Skip to content
Édouard Maigné
All projects

Home infrastructure

A second-hand server turned into a full infrastructure, with virtualisation, containers, redundant storage and secure remote access.

  • Infrastructure & networking
  • Cybersecurity

Context

I wanted a learning ground that looks like real infrastructure rather than isolated lab exercises: storage, virtualisation, services and remote access. The starting point was a second-hand Xeon D-1521 server with 64 GB of RAM and 17 TB of disks, bought for €350.

What I did

  • Proxmox as the foundation, isolating each service in its own virtual machine and spinning up new ones on demand for testing.
  • Synology DSM 7 in a virtual machine, on physical disks taken away from Proxmox and dedicated to it, in SHR RAID: RAID 5-level protection without wasting space on disks of different sizes.
  • Docker and Portainer to deploy services, and Homarr as a home page, with authentication, automatic discovery and lightweight monitoring.
  • WireGuard for remote access.
  • Then controlled exposure: DynDNS at OVH to track the changing public IP address, Nginx Proxy Manager as a reverse proxy, and Authelia to enforce strong authentication in front of the services.

The result

Infrastructure I use every day and document (33 pages for the first part), with its weaknesses identified and their fixes planned.

What I took away

Exposing a service means accepting that the whole internet will knock on the door. I learned to spot those risks myself, such as a VPN admin page open to the whole network or services with no authentication, and to fix them before opening up further.