Virtualization & separated roles
13 VMs carry separated roles: NPMplus proxy, redundant DNS, monitoring, PBS, Guacamole bastion, Outline documentation, Docker services, honeypot, Home Assistant and internal tools.
Home Lab
This 13-VM home lab lets me practice systems and network administration, proactive security, monitoring, documentation, backups and service hosting in real operating conditions.

overview
Each component has a role and remains maintainable over time.
13 VMs carry separated roles: NPMplus proxy, redundant DNS, monitoring, PBS, Guacamole bastion, Outline documentation, Docker services, honeypot, Home Assistant and internal tools.
Public services go through SRV-PROXY and NPMplus; sensitive interfaces remain local, VPN-only or bastion-only.
Outline centralizes procedures, runbooks, architecture and technical decisions.
PBS and Synology NAS structure backup, retention and recovery logic.
Grafana, Prometheus, Loki, Blackbox, SNMP, ntfy and NetAlertX provide actionable visibility, with 50/50 Prometheus targets validated UP.
VLAN segmentation, TLS, HTTP headers, CrowdSec, Fail2ban, UFW, hardened SSH, AdGuard Home + Unbound, automatic DNS synchronization and Cowrie reduce risk.
Infrastructure compliance reaches 99% through documentation, backups, hardening, inventory and monitoring checks.
architecture
A deliberately non-sensitive high-level view.
monitoring
Dashboards for availability, system metrics, public services and overall health.
Metrics collection for systems, network, HTTP, SNMP and services.
Centralized logs and incident analysis.
Useful ntfy notifications with noise reduction and adapted thresholds.
Automated network inventory to track devices, detect new assets and keep mapping up to date.
HTTP/TLS availability monitoring for public services.
Rack-integrated screen for continuous home lab status visibility.
operations
PBS, retention, verification, Synology NAS and recovery logic guide daily operations.
Backups are treated as a recovery capability, not just as an archive. Sensitive changes are documented, checked and followed through continuous improvement. Important internal services include Proxmox VE, PBS, Synology NAS, Apache Guacamole, AdGuard Home, Unbound, NetAlertX and ntfy.
services
Public and internal services presented without secrets, sensitive ports or exploitable firewall details.
Self-hosted password manager compatible with Bitwarden.
Technical knowledge base for infrastructure, procedures and decisions.
Web toolbox for developers and administrators.
Self-hosted PDF toolbox.
Self-hosted file converter.
Controlled file sharing.
One-time secret transmission.
Diagrams and visual documentation.
Local smart home platform.
Monitoring and intentionally limited public dashboards.
smart home
Home Assistant centralizes the smart home side of the lab. The goal is to reduce dependency on vendor clouds, control devices locally and connect smart home monitoring to the broader observability stack.

security
No secret, token, public admin port or exploitable firewall rule is published.
proof
Gallery limited to the three photos actually available.



The public Grafana view is intentionally limited and contains no sensitive information.
skills