I built this homelab as a working environment for personal projects and operational practice, not a static demo. After running a larger cluster for a period, I simplified the current service layer to Docker Compose on a dedicated guest. Proxmox hosts the guests, with DNS, ingress, TLS, version control, monitoring, backups, and documented recovery procedures around them. Internal details are intentionally abstracted here.
Challenges
Keeping a useful personal service environment manageable rather than maintaining infrastructure for its own sake.
Providing TLS for LAN-only services without opening inbound public access.
Making backup scope, restore steps, and operational health visible instead of assuming containers will always restart cleanly.
Approach
Consolidated the service layer into Docker Compose on a dedicated Proxmox guest after retiring the earlier cluster.
Used internal DNS and Traefik with DNS-01 certificates for LAN-only HTTPS services.
Kept service definitions and runbooks in version control, with SOPS-encrypted configuration for secrets.
Set up local and offsite application backups with isolated restore checks, plus lightweight health checks and outbound alerts.
Outcomes
A functioning self-hosted environment with documented service operations and recovery procedures.
A simpler current architecture after testing a more complex cluster and deciding it was not needed for this workload.
Verified application-level backup restores; whole-guest and separate-machine recovery remain distinct open work.