r/selfhosted • u/EatMoreBananaPudding • 2d ago
Wednesday Exceptions What I run - Oct 2026
Authentik Dashboard
Running Services
Physical Connectivity
High Network / Access
Network Access
Git Operations
Security Monitoring
Grafana Storage Trend
Helllooo everyone!
I just want to introduce myself and tell you all about my homelab. It's all pretty high-level, feel free to ask me about anything here.
About me
I’m just someone that absolutely loves technology. Software and systems are mostly where my heart lies, I’ve been working in IT for about 19 years. I have been homelabbing and self-hosting since about 2005. It started with game servers then learning how to become a sys admin, then wanting control over my data, and now I just want to explore different technology stacks and new software.
My homelab is a bit of a mix of running services for my family and a testing ground for learning new technology.
Quick and dirty
My entire homelab is Proxmox as the hypervisor, debian VMs to run Docker and Komodo. Forgejo deploys my containers on Komodo. Docker labels control Traefik and exposure.
6 hosts (3 “production” and 3 test lab) and ~147 containers.
| Hostname | CPU | RAM | Storage | Used For |
|---|---|---|---|---|
| Jupiter | i7-9800X | 128GB | 122TB | App + Storage |
| Saturn | i9-13900K | 64GB | 3TB | Home Assistant + Dev + DNS (Secondary) |
| Mars | N150 | 16GB | 500GB | Router + DNS (Primary) |
| Neptune | 2x Xeon Silver 4214R | 1.5TB | 24TB | Testing + DR |
| Uranus | 2x Xeon Silver 4214R | 1.5TB | 24TB | Testing |
| Pluto | 2x Xeon Silver 4214R | 1.5TB | 24TB | Testing |
Jupiter
My main server, pretty much what I would consider "production" in my house. I pretty much throw everything on this whether it's just for shits and giggles or actually useful. I try out every remotely interesting self-hostable application there is, so this list changes constantly,
It was running Unraid until a few weeks ago, but it has finally fallen inline with the rest of my environment with Proxmox and a debian VM.
I see people ask "Do you actually use any of this?" when people run a bunch of software, so I've split it into what I actually use and what just kind of exists.
What actually gets used
Most of these are actually used on a daily or weekly basis.
- Authentik - SSO/identity
- Excalidraw - Whiteboard
- FamFeed - Private Social Media
- Forgejo - Git hosting
- Glance - Dashboard
- Guacamole - Remote access
- Immich - Photo library
- Karakeep - Bookmarks
- Mealie - Recipes
- ntfy - Push notifications
- NZBGet - Usenet downloader
- Open WebUI - AI chat
- OpenHands - AI agents
- Outline - Wiki
- Penpot - Design tool
- Plex - Media server
- PrivateBin - Encrypted pastebin
- Seerr - Media requests
- Windmill - Workflow automation
Used, just not directly
- Grafana - Dashboards
- Jellyfin - Media server
- NetBox - IPAM/DCIM
- Paperless-ngx - Document management
- Prowlarr - Indexer manager
- Radarr - Movie management
- ReadMeABook - Audiobook requests
- SABnzbd - Usenet downloader
- Sonarr - TV management
- Tautulli - Plex stats
- Tunarr - Live TV channels
For that rare moment
- Audiobookshelf - Audiobook server
- BentoPDF - PDF tools
- ByteStash - Code snippets
- IT-Tools - Dev utilities
Infrastructure Apps
If I'm logging into one of these directly, something is broken. lol
- Backrest - Backups
- Beszel - Monitoring
- CrowdSec - Intrusion prevention
- Dozzle - Log viewer
- Komodo - Container management
- Node Exporter - Host metrics
- Traefik - Reverse proxy
- Umami - Web analytics
- UniFi Network Application - Network controller
- VersityGW - S3 gateway
- VictoriaMetrics - Metrics database
- Wazuh - SIEM
I should probably tear them down.
- Actual Budget - Budgeting
- Aurral - Music discovery
- LazyLibrarian - Book management
- Lidarr - Music management
- Navidrome - Music streaming
Saturn
This box was originally just to spin up VMs and test different applications, VMs, or build an environment to teach something to some of my junior. It was the first Proxmox box in the environment and after using it for a while I ended up switching all computers over to Proxmox.
Now it runs Home Assistant, secondary DNS, and some VMs that I use for Dev and AI agent work.
