Homelab
My homelab is split across a few boxes: a Proxmox host for compute, an Unraid box (“DROID”) as the NAS, and Ubiquiti gear for networking.
Architecture
- Proxmox hosts docker-01, a VM that runs the entire Docker stack.
- Unraid (DROID) is the storage tier for media, ebooks, and ROM libraries.
- Ubiquiti EdgeRouter, AP, and UniFi Controller handle routing, WiFi, and DHCP.
The Docker stack is defined in the AshnetHome repo. A push to main triggers a self-hosted GitHub Actions runner on docker-01, which pulls /opt/stacks in place and redeploys only the stack directories that changed. Runtime secrets (.env files, Authelia secrets) live on the host and are gitignored, so they never touch the repo.
Backup
docker-01 is backed up daily via Proxmox vzdump, with a notification fired once the backup completes. That covers the container configs, /opt/appdata, and the runtime secrets kept out of git.
Services
Edge and auth
- Traefik - reverse proxy, wildcard certificate via Cloudflare DNS challenge
- Authelia - SSO and forward-auth for most services
- cloudflared - external access tunnel
- AdGuard Home - network-wide DNS and ad-blocking
- Homepage - dashboard
Ops
- Uptime Kuma - uptime monitoring, with a public
live.ashnet.onlinestatus page - Dozzle - container logs
- Diun - image-update notifications
Media
- qBittorrent and NZBget - downloads
- Prowlarr - indexer manager
Books and docs
- Chaptarr - ebook automation (Readarr’s successor)
- Kavita - ebook and comic reader
- Paperless-ngx - document archive and OCR
Everything else
- RomM - ROM library manager
- Super Productivity - tasks, with a WebDAV sync backend
External access
Traefik terminates TLS and routes subdomains on ashnet.online, with certificates issued via a Cloudflare DNS challenge. Most services sit behind Authelia. A few (Kavita, RomM, the WebDAV sync backend) use their own login instead, because Authelia’s forward-auth cookie handshake breaks cross-client apps.
← Back to projects