Current shape

Designed for clarity, recoverability, and controlled access.

The lab brings together storage, identity, internal DNS, media services, automation, public web hosting, and documentation. Most services are private by default, with public endpoints treated as deliberate exceptions.

Primary storage

Balayang

Synology DS923+ providing NAS storage, backups, containers, and virtualisation.

Backup storage

Tiddilik

Secondary Synology used for backup targets and certificate deployment.

Compute

Proxfox

Proxmox cluster services, LXC workloads, DNS, Plex, Paperless, and NPM.

Access

Tailscale + Kanidm

Identity-aware remote access with OIDC-backed login and private service routing.

Network

Simple zones, explicit boundaries.

The network is organised around internal clients, IoT devices, service infrastructure, and clustered compute. DNS is handled internally with AdGuard Home, while reverse proxying and TLS termination are kept deliberately visible and documented.

Core zones

  • Internal: trusted household and admin devices
  • IoT: smart home and appliance devices
  • DMZ / Services: internally hosted service endpoints
  • Cluster: Proxmox and supporting compute workloads

Service catalogue

Document the service before relying on the service.

Service
Role
Exposure
Status
AdGuard Home
Internal DNS and filtering
Private
Stable
Nginx Proxy Manager
Reverse proxy and TLS routing
Private / selected public
Active
Kanidm
Identity and OIDC
Private
Active
Plex
Media service
Private / invited users
Active
Paperless
Document management
Private
Document

Runbooks

Operational notes for when memory is not enough.

This static site is intentionally low-dependency. It should remain accessible during partial outages and useful during rebuilds, migrations, and security reviews.