← Blog

Alexis Β· 2026-09-29

You Need a Homelab!

A homelab isn't just a cluster of blinking servers in a corner of your house β€” it's a live test bench, a personal production system, and an excellent way to learn about network infrastructure, security, and systems administration.

In this article I walk through the current architecture of my homelab, designed with perimeter security, high service availability, and centralised identity management in mind.

flowchart TD
    classDef internet fill:#f9f9f9,stroke:#333,stroke-width:2px;
    classDef vps fill:#e1f5fe,stroke:#01579b,stroke-width:2px;
    classDef lan fill:#e8f5e9,stroke:#2e7d32,stroke-width:2px;
    classDef security fill:#fff3e0,stroke:#ef6c00,stroke-width:2px;
    classDef apps fill:#e3f2fd,stroke:#1565c0,stroke-width:2px;
    classDef storage fill:#eceff1,stroke:#37474f,stroke-width:2px;
    classDef proxmox fill:#f3e5f5,stroke:#6a1b9a,stroke-width:2px;

    subgraph Internet [Internet]
        ExtNet([Internet User])
    end

    subgraph VPS [External VPS]
        ExtNPM[External NGINX]
    end

    subgraph Proxmox [Proxmox VE β€” Bare Metal]
        subgraph LAN [Network Layer]
            Router["pfSense (VM)"]
            IntNPM["Internal NGINX (LXC)"]
            Dashy["Dashy Dashboard (LXC)"]
        end

        subgraph Security [Security Layer]
            Authentik["Authentik SSO (LXC)"]
            AD["Samba 4 AD DC (VM)"]
            Vault["Vault (LXC)"]
        end

        subgraph Apps [Application Layer]
            HomeAssistant["Home Assistant (LXC)"]
            Nextcloud["Nextcloud (LXC)"]
            Vaultwarden["Vaultwarden (LXC)"]
            Joplin["Joplin (LXC)"]
            Forgejo["Forgejo (LXC)"]
        end

        subgraph Storage [Storage Layer]
            TrueNAS[("TrueNAS ZFS (VM)")]
        end
    end

    ExtNet --> ExtNPM
    ExtNPM --> Router
    Router --> IntNPM

    IntNPM --> Dashy
    IntNPM --> Authentik
    Authentik --> AD
    Authentik --> Vault

    IntNPM --> HomeAssistant
    IntNPM --> Nextcloud
    IntNPM --> Vaultwarden
    IntNPM --> Joplin
    IntNPM --> Forgejo

    HomeAssistant --> TrueNAS
    Nextcloud --> TrueNAS
    Vaultwarden --> TrueNAS
    Joplin --> TrueNAS
    Forgejo --> TrueNAS

    class ExtNet internet;
    class ExtNPM vps;
    class Router,IntNPM,Dashy lan;
    class Authentik,AD,Vault security;
    class HomeAssistant,Nextcloud,Vaultwarden,Joplin,Forgejo apps;
    class TrueNAS storage;

Why this architecture?

1. Perimeter and external access

To avoid exposing my home network directly to the internet and to protect my home IP, I use an approach based on an external VPS that acts as a protective shield.

2. Virtualization platform

Every service in the lab runs on a single bare-metal server managed by Proxmox VE, an open-source Type-1 hypervisor built on Debian. Proxmox lets you run both lightweight containers and full virtual machines from a single web interface, which was the first major technology challenge to master.

3. Local network and access layer

Once inside the local network, traffic passes through a system structured in distinct logical layers:

4. Identity and security

This is the most technically demanding part of the homelab, requiring deep familiarity with several interdependent systems. Getting SSO, Active Directory, and secrets management to work together correctly took significant time and learning.

5. Application layer

The day-to-day services covering productivity, home automation, and personal storage:

6. Storage layer

The physical and backup foundation of the entire system:

Conclusion

This architecture lets me enjoy the benefits of public cloud (secure remote access from anywhere) while keeping full control of my data at home. Mastering Proxmox, Samba 4 on Linux, and a full OIDC/Forward Auth SSO stack turned the homelab into a genuine learning environment β€” and the result is an infrastructure as robust as a small business, at homelab cost.