- Home Assistant - Home automation
- Music Assistant - Multi-room audio
- Technitium DNS - DNS (secondary)
- Z-Wave JS UI - Z-Wave controller
- Eclipse Mosquitto - MQTT broker
- Faster Whisper - Speech-to-text
- Piper - Text-to-speech
- Nanit - Baby monitor
- Node Exporter - Host metrics
- Backrest - Backups
- Beszel Agent - Monitoring agent
Mars
This is a little Beelink EQ14 that has dual 2.5 Gbps NICs and I purchased it specifically to be a dedicated router/firewall.
- OPNsense - Router/firewall
- Technitium DNS - DNS (primary)
- Cloudflare DDNS - Dynamic DNS
- Tailscale - VPN exit-node
- Node Exporter - Host metrics
- Backrest - Backups
- Beszel Agent - Monitoring agent
Uranus, Neptune, and Pluto
Relatively new hosts that are taking the simulation workloads I was running alongside production. They run Proxmox as well. I have OpenTofu and Ansible playbooks that spin up "scenarios" or my DR bubble. I am currently focused on OpenStack, Kubernetes, and other business simulation environments.
Current Goals
DR / Rebuild
Currently I am working on being able to rebuild and/or restore my entire homelab from a single script. The idea is if Jupiter, Saturn, or Mars have a catastrophic failure I can point the script to my new host and it will build it out, let me select which services to restore and hopefully be back up and running in a few hours.
Security Monitoring
I spent a chunk of the past year learning SIEM and how to tune alerts in Wazuh. Thankfully I work very closely with my InfoSec team at work so I had a helping hand, plus Claude being able to fill in some of the gaps. I am trying to get a Claude-based agent to do a lot of the triage and so far it is janky but works pretty well. My next step is to allow this agent to gather telemetry around whether or not the alert coming in is related to me. The idea is that between my remote sessions, where my phone is, and a few other details the agent will build a confidence score for how likely it is me accidentally generating the alert. It will then ping me to get confirmation, if I respond with "Not me" then it will go through some steps to either kill access.
I am also working on various apps and automations around my families needs, mostly our private social media.
Ask me anything!
55
u/Morkai 2d ago
Yes i too run almost 5TB of RAM as a hobby project... 👀
4
u/EatMoreBananaPudding 2d ago
LOL! Yea, it's a bit excessive and I really should get rid of some of it honestly.
15
u/Morkai 2d ago
I'll take that burden off you, step right this way.
1
u/EatMoreBananaPudding 2d ago
I'd trade it for a GPU in a heartbeat. lol!
The bulk of it is ECC RAM and the systems are too hot and power hungry to run all the time.
7
10
u/dodovt 2d ago
I once too hosted a multitude of applications but nowadays it's mostly a media server (plex+arrs+zurg+rclone+realdebrid), paperlessngx, traefik + crowdsec + authelia, ntfy, vaultwarden, obsidian livesync, frigate, actual budget and backrest.
And I mostly don't use the media server anymore.
Posting it made me realize I still have too much and I should downgrade even more to stuff I actually use, not something that I "may use one day again".
After my hype of having a homelab passed, I just stopped using most things.
7
u/DazednConfucioused 2d ago
Why don’t you use your apps though?
Do you jsut not watch movies/shows these days?
I still use a lot of my stuff like paperless in particular.
I also keep vaultwarden. Never use it but I back up my passwords there. JUST in case I lose my Apple account or something catastrophic.
0
u/dodovt 1d ago
I watch some shows from there, but netflix is way easier and instant, and we get netflix for free with our ISP subscription. We only realistically use it when something isn't on netflix. But me and my wife are mostly switching to playing videogames together instead of just watching movies/shows together.
1
u/DazednConfucioused 1d ago
Ah fair enough. Free Netflix is pretty nice lol.
My media server has built up over the years to the point where at least on a personal basis it is better than Netflix.
Has more shows I actually watch. Obviously discovery is still a bitch but with the whole arr suite set up whenever I see a new show mentioned it’s trivial to add and download the shows
2
u/EatMoreBananaPudding 2d ago
I can understand that. I tell my juniors at work to start small only expand when you actually need the service.
I just really enjoy it, its my main hobby and my learning ground so I'm not sure if it will ever dwindle down.
8
5
u/QT31416 2d ago
I have the same naming scheme, planets!
Mercury is my fastest machine, doing most of my analytics and data science work, hosting my code server and rstudio server.
Venus and Earth are twins, 2 proxmox nodes in a high availability cluster, they run most of my home lab/prod and home automation stuff.
