Skip to content

The philosophy

A homelab lives or dies by a few principles you commit to early. These matter most on a single box, and still hold when you split compute from storage.

Every service is a well-worn, widely-run tool. Every pattern is the documented one. Cleverness is what you’re decoding at 3am when the family can’t watch anything. Optimize for the future you who forgot how this works.

RAID is not a backup. A mirror keeps you running when a disk dies; it does nothing against a fat-fingered delete, a bad update, ransomware, or the house flooding. Those are what actually lose data.

So the order is: snapshots (free, local, instant undo) → a backup on separate mediaan offsite copy. Only then is a mirror worth adding, for uptime and bit-rot protection. If you can only do one thing, back up. See Storage & backups.

3. Default to consolidation, isolate on purpose

Section titled “3. Default to consolidation, isolate on purpose”

On one box, the instinct to give every service its own VM is expensive and pointless. Most things are just containers sharing the host. You isolate deliberately — for a real security boundary, for something that must stay up while the rest is down, or for heavy state you want to restore point-in-time — not by reflex. See LXC vs Docker.

4. What fixes a broken host can’t live on that host

Section titled “4. What fixes a broken host can’t live on that host”

DNS, the reverse proxy, the identity provider, your management tooling — the things you’d reach for when everything’s on fire — get extra isolation so a single bad compose up can’t take them out with everything else.

5. Private by default, public by exception

Section titled “5. Private by default, public by exception”

Nothing is exposed to the internet unless it has a reason to be. The baseline is a mesh VPN you can reach from anywhere. Public access, when needed, goes through a tunnel — so you never forward a port or reveal your home IP. See Networking.

Reverse proxy, DNS zones, auth clients, container definitions — all live as text/records you could recreate the whole lab from. Secrets are the one thing that doesn’t live in that text; they live in a secrets manager and get injected at runtime.

The tax of consolidation is shared blast radius — worst on a single box, smaller but still real when you split compute from storage (each box is still a failure domain of its own). So: don’t over-consolidate the critical plane, keep services independently restartable, and make sure each box coming back up cleanly is a thing you’ve actually tested. A homelab you’re afraid to reboot is already broken.


None of this is dogma. But every time this lab drifted from one of these rules, it bit back — usually at the worst time. Steal the ones that fit your situation.