OMEGA CORE HOST — 10.10.1.200 — PRIVATE LANAI RUNTIMEOllama:11434 · LANcompose/ai —model runtime onlyDATAPostgreSQL + pgvector:5432 · localhostQdrant:6333 · localhostEVIDENCEEvidence API:8000 · LANRuntime stateread-only FastAPIINFERENCEInference API:8001 · LANAI research accessClaude · GPTOBSERVABILITYInfluxDB:8086 · LANGrafanaProxmox CT 101FRONTENDS — compose/frontends/Open WebUI:3000 · production defaultSillyTavern:3002 · persona evaluationLibreChat:3004 · RAG evaluation+ MongoDB · Meilisearch · pgvector · RAG API (LibreChat's own stack)exactly one frontend must stay running — enforced server-sideOMEGA CONTROL — compose/ui/omega-ui:8080 · Status · Builder · Frontendsomega-builderinternal only · Modelfile assemblyomega-frontend-managerinternal only · holds the Docker socketACCESScore.internal.omegaproject.ai→ Authentik login requiredomega-ui never touchesthe Docker socket directly —frontend-manager does,internal network only— omega_internal —MONITORINGomega-collect.shomega-push.sh → S3REMOTE ACCESSTwingate on Proxmox, not hostPROXMOX HYPERVISOR — SEPARATE HOST — LXC CONTAINERSAUTHENTIK — CT 111OIDC + forward-auth SSOOpen WebUI · LibreChat · omega-uiSillyTavern (forward-auth)NPMPLUS — CT 104Reverse proxy + TLS terminationLet's Encrypt via DNS-01 (Cloudflare)*.internal.omegaproject.aiTECHNITIUM DNS — CT 107Split-horizon internal DNSLAN clients resolve real IPs;Cloudflare only sees ACME challengespushGitea Actions deployAWS — eu-west-2S3omegaproject.aiStatic assetsapi/status.jsonAccess logsKMS encryptedOAC — privateCLOUDFRONTCDN distributionHTTPS · TLSv1.2+ · ACMOAC — private S3URL rewrite functionSite TTL 1h · api/* 60sPriceClass_100ROUTE 53Hosted zoneA alias → CloudFrontwww → CloudFrontNot authoritativeNS delegated via CFSECRETS MANAGERomegaproject/monitoring/aws-credentialsIAM: monitoring users3:PutObject onlyDNSCLOUDFLARE — AUTHORITATIVE DNSomegaproject.ai · multi-provider DNS · NS records delegate to Route 53https://omegaproject.ai
ContainerImagePortBindingStack
omegacore-ollamaollama/ollama:latest11434LANai
omegacore-open-webuiopen-webui:v0.9.6 (pinned)3000LANfrontends
omegacore-sillytavernsillytavern/sillytavern:latest3002LANfrontends
omegacore-librechatdanny-avila/librechat-dev:latest3004LANfrontends
omegacore-postgrespgvector/pgvector:pg165432localhostdatabases
omegacore-qdrantqdrant/qdrant:latest6333localhostdatabases
omegacore-evidenceomegacore-evidence:latest8000LANevidence
omegacore-inferenceomegacore-inference:latest8001LANinference
omegacore-influxdbinfluxdb:2.78086LANobservability
omegacore-uiomegacore-ui:latest8080LANui
omegacore-builderomegacore-builder:latest8082internal onlyui
omegacore-frontend-manageromegacore-frontend-manager:latest8090internal onlyui

Services bound to localhost are reachable on the host only. Services bound to the LAN IP are accessible from the private network. No service is exposed to the public internet.

The Inference API (:8001) is the platform access point for AI research participants. Claude and GPT interact with OMEGA Core through this interface as part of the research programme.

omegacore-ui sits behind Authentik SSO (a self-hosted identity provider on the Proxmox side — see below) — no route on it is reachable without login, including the previously-open Model Builder. It never touches the Docker socket directly: a separate internal-only service, omegacore-frontend-manager, holds that privilege instead.

