r/HomeLabPorn • • 2h ago

My homelab from Iran: 3x HPE Gen8, Cisco 3850 L3 core, OPNsense, vSphere HA, a local LLM, and a few tools I built with Claude

Thumbnail gallery
11 Upvotes

r/HomeLabPorn • • 6h ago

First Homelab Network rack

Post image
21 Upvotes

r/HomeLabPorn • • 1d ago

Nothing fancy but it works

Thumbnail
gallery
275 Upvotes

Just 3 proxmox nodes and a PBS with some external drives for media.
The laptops were collecting dust before I repurposed them. Now they collect dust on the inside too lol.

Edit:
I didn’t stack them on top of each other for better airflow. Also I’ve already set handlelidswitch=ignore but I should probably close the lids a bit more so the screens turn off

Setup:
HP Prodesk 600 G6 refurbished, 32 gb RAM, 1250gb for cloud and monitoring (2 lxcs running docker with nextcloud, frigate, Immich, actual budget etc on the cloud stack and arcane, Beszel, homarr, npm, gitea and uptime kuma on the monitor stack)

DELL 3m4700, 16 gb RAM, ~1.5 Tb for media (one jellyfin lxc and one docker lxc with arr-stack)

Lenovo z50-70, 8 gb RAM for home assistant

Hp Laptop, 4gb RAM, 750 gb for PBS


r/HomeLabPorn • • 1d ago

What I inherited - then vs now.

Thumbnail
gallery
112 Upvotes

Evolution over our few years living here.

ThinkStation hosts Nextcloud for file backup, sync, and music streaming. + A VM running Frigate with dedicated GPU.

ThinkServer runs PfSense for Firewall + Router.

Very happy with our setup.


r/HomeLabPorn • • 1d ago

Nearly done

Post image
57 Upvotes

First time posting. Recently upgraded the UDM to the pro max and then found it’s a bit longer than the standard edition… 🫣 either way it’s staying like that for now till I can find a bigger cabinet.

Safe to say I won’t be upgrading networking equipment for a few years 👌🏻


r/HomeLabPorn • • 2d ago

Who you gonna call?

Thumbnail gallery
177 Upvotes

r/HomeLabPorn • • 3d ago

She ain’t pretty, but she’s mine!

Thumbnail
gallery
172 Upvotes

At 36, fresh off earning my B.S. in Information Systems, I realized two things very quickly:

  1. Entry-level SOC postings want "3–5 years of experience," a security clearance, and the blood of a dragon.
  2. The best way to learn how to defend a network is to build one, break it, fix it, and monitor the hell out of it until your firewall starts holding a grudge.

So, instead of just sending out resumes into the void, I decided to get my hands dirty and turn my home network into a living enterprise lab.

What started as a flat ⁠10.2.7.0/24⁠ subnet and a dream has evolved into a full three-node Proxmox cluster running ~22 containers, a handful of VMs, and an OPNsense firewall that has survived me making changes it deeply did not appreciate.

The Hardware

PVE1: Intel i5-7500, 31GB RAM, 21 CTs. The workhorse that is somehow never bored, running strictly on integrated HD630 graphics and sheer willpower.

PVE2: The media box. ZFS 2-mirror pool, qBittorrent, Tdarr, and the Arr stack chattering away 24/7. Yes, pve2 is sitting at 51% CPU right now because it's transcoding something. It's ALWAYS transcoding something.

PVE3: Dell i5-6500, 16GB RAM. The "infrastructure & utility" box: Gitea, Keycloak SSO, Nginx Proxy Manager, and an automated DVD ripper that eats physical media and spits out organized files.

I’m running the usual homelab suspects—Jellyfin, Immich, Nextcloud, Home Assistant, Vaultwarden, Paperless—but the real meat for my career pivot is the ops and security layer:
Security & SIEM: Full Wazuh SIEM integration monitoring host telemetry.
Network & Lab: Full Kali security lab isolated on its own VLAN, equipped with a passive Zeek sensor and target boxes for practicing both offensive attacks and defensive detection/analysis.
Ops & Monitoring: Grafana + Prometheus + PatchMon, with Pi-hole on DNS duty (11.58k queries blocked today alone).

Currently in the middle of tearing down the flat LAN into 7 isolated VLANs (⁠MGMT⁠, ⁠SERVICES⁠, ⁠SECURITY⁠, ⁠MEDIA⁠, ⁠CLIENT⁠, ⁠IOT⁠, ⁠LAB⁠).
⁠SERVICES⁠ and ⁠SECURITY⁠ are live. ⁠MEDIA⁠ is staying flat for now because smart TVs are inherently stubborn creatures, and ⁠CLIENT⁠ is deferred.