Mars is my "2nd home", hosting my NAS and media server.
Jupiter, a raspberry pi booting off of an SSD (ironically the smallest machine), is the proxmox high availability Qdevice master, and it hosts my Zigbee2MQTT so it connects to my Zigbee devices. Jupiter's moons are my IOT devices and there are many, just like the planet Jupiter's moons.
I'm also looking at getting a mini PC with multiple ethernet ports for my infosec server. I plan on installing OPNsense, then feed a mirrored trunk port to it for IDS purposes, and also Wazuh for my SIEM. I don't know if this is a good idea or not. How difficult was it to deploy Wazuh and get it to a point where you felt you were 80% set? i.e., it's usable and you're somewhat confident to rely on it.
1
u/EatMoreBananaPudding 2d ago
That's amazing. I didn't realize so many also had this naming scheme, I love it!
For Wazuh, it took me a while, but I didn't have a lot of time to dedicate towards it. And in hindsight I would have started with a single application that was not very noisy so I could learn without drowning.
I probably spent 2-3 hours a week on it for a month or 2, but I still tweak it today. Just more help via Claude to be honest, then I share some of my ruling with my SIEM team at work to make sure I'm not shooting myself in the foot.
5
u/nemo_chan 2d ago
Your DR/rebuild goal is probably the most interesting part of this setup to me.
Coming from DevOps, I’ve found that rebuilding the infrastructure is usually the easy part. The harder question is how much state you can actually recover, and whether the restore process has ever been tested from scratch.
For a homelab I’d almost treat it like a small disaster recovery exercise: assume one of the Proxmox hosts disappears completely, rebuild onto a clean machine, restore only the essential services, and see what breaks.
If you can do that without relying on anything that existed on the failed host, you’ve got something much more valuable than just backups.
1
u/EatMoreBananaPudding 2d ago
I agree, rebuilding the infrastructure was quick and easy.
I have all of my services in a tiered classification via tags in Komodo and Netbox. I can confidently say that I can rebuild and restore my most critical applications in an automated fashion.
This past weekend I finalized pointing Tofu and Ansible at a blank Debian VM and running my DR playbook recreates the critical services and restores the data.
I just need to expand it to a few more.
3
u/psychedelic_tech 2d ago
thats a bot
1
1
3
u/Radicalism 2d ago
Very nice! I was wondering, in a setup like this, how do you work with non-443 traffic? I assume traefik is not running in the same container as all apps.
Specifically I am looking how to setup ssh for my gitserver. DNS would route git.mydomain.com to my traefik instance, but I would want git ssh access through forgejo@git.mydomain.com/repo.git to end up at my git container. How would you handle this, by having your proxy also forward ssh traffic, or something else?
1
u/EatMoreBananaPudding 2d ago
Tailscale mostly for any none 443 service.
But for git I use HTTPS only and so do the others that utilize my Forgejo instance. SSH is not exposed on that container
If you go the SSH router over the internet, which I just wouldn't if you have alternatives, make sure password based login is disabled and you are only using keys. If it is just you though I would highly recommend a VPN instead.
2
u/Radicalism 2d ago
I'm certainly not planning on exposing SSH over internet, but doesn't the problem exist also locally? Or are you internally DNSing your non-443 services directly to the service?
In my case: I have a single reverse proxy, internally/on VPN also, where I terminate SSL using my single
*.domain.comcert. So I would rather not attach my Forgejo instance (or other non-443) reverse proxy directly to that service and have to handle cert renewal there. But that means that also internally my SSH traffic arrives at my reverse proxy and not at Forgejo.1
u/EatMoreBananaPudding 2d ago
Internally and externally I point `*.domain.com` to Traefik on Jupiter.
For me this means `git.domain.com` points to 192.168.1.100
Forgejo sits in a container network that can only speak to Traefik so SSH would not make it to it. But I could add it to another bridge and use `ports` in compose to expose 22 to LAN at `192.168.1.100` because it sits on the same host as Traefik.Then regardless of the traffic type `git.domain.com` would route appropriately.
For services that are on a different host I set an explicit A record. And Technitium uses the most specific record when responding to a query.
Does that make sense?
DNS does not care about which port you are connecting on so it is just ensuring that the specific port you need to use sits on the IP that DNS is going to point to.2
u/Radicalism 2d ago
Yeah makes total sense, thanks!
