Production Grade Homelab #2: Ansible — No More SSH and Pray
After Prometheus showed me what was broken, I needed a way to fix 14 boxes without SSHing into each one. 7 Ansible roles, Gitea Actions CI, Jinja2 Caddyfile, and a Semaphore web UI.
Practical lessons on Azure architecture, IaC maturity, DevSecOps, internal developer platforms, Docker homelab builds, and team leadership.
After Prometheus showed me what was broken, I needed a way to fix 14 boxes without SSHing into each one. 7 Ansible roles, Gitea Actions CI, Jinja2 Caddyfile, and a Semaphore web UI.
After HA cluster incidents I couldn't detect fast enough, I built a full observability stack on a dedicated LXC: 18 scrape targets, custom dashboards, Telegram alerting, and Docker log aggregation.
How I added a second Proxmox node, set up a 3-vote cluster with QDevice, converted to ZFS, enabled replication, and achieved full HA for every service — including all the gotchas.
Plain text posts were holding back my portfolio. I built a custom Hermes skill that reads a post, identifies image slots, generates contextually relevant illustrations with Agnes AI, and embeds them after my approval.
AdGuard blocks ads but still forwards every query to Quad9 or Cloudflare. Here's how I replaced that with Unbound — a pure recursive resolver that queries root servers directly, with no upstream seeing your traffic.
Migrating the Hermes AI agent from a Windows laptop to a Proxmox VM — systemd services, Tailscale DNS pitfalls, Electron on RDP, and why VMs are the right home for always-on agents.
Moving Unraid to bare metal gave it direct SMART access for the first time — and the first disk scan immediately flagged a dying boot/cache SSD and a dying data disk simultaneously, with zero parity protection running.
How three converging pressures — data risk, idle drives, and a 4-bay ceiling — drove a calculated migration from a Synology DS416play to a Proxmox-hosted Unraid array on a QNAP TL-D800C DAS, with Telegram monitoring and ~100 MB/s sustained transfer speeds.
How I used Hermes Agent to build a verified knowledge base of my entire homelab, caught real undocumented drift via SSH, and now control Plex, arrstack, and n8n from a Telegram chat.
How I built a self-hosted Telegram bot that downloads videos at any quality using n8n, yt-dlp, and FastAPI — and the four n8n quirks that made it harder than expected.
Completing the VM100 decomposition: migrating Jellyfin, Scrypted, the full Arrstack, and Homepage into dedicated Proxmox LXCs — then decommissioning the monolith for good.
How I decomposed a monolith homelab VM into dedicated Proxmox LXCs for AdGuard Home, Caddy with Cloudflare Tunnels, and Plex with iGPU passthrough — plus hardening an Intel e1000e NIC that started dropping under load.
How I migrated a bare-metal homelab server to Proxmox using direct SSD passthrough, bypassing failed Clonezilla imaging. Covers dual-interface networking, jumbo frames, NFS automounts, automated backups, and the architecture strategy this unlocks.
How I replaced label-heavy Traefik and legacy Pi-hole workflows with native Caddy and AdGuard Home for cleaner config ownership, safer exposure, and faster operations.
How I replaced 1Password with a self-hosted Vaultwarden instance — zero subscription cost, full data ownership, nightly NAS backups, and seamless Bitwarden apps across every device.
How I eliminated password fatigue across 15+ self-hosted apps with Authentik SSO, Traefik forward-auth middleware, MFA, and external access via Cloudflare Tunnel.
A complete secrets lifecycle — automated redaction before commit, leak scanning gates, rehydration workflows, and rotation practices for every service.
How a Backstage-based internal developer portal reduced ad-hoc platform requests, improved service visibility, and recovered capacity for higher-value engineering work.
How I rebuild my entire homelab from a clean Ubuntu install using a Git-backed config repo, compose-based restore, and automated secret rehydration.
A deeper look at how platform teams encode security, compliance, cost, and self-service into the delivery path without slowing innovation down.
How to make AI genuinely useful for developers with grounded internal context, prompt patterns, review guardrails, and a practical reference architecture.
How I built a daily backup pipeline that syncs configs, redacts secrets, scans for leaks, and pushes sanitized snapshots to GitHub — automatically.
Running Traefik, Pi-hole, Plex, Arr stack, Immich, Home Assistant, and more on a single Ubuntu host with Docker Compose, internal TLS, and local DNS.
How to lead engineering teams through uncertainty with honesty, useful ownership, and enough protection to keep the work from dissolving into chaos.
Introduction to my Docker-based homelab running Traefik, Pi-hole, Plex, Arr stack, Immich, Home Assistant — with automated backups and disaster recovery.
How to make Backstage self-service real with software catalogs, golden-path templates, and developer workflows teams actually want to use.
Why I see AI as a capability amplifier for engineering teams: valuable for repetitive work, learned through practice, and still dependent on human judgment.
How to move from ad hoc server changes to rebuildable systems with config allowlists, dry-run restore workflows, and Git-backed anti-drift automation.
How platform teams reclaim engineering capacity by reducing KTLO drag through self-service, automation, guardrails, and pragmatic AI adoption.
Why moving frontend delivery to the edge can reduce idle infrastructure cost, improve global performance, and simplify release operations.
A practical framework from my AADA workshop for evaluating SaaS in automotive wholesale, from workflow fit and integrations to assurance and rollout.
How to automate dependency updates with Dependabot while keeping pull request volume, alert noise, and review overhead under control.
Why I used a disciplined Git Flow model, release branches, and conventional commits to reduce release friction without adding process theatre.
No posts match your search or filter.