9 ms·
State of Homelab 2026
- ceinewydd 6mo agoLooking forward to the follow up post, State of Bunker 2029.
- atlgator 6mo agoYou are doing more than I am (e.g. synchronized file storage, books, music), but I have radarr, sonarr, overseerr, plex, and supporting apps for movies and tv shows. Plex is available externally through its remote access feature. For the actual request system, I run OpenClaw with an Overseerr extension. This allows me to manage titles remotely via Telegram without any kind of tunnel or SSO. Simple and gets the job done for the solo-user scenario.
- nateberkopec 6mo agoFor secrets management, I basically just use fnox everywhere (https://fnox.jdx.dev/ https://fnox.jdx.dev/). It's a frontend to tons more options than sops, although `age` is still included. I also think the DX is better but to each their own.
- 8cvor6j844qw_d6 6mo agoLooks interesting, thanks for sharing. I am using SOPS, might be a good replacement.
- znnajdla 6mo agoI just use Infisical self hosted
- cassianoleal 6mo agoSeeing that fnox explicitly lists Infisical as a supported provider, I imagine they serve different purposes.
- imbus 6mo ago[dead]
- oofbaroomf 6mo agoSeems like it's down right now. I guess that's the "State of Homelab"? :)
- KomoD 6mo agoUp for me.
- jsphweid 6mo agoThis is not so much a fantasy about "being independent". Instead, it's a fantasy about being a sysadmin.
- hombre_fatal 6mo agoA good example of that is the guys on r/homelab explaining how they built a NAS so their wife could save her phone media without Google Photos. Man, paying Google/Apple $5/mo is surely a much better solution for her. And are you really doing 3-2-1 on that? Save the dicking around for your own stuff.
- dugite-code 6mo agoExcept with modern tooling it's not a huge task anymore to run these services. Cost wise on the right hardware it is very cheap to run, add the privacy/personal control aspect it's no wonder so many people do it.
- Gigachad 6mo agoSoftware wise I find stuff pretty easy to set and forget. It's hardware that's always been the issue for me. When your power or internet goes out, everything goes down. While you move property, every thing is down. Currently my server has developed an issue with randomly crashing and rebooting I haven't been able to resolve yet. Using a VPS entirely removes the hardware aspect, but it also mostly defeats the point of self hosting.
- anon7000 6mo agoI don’t think it defeats the point at all. Uploading photos to Google is a massive privacy concern. Apple is maybe better in that way, but very limited cross-platform support, and when I’ve tried it, poor performance & pricing. Neither do well at higher end photography either.
- Gigachad 6mo ago
- arjie 6mo agoCloudflare Tunnel is a wonderful thing. In fact, Cloudflare itself is fantastic for homelabbers because it gives you so much for free. I used to just host direct on my own home IP, but nowadays I find it easier to just `cloudflared`. Don't have to worry about the firewall and any breaches into my network and all of that stuff. I started from a similar place as you and then eventually now my IaaC for my homelab is just idempotent bash scripts written by Claude. The pattern I find with dependencies is that they have the property that someone wants to change some attribute and so the program needs to evolve for the attribute to be changeable. This means programs evolve to have many hinges and the interactions cause bugs one cannot reason about. My needs for the homelab are fairly simple and the script can encode all the information it needs. As a human, writing such a script is tedious. As a human with an AI assistant, I've found that this is so much easier to worry about because bash is a fairly stable target. Anyway, apart from that, I landed on using systemd's containers that use podman but otherwise not too different. My (far less polished) version of this post as a memory aid to myself: https://wiki.roshangeorge.dev/w/One_Quick_Way_To_Host_A_WebApp https://wiki.roshangeorge.dev/w/One_Quick_Way_To_Host_A_WebA...
- lorenzohess 6mo agoHow do you feel about the privacy implications of Cloudflare theoretically being able to read all your data? I guess this theoretical downside is outweighed by the practical upsides?
- 93n 6mo agoFWIW: Depending on your use case, Cloudflare doesn't have visibility into to cleartext. In my setup, I use their arbitrary TCP tunneling feature to tunnel SSH for a remote host, which works great. That said: I do also tunnel HTTP, and I've come to terms with the privacy risk. Being able to setup enforcement of things like mTLS at the edge is quite nice.
- arjie 6mo agoI don't have a homelab for privacy so much as convenience. And I accept the risk of trusting vendors. I also have a datacenter cabinet and the techs there have a key to the cabinet. That's even more dangerous access theoretically. I suppose if someone compromised cloudflared (more possible in this era of supply-chain attacks and Cloudflare's renewed commitment to vibe-coding) there's a risk. C'est la vie.
