Prerequisites
What must exist, and in what order, before the platform can be deployed. This is the architecture-level view; concrete manual setup steps for the automated stages live in each repo's own prerequisites section or page, linked below.
Pre-existing / manually managed components
These are not deployed by any repo in this platform. They must already exist before
vault-deployer can start:
- Domain Registrar: owns the domain and points its nameservers at the DNS provider.
- DNS provider (Cloudflare): resolves
*.cluster.domain.comto the home network's public IP. - OpenWrt router: the single entry point from the internet, and internal gateway, DHCP/DNS server, and WireGuard/port-forward endpoint for the whole LAN. See router.md for the full configuration, rebuild checklist, and port-forwarding table, and ../application-deployer/docs/prerequisites.md for the application-facing ports and manual setup involved.
- External SMTP service: outbound mail relay used by services that send notifications (e.g. Nextcloud).
Per-stage tooling and target-host prerequisites
Each automated stage's own docs cover what its control node and target host need before it can run (control-node tools, target-host packages/services, Vault access variables):