--- id: overview title: "Container Overview" description: "See the internal containers Lego deploys and maintains for Corp v1, from Hermes and Gitea through Pages, Harbor, Argo CD, identity, ingress, and MicroK8s." --- import Drawio from '@theme/Drawio'; import architectureDiagram from '!!raw-loader!./diagrams/architecture-overview.drawio'; # Container Overview This view treats the **Corp v1 managed home-lab platform** as the software system. A container here is an independently operated service or managed service slice for which Lego owns configuration, versioning, deployment, upgrades, access, backup or recovery, and operational verification. ## Internal containers | Container | Corp v1 responsibility | |---|---| | **Hermes Agent** | Agent runtime, connected tools, model-provider integration, focused sessions, skill loading, execution, and evidence verification. | | **Corp v1 Board portal** | Docusaurus source, registries, architecture, decisions, build, publication, navigation, and deployed-content readback. | | **Gitea** | Service operation plus Corp organizations, teams, repositories, branches, pull requests, variables, permissions, skills, documentation, application source, and GitOps state. | | **Gitea Actions runners** | Runner operation, workflow versions, exact-head validation, documentation builds, image publication, and delivery evidence. | | **Penpot** | Service deployment and the project design workspaces, editable design sources, review state, accessibility evidence, and handoff. | | **LEGO Cloud Pages** | Pages workload, route structure, publication behavior, OAuth-protected access, and content readback. | | **Harbor** | Registry service, projects, repositories, robot integration, immutable application images, retention, and availability. | | **Argo CD** | Service lifecycle, AppProjects, Applications, repository access, desired-state reconciliation, health, and sync evidence. | | **Identity and access** | Keycloak, OAuth proxy configuration, protected routes, clients, policies, and sign-in behavior. | | **Ingress edge** | Cloudflare configuration, Osgiliath Nginx, ACME, Kubernetes ingress, routing, certificates, and public endpoints. | | **Gondor v1 MicroK8s** | Three-node runtime, namespaces, workloads, Services, Ingress, storage integration, readiness, image identity, and runtime readback. | | **Project workloads** | Approved application Deployments, Services, routes, configuration, release candidates, rollback state, and observable behavior. | ## External connections Only two software systems cross the Corp v1 boundary: - **Discord** supplies the communication service. Corp v1 owns the managed channel configuration represented in its operating model. - **ICA or GPT Codex** supplies LLM inference to Hermes Agent. ## Documentation path `Hermes → Gitea → Gitea Actions → Board portal build → LEGO Cloud Pages → identity/ingress → deployed readback` A documentation delivery claim requires successful exact-commit CI and distinctive content from the deployed Pages service path. ## Application path `Hermes → Gitea → Gitea Actions → Harbor → GitOps state → Argo CD → MicroK8s workload → ingress → runtime readback` Argo CD also reads desired state from Gitea. A repository or image alone is not a deployed product; the runtime image identity, readiness, route, and user-visible behavior must be verified. ## Related views - [Context](/architecture-high-level/context/) defines the home-lab boundary, human actors, and two external systems. - [Operating Model](/architecture-high-level/operating-model/) explains governance and the delivery lifecycle. - [Overview Skills](/architecture-high-level/overview-skills/) explains the instructions Hermes loads to operate these containers safely. - [Overview Repositories](/architecture-high-level/overview-repositories/) explains the versioned project and skill sources.