Projects | Homelab, 3D Printing, Robotics & Infrastructure

Production Homelab Infrastructure

The Challenge

Build a self-hosted infrastructure that rivals small enterprise deployments while maintaining security, redundancy, and observability. Requirements: 99%+ uptime, isolated network segments, automated backups, real-time monitoring, and remote access without exposing inbound ports. All on commodity hardware and a home internet connection.

The Solution

Hypervisor Cluster: Proxmox VE 8 running a 2-node cluster with quorate consensus, enabling live VM migration and high availability for stateless services. Secondary node also runs a dedicated backup server for nightly incremental snapshots (3 full + 14 daily + 6 weekly + 3 monthly retention).

Storage & Redundancy: ZFS RAIDZ1 arrays (2 independent pools) with checksummed data protection, snapshots for near-instantaneous backups, and passthrough device access for VM-native storage pools. Designed for future consolidation to TrueNAS-based SAN.

Network Architecture: Fiber-to-the-home (FTTH) bypass with managed 2.5G/10G switching, eliminating ISP modem constraints. Custom firewall with default-deny packet filtering across 6 VLANs (servers, gaming, automation, personal, IoT, guest). Split-horizon DNS with internal-only mappings prevents topology leakage.

Security & Remote Access: Zero-trust tunneling with device trust model (no port-forwards, automatic failover) with secondary failover option. All traffic isolated by VLAN with explicit firewall rules. No services exposed to the internet.

Observability & Alerting: Prometheus time-series database (90-day retention) scraping node exporters, container metrics, and application-native instrumentation. Grafana dashboards (7 categories) with multi-channel alerting (email for critical, Telegram for informational). ~10 active alert rules with 4-hour repeat intervals to prevent alert fatigue.

Reverse Proxy & TLS: Nginx Proxy Manager with wildcard Let’s Encrypt certificate (via DNS-01 challenge). Works behind NAT with automatic renewal—no public port exposure needed.

Key Results

  • 99%+ uptime maintained across 11 guest VMs and backup server
  • Complete network isolation: Per-VLAN firewall rules eliminate lateral movement
  • Automated disaster recovery: Weekly verify jobs catch backup failures before they matter
  • Zero inbound exposure: All remote access via zero-trust tunnel; no public DNS leakage
  • Production-grade monitoring: Real-time visibility into all systems; actionable alerts
  • Fiber-speed network: 10G cluster backbone, 2.5G distribution, no ISP modem bottlenecks

Tech Stack

Virtualization: Proxmox VE 8, KVM/QEMU hypervisor
Storage: ZFS RAIDZ1, incremental backup server
Firewall/Router: OPNsense
Networking: Managed switches (2.5G/10G SFP+), RouterOS, split-horizon DNS (Unbound)
Remote Access: Zero-trust tunneling (primary), secondary tunnel (fallback)
Monitoring: Prometheus + Grafana
Reverse Proxy: Nginx Proxy Manager
Container Platform: Docker with Docker Compose
Operating System: Ubuntu 24.04 LTS (VMs), Proxmox-native Linux

Timeline

Initial build: 2021. Continuously optimized and expanded through 2026 with ongoing improvements to monitoring, security policies, and capacity planning.

Self-Hosted Media & Home Automation

The Challenge

Replace commercial media services with self-hosted alternative offering user isolation, multi-member support, and integrated download automation. Bonus: automate home systems without exposing critical infrastructure to the internet.

The Solution

Media Server: Self-hosted media platform deployed on dedicated Ubuntu VM with integrated download orchestration (tracker aggregation → media detection → automated fetching → library import). Per-user categorization and separate libraries for different household members with role-based access control via SSO federation.

Playback: Native mobile apps + web UI with remote playback routed through reverse proxy. VPN protection on download path for privacy compliance.

Home Automation: Home automation system on secondary hypervisor node (not primary) for resilience. MQTT messaging, camera protocol support, smart appliance control. Isolated VLAN with explicit firewall rules limiting access to trusted services only (prevents IoT lateral movement).

Identity & Access: SSO/SAML federation deployed for unified authentication, providing federated access across media service, orchestration platform, and other services.

Results

  • Eliminated commercial media subscription costs
  • Per-user libraries & preferences isolated
  • Automated download-to-library workflow (saves hours/week)
  • IoT devices firewalled from critical services
  • SSO reduces password fatigue + audit trail via federation

Tech Stack

Media: Open-source media server with H.264/H.265 encoding
Automation: Home automation hub, MQTT, device protocols
Identity: OIDC/SAML federation
Container Orchestration UI: Portainer (dual-host HA)
Networking: VLAN isolation, per-VLAN firewall rules
Platform: Docker Compose on Ubuntu VM

3D Printer Design & Manufacturing Optimization

The Challenge

Commercial 3D printers are slow and limited. Design and build custom high-performance printer from scratch, then apply the same approach in production environments to replace expensive outsourced plastic parts.

The Solution

Started with research into high-end printer architecture—stepper motors, control boards, leadscrew specifications. Designed custom mechanical systems using CAD software. Built 3 independent printers optimized for speed, quality, and reliability.

Applied 3D design expertise to eliminate expensive supplier dependencies: designed and printed custom tooling, brackets, and equipment components—many iteratively optimized through real-world testing and field feedback.

Results

  • $47,000+ in annual manufacturing savings via in-house 3D printing
  • One part: Reduced cost from $1,700 USD (supplier) to $76 CAD (printed)
  • 3 production-grade custom printers still in daily use
  • Eliminated 6+ week supplier lead times—now 1-2 day turnaround
  • CAD design skills enabled rapid R&D cycles for custom equipment

Tech Stack

Design: OnShape, Fusion 360 CAD
Hardware: Stepper motors, custom control boards, precision mechanical components
Skills Developed: Mechanical design, materials science, iterative optimization, CAD to production workflow

Robotics Systems Engineering & Operations

The Role

Robotics Specialist: 4+ years managing technical teams, R&D, troubleshooting, and deployment of complex robotics systems in production environments.

Key Achievements

  • Eliminated equipment downtime through preventive maintenance and rapid troubleshooting protocols
  • Custom cable solutions R&D: Designed and tested bespoke cables for legacy equipment interfaces (saving on expensive commercial alternatives)
  • Robotics maintenance & repair: Troubleshot complex systems from electrical to mechanical; maintained uptime across multiple units
  • Operator equipment innovation: R&D on new control interfaces and safety equipment
  • Network & systems management: Deployed custom computers for field operations; managed network and user privilege escalation
  • Team leadership: Delegated work assignments, mentored technicians, coordinated cross-functional projects
  • Technology advisory: Evaluated and recommended new tools and processes; drove adoption of beneficial innovations

Tech Stack

Robotics: Troubleshooting, repair, R&D design
Electrical: Soldering, custom cable solutions, hardware design
3D Printing: Custom parts design (OnShape, Fusion 360)
Systems Administration: Windows, Linux, network management
Soft Skills: Team leadership, work delegation, cross-functional coordination