Homelab
About 100 Docker containers across ten Proxmox guests, with ZFS storage and private networking.
- active
- 2025 to present
- Proxmox · ZFS · Docker · Caddy · Headscale · AdGuard Home
My homelab runs the services I use every day: files, photos, media, DNS, source control, monitoring, local AI tools, and this website. It is also where I learn most of my systems work by having to keep the things I depend on running.
The server
One Proxmox host runs ten Linux guests and about 100 Docker containers. The boot pool is mirrored NVMe, and the data pool is a 27.3 TB raw ZFS RAIDZ2 array. The important data also has snapshots and copies away from the host.
I split guests by what they do instead of putting every container in one large stack. That makes upgrades and failures easier to contain and gives each group clearer access rules.
Networking
Caddy handles ingress for the services that need it. Public and private apps follow different rules, with CrowdSec and rate limits at the edge. Headscale handles remote access, and AdGuard Home provides split DNS and network-wide filtering.
Most services stay private. I only expose something publicly when it has a good reason to be public, such as Forgejo and this site.
Monitoring
Uptime Kuma runs 62 service checks and nine heartbeat monitors. The heartbeat checks cover scheduled jobs, where no alert could mean either that nothing happened or that the job stopped running. Beszel, Scrutiny, and container logs cover host health, disks, and resource use.
Where I can, checks test useful behavior instead of only checking whether a port answers.
Backups and restore
The public configuration repo comes from an allowlisted backup and restore script. Environment files become templates, systemd secrets are redacted, and the pre-commit check blocks the snapshot if something still looks sensitive.
The repo only keeps what is useful for rebuilding. Restore rules sit next to the collection rules, so it is clear where each file belongs when I need it.