HomeLab
My HomeLab is a personal infrastructure environment where I experiment with virtualization, networking, system administration, and self-hosted services.
Architecture
My HomeLab runs on a virtualized Proxmox infrastructure hosting internal services, research environments, and infrastructure management workloads. The architecture separates public services from a private management plane. Remote administration, internal DNS resolution, and access to sensitive services are provided through Tailscale without exposing the internal network directly to the Internet.
Private Network & Remote Administration
A dedicated bastion VM acts as the entry point to the private infrastructure. It is connected to the Tailscale network and provides both SSH jump-host access and subnet routing to the internal LAN.
Internal services can therefore be reached directly from authorized Tailscale devices while remaining unreachable from the public Internet.
SSH Jump Host
Subnet Router"] end subgraph LAN["Private HomeLab Network"] Vault["Vault
Secrets & Identity"] Services["Internal Services"] VMs["Virtual Machines"] end Admin -->|"Tailscale
SSH ProxyJump"| Bastion Bastion -->|"Private subnet routing"| Vault Bastion --> Services Bastion --> VMs classDef external fill:#f5f5f5,stroke:#666,stroke-width:1px; classDef gateway fill:#e8f1ff,stroke:#3169a8,stroke-width:2px; classDef security fill:#fff2cc,stroke:#b38f00,stroke-width:2px; classDef workload fill:#eef7ee,stroke:#4d7c4d,stroke-width:1px; class Admin external; class Bastion gateway; class Vault security; class Services,VMs workload;
Workload Distribution
Services and workloads are distributed according to their role. The R730 hosts the primary virtualized workloads, while the R720 provides a separate backup and recovery target.
Primary Compute"] R720["Dell PowerEdge R720
Backup & Recovery"] RPI["Raspberry Pi 4
Monitoring"] R730 -->|"Backup"| R720 RPI -.-> R730 RPI -.-> R720 class R730,R720 server; class RPI monitor;
Infrastructure & Technologies
My HomeLab serves as a practical environment for experimenting with virtualization, networking, security engineering, system administration, and self-hosted services.
- Virtualization: Proxmox VE, virtual machines and containers
- Systems: Debian, Linux administration
- Networking: Tailscale, subnet routing, split DNS, nftables
- Remote access: Bastion host, SSH ProxyJump, private Tailnet
- Security: HashiCorp Vault, ACL policies, audit logging, secrets management
- DNS: Cloudflare public DNS and private split-horizon DNS
- Automation: CI/CD runners and infrastructure automation
- Monitoring: Service availability and infrastructure monitoring
Self-Hosted Services
I use my HomeLab to deploy and maintain several services for development, experimentation and infrastructure management.
- GitHub Actions Runners — Self-hosted CI/CD workloads
- SonarQube — Static analysis and code quality
- Uptime Kuma — Service monitoring and availability
Hardware
| Device | Role | CPU | Memory | Storage | Network |
|---|---|---|---|---|---|
| Dell PowerEdge R730 | Compute / Virtualization | 2 × Xeon E5-2650L v4 (14 cores, 1.70 GHz) | 64 GB DDR4 | 6 TB SSD, 250 GB NVMe SSD | — |
| Dell PowerEdge R720 | Backup / Storage | 2 × Xeon E5-2609 (4 cores, 2.40 GHz) | 72 GB DDR3 | 2 TB SSD | — |
| Raspberry Pi 4 Model B | Monitoring | Quad-core Cortex-A72 (ARMv8), 1.8 GHz | 4 GB | 32 GB | — |
| Dell PowerConnect 2848 | Network switch | — | — | — | 48 × GbE, 4 × SFP |
Acknowledgements
Special thanks to Lucas Perfeito for his valuable help in building, configuring, and maintaining this HomeLab.