- willio58 6mo agoI recently did the math and was floored to see I’d be spending 1.3k per year on streaming alone. So I said screw it, bought a nas and 36 TB of hard drives and set up an arr stack. I cancelled all of our streaming subscriptions 2 months ago and it’s been the best decision I’ve ever made. Plus my whole family is doing the same from all around town. I’m saving my extended family on the order of 5-6k per year total. The nas is going to pay itself off in a few months, then it’s all savings from there. If only these media billionaires didn’t get so greedy, I would have happily kept paying them. Especially with Claude code, setting up something like this is basically just sitting down and prompting for a couple of hours. The emerging benefits are nice too. Like we don’t have to sift through junk of Netflix or Hulu to find stuff we would actually watch. All of it is stuff we would watch because we added it ourselves. Really fun!
- anon7000 6mo agoAnother huge benefit is you can actually get high-bitrate streaming. Ripping a 4k Blu-ray & streaming it from home (for those who may not want to sail the seas) is sooooo much higher quality than typical streaming.
- Gigachad 6mo agoIt is so sad how with the internet we have accepted terrible media quality. Instant messaging and social media reduces photos to 1MP and heavily compressed. It's fine for a photo or meme you are only looking at once and scrolling past. But if it's something you'd want to save, the quality is garbage. I'd honestly rather apps stop providing hosted media and just do the delivery, let me worry about backing up history. iMessage seems to be the only one sending things in full quality.
- watermelon0 6mo agoThe main difference is that iMessages count towards iCloud quota, whereas (most?) other messaging services have free storage.
- 6mo ago
- cadamsdotcom 6mo agoThere should be volunteer groups at local libraries running these services for their local communities. It’d be a great way for kids to learn to operate services and a great alternative for anyone who wants to use the fantastic open source stuff that’s out there but lacks expertise or time.
- bsder 6mo ago> There should be volunteer groups at local libraries running these services for their local communities. The problem with bespoke anything in computers is always the support. No one wants to be on the hook for customer support. I absolutely agree with them. There are a ton of "services" that exist solely to enable people to cut a check and say "Customer support is over there. Go talk to them and leave me alone."
- znnajdla 6mo agoIn Ukraine I have visited SaaS company offices serving production traffic with an actual bunker like this. Physically underground.
- AdrienPoupa 6mo agoThis is very cool, but you should not use Cloudflare Tunnels to stream media. This is forbidden by their terms of service (or at the very least not the intended use of Tunnels and they may disable your service). Use Wireguard or Tailscale instead. https://www.xda-developers.com/cloudflare-tunnels-are-great-but-never-use-them-for-media-streaming/ https://www.xda-developers.com/cloudflare-tunnels-are-great-...
- ZeWaka 6mo agoYep, I rent a $5 VPS in my region that I tailscale to for exactly that reason, as well as to un-CGNAT myself. For an easy GUI solution for the latter, highly recommend Nginx Proxy Manager.
- watermelon0 6mo agoCloudflare Tunnel publicly exposes your services, whereas Wireguard/Tailscale are VPNs. Tailscale (but not Headscale) offers Funnel, which is a reverse proxy, but you cannot use it with your own domain. Pangolin is the closest alternative to CF Tunnel, but self-hosted NetBird with reverse proxy functionality can also be used.
- oynqr 6mo agoThe intersection of people who can self host headscale or netbird and those who can not set up their own reverse proxy is probably the empty set.
- antihero 6mo agoCan tailscale funnel do custom domains yet? Personally I'm switching to rathole+traefik, weirdly something I was researching and experimenting with in the early hours of this morning (I have now not slept and have to go to work).
- ffsm8 6mo agoHaven't used it like that myself, but stumbled upon this last year https://tailscale.com/docs/concepts/domain-ownership https://tailscale.com/docs/concepts/domain-ownership This let's you use your own domain for your tailnet, isn't the funnel but - but isn't it even better? Unless you actually want a publicly routable domain name, then you're back some hosted ingress I guess
- oaiey 6mo agoSounds more like a state of the private download engine to me :)
- colordrops 6mo ago> I originally intended to try out the NixOS for the sake of reproducible builds and being able to store the configuration in a single place but got too lazy about it. Ironically once I got over the hump of learning NixOS, I can't imagine using anything else for declarative configuration. Too lazy to use a traditional system which requires custom wiring.
- MrLokans 6mo agoI'll definitely give it a try, somewhere in the future
- nodesocket 6mo agoI have a homelab with 4x Raspberry Pi 4's running Kubernetes a GMKtec Intel i5-12450H and a ProLiant ML350p Gen8 (which uses an ungodly amount of power). I'd add the following software/tools which have been awesome: - Portainer running on GMKtec & ProLiant - Dozzle (docker log viewer) on GMKtec & ProLiant - Beszel (server monitoring, awesome) all hosts - Kubetail (Kubernetes log viewer on Pi K8s) - HomeAssistant - Jellyfin - UptimeKuma (uptime and notifications) - Semaphore UI (ansible playbook runner) - Metabase (querying and visualization for dbs)
- mrmlz 6mo agoI've recently upgraded my ageing X8SIL Supermicro with an i5 to a X10 Sm board with a 2960 V4 14core Xeon... I was expecting a horrible power situation but it's less than 100w with a handful of spinning disks etc. I see lots of people complaining on power with their re-used ProLiant and others etc. Is it the throttling or bios settings that messes with the idle power? Or are you just running it at 100% and my low usage is what saves my electricity bill?