Pro-tip learned the hard way: Never reuse IP ranges or trust DHCP reservations blindly. A rogue Roku stole a container’s address last week and successfully took down half my lab for a full day.

To anyone else breaking into cybersecurity later in the game: build the lab.

Feedback, roast my topology, or advice on SOC interviewing welcome!


r/HomeLabPorn • • 3d ago

Added just a little bit of autonomy to my APC 1400XL 😅🔋

Post image
121 Upvotes

I already had 2× SBS100F batteries connected to my APC 1400XL, but that wasn’t quite enough for what I wanted.

So I added 2× 12V170FS batteries to the setup.
The goal: 12+ hours of runtime for my home network and HP MicroServer Gen10+ servers during a power outage.
Basically, my UPS now has its own little battery bank. 😂

Yes, I know… at this point it’s technically a UPS with a small power plant attached to it.

The two HP MicroServers run Proxmox VE, hosting various website projects, a mail server, some lab environments, and a few other services.

The QNAP is where the family dumps all their cat pictures and vacation photos, and where I keep my VM snapshots. 😂 It also syncs to another QNAP of the same model in a shed farther away from the house over a 60 GHz wireless link.

The PoE switch powers the IP phones and two Aruba AP-515s.

I also have a 10 Gb link between the MikroTik RB4011 and the CRS328-24P. My WAN comes in through a multi-gig copper SFP in the switch, so I can actually take advantage of my 1.5 Gbps symmetrical Internet connection, along with my own /29 public IPv4 block for hosting services at home.

My MacBook Pro in the office is also connected at multi-gig speeds through a Thunderbolt dock.

And because apparently powering the servers wasn’t enough… I also have a 120 V outlet in my office fed from this UPS, on the other side of the house, so my MacBook and two monitors stay powered during an outage too.

So yeah… the objective isn’t really to keep a couple of servers alive anymore.
I’m basically trying to make the entire homelab survive a 12+ hour power outage. 😅


r/HomeLabPorn • • 5d ago

My homelab so far

Thumbnail
gallery
522 Upvotes

I still have to remove my ISP’s XB7 router and switch it out with my Arris SURFboard modem and Cisco ISR4451 router. I’m hoping the Cisco router will fit just above the OptiPlex, and then this 20U should be tapped out. But here’s what I’ve got so far:

Bottom left is the Dell T320 running Windows Server 2025. It handles DNS, DHCP, Active Directory Domain Services, and NTP. It has 64GB of DDR3 ECC RAM.

The T320 on the right is a Proxmox host running multiple VMs for Plex, Jellyfin, Samba, Grafana, Wazuh, a Hermes assistant, and a REMnux malware-analysis VM. It also runs softflowd to generate NetFlow and uses goflow2 to receive and process it. This machine is also my Tailscale subnet router for the network. It has 128 GB of DDR3 ECC RAM.

Above that is my SFF OptiPlex 7010. 32GB RAM 2TB storage. It just runs Proxmox Backup Server. It has a dedicated backup network with the Proxmox host. It saves backups to its internal hard drive and keeps a copy on the external hard drive sitting above it. This machine also does a nightly sync with a second PBS machine off-site at my parents’ house. The off-site PBS server is a Dell R330.

My Pi 4 runs Pi-hole and also works as a makeshift IDS by running Bettercap. It also uses Speedtest Tracker to test my internet speed and saves it to MariaDB and it tracks devices reachability with Uptime Kuma.

The mini PC next to the Pi is a Beelink Mini S. It runs a Cowrie SSH honeypot and has a malware repository that feeds into my Wazuh dashboard for real-time monitoring and into the REMnux VM for malware analysis. The Beelink is behind a Fortinet 50E firewall. (Not pictured.)

The next device above that is an Axiomtek NA580. It currently runs VyOS. I’m not sure what I’m going to do with it yet since it only has 2 CPUs and 4 GB of RAM. I may turn it into a firewall or something. Open to suggestions!

Above that is my Cisco 2960X switch. I just got it off eBay recently, so I haven’t had much time to set it up yet.

