HOMELAB//FIELD NOTES
// multi-node proxmox · unifi · truenas · n8n

Homelab systems that are actually running, not sketched.

Everything here came out of one real lab — three Proxmox nodes, UniFi networking, TrueNAS storage, Pi-hole, Prometheus. The failures are documented too. If a kit ships, it is because it runs on this hardware, and the incidents that produced it are written down instead of hidden.

Kits

Download once, files are yours. No subscription, no account, no update treadmill.

Starter kit

The Agent-Run Homelab

$39 $59

The topology, the agent-integration pattern and its guardrails, a working monitoring stack, backup and security practice, and a pitfalls chapter where every entry is a real incident.

  • 6 documents — pattern, agent integration, monitoring, storage, pitfalls
  • 4 importable n8n workflows, tested
  • Prometheus/Grafana compose + alert rules worth the noise
  • Secret scanner + doc sanitizer with a publish gate (MIT)
Get the kit
Automation

Self-Hosted Ops Pack

$29

Four n8n workflows for people who run their own servers and are tired of being the only alerting system in the house.

  • Uptime check → Telegram alert, silent when healthy
  • Nightly health digest across hosts
  • Backup-freshness verification — the one with real payoff
  • Pi-hole weekly DNS report
Get the pack
New

Auto-Rip Pipeline Kit

$29

Drop in a DVD or CD, walk away. An unattended ripper that classifies the disc, rips to a staging area, then refuses to file anything until a human confirms the title — because disc labels lie and MusicBrainz mis-matches.

  • udev + systemd trigger on disc insert, ejects when done
  • TV-vs-movie detection that survives decoy padding titles
  • Audio CD → FLAC via abcde with the flags that actually work
  • Manifest-driven confirm-before-filing gate + bulk approve
  • The 13 gotchas that cost us evenings, written up
Get the kit
Network

UniFi Network Pack

$39

VLAN and firewall-zone design that quarantines the things you do not trust, plus the UniFi API recipes that took an hour each to get right.

  • Zone-based isolation model with an access matrix
  • Why IoT and untrusted hosts never touch your main VLAN
  • The two-key-store trap that wastes an hour every time
  • Verified Integration-API recipes: DNS records, client policy
  • Dual-WAN failover and a WAN-IP change logger
Get the pack
Security

Homelab Security Hardening Pack

$29

The audit we ran on our own lab, method and findings included — the parts that were inconsistent across nodes, the device-passthrough bug class, and how to contain the smart devices you cannot trust.

  • A repeatable host-hardening checklist per node
  • Firewall drift: catching config that diverged per host
  • The passthrough bug class that quietly breaks device access
  • Smart-device quarantine: block telemetry, keep the function
  • How to verify the hardening actually stuck
Get the pack

Services

When you would rather it were done for you. Scoped and quoted before anything starts — no open-ended billing, and we say plainly when something is out of scope.

Audit

Homelab & Network Security Audit

from $149

A review of your network edge, VLAN isolation, exposed services and host configuration, delivered as a severity-rated report with concrete fixes. If your setup is clean, you get a short report saying so rather than padding.

Request a quote
Network

UniFi Build-out & VLAN Design

from $249

Design and implement segmented VLANs with firewall zones, so guest, IoT and lab traffic cannot reach what matters. Includes a documented access matrix and the API automation to keep DNS records in sync.

Request a quote
Automation

Custom n8n / Python Automation

from $99

You describe the repetitive thing; we build it, test it against real failure cases, and hand over something documented enough to maintain. Monitoring, backups, scraping, glue between services that have no business talking to each other.

Request a quote

Proof

Three things that actually happened here. Each one cost an evening — the kits are what they bought.

A backup mount sat dead for 11 days

The share was served by a VM on the same node, the mount raced its startup, and systemd recorded it failed once and never retried. Every service kept writing to the empty folder underneath. The fix is four fstab options — the lesson is that nothing told us.

A node dropped out of the cluster and refused SSH

Root had been remounted read-only at boot because the fstab entry for / was missing. Nothing about it looked like a disk or network fault. There is a diagnostic checklist now.

A container could read a share but not write to it

Container root maps to an unprivileged host UID, so the host-side mount was owned by the wrong user. The fix is a UID pair in the mount options — and a way to prove it survived a reboot.

Free: Uptime → Telegram alert

One of the four ops workflows, free. It checks a URL every five minutes and messages you when it is down — and stays completely silent while things are healthy. Import it, and if it earns its place, the other three are in the pack.

Download free