Homelab
My own server at home, where I self-host open-source applications. I'm passionate about data sovereignty and security: my applications and data stay in my own hands and under my control. This website runs on it too.
Architecture
Public
- Internet
- Caddy (HTTPS)
- Public apps
Private (VPN)
- WireGuard client
- WireGuard tunnel
- Firewall rules
- Pi-hole (local DNS)
- Private apps (HTTPS)
Backup & restore
- Data on RAID 1
- Borg Backup
- Ansible
- Full server restored
Hardware & operating system
- Server in a desktop case running vanilla Debian.
- RAID setup with 2× 8 TB Seagate Exos drives for redundancy.
Public apps
- Uptime Kuma, Jenkins, Immich, Jellyfin and Nextcloud: trusted applications that I keep up to date and that need to be publicly reachable.
- Public index at freedombox.be.
Private apps over WireGuard
- Vaultwarden, the Matrix chat server, Dockge and other apps are only reachable through my WireGuard VPN.
- Pi-hole resolves local domain names, so everything is reachable over HTTPS through the tunnel.
- Firewall rules fine-tune the tunnel and keep it secure.
- Local index at deploige.vpn, reachable through the tunnel.
Backups
- Backups with Borg Backup.
- A complete Ansible configuration restores the Borg backups and can rebuild the entire server.
Matrix chat server
- For family and friends: secure communication, with the data in our own hands.
CI/CD with Jenkins
- Deployment pipelines for my projects: kokenmetlisa.be, haskey.be, this website and my Discord bot Alfred.