Infrastructure Map

A sanitized overview of my active self-hosting environment.

My homelab is actively evolving into a self-hosted project environment for portfolio infrastructure, AI workflow tools, small web apps, and monitoring/security experiments. Recent work includes organizing multiple Docker-hosted projects, improving remote access with Tailscale, and using Cloudflare Tunnel concepts for safer public exposure where appropriate. I am also using it to learn practical storage and backup work: TrueNAS, SMB/NFS, Time Machine and Windows backup planning, ZFS snapshots, and monitoring.

Sanitized Infrastructure Map

Internet / AT&T Fiber
Gateway / Router Layer
10Gb Switch
Proxmox Host
Uptime Kuma
AdGuard
Wazuh
CrowdSec
Tailscale
UniFi OS Server
Portfolio Website
Hermes LabOps
Self-Hosted 1099 Tax Planner
Friend Static Website
Senior Tech Companion
NAS / Storage / Backups

This diagram is intentionally sanitized and does not include public IPs, private IPs, hostnames, internal URLs, tokens, or sensitive service details.

Monitoring and Alerting Philosophy

I want services to be understandable, not mysterious. Monitoring should answer three questions quickly: what is down, what changed, and what needs action. Alerts should be useful enough to respond to, quiet enough to trust, and documented enough to learn from.

Core Components

Infrastructure Areas

Proxmox

Virtualization platform used to organize and run self-hosted services and lab systems.

NAS / Storage

Storage and backup planning for media, project files, and infrastructure experiments.

Uptime Kuma

Service monitoring and uptime visibility for self-hosted applications and infrastructure.

Homepage / Actual Budget

Self-hosted dashboard and budgeting services used to practice organizing internal tools without making private services public.

AdGuard

DNS filtering and network-level visibility for safer and cleaner browsing.

UniFi OS Server

Network management and visibility experiments for learning device organization and network planning.

Device Inventory Lab

Planned public-safe work for tracking known devices, network changes, and sanitized network health summaries.

Wazuh

Security monitoring and endpoint visibility for learning alerting and log review.

CrowdSec

Security tool used to learn behavior-based detection and community-driven threat intelligence concepts.

Tailscale

Remote access layer for securely reaching internal services without broadly exposing them.

Docker Project Hosting

Active environment for organizing multiple self-hosted projects, internal apps, AI workflow experiments, and small web projects.

Cloudflare Tunnel Concepts

Public exposure planning for selected services while keeping private services, internal routes, and sensitive details out of public content.

Storage and Backups

TrueNAS, SMB/NFS, Time Machine and Windows backup planning, ZFS snapshots, and backup monitoring are current or planned learning areas.

Network Capacity

5 Gbps AT&T Fiber and higher-speed LAN experimentation give me room to practice real networking, monitoring, and service planning.

Artifacts To Add

Sanitized Homelab Screenshots

Uptime Kuma dashboard
Proxmox VM/container list
AdGuard DNS view
Wazuh/CrowdSec dashboard
Tailscale device map
TrueNAS planning notes
Cloudflare Tunnel setup
10Gb network layout

Replace with sanitized screenshot - remove customer data, public IPs, emails, phone numbers, API keys, and private paths.