anthony.wingerter

homelab · public tour

The homelab

Everything on this site runs on hardware in my house. This is the tour: how it fits together, what watches it, and what it's doing right now. No addresses, no secrets, just the architecture.

00Right now connecting

cpu

–

docker host · 32 threads

memory

–

of the VM's RAM

uptime

–

since the last reboot

disk

–

app data volume used

~ — tail -f /var/log/homelab (anonymised)
  • waiting for the homelab to report in…

Real numbers from the lab, refreshed every few seconds. Counts only: no IP addresses, hostnames or internal service names ever leave the house.

01How it fits together

~ — topology.svg
Homelab architecture Internet traffic passes the pfSense firewall and a core switch to a Proxmox hypervisor. Proxmox runs Docker hosts; a Caddy reverse proxy with automatic TLS fronts the public site and home-network-only apps. Every device ships logs to VictoriaLogs; Prometheus and Grafana chart metrics; vmalert and Alertmanager send email alerts. Internetvisitors · bots pfSensefirewall · VLANs Core switch10 GbE uplink Proxmox VEAMD EPYC 7302P · 128 GBZFS: NVMe mirror + SSD pool Docker hosts (VMs)~25 containers Caddyreverse proxy · auto TLS public: this site · cloud files home-network only: apps · dashboards · Git VictoriaLogslogs from every device Prometheus · Grafanametrics · dashboards vmalert · Alertmanageremail when something breaks solid: traffic · dashed: logs and metrics

02The parts

hardware

  • Supermicro H12SSL-i with an AMD EPYC 7302P (16 cores, 32 threads) and 128 GB of RAM
  • ZFS everywhere: a mirrored NVMe pool for VM disks and a multi-SSD pool for the host
  • 10 GbE to the core switch; an LSI HBA for the bulk-storage shelf (being recabled)

network & security

  • pfSense at the edge: default-deny inbound, VLAN segmentation, split-horizon DNS
  • Admin tools answer only on the home network; outsiders get a themed 403 (and end up in the morning report)
  • One wildcard certificate via DNS challenge, so new hostnames never appear in public certificate logs

platform

  • Proxmox VE hypervisor running Ubuntu Docker hosts
  • About 25 containers: cloud files and office docs, media, dashboards, GitLab, and this website
  • Caddy reads Docker labels and wires up routes and TLS automatically

observability

  • VictoriaLogs collects everything: firewall, switch, hypervisor, every container (Vector + syslog)
  • Prometheus + Grafana for host metrics and dashboards
  • vmalert + Alertmanager email me when a service stays down, plus a daily digest of who knocked on the door

this website

  • Hand-written HTML, CSS and vanilla JS: no framework, no build step, no trackers, no cookies
  • Strict Content-Security-Policy; fonts self-hosted; the live numbers come from small collectors on the host
  • The hockey schedule syncs a team calendar, adds rink weather and publishes subscribable feeds

on the bench

  • Recabling the 12-bay bulk-storage shelf (flaky power and data cables took a ZFS pool offline)
  • A family hub with shared recipes for the kitchen tablet
  • CI pipelines on the new GitLab

03Poke at it

The terminal on the home page talks to the lab too. Try homelab, status, ping or nextgame. There are a few hidden ones as well.