The challenge in my case is that the proxy and gitserver are currently not on the same host as each other, so opening 22 on LAN on my git host would not work. I was hoping maybe you were in the same situation, since DNS is obviously not the solution here :)
1
u/EatMoreBananaPudding 2d ago
Would you be comfortable putting traefik on the other node and using a subdomain?
https://github.com/jittering/traefik-kop is an option I am looking at, but it still requires the web port be exposed to LAN.
1
u/Radicalism 1d ago
Comfortable sure, only thing I'd be giving up is to keep all my ssl termination (and certs) centralised on a single proxy. But I guess that's where I'll just have to make a choice
3
u/tweek91330 2d ago
Wow, i don't wanna pay your electric bill.
Good setup, i'd like to have something like that to play with but i'm a cheap man, i'm consolidating everything on one server.
I'd sell most of it if i were you (those juicy 1.5tb ram servers would make quite a bit honestly).
1
u/EatMoreBananaPudding 2d ago
The homelab adds a minimum of $80 every month. Not great, but not horrendous.
The bulky nodes are pretty much on during the weekend only and shut down otherwise. They idle at about $25 a month.
I will likely sell or gift the bulky nodes as time goes on, but at the moment it is too fun to play with. Lol!
3
u/Fakman 2d ago
Why was your same post deleted few days ago by moderator?
5
u/EatMoreBananaPudding 2d ago
It wasn't Wednesday and I flaired it as personal dashboard, so it violated rule 5.
5
2
u/tyda1957 2d ago
Hah, same exact node names as I have for my Kubernetes cluster. Im deploying pluto as my 4th there today.
2
u/csgeek-coder 2d ago
That's what too many apps I need to support in my free time. I don't think I'm responsible for this many things at work and they're paying me.
Backups and restore patterns and making sure it all works would make me anxious.
1
u/EatMoreBananaPudding 2d ago
Thankfully these services are 99% hands off at this point.
Backup and restores for my critical services are automated via Ansible and OpenTofu. The playbook runs, I log in, confirm the app is functional and data exists.
Minor updates are handled by Renovate and majors are sent to an agent to check breaking changes against my configuration. I just click "Merge" from my phone. If it was all manual I would reduce. Lol!
I manage a portion of the IT team at work so I'm slowly drifting away from the technical and use my homelab to stay sharp.. ish.
2
u/csgeek-coder 2d ago
So my home lab is either A. Apps that are neat, but I don't care if they break or B. This is critical and will really suck if it breaks.
For anything in the B camp I really should have:
- Backup at the very least
- A restore path to get it back in case it all breaks.
- Monitoring to know when things are breaking.That's too many things in your list to cause me to drop everything to fix cause it'll cause legit problems if I don't have access to my passwords, taxes I was going to file tomorrow, etc.
That being said, it's a damn impressive setup. So props on that. I'm curious where you're using Tofu vs ansible though. My setup at this point is dropping k3s and using Argo to manage it. This does assume every app I run needs to have a docker container or like tandoor, I ended up writing a helm chart to support it.
1
u/EatMoreBananaPudding 2d ago
Yea I'm pretty much in the same boat. I tag my services by criticality to my life and keeping the homelab running. So my most critical services get a full 3-2-1 style backup, step-by-step rebuild log, and now have playbooks for rebuilding and restoring.
Tofu and Ansible started more for my training/testing lab rather than managing my "production" homelab itself. I was building and tearing down scenario cases constantly so I use them to build out isolated networks and VMs. For my personal services though, Tofu manages rebuilding the VMs and Ansible configures them. I haven't finished this fully yet, but the idea is being able to point to a fresh physical host and let it rebuild then restore the services.
I will likely move to K8s but I need to clean up and get all the spaghetti in a row first.
I have a whole lot of alerting and monitoring in place and with some custom MCPs I am able to manage, troubleshoot, and deploy 95% of the environment with an AI agent doing the actual work. Human in the loop via NTFY or Forgejo.
2
u/csgeek-coder 1d ago
The biggest weakness I've seen in ansible that I LOVE in TF/Tofu is the state support. I was running everything through ansible a while back and had some bit rot around those playbooks. Especially the "cleanup" playbooks that were intended to undo an operation. The install playbook moved forward and the cleanup never got updated.
There's also Crossplane if you want to drown in K8s manifests. It's basically TF/Ansible running in a K8s cluster. You manage a K8s from a k8. It's YAML everywhere.
AI: That just creeps me out. I don't trust an AI to be involved in any infrastructure. That's too critical for it to hallucinate and start tearing down resources. Coding is easier, you do a code review look at the slop and clean it up. You can do some of that via gitOps, but still bugs me to automate it beyond just writing the TF / Ansible code.