- nodesocket 6mo agoI'm at about 150 watts at idle with 2x Intel E5-2640 with 8x drives. I've gone through the BIOS pretty thoroughly and optimized as much as possible.
- mrmlz 6mo agoAh okay 150w is not _that_ bad - more than a rpi for sure but still :) And another cpu+chipset is always going to eat som Watts just by existing.
- SuperMouse 6mo agoFor me it's a Intel n100 box with Proxmox. Auto Updates (without auto reboot) fully activated). It just works. For accessing my home network I've rented a 1€-VPS that acts as a Wireguard connection hub.
- stefandesu 6mo agoCan you point us to the service that offers a 1€ VPS?
- SuperMouse 6mo agoIonos (VPS XS+) 1 Core with 512MB RAM combined with Wireguard easily shuffles a few GBit/s.
- BenjiWiebe 6mo agoI also used Ionos for quite a while as a wireguard endpoint to un-CGNAT myself. I think I paid a bit more than that but it was still really cheap.
- Hamuko 6mo agoProbably of interest to you: https://lowendbox.com/blog/1-vps-1-usd-vps-per-month/ https://lowendbox.com/blog/1-vps-1-usd-vps-per-month/
- import 6mo ago> There’s something appealing in that idea, being independent and prepared, a male fantasy likely never coming to life There’s still cloudflare in the middle of the everything and it doesn’t make it “independent”.
- lorenzohess 6mo agoHow do you feel about the privacy implications of Cloudflare theoretically being able to read all your data? I guess this theoretical downside is outweighed by the practical upsides?
- MrLokans 6mo agoYes, the convenience of being able to access your data everywhere is very hard to overcome. The largest downside is the reliability of the Cloudflare platform, as if it goes down, you'll have problems accessing any of the exposed services, and it has indeed been problematic some time ago, when they were down for an extended period of time. If I overcome my laziness, I'm going to invest a bit into Tailscale/WireGuard set-up, with some bastion host perhaps.
- tobi_bsf 6mo agoI will never get why the F people are putting all this stuff into the public internet vs just using tailscale.
- antihero 6mo agoIt is nice to download an app and then just point it at a public URL as opposed to having to rely on the device being in the same tailnet.
- s_ting765 6mo agoTailscale is an overkill solution. Opening ports 80 and 443 for a reverse proxy is enough security provided your apps don't have broken authentication. I've been doing this for years now.
- Hamuko 6mo agoValidating every single service I run on my home server for security (currently at 30 containers + other non-containerised random crap) vs. enabling the built-in Wireguard server on my router (which is more or less as simple as setting up Tailscale). I have a very different idea on which of these is overkill.
- s_ting765 6mo agoWhat makes you think simply throwing random crap on a home VPN network is secure? Tailscale/Wireguard is overkill because it is not needed where access controls work fine which is true for the majority of the popular self-hosted apps. And you now have to install a VPN client/cert on every device you want to access your services from. That's a major oof.
- fiend00 6mo agoAn external non-technical user needs to connect to your Jellyfin via their Smart TV (that doesn't have tailscale available to install), I guess.
- Floflox 6mo ago[dead]
- lukebaze 6mo agoThe support problem is real, but it's also solvable if you're not trying to support strangers. Ran Nomad + Consul for 50 services at my last place and the ops overhead was brutal until we stopped treating it like a public service. In practice, homelab stuff works great when it's just you or a small team that actually knows how to SSH into a box. Library volunteers handling production services for the community? That's a different animal entirely, fwiw.
- zihotki 6mo agoFor those who's looking into a good homelab servers - better look at the refurbrished/used mini-pc based on 5th gen of Intel, like i5 11500T (HP ProDesk 400 G5 Mini for example), or ryzen. You'll get better thermals, better CPU, more expansion slots for cheaper than you can get out of NUC. On top of that, resellers also often have upgrades for RAM and NVME available. WD-Red OEM 1Tb for less than 100 dollars sounds like bargain.
- theandrewbailey 6mo ago> 5th gen of Intel, like i5 11500T That's an 11th gen Intel Core CPU, not 5th.
- prmoustache 6mo agoAuthor seems to be mixing up homelab and selfhosting which are 2 different concepts. Self hosting is hosting services and data you actively use. While I don't seek 99.9999% of availability, this is not where I want to explore and break things on purpose. Homelab is en environment one use to learn and that is ready to be scratched/broken for the sake of learning. This is definitely not the place where I want to host my personnal services and files (or at least not as primary copy/endpoint).
- alexwelsh 6mo ago[dead]
- cybercatgurrl 6mo agoI was with you until you decided to gender your desires.