Everything on this site runs on hardware in my house. This is the tour: how it fits together, what watches it, and what it's doing right now. No addresses, no secrets, just the architecture.
00Right now connecting
cpu
–
docker host · 32 threads
memory
–
of the VM's RAM
uptime
–
since the last reboot
disk
–
app data volume used
~ — tail -f /var/log/homelab (anonymised)
waiting for the homelab to report in…
Real numbers from the lab, refreshed every few seconds. Counts only: no IP addresses, hostnames or internal service names ever leave the house.
01How it fits together
~ — topology.svg
02The parts
hardware
Supermicro H12SSL-i with an AMD EPYC 7302P (16 cores, 32 threads) and 128 GB of RAM
ZFS everywhere: a mirrored NVMe pool for VM disks and a multi-SSD pool for the host
10 GbE to the core switch; an LSI HBA for the bulk-storage shelf (being recabled)
network & security
pfSense at the edge: default-deny inbound, VLAN segmentation, split-horizon DNS
Admin tools answer only on the home network; outsiders get a themed 403 (and end up in the morning report)
One wildcard certificate via DNS challenge, so new hostnames never appear in public certificate logs
platform
Proxmox VE hypervisor running Ubuntu Docker hosts
About 25 containers: cloud files and office docs, media, dashboards, GitLab, and this website
Caddy reads Docker labels and wires up routes and TLS automatically