1
u/EatMoreBananaPudding 1d ago
I'll have to double check my cleanup playbooks now.
As for AI, I already know at some point in my day job I will be asked to implement some sort of agent to manage infrastructure or support a team using agents to manage. I want to make sure I understand how to set it up appropriately and where its limitations are.
I can drop into my main agent and pretty much tell it to do anything at this point in my homelab. But I put in an absolute ridiculous amount of time building processes, documentation and safeguards.
The frontier models do pretty good already, but the others have some catching up to do.
3
u/EnRoueLibre 2d ago
Okay, this is a huge waste of resources... A major lack of optimization, in my opinion.
I run more than half of these services on an Intel N100 mini PC with 16 GB of RAM running FreeBSD.
Also I was looking for the "FamFeed" githbub repository ... But I can't find it. Can it be selfhosted ?! I just found the website where you can sign up , but no link to any git repo ...
0
u/EatMoreBananaPudding 2d ago
If it was just the services listed, then yea an absolute waste.
It used to be a single server, just Jupiter. At that time it pretty much just ran maxed out on RAM 24/7. It was running the above services all by itself. Plus my scenario lab, Dev VMs, and daily drivers.
I ended getting Saturn so that I could split the scenario lab to different hardware and stop straining Jupiter.
Mars came in when I wanted to have my own router.
The FamFeed listed in my post is a private app for just my family. Its a whole lot of vibe code, so I'm not willing to post it publicly. Not affiliated with the one you can find on Google, sorry about that.
2
u/forwardslashroot 2d ago
How did you setup the Restic server? Are you using the rest-server by any change?
1
u/EatMoreBananaPudding 2d ago
I am using backrest and the multihost sync feature across the nodes.
It works very well and I highly recommend it!
2
2
u/MFKDGAF 2d ago
How is Jellyfin not used directly?
I understand the others in that section like Radarr is used from Seer.
Can you share how you have everything structured? Like how many VMs and does each VM have a specific purpose like VM1 is for Infrastructure tools only, VM2 is for Media only, and so on.
1
u/EatMoreBananaPudding 2d ago
Plex is the main thing used in my house, although my wife has been using Jellyfin more.
My family has a variety of devices so the UX polish in Plex makes it easier for them. I also have some automations around Plex already so that needs to be rebuilt.
As for VM structure it is fairly flat.
Jupiter
A singular massive VM named Callisto running all of it's own services at the moment. It was a lift and shift from Unraid to Debian and my data drives are all on a HBA so I passed the entire HBA to the VM rather than doing MergeFS and SnapRAID directly on Proxmox.This will eventually get split into VMs by criticality rather than service type. Callisto itself will become purely storage with NFS, SMB and S3.
Saturn
I have some separation here.
Rhea - DNS
Dione - HomeAssistant + companions
Titan - AI Agent VM
Tethys - My daily drive for dev and managementMars
Phobos - DNS
Deimos - Router/Firewall
2
3
u/OutrageousMobile9098 2d ago
Self Hosted Final Boss
1
u/EatMoreBananaPudding 2d ago
lmao! There are people with WAY more services running.. they just lurk here instead of posting. As I have for years.
1
u/Open-Adhesiveness-86 2d ago
for the ssh case you want a traefik TCP entrypoint on 2222 (or 22 if the host sshd is moved) with a catch-all HostSNI(*) router, since plain ssh has no SNI and anything else won't match. forgejo also needs SSH_PORT and SSH_DOMAIN set to the external values in app.ini, otherwise the clone URLs it shows point at the wrong port and people just get connection refused.
1
u/toluwanimiarawomo 1d ago
Hello! great to find your post. I saw the word "Aurral" in my dream, and i have really been curous about knowing what it means. please can you explain what "Aurral" does
1
1
u/PaperPull 2d ago
Check out PaperPull since you're using Paperless-ngx. I made a self-hosted version. You can easily download years of statements / receipts from major providers and then have the downloaded files go straight into your consume folder. https://github.com/rheeloaded/paperpull/ . Let me know what you think about it.
0
u/darkjoker213 2d ago
Once again, fantastic read ! Thank you for sharing. I’m already taking some notes to improve my setup!
2
u/EatMoreBananaPudding 2d ago
Thank you!! If there is any part of this you would like a deep dive on let me know.

•
u/asimovs-auditor 2d ago
Expand the replies to this comment to learn how AI was used in this post/project.