DJY89
← Work index
0x0011f41 · SEC/WORK/MAINFRAME · REV.03

Personal Infrastructure Server

A self-hosted Debian 12 control point for WireGuard access and scheduled automation, with service recovery, failure alerts, and documented operations.

Live
Next case ↗
ILLUSTRATIVE
Sample data
CPU
12%
RAM
1.2G
Disk
34G
Services
WireGuard VPN
3 peers
Email Triage
Scheduled
Product Sync
Mon 05:00
DB Backup
17:45
Fail2ban
2 bans
Service checks
Sample
VPN Peers
Desktop
4m ago
Laptop
12m ago
Mobile
2d ago
Network
Transfer
487 GB
Bandwidth
24 Mbps
Blocked
1,247
Personal Infrastructure ServerFIG.01

Overview

A Debian 12 server with WireGuard VPN for secure remote access. It hosts the lightweight automation behind Email Triage, Product Sync Pipeline, and other scheduled workloads while GPU-heavy work stays on the Windows workstation.

Infrastructure Purpose

Secure Remote Access

  • WireGuard VPN for encrypted tunneling
  • Multiple client device support
  • Split tunneling options for specific services

Production Service Hosting

Hosts automation services including:

  • AI-powered email classification
  • Scheduled data sync pipelines
  • Automated backup systems

Technical Stack

Operating System

  • Debian 12 (Bookworm) - Stable, security-focused
  • Automated security updates
  • Minimal attack surface

Service Management

All services run as systemd units with automatic restart:

Code · ini
[Unit]
Description=Production Service
After=network.target
 
[Service]
Type=simple
User=automation
WorkingDirectory=/opt/service
ExecStart=/usr/bin/node dist/index.js
Restart=always
RestartSec=10
 
[Install]
WantedBy=multi-user.target

Service Architecture

Process Isolation

  • Each service runs under dedicated user account
  • Separate working directories
  • Environment-based configuration

Logging & Monitoring

  • journald for centralized service logs
  • Custom log rotation policies
  • Email alerts on service failures

Scheduled Operations

Cron-based scheduling for automation services with staggered execution times to avoid resource contention.

Reliability Features

Automatic Recovery

  • systemd auto-restart on failures
  • Health check endpoints for critical services
  • Watchdog integration for long-running processes

Backup Strategy

  • Configuration backups to separate storage
  • Service state snapshots before updates
  • Documented recovery procedures

Security

Access Control

  • SSH key-only authentication
  • Fail2ban for intrusion prevention
  • Firewall rules allowing only necessary ports

Updates

  • Unattended security updates enabled
  • Quarterly maintenance windows for major updates
  • Rollback procedures documented

Operational Stats

  • Service recovery: systemd restarts services on failure
  • Active VPN Clients: 3
  • Production Services: 3
  • Monthly Data Processed: ~500GB

0x0011f42 · SEC/WORK · MEASURED RESULTS

Service Recovery

systemd

Automatic restarts on failure

VPN Clients

3

Active devices

Production Services

3

Mission-critical systems

GPU Workloads

0

Heavy generation stays on the local workstation

0x0011f43 · SEC/WORK · RELATED SYSTEMS