Multi-site homelab infrastructure, documented as production-style runbooks. I'm a Linux systems administrator and this is where I design, break, fix, and document infrastructure.
Everything here is real and running — three Proxmox hosts across two sites, ZFS storage on TrueNAS SCALE, OPNsense edge routing over XGS-PON fiber, automated verified backups, and a containerized service stack.
| Repo | What it is |
|---|---|
| homelab-automation | Runbooks and IaC - terraform and ansible configuration files |
| homelab-docs | Runbooks and design docs: storage, backup, networking, power, services |
| homelab | Sanitized configs: Docker Compose stacks, NUT, restic scripts, tooling |
flowchart TB
INET((Internet<br/>XGS-PON Fiber))
ONT[XGS-PON ONT-on-a-stick<br/>SFP+ module]
subgraph SW [MikroTik CRS310-8G+2S+ — RouterOS]
BW[bridge-WAN<br/>SFP+ cage + 1 port]
BL[bridge-LAN<br/>remaining ports]
end
subgraph WU [wu — Proxmox host, ODROID-H3]
FW[OPNsense VM<br/>Router / Firewall]
end
subgraph LAN [Local Network]
PH[Pi-hole DNS<br/>ODROID-XU4]
SW1[swearengen<br/>Proxmox Host + TrueNAS SCALE VM<br/>ZFS RAIDZ1 pool — PCIe SATA passthrough]
FARN[farnum<br/>Plex Media Server VM over NFS]
HA[Home Assistant VM]
end
subgraph REMOTE [Remote Site]
RPX[Remote Proxmox<br/>Pi-hole + LinuxGSM game server]
end
VPS[vps1<br/>Off-site restic backup target — SFTP]
INET --- ONT --- BW
BW ---|"wu NIC 1 → WAN vNIC"| FW
FW ---|"LAN vNIC → wu NIC 2"| BL
BL --- LAN
LAN -. WireGuard/SSH .- REMOTE
LAN -. restic over SFTP .- VPS
Traffic path: fiber terminates on the ONT SFP+ in the switch's isolated bridge-WAN, which hands off to a dedicated NIC on wu; the OPNsense VM routes/firewalls and sends LAN-bound traffic out a second NIC back into the switch's bridge-LAN — router-on-a-VM with a physical hairpin through the CRS310.
- Ansible fleet management — converting host configuration (baseline, NUT, restic, Docker hosts) to roles across all sites
- Monitoring modernization — Prometheus + Grafana + node_exporter fleet-wide
- Terraform — declarative provisioning for new Proxmox VMs going forward
- VLAN segmentation — flat L2 network redesigned into trust zones on the CRS310
- 30TB storage migration: mdadm RAID5 → TrueNAS SCALE / ZFS RAIDZ1 with PCIe SATA passthrough (runbook)
- SSHFS → NFS for all cross-host storage access
- Automated restic backups across all sites with 90-day retention and scheduled integrity verification
- PowerPanel (pwrstat) → NUT UPS monitoring conversion (in progress, one host complete)
- Early adopter of the XGS-PON ONT-on-a-stick guide (pon.wiki guide)
📫 https://linkedin.com/in/andy-alexander-linux · Ormond Beach, FL · open to remote systems roles