HomeLab

Home > Projects > HomeLab
thumbnail
UbuntuBashDockerVPNNASNGINX

A personal server for self hosting various apps and services.

Geo-Distributed Home Lab & DevOps Sandbox

Personal Infrastructure & Systems Engineering Project

System Architecture & Overview

This project is a high-availability, geo-distributed home lab environment designed as an active sandbox for exploring DevOps methodologies, systems administration, and network architecture. Spanning multiple hardware nodes across geographically distinct locations in Toronto, the infrastructure utilizes high-density storage arrays, redundant storage methods, secure overlay mesh networks, and containerized application delivery. The environment serves as a resilient playground for testing enterprise-grade configuration management, secure reverse-proxy routing, and secure storage replication.


Key Technical Contributions

Hybrid Storage & Node Virtualization

  • TrueNAS SCALE Deployment: Provisioned and maintained a multi-node storage network utilizing TrueNAS SCALE as the base operating system, leveraging ZFS file systems for data integrity, dataset pool management, and redundant snapshots.

  • Bare-Metal & Hypervisor Administration: Configured local hardware nodes to optimize resource allocation, memory caching, and storage utilization across physically separated environments.

Geo-Distributed Networking & Access Security

  • Mesh VPN Overlay: Implemented a secure, peer-to-peer mesh VPN network to bridge geographically isolated nodes, establishing a unified, low-latency private local network (LAN) accessible from any external client.

  • Edge Routing & Ingress Management: Architected secure, public-facing entry points utilizing Cloudflare Tunnels to bypass CGNAT (Carrier-Grade NAT) and establish encrypted, port-forwardless web routing for self-hosted apps.

Containerization & Application Delivery

  • Containerized Microservices: Deployed and managed a suite of web applications and infrastructure services using Docker containers, optimizing resource footprints and ensuring isolated environments.

  • Reverse Proxy & Traffic Shaping: Structured traffic routing, SSL/TLS certificate automation, and local DNS resolution within the container network to ensure seamless internal and external application access.

DevOps Workflows & Continuous Testing

  • Infrastructure as Play: Leveraged the sandbox to manually simulate hardware failures, test network routing recovery, evaluate backup orchestration strategies, and validate new service rollouts prior to production deployment.
2026 — Built by Kyle Levy