[{"data":1,"prerenderedAt":189},["ShallowReactive",2],{"post-en-my-homelab":3},{"id":4,"title":5,"body":6,"date":174,"description":175,"draft":176,"extension":177,"meta":178,"navigation":179,"path":180,"readingTime":181,"seo":182,"stem":183,"tags":184,"translations":186,"__hash__":188},"enBlog\u002Fen\u002Fblog\u002Fmy-homelab.md","What I self-host at home",{"type":7,"value":8,"toc":160},"minimark",[9,13,17,20,31,34,37,45,48,51,59,62,65,73,76,79,87,90,93,96,104,107,110,118,121,124,138,141,145,148,151,154,157],[10,11,5],"h1",{"id":12},"what-i-self-host-at-home",[14,15,16],"p",{},"I host a good part of my services myself. Not out of principle. It's mostly a question of data. Working in IT and following the news on the subject, you grow fairly wary of where your files end up. I'd rather keep control than depend on a service that can shut down, change its pricing, or access what I store. And on the side, it's a good learning ground.",[14,18,19],{},"Here's what's running at home right now.",[21,22,24],"h2",{"id":23},"immich",[25,26,30],"a",{"href":27,"rel":28},"https:\u002F\u002Fgithub.com\u002Fimmich-app\u002Fimmich",[29],"nofollow","Immich",[14,32,33],{},"For photos. It's my Google Photos replacement. You get the same features: a timeline, face recognition, and a mobile app that automatically backs up the camera roll.",[14,35,36],{},"The point that matters to me is that face recognition and the machine learning run locally. No photo passes through an external server. The trade-off is that it's RAM-hungry, and the project moves fast: updates are frequent and it's worth reading the changelog before upgrading.",[21,38,40],{"id":39},"nextcloud",[25,41,44],{"href":42,"rel":43},"https:\u002F\u002Fgithub.com\u002Fnextcloud\u002Fserver",[29],"Nextcloud",[14,46,47],{},"For files. It's my personal Drive. I mainly use it to sync folders between my workstation and my phone, and to share links now and then.",[14,49,50],{},"It's a fairly heavy solution. The platform covers a huge range of use cases, calendar, contacts, office suite, of which I only use a small part. But for reliable file sync and storage, it does its job.",[21,52,54],{"id":53},"vaultwarden",[25,55,58],{"href":56,"rel":57},"https:\u002F\u002Fgithub.com\u002Fdani-garcia\u002Fvaultwarden",[29],"Vaultwarden",[14,60,61],{},"My password manager. It's a Rust reimplementation of Bitwarden, lighter than the official server, and compatible with every Bitwarden app and extension.",[14,63,64],{},"That one I recommend without hesitation. The memory footprint is minimal, it's stable, and I don't touch it once configured. The kind of service you end up forgetting about because it never causes any trouble.",[21,66,68],{"id":67},"movary",[25,69,72],{"href":70,"rel":71},"https:\u002F\u002Fgithub.com\u002Fleepeuker\u002Fmovary",[29],"Movary",[14,74,75],{},"For keeping the list of films I've watched. Nothing vital, but I forget what I've seen fast, and trying to recall a title two weeks later is a lost cause.",[14,77,78],{},"I log what I watch as I go, with dates and ratings. It's simple and does exactly what I want from a tracker: a record, without a social network layered on top.",[21,80,82],{"id":81},"paperless-ngx",[25,83,86],{"href":84,"rel":85},"https:\u002F\u002Fgithub.com\u002Fpaperless-ngx\u002Fpaperless-ngx",[29],"Paperless-ngx",[14,88,89],{},"For managing scans of my documents: invoices, administrative mail, all the paper that piles up. It runs OCR on each file and indexes the content, which lets me find any document through full-text search.",[14,91,92],{},"What I like is the automation with my scanner. When I scan a document, it's dropped on a network location. A Paperless worker watches that folder, picks