to-end encrypted notes on geo-distributed object storage, reachable only over a private WireGuard mesh.
ssh hub.mesh "docker compose ps" — 9 services healthy
3VPS nodes, 2 continents
0public ports on the app stack
E2EEserver stores ciphertext only
~$3per month for the edge nodes
Architecture
[ laptop ] [ phone ] public DNS desktop app mobile app SPF · DKIM · DMARC │ (via SD-WAN │ (via cellular CGNAT) │ exit node) │ └──── WireGuard ───┴──────────────┐ ▼ ╔══════════════════════════════════════════════════════════════════╗ ║ HUB · Ubuntu · default-deny firewall · IPS · auto-patching ║ ║ ║ ║ mesh interface ── routes peer ↔ peer ║ ║ │ ║ ║ ▼ the only listener, bound to the mesh IP ║ ║ ┌──────────── Caddy · TLS from a private ACME CA ───────────┐ ║ ║ └───┬────────────┬────────────┬────────────┬────────────┬──┘ ║ ║ ▼ ▼ ▼ ▼ ▼ ║ ║ sync API identity events publish Garage S3 ║ ║ │ (auth + 2FA) (SSE) attachments║ ║ ▼ │ ║ ║ MongoDB │ SMTP AUTH ║ ║ (ciphertext) ▼ ║ ║ Postfix send-only + OpenDKIM ──► TLS 1.3 out ║ ╚══════════════════════════════════════════════════════════════════╝ │ mesh tunnels (edge nodes dial out · no NAT ports) ┌─────┴──────────────────────────┐ ▼ ▼ ╔══════════════════════╗ ╔══════════════════════╗ ║ EDGE · US Alpine ║ ║ EDGE · NL Alpine ║ ║ iptables DROP v4+v6 ║ ║ iptables DROP v4+v6 ║ ║ SSH via mesh only ║ ║ SSH via mesh only ║ ║ IPv6 · weekly patch ║ ║ IPv6 · weekly patch ║ ╚══════════════════════╝ ╚══════════════════════╝
What it does
01Zero-knowledge notes
- Notes are encrypted on-device (XChaCha20-Poly1305, Argon2 key derivation) before sync.
- The server only ever holds an IV and ciphertext: no titles, no content.
- Verified client builds: release checksum matched across three sources.
02Distributed object storage
- Garage S3 replaces MinIO (archived 2026).
- CRDT-based metadata, built for geo-distributed commodity nodes.
- Single node today; designed to grow to 3 zones with replication factor 3.
03Software-defined mesh
- WireGuard hub-and-spoke across regions, with peer-to-peer routing.
- NAT traversal from cellular CGNAT and nested inside another SD-WAN.
- Zero-trust: services are invisible to the internet.
04Hardened hosts
- Default-deny firewalls on IPv4 and IPv6; key-only SSH, no root login.
- Crowd-sourced IPS on the hub; unattended security updates everywhere.
- Idempotent provisioning script with an auto-rollback firewall.
05Own the mail path
- Send-only Postfix with SASL login and DKIM signing.
- SPF, DKIM and DMARC aligned; delivered over TLS 1.3.
- Notifications go to a privacy alias, never a real address.
06Private PKI
- Caddy runs an internal ACME CA with short-lived certificates.
- One root trusted per device; nothing is exposed publicly.
- Docker ports bound to the mesh IP, because Docker bypasses host firewalls.
Defense in depth
| Layer | Control | Protects against |
|---|---|---|
| device | E2EE before upload · encrypted ZFS at rest | stolen laptop, compromised server |
| transport | TLS (private CA) inside WireGuard | interception, network snooping |
| network | mesh-only services · default-deny firewalls | scanning, exposed attack surface |
| host | key-only SSH · IPS · auto-patching | brute force, known CVEs |
| server data | ciphertext only · scoped S3 keys | database theft, insider access |
| supply chain | checksum-verified client builds | tampered app binaries |
Stack
WireGuardDocker ComposeCaddy
NotesnookGarage S3MongoDB
PostfixOpenDKIMCyrus SASL
CrowdSecUFW / iptablesUbuntuAlpine
IPv6ZFSrclone
Lessons from the trenches
- Docker bypasses the host firewall. Bind published ports to a specific IP, never
0.0.0.0. - Alpine kernel upgrades remove the running kernel's modules: reboot before loading new ones.
- The iOS Keychain survives app deletion, so a half-finished login comes back after a reinstall.
- Electron apps silently block plain HTTP. "Could not connect" meant "no TLS".
- Apps default to the vendor's cloud. Configure custom servers before signing up.
- Reliability through replication, not premium hardware: cheap nodes plus redundancy.
Background
Started out on an enterprise storage team running a three-site distributed file system with Kerberos ACLs and replicated databases. This project rebuilds the same ideas with modern open-source tools: geo-distributed storage, identity-based access and a private network between sites, with end-to-end encryption on top.
Next up: multi-node Garage across all three sites, a hash-chained append-only audit ledger, and immutable snapshots.