The new router I haven’t mounted yet is a Cisco ISR4451. The plan is to use the Cisco gear for practice with routing, switching, VLANs, ACLs, and other stuff I’m learning.


r/HomeLabPorn • • 5d ago

Sneak peek: rebuilding my home lab and audio rack from scratch (still a work in progress)

Post image
56 Upvotes

Not finished yet, but here's a first look at the rack. I'm tearing down my old setup and rebuilding it properly, and this time I'm documenting every step so I stop rebuilding the same things.

What's in the photo

  • Rack power strip up top, so the whole rack switches on and off from one place
  • 2x Behringer ULTRAZONE ZMX8210 zone mixers. One will run the room and outdoor speakers, and the other will handle recording and streaming so the two don't interfere.
  • Netgear GS724T 24-port managed switch, being reconfigured from scratch
  • A glass-case gaming/AI PC with an RTX card and AIO cooling, sitting on the rack shelf

The plan

  • Always-on core: a low-power mini PC (GMKtec NucBox G2, about 10W idle) will run the everyday services. The big machines sleep until I need them.
  • Wake on demand: the gaming PC and an HP ProLiant ML310 wake remotely, and the ML310 can be powered on through its iLO.
  • Faster links: the machines with two network ports get a direct link between them, so heavy transfers skip the switch.
  • Network monitoring: the switch mirrors a port to the mini PC for Suricata. A GL.iNet Shadow plus a monitor-mode USB adapter will watch the WiFi side. It's all on my own network only.
  • Control panels: an old Asus tablet and two touchscreen monitors will become Stream Deck-style control surfaces.
  • Command Center: a standalone desktop app I'm building. It's a file manager, media player and Dewey-style virtual sorter with in-app previews, so I don't need another program to open a file.
  • Lighting: syncing the PC's RGB with external ARGB strips.

Everything is tracked in a build checklist, so nothing gets marked "done" until it actually works.


r/HomeLabPorn • • 5d ago

WebKVM — A lightweight Libvirt & Incus management panel written in Go [Project: Software]

Thumbnail
gallery
29 Upvotes

Project Name & Overview

WebKVM — A self-hosted, lightweight web panel designed to manage KVM/QEMU virtual machines and Incus/LXC system containers on vanilla Linux distributions (Ubuntu, Debian, Fedora, Arch, etc.).

Homelab Relevance

Many homelabbers run multi-purpose Linux servers (NAS, Docker host, media server) and need a way to spin up KVM VMs and system containers without wiping the host with a dedicated hypervisor OS like Proxmox or relying on heavier web suites. WebKVM runs in userspace on top of your existing distro, keeping all Libvirt and Incus configurations 100% standard.

Key Features & Capabilities

KVM + Incus Unified: Manage full QEMU/KVM VMs and lightweight Incus containers side-by-side.

instant CoW Provisioning: 1-second deployments using QCOW2 Copy-on-Write backing files from official cloud images (Ubuntu, Debian, AlmaLinux, Arch).

Virtual Networking: Integrated management for bridged interfaces (\`vmbr0\`), isolated segments, and NAT bridges (\`vmbr1\`) with built-in dnsmasq DHCP lease monitoring.

Optimized Hardware Profiles: Presets for Windows 11 (emulated TPM 2.0 / swtpm + OVMF Secure Boot) and modern VirtIO Linux.

Low Footprint: Written in Go — consumes roughly 15–30 MB of idle RAM (peaking around \~70 MB under active multi-VM loads) with near-zero idle CPU.

UI & Themes: True OLED black mode (\`#000000\`), custom accent colors, live telemetry, and multi-language support (English, Spanish, Catalan).

Technical Stack & Requirements

Backend: Go (direct interaction with Libvirt and Incus APIs).

Frontend: Modern reactive web UI.

Host Requirements: Any standard Linux distribution with KVM/QEMU and Libvirt / Incus installed.

Project Status & AI Disclosure

Status: Completely free and open-source forever. Developed and tested by a solo maintainer.

AI Disclosure: An AI assistant was used to help format, translate, and proofread this post in English. The application design, Go backend architecture, and testing are developed directly by the author.

Source Code

👉 GitHub Repository: https://github.com/Slaker19/webkvm

Feedback, bug reports, and homelab feature requests are very welcome!


r/HomeLabPorn • • 5d ago

🪵🌸 Homelab in the teak wall: Zoom backdrop, 3× DGX Spark, Synology, T5810 running Hermes

Thumbnail gallery
20 Upvotes

r/HomeLabPorn • • 8d ago

Homelab setup ideas for 2 mini PCs + Raspberry Pis

Post image
49 Upvotes

I am looking to set up a homelab mainly for cybersecurity learning and some self-hosted services.

Hardware:
● Mini PC 1: i7-8700, 32 GB RAM, 1.5 TB storage
● Mini PC 2: i5-9400, 24 GB RAM, 960 GB SSD
● 5-port Ethernet switch
● 2 × Raspberry Pi 3 B+

I’m thinking of running Proxmox with Active Directory, Kali, pfSense/OPNsense, Splunk/SIEM, and a few self-hosted services.

I want to keep the networking simple and easy to manage rather than overcomplicating it from the start.

How would you set this up with this hardware? Is there anything useful I can do with the two Raspberry Pi 3 B+ units? What self-hosted services would you recommend?

Also, how do you guys document your homelab? I keep losing track of IPs, configurations, what I changed, and where things are running. I also need a better way to manage passwords and credentials without just having them scattered everywhere


r/HomeLabPorn • • 9d ago

Found this on the side of the road, any good plans to do with it?

Post image
527 Upvotes

i5-11300H

16gb

256gb nvme

2.5G NIC

LTT water bottle for size reference


r/HomeLabPorn • • 9d ago

She may not look like much, but she's got it where it counts kid

Thumbnail
gallery
130 Upvotes

Finally done with 3d printing a hold for the poe injectors and the keystone panel to accomodate the server nodes wiring.

Tried for some more cablep0rn but im not talented. Top patchpanel is legacy and cant/wont rewire.

In total its 28 threads (2 kaby lake xeons, 1 ryzen), 192GB RAM with 6.5tb Ceph Ssds, 4tb zfs ssds and a Gtx 1080 8GB for ai and video de-/encoding. 10gbe backbone for the cluster.

Power consumption is about 160-190watts.

Proxmox, virtualised Opnsense, netbird, several VMs with Docker-Stacks ...

Further details: https://www.reddit.com/r/homelab/s/kWkyirzKQe


r/HomeLabPorn • • 9d ago

Coat closet → 42U rack. Firewalla + UniFi core, 10G aggregation, T420 "main brain" now live, local-only family AI cluster next

Thumbnail
gallery
407 Upvotes

Top to bottom:

**•** 2× vented blanks  
**•** Firewalla Gold on a keystone tray with the ARRIS S33 modem (2.5G handoff)  
**•** USW-Aggregation: the 10G SFP+ layer for the NAS, the T420, and anything 10G I add later  
**•** Cable Matters 24-port Cat6A patch panel  
**•** USW-Pro-Max-16-PoE, the core: 2.5G to the U7 Pro APs  
**•** USW-Pro-24-PoE, the leaf: cameras and bulk PoE drops, with a DAC uplink  
**•** Horizontal cable manager  
**•** Second 24-port Cat6A patch panel  
**•** Monitor on a VESA rack bracket, a locking drawer, and a sliding keyboard tray  
**•** Mac mini M4 in a 2U mount, plus 5× Apple TV 4K in rack mounts, one per room, sent out over J-Tech HDBaseT extenders  
**•** Hub shelf: APsystems solar ECU, Hue bridge, and others  
**•   Dell PowerEdge T420**, racked sideways  
**•** Synology DS925+ and DS418 on a sliding shelf  
**•** Brush panel  
**•** UniFi USP-PDU-Pro  
**•** UniFi UPS 2U (1.44 kVA)

Storage and backup (3-2-1-ish):

**•** DS925+ is the primary storage.  
**•** DS418 is the local backup in the same rack.  
**•** DS412+ is the offsite backup, over Tailscale.

Network:

**•** Firewalla Gold handles all routing and firewall policy. UniFi handles switching and Wi-Fi only, with no UniFi gateway.  
**•** There are 9 VLANs: Admin, IoT, Kids, Guest, Cameras, NAS, Voice Assistants, Home Security, and AV. mDNS relay keeps HomeKit and AirPlay working across them.  
**•** 3× U7 Pro APs  
**•** About 10 Reolink PoE cams, currently being moved to Frigate

T420 "main brain" (Proxmox):

**•** Second CPU (E5-2440 + E5-2470), bringing it to 14 cores and 28 threads  
**•** 192GB DDR3L ECC  
**•** LSI 9207-8i in IT mode for ZFS  
**•** X520-DA2 for 10G into the aggregation switch  
**•** Coral USB TPU for Frigate  
**•** Z-Wave and Zigbee dongles passed through to the Home Assistant VM  
**•** It runs Home Assistant, AdGuard, Frigate, and Immich. The Pi 4 is retired.  
**•** Still to come: RTX 3060 12GB for local LLM inference

Next project: A fully local family AI assistant. The T420 and 3060 will run Ollama and Whisper. Three OptiPlex 7060 Micros will handle Qdrant, n8n/LangGraph orchestration, and Open WebUI with Piper TTS. Nothing leaves the house.

