e1996d43967d3a7c8b762a9767c0b7bd94205dd2
Replaces DIY natpmpc sidecar with gluetun's built-in NAT-PMP handling for the protonvpn provider. The natpmpc UDP response was being dropped by gluetun's firewall since conntrack doesn't track stateless UDP from the gateway. With VPN_PORT_FORWARDING=on, gluetun handles the NAT-PMP exchange internally and exposes the port at :8000/v1/openvpn/portforwarded. Helper sidecar now just polls that endpoint.
infrastructure
Personal infrastructure-as-code for Legion (k3s home server) and supporting tooling.
| Doc | What it covers |
|---|---|
AGENTS.md |
Full reference: machines, secrets, services, domains, namespaces, common operations |
servers/legion/README.md |
What's running on Legion and how deployment works |
servers/legion/RUNBOOK.md |
Disaster recovery — full restore from scratch |
Quick start
cd servers/legion
direnv allow
terraform plan
terraform apply
Push to servers/ to deploy app changes via Argo CD.
Languages
HCL
78.4%
Shell
17.5%
Python
2.6%
Dockerfile
1.5%