HashiCorp Vault
Secrets management and internal PKI.
Homelab / Services
Homelab services — by category and role.
The service list covers the lab’s platform and application workloads: identity, edge, Git/CI, observability, storage, and apps. Each card shows name, category, and role in the overall system.
Platform
Secrets management and internal PKI.
Edge reverse proxy and TLS termination.
Central identity provider for SSO.
Self-hosted Git — source of truth for IaC, docs, CI, and the portfolio; private GitHub mirror only for offsite.
Self-hosted CI fleet — Linux amd64, macOS Apple Silicon, Windows 64-bit, and Windows ARM64.
OpenTofu collaboration and remote state.
Knowledge base and handbooks for the lab platform.
Technical training path around the homelab.
Identity-aware remote edge for HTTPS — tunnel into the lab, OIDC against Keycloak.
Overlay VPN node for dual remote; public tunnel connector on Ingress.
Central entry point for administration and automation.
PXE and ISO boot for installations.
Self-hosted remote desktop for devices in the lab.
Observability
Dashboards for hosts, apps, and uptime.
Metrics collection and alerting foundation.
Central log aggregation.
Alert routing and notifications.
SIEM and host audit for SSH, sudo, and auth events.
Ops
Compute foundation of the lab — hypervisor cluster for nearly all guests and workloads.
Additional hypervisor site for resilience.
Host lifecycle, configuration, and patch orchestration.
Cluster and datacenter overview for Proxmox.
Primary backup for VMs and containers — not for file shares.
Selective offsite backup at a second site.
Mail gateway for filtering and relay.
Service desk for incidents, changes, and problems.
Network control for Wi-Fi, switching, and firewall.
Storage
Warm/cold shares on external USB disks.
ZFS hot shares for documents, pictures, and media.
Second medium — file copies and cold archive.
Home
Smart-home hub and automation.
Apps
Launch portal for lab services.
Audiobooks and radio plays.
Bookmarks and read-later.
Read-only ops assistance — diagnose and next steps, no apply.
Local tutor/chat via Ollama — same local models as the ops pipeline, no blind ops.
PDF tools (merge, split, OCR).
Ebooks, magazines, and comics (Kavita).
Credential manager for lab and everyday logins.
Webmail client (Roundcube).
Always-on Tor client — remote browser behind SSO, SOCKS for CLI, onion ops doors.
Simple file sharing.
Self-hosted photo library.
Document archive and OCR.
Inventory and address planning for the lab infrastructure.