A homelab isn't just a cluster of blinking servers in a corner of your house β it's a live test bench, a personal production system, and an excellent way to learn about network infrastructure, security, and systems administration.
In this article I walk through the current architecture of my homelab, designed with perimeter security, high service availability, and centralised identity management in mind.
flowchart TD
classDef internet fill:#f9f9f9,stroke:#333,stroke-width:2px;
classDef vps fill:#e1f5fe,stroke:#01579b,stroke-width:2px;
classDef lan fill:#e8f5e9,stroke:#2e7d32,stroke-width:2px;
classDef security fill:#fff3e0,stroke:#ef6c00,stroke-width:2px;
classDef apps fill:#e3f2fd,stroke:#1565c0,stroke-width:2px;
classDef storage fill:#eceff1,stroke:#37474f,stroke-width:2px;
classDef proxmox fill:#f3e5f5,stroke:#6a1b9a,stroke-width:2px;
subgraph Internet [Internet]
ExtNet([Internet User])
end
subgraph VPS [External VPS]
ExtNPM[External NGINX]
end
subgraph Proxmox [Proxmox VE β Bare Metal]
subgraph LAN [Network Layer]
Router["pfSense (VM)"]
IntNPM["Internal NGINX (LXC)"]
Dashy["Dashy Dashboard (LXC)"]
end
subgraph Security [Security Layer]
Authentik["Authentik SSO (LXC)"]
AD["Samba 4 AD DC (VM)"]
Vault["Vault (LXC)"]
end
subgraph Apps [Application Layer]
HomeAssistant["Home Assistant (LXC)"]
Nextcloud["Nextcloud (LXC)"]
Vaultwarden["Vaultwarden (LXC)"]
Joplin["Joplin (LXC)"]
Forgejo["Forgejo (LXC)"]
end
subgraph Storage [Storage Layer]
TrueNAS[("TrueNAS ZFS (VM)")]
end
end
ExtNet --> ExtNPM
ExtNPM --> Router
Router --> IntNPM
IntNPM --> Dashy
IntNPM --> Authentik
Authentik --> AD
Authentik --> Vault
IntNPM --> HomeAssistant
IntNPM --> Nextcloud
IntNPM --> Vaultwarden
IntNPM --> Joplin
IntNPM --> Forgejo
HomeAssistant --> TrueNAS
Nextcloud --> TrueNAS
Vaultwarden --> TrueNAS
Joplin --> TrueNAS
Forgejo --> TrueNAS
class ExtNet internet;
class ExtNPM vps;
class Router,IntNPM,Dashy lan;
class Authentik,AD,Vault security;
class HomeAssistant,Nextcloud,Vaultwarden,Joplin,Forgejo apps;
class TrueNAS storage;
1. Perimeter and external access
To avoid exposing my home network directly to the internet and to protect my home IP, I use an approach based on an external VPS that acts as a protective shield.
2. Virtualization platform
Every service in the lab runs on a single bare-metal server managed by Proxmox VE, an open-source Type-1 hypervisor built on Debian. Proxmox lets you run both lightweight containers and full virtual machines from a single web interface, which was the first major technology challenge to master.
3. Local network and access layer
Once inside the local network, traffic passes through a system structured in distinct logical layers:
4. Identity and security
This is the most technically demanding part of the homelab, requiring deep familiarity with several interdependent systems. Getting SSO, Active Directory, and secrets management to work together correctly took significant time and learning.
5. Application layer
The day-to-day services covering productivity, home automation, and personal storage:
6. Storage layer
The physical and backup foundation of the entire system:
This architecture lets me enjoy the benefits of public cloud (secure remote access from anywhere) while keeping full control of my data at home. Mastering Proxmox, Samba 4 on Linux, and a full OIDC/Forward Auth SSO stack turned the homelab into a genuine learning environment β and the result is an infrastructure as robust as a small business, at homelab cost.