Homelab

A repurposed laptop running Ubuntu Server. Services are defined in git as Docker Compose stacks, private services sit behind a VPN, storage is encrypted, and the public site has zero open ports.

Overview

My homelab is an old laptop given a second life as an Ubuntu Server box. It hosts my own tools (including FlashServerDash and the FlashVCTPredictions bot), a private file cloud, and this website. The guiding rules are simple: everything is reproducible from git, nothing private is reachable from the internet, and the public parts don’t need a single open port.

Highlights

  • Infrastructure in git. Every service is a Docker Compose stack kept in a git repository, so rebuilding or moving the server is a checkout and a docker compose up, not an afternoon of remembering what I clicked.
  • Automatic TLS everywhere. Traefik is the reverse proxy and gets wildcard Let’s Encrypt certificates using the DNS-01 challenge through Cloudflare DNS. Internal services get real, trusted HTTPS without being publicly reachable.
  • Private by default. Admin tools and personal services are only reachable over a Tailscale network. If you’re not on the tailnet, they don’t exist.
  • Encrypted, fail-closed storage. Nextcloud (backed by MariaDB and Redis) keeps its data on a LUKS-encrypted volume. The mountpoint is set up to fail closed: if the encrypted volume isn’t unlocked and mounted, the service won’t start and write data to the unencrypted disk underneath.
  • Zero open ports for the public site. This website is served through a Cloudflare Tunnel. The server makes an outbound connection to Cloudflare, so the home network has no inbound port forwarding at all.

How it works

Public traffic and private traffic take completely different paths.

Public (this site):

  1. Visitorbrowser, over HTTPS
  2. Cloudflare edgeTLS, caching
  3. Tunneloutbound-only connector
  4. nginxstatic files + security headers

Private (everything else):

  1. My deviceson the tailnet
  2. Tailscaleencrypted WireGuard mesh
  3. Traefikrouting + wildcard TLS
  4. ServicesCompose stacks

Because the two paths never meet, a mistake in a private service’s config can’t accidentally publish it to the internet.

Stack

Ubuntu Server · Docker Compose · Traefik · Let’s Encrypt (DNS-01 via Cloudflare) · Cloudflare Tunnel · Tailscale · LUKS · Nextcloud · MariaDB · Redis · nginx