Home infrastructure
Four years in: a two-node Proxmox cluster, an HA reverse proxy, six VLANs and 25+ self-hosted services, some of them used daily by people outside this household. Web services are reachable without a single open port; the game and voice servers that do need one are isolated in their own VLAN. Everything below is designed, built and operated by hand.
Compute & storage
A two-node Proxmox VE cluster with shared TrueNAS storage, a dedicated backup server, and a Raspberry Pi quorum device to prevent split-brain during single-node failures.
VLAN segmentation
Each workload class lives in its own VLAN with tailored firewall rules. This limits blast radius if any service is compromised and enforces least-privilege networking by default.
Inter-VLAN rules
WAN ingress
Technitium DNS server
local.screedy.com. Forwarder zone for screedy.com — local overrides resolve to Traefik VIP, unknown records forwarded to Cloudflare. Secondary Technitium syncs via zone transfer.Domain conventions
Deployed applications
25+ self-hosted services across six VLANs, all accessible via Traefik with wildcard TLS certs issued through a Cloudflare DNS challenge — no open WAN ports required for web access.
local.screedy.com, forwarder for screedy.com. Secondary node provides HA for DNS resolution.Security posture
Defence in depth — from VLAN segmentation at the network layer up through zero-trust tunnels, automated TLS, a web application firewall, intrusion prevention, SIEM alerting, and per-service access controls.
- Six VLANs isolate workloads by risk profile and purpose
- Default-deny between all VLANs — explicit allow rules only
- Media (30) and Game (40) have no outbound to internal services
- VLAN 55 (Exposed) further isolates exposed services from VLAN 50
- The Traefik HA pair (VIP) on VLAN 20 is the sole ingress point for proxied web traffic
- Cloudflare Tunnel — no inbound WAN ports for web services
- All external traffic terminates at Cloudflare edge
*.local.screedy.comis never published to public DNS — unreachable externally by design- Cloudflared LXC isolated from backend VLANs — only permitted to reach Traefik
- Wildcard certs for
*.local.screedy.comand*.screedy.comvia Cloudflare DNS challenge - No HTTP-01 challenge — WAN ports 80/443 remain closed
- Certificates managed on traefik-01 and synced to the backup node, renewed automatically before expiry
- HTTPS backends use
serversTransportwith appropriate cert verification settings - HSTS, XSS protection, frame options, referrer policy enforced via Traefik middleware
- Wazuh agent on Traefik LXC ships access logs and daemon logs as JSON
- Custom Wazuh rules for brute force, 5xx storms, blocked access, slow response anomalies
- Traefik access log captures ClientHost, X-Forwarded-For, DownstreamStatus, Duration, RouterName
- Prometheus scrapes Traefik metrics — Grafana dashboards for request rates and error spikes
- Rate-limit middleware on Traefik: 100 req/s average, burst 50
- Basic auth on Prometheus endpoint enforced via Traefik middleware
- CrowdSec analyses Traefik access logs from Loki for scanning, CVE exploit attempts and brute force
- Offending IPs are banned on both Traefik nodes within about a minute
- Community blocklist of ~15,000 known attackers enforced alongside local detections
- Real client IP taken from
Cf-Connecting-Iponly when the request comes from the tunnel connector - Cloudflare WAF rules challenge traffic from cloud-provider networks at the edge
- CrowdSec AppSec inspects every public request inline, before it reaches a service
- Virtual-patching rules block exploits for known CVEs on the very first request
- Blocks the single malicious request instead of banning the visitor, so a stray bad URL never locks out a real user
- Fails open — if CrowdSec or its WAF is unreachable, traffic flows and only detection pauses
- Generic OWASP rules (SQL injection, XSS) staged behind a false-positive review
Monitoring & alerting
Metrics, logs, and security events aggregated into a coherent observability pipeline — so problems surface before they become outages.
/metrics on :8080), CrowdSec, Unpoller (UniFi network metrics), and itself. Basic auth enforced by Traefik middleware.Why this setup?
The decisions that shaped this setup — and the trade-offs considered.
service.screedy.com to the Traefik VIP via Technitium's forwarder zone. External clients get Cloudflare's public record. Same domain, different resolution path — no internal traffic hairpins through Cloudflare, and no UX difference for users.Cf-Connecting-Ip, trusted only from the tunnel connector — otherwise every visitor would look like cloudflared, and one ban would block everyone. AppSec adds a second, inline layer: individual exploit requests are blocked immediately, while IP bans handle repeat behaviour.Full stack
Every technology actively used, managed, or operated in this environment.
What's next
Active migrations and planned improvements to move the lab closer to a fully HA, zero-trust production posture.