the big board · poster edition · index 02/02

YOUR DATA.
YOUR BOX. YOUR RULES.

Seven services. One Debian VPS. Zero rented clouds. Every door below runs from one repo — kefohaine/server — behind a Cloudflare edge and a Caddy reverse proxy. (talk.fxmq.net is real but stays off this board — signaling only.)

01 cloud.fxmq.net02 vault.fxmq.net03 kuma.fxmq.net 04 mc.fxmq.net05 mail.fxmq.net06 tail.fxmq.net07 www.fxmq.net
01

Cloudcloud.fxmq.net → Nextcloud 34

public · open

Stop paying rent for your own files. This cloud is yours — the landlord is a container.

Your files, calendar, contacts, photos and even video calls on your own domain. Sync with desktop & mobile apps, or use the web. CardDAV/CalDAV auto-discovery means your phone finds the address book and calendars with zero fiddling. Every email this lab sends comes from its own mailserver — no Google, no Microsoft in the loop.

files & synccalendar · contactsphotostalk chat & callsmail apppostgres 17 + redis
02

Vaultvault.fxmq.net → Vaultwarden

public · encrypted

One vault for every password — Bitwarden-compatible, but the keyholder is you.

A drop-in Bitwarden server in a single Rust container. Point the official Bitwarden browser extension, desktop or mobile app at vault.fxmq.net and your passwords, passkeys and TOTP codes live in your own vault. Invites & verifications arrive from the lab's own mailserver — proof of life without a SaaS middleman.

passwordspasskeysTOTP seedssecure notesany bitwarden client
03

Kumakuma.fxmq.net → Uptime Kuma

public · watchdog

Every service on this board has a watchdog. Kuma barks in green and red.

Uptime Kuma runs heartbeat, HTTP(S) and port checks against the whole stack and paints it on a live dashboard. When something below dies, it doesn't stay dead silently — the dashboard is public so the status of every door here is on display, including the monitor's own opinion of itself.

http(s) checkstcp checksstatus pagenotifications
04

Mcmc.fxmq.net → PufferPanel + Minecraft

no sign-up · play

Minecraft, zero install. Open a tab, click, and you're mining.

The play corner of the lab. /play loads a full Minecraft 1.8.8 client (EaglercraftX) straight in the browser — no download, no login, no account. Java veterans on any version from 1.7.10 to latest drop in over port 25565 through the Via family. Behind it all, PufferPanel at /panel manages the servers (registration is closed; accounts are made by the operator on request).

/play in-browser 1.8.8/panel server UIjava :25565 (1.7.10→latest)paper servers
05

Mailmail.fxmq.net → Roundcube + Docker Mailserver

public · dns-only

Mail on your own domain — read it in the browser, or with any real client.

Webmail (Roundcube) plus a full Postfix/Dovecot platform behind it: SMTP on 25/465/587 and IMAPS on 993. DKIM, SPF and DMARC are published; spoof protection means a mailbox can only ever send as itself. The TLS certificate is the very same Let's Encrypt cert as this website — web and mail share one trust anchor. Every service in this lab uses it to send you email: that's the whole point of owning a domain.

webmailsmtp 25/465/587imaps 993dkim · spf · dmarcspoof-proofquotas
06

Tailtail.fxmq.net → the operator's cockpit

tailnet only · 403 outside

The back door that isn't a door: only your own devices can even find it.

This one isn't for the public. tail.fxmq.net exists only inside the Tailscale network — it isn't in public DNS and Caddy answers 403 to everyone else, forged Host headers included. On the net it's the cockpit: / lists every door, /ttyd opens a real terminal on the host. If you can open it, you're supposed to be here.

/ vhost index/ttyd host terminalnot in public dnstailscale split-dns
07

Wwwwww.fxmq.net → this board · drop folder · stubs

public · you are here

The front door of the domain — and a drop folder anyone can reach.

www.fxmq.net keeps the lights low: / serves an empty index.html placeholder, /download is a read-only public drop folder served by Caddy's file browser (drop a file, share the link), and /1 and /2 are two maximalist showcases of everything on this board — this poster is /2. Talk to the lab: the whole thing ships from one repo, so every page you see is version-controlled.

/download drop folder/1 terminal registry/2 poster (this)