Infrastructure & Ops

Personal Homelab & Infrastructure

A robust, self-hosted, and power-resilient hybrid infrastructure engineered for media distribution, virtualization testing, and strict network security segmentation.

Compute & Storage Nodes

Core Storage & Services

UGREEN NAS

Dedicated network-attached storage and media repository running containerized microservices.

  • Media Server Stack: Runs 8 integrated containers including Jellyseerr, Prowlarr, Radarr, Sonarr, qBittorrent, Gluetun VPN, Flaresolverr, and Tailscale.
  • Dashboard & Portal Stack: Hosts Homarr as a centralized dashboard for monitoring and launching self-hosted apps.
  • Library Management Stack: Runs Kavita for digital book and comic management.
Media & Game Server Node

Windows 11 Pro Rig

High-performance primary server handling media transcoding and game server hosting.

  • Jellyfin & Intel ARC: Leverages integrated Intel ARC graphics hardware acceleration for smooth video transcoding.
  • Dedicated Services: Hosts personal Minecraft servers with hardwired, high-bandwidth connection to the UGREEN NAS.
  • Remote Access: Integrated with Tailscale for secure remote streaming outside the home network.
Virtualization & Change Control

Proxmox VE Test Node

Dedicated staging environment for infrastructure validation.

  • Change Control: Used as a sandbox environment to test configurations, updates, and container deployments safely.
  • Compatibility Testing: Validates stability before pushing production changes to the Windows host or UGREEN NAS.
Network-Wide Security

Raspberry Pi 5

Dedicated hardware appliance enforcing network-wide privacy and security filtering.

  • Pi-hole Deployment: Acts as a network-wide DNS sinkhole to block advertisements and telemetry tracking at the network edge.

Resilience & Network Segmentation

Power Resilience & Safety

Comprehensive backup power and surge mitigation ensuring 24/7 uptime during environmental instability.

  • UGREEN UPS: Direct power backup paired with the UGREEN NAS to prevent data corruption during short outages or brownouts.
  • On-Site Generator: Automatically kicks in during extended grid failures to keep critical infrastructure online.
  • Surge Protection: Whole-home surge protector installed to shield sensitive server components from electrical spikes.

Network Segmentation & Access Control

Enterprise-grade isolation practices enforced across physical and logical layers.

  • Managed Switch & VLANs: Systems are organized into isolated VLANs based on function and security clearance.
  • IP/MAC Filtering: Strict access policies ensure equipment can only be reached by authorized users physically on-premise or authenticated via secure tunnels.