Homelab

There is no cloud. It's a Dell workstation in a spare room.

A mid-2026 state-of-the-homelab. One Xeon running Proxmox, a Raspberry Pi, a bare-metal ESXi box, and twelve devices stitched together with Tailscale: what runs, what it costs, and the single point of failure I keep choosing on purpose.

One workstation, opened up to reveal an entire datacenter nested inside it.

Everything I have written about on this site runs on a computer sitting on a shelf in a spare room. This journal, the agents I have described, the publishing machine that embarrassed itself for fourteen weeks: none of it is in a cloud. It is a Dell workstation and a Raspberry Pi and a handful of other boxes, none of them younger than a few years, all of them in my house.

People like to say there is no cloud, only someone else's computer. Mine is a Xeon workstation I can hear from the next room. This is a mid-2026 state-of-the-homelab: what actually runs, how it is wired, what it costs, and the one design decision I keep making that I probably should not.

The one box that is secretly everything

The center of it is a Dell Precision 7920, a workstation from the Skylake era running a single Xeon Gold 6148 — twenty cores of 2017-vintage silicon that shipped for servers and ended up under a desk in my house. It runs Proxmox, and Proxmox runs a rotating cast of virtual machines. That is the whole 'datacenter'. One tower.

The machine that most of my public life runs on is itself just one of those VMs: twenty virtual cores, 22 gigabytes of RAM, Ubuntu 24.04, a 489-gigabyte disk that is 51 percent full and climbing. It has been up for five days as I write this, which is the honest number — I reboot it more than a serious operator would, almost always because I broke something myself.

On that single VM, right now:

There is no wall between 'production' and 'playground' here, because there is nobody to enforce one but me. This journal's build pipeline lives a few directories over from a fantasy-football simulator and a personal AI assistant, and all of them read and write to the same 489 gigabytes.

The satellites

Around the one big box are the smaller ones, each doing a job the workstation should not:

Nothing is rack-mounted. There is no rack. It is shelves, a spare room, and a longer power strip than I would like to admit to.

The nervous system is Tailscale, and nothing faces the internet

Twelve devices are on the tailnet: six Linux boxes, two Windows machines, two Macs, and two iPhones. Tailscale is what turns a pile of unrelated hardware into something that behaves like a single flat network, and it is what enforces the most important rule in the entire setup.

Nothing here is exposed to the public internet. No port forwards on the router, no reverse proxy aimed at the world, no dynamic-DNS hostname you could discover and knock on. Every service binds to the tailnet and nowhere else. If you are not on my Tailscale network, none of these machines exist: the ports do not answer, because there is no path to them to answer on.

That is the best security decision in the whole lab, and it was close to free. The attack surface from the open internet is not small, it is zero — not because I hardened three dozen services one by one, but because I never gave the internet a way in at all. The sites that are genuinely public, this journal among them, are pushed outward to a hosting provider. The homelab stays dark and just builds them. The lab is where things are made; it is not where they are served.

A cluster of small machines under a translucent protective dome; an incoming arrow is deflected off the dome while a single line exits to one separate machine.
One Proxmox host and its VMs, a Pi, an ESXi box, and two NUCs, all bound to the tailnet with nothing listening on the public internet. The only thing that crosses the boundary is an outbound deploy to the host that serves the public sites.

The day job followed me home

I work on enterprise virtualization for a living, so of course there is a virtualization lab running inside the virtualization host. Nested on the Proxmox box is a real, if small, VMware Cloud Foundation environment: vCenter 9.1, ESXi 9.1 nodes, and a Kubernetes layer on top. Running the enterprise stack on hardware it was never blessed for is the fastest way I know to learn exactly where its edges are.

The Xeon 6148 is Skylake-SP, and the 9.0 release of the platform dropped support for it, so on that hardware it is 9.1.x or nothing — a constraint you only ever discover by walking straight into it. There is an Intel VMD storage-controller setting that will hide every disk from the installer if you leave it in the wrong state. Storage tiering expects NVMe with sustained write endurance that consumer drives simply do not have, so a perfectly healthy-looking drive gets disqualified against a spec you did not know you were being graded on. None of that is in the glossy documentation. All of it is in my lab notes now.

What it costs, honestly

The homelab photos online never show the electricity bill. A 2017 Xeon workstation draws real power and dumps real heat into a room that was not built to absorb it, and the storage runs warm enough that I think about airflow more than I ever expected to. It is not free and it is not silent.

And there is a structural problem I have simply decided to live with: nearly all of it depends on that one workstation. If the 7920 dies, it does not take down one thing. It takes down the journal, the agents, the media server, the VMware lab, and the reason the twelve-device network exists at all, in the same instant. The satellites would survive. The thing they orbit would not.

Real redundancy — a second host, shared storage, automatic failover — costs more than this entire lab is worth to me, so I keep choosing the single point of failure on purpose. I take backups, and I accept the risk. Every homelab is a negotiation between what you would build with someone else's money and what you will actually pay for with your own. This is where I settled.

For the record, a couple of the VMs run workloads I do not write about publicly. Every homelab has a drawer it does not open for guests. Mine is no exception, and that is the last I will say about it.

The honest read

The homelab is not the project. It is the substrate underneath all the other projects. The publishing machine needed somewhere to run its timers. The agents needed somewhere to live between the times I talk to them. The memory folder they share needed a disk to sit on. This is that somewhere: one aging workstation, a Pi doing the steady unglamorous work, a few satellites, and a standing promise that none of it touches the open internet.

Which leaves me staring at the same shape I keep finding in everything I build. The publishing machine could produce but never learned to judge. The memory folder could remember but never learned to forget. And the homelab will run almost anything I hand it, on hardware with no redundancy underneath it at all — the most production-critical thing I own is also the least protected. I keep building the capability and skipping the safety net. At least this time I know exactly which box to carry out first if the room ever fills with smoke.

References

The memo

Get the memo before it becomes consensus.

One sharp memo on sports AI, media rights, athlete data, scouting systems, or sports business. No generic roundup.

Or follow on X: @TheFieldSignal