Back to portfolio

> Homelab

> Personal self-hosted infrastructure I've designed, deployed and maintained for over 5+ years:

> Project information

  • Category: Self-Hosted Infrastructure
  • Role: Design, deployment & maintenance
  • Running since: 5+ years
  • Host: HP ProDesk · Proxmox VE 9

> End-to-end self-hosted infrastructure

I run a production-grade homelab on Proxmox VE using LXC and Docker to isolate services, Caddy and Cloudflare Tunnel to expose them securely without opening ports, a self-managed identity layer with LDAP/SSO, and Home Assistant as the central automation platform for the house.

It's more than installing apps: it involves architecture design, troubleshooting at the system, network and hardware level, and ongoing maintenance (e.g. migrating Proxmox 8 → 9 / Debian Bookworm → Trixie in 2026).

> Stack

Virtualization

Proxmox VE LXC Docker / Compose Portainer Arcane

Networking & Exposure

Caddy Cloudflare Tunnel DNS / DHCP WireGuard Pi-hole

Identity & Security

Tinyauth Pocket-ID LLDAP SSO

Home Automation

Home Assistant Zigbee2MQTT MQTT PIR / Presence

Integrations & Scripting

Python Bash / PowerShell rclone / inotify Custom HA Integration

Storage & Edge

NFS Raspberry Pi / DietPi Copyparty Wake-on-LAN

> Breakdown by area

Infrastructure

Virtualization with Proxmox

Standalone host (no Ceph/HCI) with local-lvm storage, local and remote backups and NFS. Full migration from Proxmox 8→9 / Debian Bookworm→Trixie in 2026, resolving enterprise repository, UEFI boot, and common issues.

Stack: Proxmox VE · LXC · ext4/LVM

Containers

Docker orchestration

Services running in Docker Compose, managed with Portainer Business and Arcane, resolving real-world permission issues and UID/GID mismatches between host and containers.

Stack: Docker · Portainer · Arcane

Networking

Secure exposure without open ports

Internet → Cloudflare Tunnel → Caddy → Tinyauth → internal service architecture (e.g. Jellyfin), keeping only HTTPS/443 as the public entry point. Manages DNS/DHCP and a planned ~150 static IP entries.

Stack: Cloudflare Tunnel · Caddy · WireGuard

Identity

Self-hosted SSO with LDAP

Centralized identity with LLDAP + Pocket-ID + Tinyauth, including debugging LDAP group synchronization and user/group filters.

Stack: LLDAP · Pocket-ID · Tinyauth

Home Automation

Home Assistant + Zigbee2MQTT

Presence automations (PIR), multi-device and multi-person notifications, and Zigbee devices over MQTT, with delay logic, helpers and anti-retrigger handling.

Stack: Home Assistant · Zigbee2MQTT · MQTT

Software

Custom integration: ha-bicing

A custom Home Assistant integration exposing Bicing station data (available bikes, docking stations) as entities, maintained as an open-source project on GitHub.

Stack: Python · Home Assistant · Git

View repository →