Skip to content

Repository files navigation

My Homelab

Created: 2026-07-09
Last updated: 2026-09-16

I retired Portainer on 2026-09-16. Its records are archived and Dockhand took over container management across seven Docker hosts. Prometheus has 57 healthy targets and Wazuh has 15 active remote agents.

I retired Game 01 on 2026-09-12. Its records are archived. CT 123 and its 80 GiB root disk, including the game data, are deleted.

Proxmox VE UniFi Splunk Wazuh Prometheus Cloudflare Ansible NetBird

This repository documents my five-node Proxmox cluster, segmented UniFi network, deployed platforms, automation, monitoring, & security work. The walkthrough guides are the quickest way to follow a build from its first command to the checks I ran afterward.

Version figures

A version figure in this repository is a point-in-time observation, not a durable fact. I give it an observation or verification date in the same record. A dated event or snapshot field already supplies that date, so I do not repeat it after every figure in that record.

Start Here

Lab architecture

Homelab architecture: two WAN uplinks and Cloudflare in front of a UniFi zone-based firewall, the five-node Galaxy Proxmox cluster, and workload VLANs for security, access, and applications

Traffic enters through two WAN uplinks. Cloudflare Tunnel carries the published HTTP services without an inbound port forward. The UniFi gateway holds 23 networks, including 16 routed LAN networks, and enforces policy across 12 zones. The Galaxy cluster hosts the workloads; UniFi sends CEF events to Splunk on Security-A, Wazuh reports 15 active remote agents, & Prometheus reports 57 targets UP across seven jobs. I verified these figures on 2026-09-16. The earlier 2026-09-06 readback came alongside a full audit of the inventory records against the cluster and the controller, and the fixes that audit produced.

Repository layout

The guides provide the reading path. Detailed records stay with the system that owns the work, and screenshots remain beside the change that produced them.

Category What it holds Example
Guides Visitor walkthroughs across infrastructure and platforms Galaxy Proxmox Cluster
Architecture Environment-wide designs and research External service ingress
Infrastructure Network, compute cluster, and physical hardware Galaxy cluster
Platforms Deployed services with their docs, config, and source Splunk Enterprise build log
Engineering Shared automation and pre-deployment projects Preview server
Operations Cross-system inventories and maintenance records Galaxy inventory
Security Incident reports and assessments UniFi firewall audit
Backups Config files copied off a host before an edit How a file gets here
Archive Superseded records kept for history Retired ai-alpha-01 record

Build and Change Records

Record What it covers
Splunk Enterprise build log Rocky Linux VM, Splunk Enterprise 10.4.0, HEC, SC4S, UniFi CEF ingestion, netops routing, & 40 screenshots
Security-A migration VLAN 72, the Security-A zone, address changes, firewall policy, service moves, & post-migration checks
Galaxy Corosync link addition VLAN 71 interfaces, Corosync link1, four-node rollout, quorum checks, & link-failure tests
April 2026 incident response Review, containment, corrective actions, service validation, & closure after the Vercel disclosure
TeamSpeak UDP relay outage UDP relay symptoms, Docker proxy diagnosis, network-path rebuild, & voice checks
NetBird routed VPN path First peer enrollment, routed resource, access policy, routing peer, masquerade, & HTTPS tunnel test
SSH authorized-key cleanup Nineteen-host inventory, 15 reachable targets, fingerprint comparison, authorized-key cleanup, & final access checks

Roadmap

Current priorities from my central TODO:

  1. Maintain the verified fleet access model and onboard future hosts through the Linux host baseline.
  2. Move Coolify off root SSH on app-01 and clear out its leftover keys.
  3. Put UPS-01 back on a data cable, or accept it as unmonitored and say so once.
  4. Decide how far Threat Management coverage goes across the eight routed LANs still outside inspection.
  5. Close the three account findings the password standardization turned up.

I keep closed work in Completed Work, separate from the roadmap and system backlogs.

About

Documentation, configuration, and automation for a Proxmox-based homelab.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages