Personal Proxmox VE homelab — documented as an operations practice, not a screenshot dump.
I run a single-node hypervisor at home with LXC-first workloads, reverse proxy, DNS, backups to Proxmox Backup Server, and runbooks that agents and I can follow. The private control plane lives elsewhere; this repo is the public-safe view for portfolio and hiring.
Portfolio: vastpakt.be
This is not only “servers online”. Most guests run applications I operate end-to-end:
- deploy / update / restart discipline
- DNS + reverse proxy so users can reach the app
- monitoring (“is the app path up?”)
- backups and restore thinking for data-bearing apps
- clear boundaries: what is critical vs lab
In other words: ICT application operations on a small private platform — the same mental model as application administration at work (keep the app usable, recoverable, and understood), just at home scale.
· Operator: ChristopheAI
| Piece | Role |
|---|---|
| Intel NUC (i7-10710U, 16 GB RAM, NVMe) | Proxmox VE host |
| Separate mini-PC | Proxmox Backup Server (PBS) |
| External HDD | Extra bulk storage / mounts for media & shares |
Exact firmware/IPs stay private.
| Role | Examples |
|---|---|
| Access & edge | Caddy reverse proxy, AdGuard Home (DNS), Tailscale |
| Reliability | Uptime Kuma, LibreNMS, pulse/monitoring CT |
| Personal data | Immich (photos), Samba shares, Vaultwarden |
| Knowledge / ops | Obsidian LiveSync (CouchDB), NetBox (scoped inventory), Mealie |
| Network | UniFi controller, LAN discovery |
| Lab / dev | ML/dev VM, automation sandbox, Windows lab VM (often stopped) |
Guest names and roles are documented without LAN addresses. See docs/services.md and docs/workload-inventory.md.
This lab is operated like a small production environment:
- Measure before changing — inventory and health from the host, not memory
- Runbooks over folklore — health checks, backup/restore, incident triage
- Agent-assisted ops — I use coding/ops agents with a private control plane (runbooks + rules); they read docs and propose checks, they don’t get free rein on red-sensitive services
- Public-safe by default — no credentials, no internal IPs, no raw secret-bearing config in this repo
Details: docs/operating-model.md
| Doc | Content |
|---|---|
docs/application-operations.md |
Application beheer on this platform |
docs/architecture.md |
Topology and design choices |
docs/services.md |
Service catalog by role and priority |
docs/workload-inventory.md |
Guest map (IDs/names, no IPs) |
docs/networking.md |
DNS, proxy, remote access principles |
docs/monitoring.md |
Observability and alerting intent |
docs/backup-restore.md |
PBS, criticality, restore drills |
docs/discovery-method.md |
How inventory is produced |
runbooks/ |
Health check, incident triage, monthly maintenance |
Proxmox VE · LXC · QEMU · PBS · Caddy · AdGuard · Tailscale · Immich · NetBox · Uptime Kuma · Linux · runbooks
Active. Public docs last refreshed 2026-07-15 from the live private control plane (sanitized). Inventory drifts; treat private host checks as source of truth for “what’s running right now”.
MIT — see LICENSE.