up the file, processes it and files it automatically. Nothing to do by hand: the document lands straight in the library.",[14,94,95],{},"And since everything goes into the encrypted offsite backup, even if the house burns down I get all my paperwork back without trouble. It's the kind of scenario you never think about until it happens.",[21,97,99],{"id":98},"nginx-proxy-manager",[25,100,103],{"href":101,"rel":102},"https:\u002F\u002Fgithub.com\u002FNginxProxyManager\u002Fnginx-proxy-manager",[29],"Nginx Proxy Manager",[14,105,106],{},"This is the reverse proxy that exposes all of it. Each service has its own subdomain, and NPM handles routing to the right container and managing HTTPS certificates through Let's Encrypt, automatic renewal included.",[14,108,109],{},"The interface is graphical, which avoids editing Nginx configurations by hand. I add a domain, point it to the container, enable SSL, and it's live. To get started with a reverse proxy, it's the most approachable option.",[21,111,113],{"id":112},"wireguard",[25,114,117],{"href":115,"rel":116},"https:\u002F\u002Fgithub.com\u002FWireGuard",[29],"WireGuard",[14,119,120],{},"For reaching everything from outside without exposing the services directly on the internet. It's my personal VPN.",[14,122,123],{},"When I'm remote and want to open Immich or Nextcloud, I bring up the Wireguard tunnel and reach the local network as if I were home. The protocol is fast and light, noticeably more than older VPN solutions like OpenVPN.",[21,125,127,132,133],{"id":126},"grafana-and-prometheus",[25,128,131],{"href":129,"rel":130},"https:\u002F\u002Fgithub.com\u002Fgrafana\u002Fgrafana",[29],"Grafana"," and ",[25,134,137],{"href":135,"rel":136},"https:\u002F\u002Fgithub.com\u002Fprometheus\u002Fprometheus",[29],"Prometheus",[14,139,140],{},"To keep an eye on the machine. Prometheus collects the metrics (CPU, RAM, disk space, container health), and Grafana displays them in dashboards.",[21,142,144],{"id":143},"a-bit-of-the-setup","A bit of the setup",[14,146,147],{},"Nothing complex. Everything runs in Docker containers on a single machine, orchestrated with Docker Compose. Each service in its own container, with its volumes for data persistence.",[14,149,150],{},"Nginx Proxy Manager is the entry point. Wireguard handles remote access. The rest of the services stay on the internal network, without being directly exposed.",[14,152,153],{},"No cluster, no Kubernetes, no high availability. One machine, some containers, regular backups. That's enough for personal use, and it stays easy to diagnose when something breaks.",[14,155,156],{},"For backups, everything is sent to Infomaniak through their Swiss Backup offering, combined with Restic. Restic encrypts the data client-side before sending. So the files leave the machine already encrypted, and stay hosted in Switzerland.",[14,158,159],{},"It's not perfect and the configuration keeps evolving. But the infrastructure is mine, and that's what matters.",{"title":161,"searchDepth":162,"depth":162,"links":163},"",2,[164,165,166,167,168,169,170,171,173],{"id":23,"depth":162,"text":30},{"id":39,"depth":162,"text":44},{"id":53,"depth":162,"text":58},{"id":67,"depth":162,"text":72},{"id":81,"depth":162,"text":86},{"id":98,"depth":162,"text":103},{"id":112,"depth":162,"text":117},{"id":126,"depth":162,"text":172},"Grafana and Prometheus",{"id":143,"depth":162,"text":144},"2026-07-29","A tour of my homelab. The services I run, why, and how it's wired together.",false,"md",{},true,"\u002Fen\u002Fblog\u002Fmy-homelab",null,{"title":5,"description":175},"en\u002Fblog\u002Fmy-homelab",[185],"devops",{"fr":187},"mon-homelab","Ou3zMawL1V9Eq-VIbPRN9jtJDM_d5-y2kjRhfQScCM0",1785313134204]