01 Index
I host all of it myself.
Mail, chat, source control, storage, backups, this page. It runs on machines I own, reached through a small box at the edge that only ever dials outward. I taught myself, mostly by breaking things and then having to fix them.
- Role
- Systems engineer
- Works on
- Infrastructure, security, operations
- UNIX
- 11 yearsself-taught, still going
- Hosting
- 24 serviceson hardware I own
- Desktop
- HyprlandAurora Glass, the theme this page uses
02 Infrastructure
Everything here runs on hardware I own.
Nothing is rented except the address it answers on.
-
You open a hostname
Public DNS points at the edge box. It has never pointed at my house.
-
The edge terminates TLS
Traefik and Let's Encrypt. Anything private stops here for a login check.
-
A tunnel carries it home
WireGuard, dialled outbound. The router forwards nothing inward.
-
A container answers
Unprivileged user, own network, capabilities dropped.
-
The reply goes back the same way
Nothing on the home side was ever listening.
- Deploys
- Pulled from gitedit the box by hand and it gets overwritten
- Privileges
- One account per serviceno shell, no home directory, caps dropped
- Builds
- Nested container daemona bad commit gets a sandbox, not the host
- Storage
- Triple parity, encryptedthree drives can fail; offsite still owed
- Mine, end to endSPF, DKIM, DMARC, DANE, MTA-STS
03 Machines
Four boxes, three of them mine.
Two at home carry the load and the workstation sits on my desk. The fourth is rented and holds the public edge.
- OS
- Debian 13
- CPU
- Ryzen 9 3950X16 cores, 32 threads
- Memory
- 128 GB DDR4
- GPU
- RTX 4060, 8 GB
- Runs
- Every container, the game panel, local inference
- OS
- TrueNAS
- CPU
- Celeron N5105
- Pool
- 8 x 12 TB IronWolfRAIDZ3, about 50 TiB usable
- At rest
- AES-256-GCM
- Link
- Direct cable to compute
- OS
- Debian 13
- CPU
- 2 vCPU
- Memory
- 4 GB
- Runs
- The gatewayTLS, access control, tunnel
- Exposure
- The only public surface
- OS
- CachyOS
- CPU
- Ryzen 7 5700X
- GPU
- RTX 3090
- Desktop
- HyprlandAurora Glass
04 Stack
What I actually use.
Not a list of everything I have ever opened. These are the things that are running right now, or that I have shipped something real with.
- Orchestration
- Docker Compose Kubernetes k3s AKS ArgoCD KEDA CloudNativePG
- Edge and network
- Traefik Envoy Gateway Gateway API Linkerd WireGuard HAProxy Pi-hole Unbound
- Identity and security
- Keycloak OIDC Coraza ZAP SonarQube DefectDojo Vaultwarden
- Data
- PostgreSQL ZFS MinIO Redis
- Observability
- OpenTelemetry Prometheus Grafana Loki
05 Experience
Where the hours went.
Self-taught, self-reported, rounded down.
- UNIX and Linux
- 11 yr
- Docker and Compose
- 5 yr
- Game servers
- 10 yr
- Certificates and PKI
- 5 yr
- Network security
- 7 yr
- Enterprise infrastructure
- 3 yr
- Cybersecurity
- 6 yr
- ZFS
- 3 yr
- Kubernetes
- under a year
- Observability
- under a year
06 Contact
Say hello.
Homelab war stories, security questions, or nothing in particular. All fine. There is no form here, just addresses that reach me.
- contact@celyrian.com
- Matrix
- @celyrian:matrix.celyrian.comon a homeserver I run
- Discord
- ItzCelyrian
- Security
- .well-known/security.txtsigned, if you found something