Hey r/homelab! I wanted to share my setup. I’ve been running this for over a year now, and I’m incredibly happy with it. It’s a very simple, quiet hardware setup, but it does exactly what I need without breaking the bank on my electricity bill (pulls about 35W on average).
The Hardware:
- Host: Intel NUC 10 (NUC10i7)
- RAM: 16 GB
- Storage: 1TB NVMe (Internal) + 500GB External USB SSD dedicated purely to automated Proxmox backups.
- Networking: Standard ISP Router (Telekom Speedport) + a managed Netgear switch (used as unmanaged right now).
- Smart Home: Zigbee Coordinator (since all my smart devices are Zigbee, I don't need fancy Wi-Fi segregation).
The Software (Proxmox VE): I currently run about 31 guests, heavily favoring LXCs (28 LXCs and 3 VMs) to save resources.
- Local Services: Vaultwarden, Paperless-ngx, Home Assistant, Pi-hole, InfluxDB & Grafana (for extensive monitoring), and Immich (planned revival).
- Honeypots & Active Defense: I run a few network traps (like an SMB trap and a fake Bitcoin node). If any of these are tripped, they automatically trigger my AI agent, which then investigates the incident closely and takes appropriate countermeasures if necessary.
- Off-Site (VPS): A €2 VPS running Uptime Kuma, plus another VPS running a self-hosted Mailserver featuring a custom API that I can trigger from anywhere.
Networking & Zero Trust: This is where it gets fun. I don't use VLANs locally. Instead, my routing is strictly split:
- External Traffic: Goes through a Cloudflared Tunnel straight to Nginx on my server. I have absolutely ZERO open web ports on my router.
- Internal Traffic: I rely on Pi-hole for local DNS resolution and ad-blocking.
- Origin Protection & CrowdSec: Nginx strictly allows traffic only from the CF Tunnel and my Uptime Kuma VPS. I also use a clever Nginx trick (
map $http_cf_connecting_ip) to extract the real IP from Cloudflare for my CrowdSec logs without breaking my origin protection.
My AI Lab Assistant: Instead of just running standard services, I use an open-source AI agent framework, which I've set up as my Homelab co-pilot. It has SSH access to all LXCs, integrates with the Proxmox API, and uses a Telegram interface. It can perform security audits, monitor/restart failing services, and even deploy new containers.
A quick disclaimer: I am fully aware that giving an AI agent root access across my server and my VPS is an enormous security risk. I’ve tried my best to isolate and mitigate this risk wherever possible. However, the immense convenience, automation, and power it brings to my daily operations make it a tradeoff I am consciously willing to accept.
The Pros & Cons: I love the simplicity and the fact that the i7 easily handles the load with 16GB of RAM. However, I’m well aware of the tradeoffs:
- No High Availability: If the NUC dies, the lab is down. Thankfully, the external SSD backups mean I only lose uptime, not data.
- Limited Storage: 1TB will get tight once Immich is back in full swing.
- No GPU: Transcoding or heavy local AI tasks aren't really an option.
- No VLANs: A conscious choice for now due to Zigbee, but I know it's a homelab sin!
I'm perfectly fine with these compromises for now. Sometimes less really is more! Let me know what you think.
https://www.reddit.com/gallery/1w92wkx
Source: r/homelab · by /u/leofleischmann