NetworkDriverPurpose
omega_internalbridgeCross-stack communication — container name resolution between stacks
ai_defaultbridgeInternal to the AI stack — Ollama only now; frontends reach it via omega_internal instead
librechat_defaultbridgeInternal to LibreChat's own stack (MongoDB, Meilisearch, its own pgvector, RAG API)
databases_defaultbridgeInternal to the databases stack
evidence_defaultbridgeInternal to the evidence stack

Each compose stack uses its own isolated bridge network. omega_internalis an external network created manually on the host — it must exist before any stack is started. Services address each other by container name, not IP.

ComponentServicePurpose
Static siteAWS S3Hosts built site assets — deployed via GitHub Actions on merge to main
CDNAWS CloudFrontGlobal distribution, HTTPS termination, OAC for private S3 access
TLS certificateAWS ACMManaged certificate for omegaproject.ai — auto-renewing
EncryptionAWS KMSServer-side encryption for S3 objects
DNS (zone)AWS Route 53Hosted zone for omegaproject.ai — aliases CloudFront distribution
DNS (authoritative)CloudflareAuthoritative nameservers — delegates to Route 53 NS records
Live statusS3 api/status.jsonPlatform monitoring bundle pushed every 5 min from OMEGA Core
CI/CDGitHub ActionsSite deploy on site/** changes; Terraform apply on infrastructure/** changes

The Evidence API (omegacore-evidence) is a read-only FastAPI service that exposes live platform state. It is the authoritative source of runtime evidence for auditing, AI-assisted review, and operational monitoring.

EndpointDescription
GET /healthAPI liveness check
GET /state/servicesLive Docker container state and health
GET /state/databasesPostgreSQL connectivity and pgvector version
GET /state/modelsInstalled Ollama models
GET /state/systemCPU, memory, disk and load average
GET /state/reportFull platform report aggregating all collectors

The Inference API (omegacore-inference) is the platform access point for AI research participants. Claude and GPT interact with OMEGA Core through this interface as part of the AI security and evaluation research programme. It is LAN-only and not exposed to the public internet.

EndpointDescription
GET /healthAPI liveness check
GET /versionAPI and Ollama version information
GET /modelsAvailable models on the platform
POST /querySubmit a prompt to a named model and receive a response

Remote access to the OMEGA Core host is provided by Twingate, running as a Docker container on the Proxmox hypervisor — not on the OMEGA Core host directly. This isolates the access control plane from the platform itself.

Remote device  →  Twingate (Proxmox)  →  LAN  →  OMEGA Core host

OMEGA Core runs on a MINISFORUM AI X1 Pro-470, purchased as a barebone unit and self-configured. Selected for AMD NPU capability, high memory bandwidth, PCIe 4.0 storage performance and future GPU expansion via OCuLink.

ComponentSpecification
HostMINISFORUM AI X1 Pro-470 (Barebone)
CPUAMD Ryzen AI 9 HX470 — up to 86 TOPS
MemoryCrucial 64GB DDR5-5600 (2×32GB SODIMM)
StorageWD_BLACK SN7100 2TB NVMe — 7,250 MB/s read, 6,900 MB/s write
NetworkDual 2.5GbE · WiFi 7 · Bluetooth 5.4
AI ComputeAMD Radeon 890M iGPU — available for local model inference
ExpansionOCuLink port for external GPU (future)

All major architectural choices are documented as Architecture Decision Records. ADRs record what was decided, why, and what alternatives were considered.

ADRDecision
ADR-001Ubuntu Server as the platform host
ADR-002Docker for all service containerisation
ADR-003PostgreSQL with pgvector for relational and vector storage
ADR-004Qdrant as dedicated vector database
ADR-005Ollama for local model hosting and inference
ADR-006InfluxDB for time-series observability metrics
ADR-007Prompt Engineering Workbench — two-stage Model Builder design
ADR-008Evaluation frontends — running multiple chat UIs side by side, not picking one upfront
ADR-009Dev environment pattern for Open WebUI — superseded by ADR-011
ADR-010Authentik for centralised SSO across OMEGA Core frontends
ADR-011Backup-before-upgrade, replacing the standing dev instance from ADR-009
ADR-012omega-ui restructure — Status/Builder/Frontends behind login, Docker control isolated in its own service

Full ADR documentation is maintained in the project wiki.