R2-D2
Dashboard
Node Red
Restreaming
The Force
UpdatedNever
v1.0.0

Overview

Loading…
R2-D2
Dashboard
Node Red
Restreaming
The Force
UpdatedNever
v1.0.0
DDroidspeak / Docs
Operator handbook
Droidspeak
What is R2-D2?
Runtime architectureAuth — Keycloak migration plan
FleetRestreamingGalaxy MapThe RepublicTemple ArchivesSTANAG 4817The Force
Tech StackNext.js 15 + React 19Tailwind v4ZustandTanStack Table + DataViewhls.jsLow-latency playerreagraphoglreact-grid-layoutMonacoScalar API Referencefumadocs
Cluster InfraTrailBaseReductStoreRestreamer (datarhei/core)TBMQKeycloakLonghornkube-vipIngress (Caddy + nginx-ingress + Traefik)Netbird
Operator QA Runbook
Install — RKE2Install — Dokploy
Contributor guideRelease Notes
Cluster Infra

Netbird

Overlay VPN — cross-site reachability and the daemon socket the dashboard probes through.

Netbird is the cluster's overlay VPN — peer-to-peer WireGuard mesh, central management plane. The dashboard uses Netbird to reach instances at remote sites that aren't on the same L2.

Where it sits

Chart / values(in the parent repo)
ModeDaemonSet on every node + a central management API
Wire protocolWireGuard

How the dashboard uses it

src/lib/netbird.ts is the TS wrapper. The dashboard probes inter-instance reachability (the green/red pip on a Node-RED row, the Galaxy Map's backhaul status overlay) by asking the Netbird daemon for peer state.

The daemon socket path

A recent fix (commit a2b66509) corrected the Netbird daemon socket path used by the dashboard's probe and added an always-try HLS fallback so probe failure doesn't cascade into video tile failure.

Symptom that originally led to the fixProbe couldn't open the daemon socket, all peers showed unreachable, HLS tiles spuriously failed
FixCorrect socket path + decouple HLS init from probe state

What Netbird does not do

  • Not the cluster CNI. Pod-to-pod traffic stays on the cluster CNI (Cilium / canal depending on the cluster).
  • Not auth. Peer membership is managed by the Netbird management plane; the dashboard doesn't authenticate users via Netbird.
  • Not the L7 ingress. That's nginx-ingress / Caddy / Traefik — see Ingress.

Operator quick-reference

SymptomFirst check
All peers unreachable from one nodenetbird status on the node — is the daemon up?
Some peers reachable, some notManagement plane — are the peers in the same group?
Daemon socket error in dashboard logsSocket path drift — verify against the commit that fixed it

See also

  • Ingress — the L7 edge
  • Galaxy Map — backhaul overlay consumer

Ingress (Caddy + nginx-ingress + Traefik)

The edge routing model — *.office.ilab.zone via Caddy, port 80 via Traefik, in-cluster via nginx.

Operator QA Runbook

Field checks for media ingest, network reachability, ports, and stream validation with FFmpeg, GStreamer, ping, nc, and nmap.

On this page

Where it sitsHow the dashboard uses itThe daemon socket pathWhat Netbird does not doOperator quick-referenceSee also