-
Internet
Any visitor, anywhere in the world.
-
Cloudflare
First stop for all outside traffic: hides my home IP, filters attacks and caches copies close to the visitor.
-
My phone (Element)
From Element I talk to Hermes and get alerts and messages, wherever I am.
-
MikroTik router
Connected straight to the fibre. Network split into VLANs, audited firewall and a WireGuard VPN to get in from outside.
-
Home devices
Laptops, the TV, phones: everything on the home network, split into VLANs.
-
GPU PC (Ollama)
Hermes's language model runs here, locally: nothing leaves my network. If the PC is off, questions wait in a queue.
- LLM locales (Ollama, Qdrant, RAG)
-
Git repository
All the infrastructure lives as versioned code. Every change starts here.
-
Traefik
The server's only public door: automatic TLS certificates and one route per published service. Internal dashboards never go through it.
-
Caddy + Authelia
The way into internal dashboards, only from home or the VPN, with single sign-on and two-factor auth.
-
Technitium DNS
Resolves internal names and blocks ads and trackers for the whole house. Migrated from Pi-hole without losing a single query.
-
IP sync
My connection has no fixed IP: every 5 minutes it checks the public IP and, if it changed, updates Cloudflare so the domains keep pointing home.
-
This website
An 11 MB Rust binary using about 12 MB of RAM, in its own unprivileged container with the strictest firewall on the server.
-
PostgreSQL
Stores contact form messages. No network at all: it's only reachable through the local socket.
-
Matrix (Synapse + Element)
My own messaging server. Hermes, server alerts and this site's messages all live here.
-
Paperless-ngx
Scans and classifies documents with OCR. Deliberately isolated: it holds personal paperwork.
-
Obsidian
The homelab's documentation: procedures, incidents and postmortems. Hermes reads it to answer.
-
n8n
Automations between services: scheduled jobs and notifications.
-
Homepage
The landing dashboard for every service, generated by Ansible from the same list Traefik uses.
-
Game servers (AMP)
Game servers for friends, with the firewall opened automatically only while they're running.
-
Plex
The household media server, with hardware transcoding.
-
Automated library (*arr)
A set of services that keeps the library tidy on its own: names, metadata, subtitles and the quality I choose.
-
Live TV
Free-to-air public channels with their programme guide, served to Plex as if it were a TV tuner.
-
GPU passthrough
An NVIDIA GPU assigned to the Plex container to convert video in hardware without loading the CPU.
-
Hermes (AI assistant)
The bot that answers questions about the server's health in natural language. The one on this page is its no-AI version.
- Python
- LLM locales (Ollama, Qdrant, RAG)
-
Qdrant
Vector database: stores the documentation and conversations so Hermes finds what's relevant (RAG).
- LLM locales (Ollama, Qdrant, RAG)
-
Zabbix
Metrics and alerts for every machine: CPU, disks, RAID, ZFS, Docker containers.
-
Wazuh
Security: vulnerabilities, suspicious logins and CIS checks on every container.
-
IaC control node
From here Terraform creates the machines and Ansible configures them. The AI agents I work with run here too.
-
ZFS storage
ZFS pools and software RAID for the systems and the library, watched by Zabbix.
-
Proxmox VE
The hypervisor: about twenty LXC containers and the lab's virtual machines.
-
OpenShift cluster (OKD)
Three nodes to practise OpenShift: 3/3 Ready and 33/33 healthy operators.
- OpenShift (OKD)
- Kubernetes / K3s
-
Repository backup
A second repository that updates itself on every infrastructure commit.
Simplified view: no addresses, ports or internal names.