Skip to content

Hudater/homelab

Repository files navigation

Homelab

Resume Portfolio Infrastructure Status Links

Everything-as-Code private cloud. 2 OCI regions + on-premises Proxmox. Zero-trust access, identity-driven authorization.

k3s, OpenTofu, NetBird, Authentik, Traefik, OCI, Proxmox, Grafana, Loki, Prometheus Blog

Homelab Architecture


Architecture

Three regions connected over a NetBird WireGuard mesh. No self-hosted service is publicly reachable. All access goes through Traefik with Authentik forward authentication.

Region Role
OCI Mumbai Primary cloud region
OCI Zurich Secondary cloud region, DR and future CDN candidate
On-premises Noida Primary compute, Proxmox hypervisor and k3s cluster

The on-premises site runs two environments: prod (stable) and staging (testing), separated by VLANs. OPNsense handles firewall and inter-VLAN routing.

Full architecture writeup


Design Principles

  • Everything-as-Code: Infrastructure, DNS, identity, cluster config, and service definitions are managed via OpenTofu. No manual provisioning.
  • Zero-trust access: NetBird overlay + Traefik + Authentik Proxy Outpost. Nothing is reachable without passing auth.
  • Identity-first: Users sign in via Google OAuth through Authentik. A custom enrollment flow assigns group membership at sign-in time. JWT sync propagates groups to all services automatically. Humans and servers are managed as separate groups.
  • Incremental k8s migration: Core services run on Docker Compose today. Stateless workloads will move to the on-prem k3s cluster under ArgoCD.

Tech Stack

Layer Tech
Hypervisor Proxmox VE
Firewall / Routing OPNsense
Cloud Oracle Cloud Infrastructure (Mumbai + Zurich)
Container Orchestration k3s, 3 control plane + 3 worker nodes, on-prem
Provisioning OpenTofu + Terragrunt, remote state on HCP
Overlay Networking NetBird, WireGuard-based mesh
Reverse Proxy Traefik
Identity Authentik, Google OAuth + Proxy Outpost for forward auth
DNS Technitium, clustered
Monitoring & Observability Loki, Grafana, Prometheus, Alloy
Services Docker Compose, k3s migration ongoing
Domain Management Cloudflare, IaC managed

IaC Coverage

Component Tooling State CI
OCI Mumbai OpenTofu + Terragrunt HCP GitHub Actions
OCI Zurich OpenTofu + Terragrunt HCP GitHub Actions
Cloudflare DNS OpenTofu HCP GitHub Actions
Resume pipeline Cloudflare Workers + KV HCP GitHub Actions
k3s cluster OpenTofu + Ansible HCP None, ArgoCD planned
Core services (Authentik, NetBird, Technitium) OpenTofu HCP None
Docker Compose stacks Git-tracked None

Services

Zero-trust stack: NetBird + Traefik + Authentik. All services sit behind this.

Self-hosted AI: Ollama + Open WebUI, running on AMD RX 7600 GPU. Docker MCP Gateway integration planned.

Utilities: IT-Tools, Stirling PDF, Portainer & much more

Monitoring & Observability: Loki, Grafana, Prometheus, Alloy. Setup in progress.

WIP: Forgejo at git.hudater.dev


Repositories

Follows separation of concerns: infrastructure-iac for infrastructure, infrastructure-services for services.

Repository Status Responsibility
infrastructure-iac Active OpenTofu IaC for OCI regions, k3s cluster, and core services
infrastructure-services Active Docker Compose stacks and service manifests
infrastructure-ansible WIP, private Configuration management, post-IaC stabilization
resume-pipeline Active Cloudflare Workers + KV pipeline for resume.hudater.dev
archive-docs Archived Historical docs, live at archive-docs.hudater.dev

Contact

harshit@hudater.dev

About

This project started in 2021 with some basic compose files and a raspberry pi. Now it has scaled to 3 regions, multiple machines running k3s, docker compose and bare metal workloads. This repo features architecture and documentation for my hybrid homelab platform serving as a single point of showcase

Topics

Resources

License

Stars

0 stars

Watchers

0 watching

Forks

Releases

No releases published

Packages

 
 
 

Contributors