Homelab

My own server at home, where I self-host open-source applications. I'm passionate about data sovereignty and security: my applications and data stay in my own hands and under my control. This website runs on it too.

Architecture

Public
  1. Internet
  2. Caddy (HTTPS)
  3. Public apps
Private (VPN)
  1. WireGuard client
  2. WireGuard tunnel
  3. Firewall rules
  4. Pi-hole (local DNS)
  5. Private apps (HTTPS)
Backup & restore
  1. Data on RAID 1
  2. Borg Backup
  3. Ansible
  4. Full server restored

Hardware & operating system

  • Server in a desktop case running vanilla Debian.
  • RAID setup with 2× 8 TB Seagate Exos drives for redundancy.

Public apps

  • Uptime Kuma, Jenkins, Immich, Jellyfin and Nextcloud: trusted applications that I keep up to date and that need to be publicly reachable.
  • Public index at freedombox.be.

Private apps over WireGuard

  • Vaultwarden, the Matrix chat server, Dockge and other apps are only reachable through my WireGuard VPN.
  • Pi-hole resolves local domain names, so everything is reachable over HTTPS through the tunnel.
  • Firewall rules fine-tune the tunnel and keep it secure.
  • Local index at deploige.vpn, reachable through the tunnel.

Backups

  • Backups with Borg Backup.
  • A complete Ansible configuration restores the Borg backups and can rebuild the entire server.

Matrix chat server

  • For family and friends: secure communication, with the data in our own hands.

CI/CD with Jenkins

  • Deployment pipelines for my projects: kokenmetlisa.be, haskey.be, this website and my Discord bot Alfred.

Technology

  • Debian
  • RAID
  • WireGuard
  • Pi-hole
  • Caddy
  • Borg Backup
  • Ansible
  • Jenkins
  • Dockge

This website

2026

My online CV, built with SvelteKit and deployed fully automatically to my homelab through my own CI/CD pipeline.

Architecture

  1. Git push
  2. Jenkins
  3. Podman build
  4. SSH
  5. Podman Compose + nginx
  6. Caddy
  7. jan.deploige.be
  • Static site built with SvelteKit (adapter-static) and TypeScript, in Dutch and English.
  • Jenkins builds a container image with Podman and copies it to the server over SSH.
  • On the server the image runs with Podman Compose, behind Caddy as a reverse proxy.

Technology

  • SvelteKit
  • TypeScript
  • Podman
  • Jenkins
  • nginx
  • Caddy

Kokenmetlisa

A website where my sister can post dishes she likes and share her own recipes online.

Architecture

Application
  1. SvelteKit (frontend)
  2. Spring Boot (backend)
Deployment
  1. Git push
  2. Jenkins
  3. Homelab
  4. kokenmetlisa.be
  • Backend in Java with Spring Boot, frontend with SvelteKit.
  • Deployed automatically through a Jenkins pipeline on my homelab.

Technology

  • Java
  • Spring Boot
  • SvelteKit
  • Jenkins

Alfred (Discord bot)

A Discord bot I use to learn how Discord bots work and to experiment with.

Architecture

  1. Git push
  2. Jenkins
  3. Homelab
  4. Discord
  • Written in TypeScript with discord.js.
  • Deployed automatically through a Jenkins pipeline on my homelab.

Technology

  • TypeScript
  • discord.js
  • Jenkins

Cloudflare automation at Black Talon

2025 - 2026

Internship project: a base framework to roll out Cloudflare configurations for customers automatically with infrastructure as code.

Architecture

Rollout
  1. Configuration in Git
  2. CI/CD pipeline
  3. OpenTofu
  4. Cloudflare API
Demo
  1. Visitor
  2. Cloudflare (security)
  3. Demo application on Hetzner
  • Cloudflare services are managed as code with OpenTofu instead of through the dashboard.
  • Multi-environment support: you pass in a variable, and every service is deployed with that variable as a prefix.
  • A CI/CD pipeline validates and rolls out changes automatically.
  • Demo applications on Hetzner show how Cloudflare protects them.

Technology

  • Cloudflare
  • OpenTofu
  • CI/CD
  • Hetzner

© 2026 jan.deploige.be. All rights reserved.