Public & private paths
Public website → Cloudflare Tunnel → Nginx → static files.
Tailscale provides private remote access.
Infrastructure / an ongoing project
A place to run useful services and understand what happens underneath them.
Public website → Cloudflare Tunnel → Nginx → static files.
Tailscale provides private remote access.
Proxmox runs VMs and LXCs. The Debian media VM owns media storage and runs Plex and Jellyfin.
The Pi keeps lightweight services separate from main-server maintenance.
Beszel for host metrics. Uptime Kuma for availability. Glances and Dozzle for investigation.
Compute & storage
Intel Core i5-7500 · 32 GB DDR4 · 1 GbE
Always-on network services
4 GB LPDDR4 · ARM Cortex-A72
Proxmox VE · Debian · Docker · Portainer · Nginx
Pi-hole · Unbound · Tailscale · Cloudflare Tunnel · NetAlertX
Beszel · Uptime Kuma · Glances · Dozzle
Plex · Jellyfin · Navidrome · Homepage · Filebrowser · IT-Tools · UpSnap · Arcane
Media storage moved from TrueNAS to Debian, alongside Plex and Jellyfin. Jellyfin uses read-only media mounts with separate configuration.
The published notes do not establish a complete backup schedule or restore-test history. Those details remain to be documented; read-only mounts are not backups.
The migration and its tradeoffs →Private addresses, internal hostnames, credentials, and admin endpoints stay out of public documentation. Service names describe roles, not an invitation to access them.
VM/LXC placement and per-service access rules are only shown where the existing documentation establishes them.
Why moving storage and media services to one Debian VM made my homelab simpler to operate.
Setting up Beszel as a lightweight, clean, node-based monitoring dashboard across Proxmox, Pi 4, and Windows.
Why adding a dedicated Raspberry Pi 4 Model B for 24/7 low-power DNS & services was the best upgrade for my homelab.