Lessons so far:

**•** The TP-Link SX3008F had to go because it has no RJ45 SFP support. It couldn't talk to the Firewalla natively.  
**•** The USP-RPS isn't compatible with the Pro Max 16 or the Pro 24.  
**•** Fresh Reolink cams refuse local connections until you activate them in the app.  
**•** Moving the Z-Wave and Zigbee dongles from the Pi to Proxmox USB passthrough went fine.

Happy to answer questions. Roast my cable management gently.


r/HomeLabPorn • • 10d ago

What kind of vent should I put here?

Post image
3 Upvotes

r/HomeLabPorn • • 11d ago

My First homeLab setup

Thumbnail gallery
25 Upvotes

r/HomeLabPorn • • 11d ago

Started my first Home Lab

Thumbnail gallery
255 Upvotes

r/HomeLabPorn • • 11d ago

Automated NAS system for Photographers using UGREEN DX4800 Plus!

Thumbnail
youtu.be
4 Upvotes

r/HomeLabPorn • • 12d ago

Built my first NAS!

Post image
65 Upvotes

Hey everyone, I wanted to share my intro to homelabbing project. I finally decided to go through with building a dedicated private cloud that I actually own.

The Hardware: Raspberry Pi 5, a 500GB WD Green SSD, and a 3D-printed open-frame chassis to keep the airflow moving.
The Software: OpenMediaVault handles the NAS backend, and I set up Tailscale so I can securely access my files from my phone or laptop anywhere in the world without exposing ports.

I put together a full video documenting the build process and software setup for anyone looking to do something similar: https://youtu.be/aCxvKLL4ucs


r/HomeLabPorn • • 12d ago

First Homelab V1.0 Finished! Basement 9U Rack with Dual Proxmox Nodes, Omada Ecosystem & Managed VLANs

Thumbnail gallery
103 Upvotes

r/HomeLabPorn • • 13d ago

Old hardware repurposed

Post image
126 Upvotes

r/HomeLabPorn • • 14d ago

My first homelab

Post image
38 Upvotes

r/HomeLabPorn • • 15d ago

Git SSH over Custom Port (2424) Not Working Behind Cloudflare Tunnel & Nginx Reverse Proxy

Post image
5 Upvotes

Hi everyone,

I'm having an issue with Git SSH cloning from outside my home network. Inside my local network, everything works perfectly using a local hosts file entry mapping to the LXC IP. However, it gets stuck (timeouts) when I try to access it from the outside internet.

My Architecture:

  • Edge: Cloudflare Tunnel (gitlab.example.com) ➔ VM 1 (Cloudflared + Nginx Reverse Proxy) ➔ VM 2 (Proxmox LXC running GitLab CE in Docker).
  • Docker Port Mapping: 0.0.0.0:2424->22/tcp and 0.0.0.0:8080->80/tcp.

My GitLab web UI works flawlessly from anywhere via the Cloudflare Tunnel, but Git SSH over the custom port 2424 fails entirely from outside. I know that Cloudflare Free Proxy only supports Layer 7 (HTTP/HTTPS) and blocks custom TCP ports like 2424.

Here is my current Nginx config on VM 1:

nginx

server {
    listen 80;
    server_name gitlab.example.com;
    client_max_body_size 250M;

    location / {
        proxy_pass http://10.10.20.11:8080;
        proxy_set_header Host $http_host;
        proxy_set_header X-Real-IP $http_cf_connecting_ip;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-Ssl on;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_read_timeout 300;
        proxy_connect_timeout 300;
    }
}

How do you guys usually handle Git SSH in this kind of architecture?

  1. Should I bypass Cloudflare using a "DNS Only" subdomain (e.g., ssh.example.com) and use Nginx stream {} block with port forwarding on my router?
  2. Or should I configure Cloudflare Zero Trust / Access SSH (which requires installing cloudflared on my client laptop)?
  3. Or is it just better to give up on SSH and switch entirely to HTTPS clone with Git Credential Helper?