murphy.dev/ status

Architecture

What is deployed today — not a target state. Everything public is static, served from Cloudflare's edge. Everything private is locked by Cloudflare Access before it reaches an origin. The home lab is deliberately not exposed.

1 · Visitor
Browserany device
2 · Cloudflare edge
murphy.dev zone
  • DNS, proxied — origins are never addressable
  • TLS, HSTS, strict CSP from _headers
  • Bot Fight Mode · AI scraping blocked
  • www → apex, 301
Cloudflare Access
  • Google as the identity provider
  • Allow list: one email
  • Guards 2 hosts + both staging sites
  • 14-day sessions, straight to Google
3 · Origins
murphy.devmurphy.devpublicPages
statusstatus.murphy.devpublicPages
lifelife.murphy.devbehind AccessPages
Punchpunch.murphy.devbehind AccessWorker

How it ships

  1. Push to staging → GitHub Actions builds both apps, runs verify-dist (no inline scripts, no broken links, headers present), uploads the package.
  2. Cloudflare Pages builds the same commit for the staging projects and serves it at the staging- hosts, behind Access, badged and noindex.
  3. Fast-forward main → the production projects build and go live.
  4. Each site writes /version.json at build time, which is how this page knows what is actually running.

3 of 4 live services have a staging twin.

Home lab

NUC · k3sUbuntu 26.04, Ansible-managed
  • VictoriaMetrics · 30-day retention
  • Grafana dashboards, blackbox + SMART exporters
  • ntfy → phone alerts
Tailscale onlyno tunnel

Nothing on the lab is published to the internet. There is no Cloudflare Tunnel, so2 lab services are reachable from the tailnet and nowhere else — which is also why this site cannot check them. A tunnel plus an Access policy would put them onmurphy.dev without opening a port; it isn't set up yet.

Why this shape

Static, not servers
Every public page is prebuilt. There is no origin to patch, scale or pay for at idle; the only moving part at request time is the status probe.
Access instead of a login page
The private sites have no auth code, no sessions and no password to leak. The sign-in page on murphy.dev is a doorway, not the lock.
One registry
The launchpad, this diagram and the probe all read the same list. Adding a service in one file is what makes it appear everywhere.
The lab stays closed
Monitoring lives inside the network where the things it monitors are. Exposure would be a choice, not a default.