> Homelab
> Personal self-hosted infrastructure I've designed, deployed and maintained for over 5+ years:
> Project information
- Category: Self-Hosted Infrastructure
- Role: Design, deployment & maintenance
- Running since: 5+ years
- Host: HP ProDesk · Proxmox VE 9
> End-to-end self-hosted infrastructure
I run a production-grade homelab on Proxmox VE using LXC and Docker to isolate services, Caddy and Cloudflare Tunnel to expose them securely without opening ports, a self-managed identity layer with LDAP/SSO, and Home Assistant as the central automation platform for the house.
It's more than installing apps: it involves architecture design, troubleshooting at the system, network and hardware level, and ongoing maintenance (e.g. migrating Proxmox 8 → 9 / Debian Bookworm → Trixie in 2026).
> Stack
Virtualization
Proxmox VE LXC Docker / Compose Portainer ArcaneNetworking & Exposure
Caddy Cloudflare Tunnel DNS / DHCP WireGuard Pi-holeIdentity & Security
Tinyauth Pocket-ID LLDAP SSOHome Automation
Home Assistant Zigbee2MQTT MQTT PIR / PresenceIntegrations & Scripting
Python Bash / PowerShell rclone / inotify Custom HA IntegrationStorage & Edge
NFS Raspberry Pi / DietPi Copyparty Wake-on-LAN> Breakdown by area
Virtualization with Proxmox
Standalone host (no Ceph/HCI) with local-lvm storage, local and remote backups and NFS. Full migration from Proxmox 8→9 / Debian Bookworm→Trixie in 2026, resolving enterprise repository, UEFI boot, and common issues.
Stack: Proxmox VE · LXC · ext4/LVM
Docker orchestration
Services running in Docker Compose, managed with Portainer Business and Arcane, resolving real-world permission issues and UID/GID mismatches between host and containers.
Stack: Docker · Portainer · Arcane
Secure exposure without open ports
Internet → Cloudflare Tunnel → Caddy → Tinyauth → internal service architecture (e.g. Jellyfin), keeping only HTTPS/443 as the public entry point. Manages DNS/DHCP and a planned ~150 static IP entries.
Stack: Cloudflare Tunnel · Caddy · WireGuard
Self-hosted SSO with LDAP
Centralized identity with LLDAP + Pocket-ID + Tinyauth, including debugging LDAP group synchronization and user/group filters.
Stack: LLDAP · Pocket-ID · Tinyauth
Home Assistant + Zigbee2MQTT
Presence automations (PIR), multi-device and multi-person notifications, and Zigbee devices over MQTT, with delay logic, helpers and anti-retrigger handling.
Stack: Home Assistant · Zigbee2MQTT · MQTT
Custom integration: ha-bicing
A custom Home Assistant integration exposing Bicing station data (available bikes, docking stations) as entities, maintained as an open-source project on GitHub.
Stack: Python · Home Assistant · Git