Certificate
- Type: Let’s Encrypt wildcard
- Domain:
*.ayinza.dev - Path:
/etc/letsencrypt/live/ayinza.dev/ - Mounted: Read-only into Nginx on both nodes
The two servers communicate through an encrypted WireGuard tunnel. Contabo acts as the WireGuard server, Azure as the client.
| Property | Value |
|---|---|
| Subnet | 10.10.0.0/24 |
| Port | 51820 (UDP) |
| Contabo (server) | 10.10.0.1 |
| Azure (client) | 10.10.0.2 |
| Config location | /etc/wireguard/wg0.conf (Contabo) |
Docker overlay networks span both Swarm nodes, enabling services on different servers to communicate by service name.
| Network | Used By | Purpose |
|---|---|---|
ingress | All services | Default Swarm routing mesh |
dev_sseris-network | All DEV services + Nginx | DEV inter-service communication |
sseris-uat-network | All UAT services + Nginx | UAT inter-service communication |
shared_harbor | Harbor, Nexus, Portainer, Docs + Nginx | Shared services communication |
Certificate
*.ayinza.dev/etc/letsencrypt/live/ayinza.dev/Renewal