Infrastructure
HomeProd
A 3-node Proxmox cluster spanning my home lab and a Hetzner server, with live migration, HA, and automated backups to BackBlaze B2. A private cloud with proper DR, monitoring, and security tooling. It just happens to also run Minecraft.
3 Proxmox Nodes
2 Locations
28 Running Services
24/7 Uptime Target
Networking & Security
5 services- OPNsenseFirewall and routing. Network segmentation, VLANs, traffic rules, and VPN for roaming and site-to-site.
- Nginx Proxy Manager + CrowdSecReverse proxy for all inbound traffic, backed by CrowdSec's community threat intelligence.
- AdGuard HomeNetwork-level DNS filtering. Ads and trackers don't make it off the wire.
- TeleportZero-trust access. No exposed SSH, bastion-free, audited, identity-aware.
- WazuhFull SIEM. Security monitoring, threat detection, and compliance.
Observability & Platform
4 services- Grafana + Prometheus + LokiFull observability. Metrics, logs, and traces across every node and service.
- ElasticsearchSearch backend for Wiki.JS, Nextcloud, and n8n. Also handles logs for Eramba.
- Proxmox Backup ServerAutomated VM and container backups to BackBlaze B2. Retention policies, restore testing.
- HeimdallInternal dashboard. One place to see everything running.
AI & Automation
1 service- AIStack Open WebUI + n8n + Bedrock Access Gateway + SearXNGOpen WebUI for the interface, AWS Bedrock for models via a self-hosted gateway, SearXNG for web search without leaking queries, and n8n tying it all together. Home of my personal AI, "Hermes".
Communication & Collaboration
4 services- MailcowSelf-hosted email. SMTP, IMAP, spam filtering, webmail. And no, it doesn't end up in spam.
- RocketChatDiscord is a dangerous place for children, of which I have several, who like to play games online.
- JitsiSelf-hosted video conferencing for RocketChat voice and video.
- CoturnTURN/STUN server supporting WebRTC services like Jitsi.
Data & Storage
4 services- NextcloudFile storage, calendars, contacts, collaboration. Google Drive without the surveillance.
- VaultwardenBitwarden-compatible self-hosted password manager.
- MariaDB + PostgreSQLDatabase backends powering the service stack.
- ValkeyRedis-compatible in-memory cache and data store.
Business & Productivity
5 services- ZammadHelp desk and ticketing. Because WhatsApp was getting silly.
- DolibarrERP. Mainly because it was interesting.
- ErambaGRC platform. More useful than I'd like to admit.
- Wiki.JSInternal wiki and knowledge base.
- WordPressWeb hosting. Soon to be retired (I hope).
Game Servers
3 services- PterodactylGame server management panel. Provisioning, monitoring, and console access.
- EnshroudedDedicated server. Yes, this runs in the same cluster as the SIEM.
- MinecraftObviously.
Media & Home
2 services- PlexMedia server. The whole reason home networking exists.
- Home AssistantLights, heating, presence detection, and a frankly unreasonable number of automations.