Go to file
2026-07-15 08:27:17 +00:00
.devcontainer Add genisoimage package 2026-07-14 03:35:44 +00:00
ansible Deploy initial playbook 2026-07-15 07:49:29 +00:00
docs Initialize first instance of README and its secondary contents 2026-07-15 08:22:09 +00:00
hamster First instance of hampter website (for fun) 2026-07-15 07:51:26 +00:00
portal First instance of hampter website (for fun) 2026-07-15 07:51:26 +00:00
terraform Add #cloud-config at the top 2026-07-14 05:51:18 +00:00
.gitignore Update .gitignore 2026-07-15 07:51:12 +00:00
README.md Fix mermaid graph and some typos 2026-07-15 08:27:17 +00:00

Enterprise Hybrid IaC Homelab: Version 2 🚀

THis is my Homelab Version 2. This project is an advanced, expanded, and more secure iteration of the private cloud architecture first built in Homelab v1.

Version 2 upgrades the OS baseline, scales the virtual infrastructure from 3 to 5 virtual machines, shifts from experimental Podman Quadlets to robust system-level sytemd service wrappers, and introduces secure, zero-config WAN networking (Cloudflare Tunnels & Playit.gg) to bypass local NAT limitations.


1. What's New in Version 2? (V1 vs V2 Comparison)

Engineering Metric Homelab V1 Homelab V2 (Current Project)
Control Laptop OS Nobara Linux Bazzite (Atomic/Immutable Fedora-based OS)
Physical Host OS RHEL 10 AlmaLinux 10 (Network Bridge br0)
VM Capacity 3 Virtual Machines 5 Virtual Machines (Scaled & Isolated workloads)
Container Engine User-level Podman Quadlets System-level systemd Podman wrappers (compatible with Debian 12 Podman 4.3.1)
Identity Management None (Local files/User lists) FreeIPA Identity Manager (freeipa.lab.local)
Web Reverse Proxy Local Nginx bindings Cloudflare Zero Trust Tunnel (--net=host container)
Game Server Hosting None Minecraft & Palworld Dedicated VMs router port-forwarding
Shared Storage None Rclone FUSE Google Drive Mount (user_allow_other enabled)

2. Infrastructure Architecture

This lab runs on a dedicated physical BOSGAME PC acting as our baremetal KVM hypervisor. The VMs are bridged directly to the local LAN, allowing them to act as first-class network devices.

graph TD
    Laptop["Laptop: Bazzite OS"] -->|SSH / IaC Control| Hypervisor["Hypervisor Host: AlmaLinux 10"]

    subgraph Host ["Hypervisor Host (172.30.1.200)"]
        Bridge["Physical Bridge: br0"]
        KVM["KVM / QEMU Hypervisor"]
        Cloudflared["cloudflared container (--net=host)"]

        Bridge --- Cloudflared
        Bridge --- VM1["freeipa (172.30.1.85)"]
        Bridge --- VM2["portfolio (172.30.1.93)"]
        Bridge --- VM3["minecraft (172.30.1.91)"]
        Bridge --- VM4["palworld (172.30.1.90)"]
        Bridge --- VM5["navidrome (172.30.1.92)"]
    end

    subgraph Cloudflare ["Cloudflare Edge (WAN)"]
        CF_Edge["Cloudflare Proxy"]
        CF_Edge -->|Secure Tunnel| Cloudflared
        CF_Edge -->|portfolio.shooey.xyz| VM2
        CF_Edge -->|hampter.shooey.xyz| VM2
        CF_Edge -->|ipa.shooey.xyz| VM1
    end

    subgraph Playit ["Playit.gg Edge (WAN)"]
        Playit_Edge["Playit Relays"]
        Playit_Edge -->|UDP Tunnel| VM4
        Playit_Edge -->|TCP Tunnel| VM3
    end

3. Project Documentation Directory

To keep the project clean, the documentation is modularized as below: