Skip to content
SELF-HOSTED

The self-hosting stack I actually use in 2026

The full map of what runs in my closet: Proxmox, Tailscale, Docker, Home Assistant, Immich, Jellyfin, Borg, and the decisions behind each one. This is the reference post every future essay on this site links back to.

published
author
read
8 min (~1,724 words)
Server rack in a home office with cables and amber indicator LEDs
0%

Every homelab essay is really a fight with a closet. Mine is a narrow one, off the hallway of a fourteenth-floor apartment, next to the water heater. It holds a single 8U open-frame rack, two fans that I swapped out after the stock ones started sounding like an angry hair-dryer at three in the morning, a UPS that has saved me twice, and cables I keep meaning to re-run but probably won't until something forces my hand.

This essay is the map for everything else I'll write on this site. It's the stack I actually run today — not the one I'd describe in an interview. Version numbers are what's installed right now. Every piece of software on this page is running in that closet as I write. Future posts will drill into individual layers; this one is the index.

The rig

One host does most of the work. I tried the three-node cluster thing in 2023, decided I was babysitting consensus protocols instead of watching movies, and consolidated to a single beefy machine with a clear backup story. It turns out "high availability" matters less when your users are "me, my partner, and occasionally my father-in-law looking at old photos."

  • Main host — Minisforum MS-01, Core i9-13900H, 64 GB DDR5, 2 × 2 TB NVMe in ZFS mirror, 1 × 8 TB SATA SSD for bulk media. Draws about 35 W idle, 70 W under compile load. Cost ~$1,100 new, which is about one month of what three Vultr instances of equivalent spec cost.
  • NAS — a separate Jonsbo N2 with 4 × 8 TB Exos drives in a ZFS RAIDZ1. Runs TrueNAS Scale, acts as the cold-ish bulk tier and target for every backup.
  • Edge — a GL.iNet Flint 2 running OpenWrt for the LAN, an ISP box I still can't fully tame, and a Unifi U6-Pro AP upstairs because the ISP wifi is a tragedy.
  • UPS — a CyberPower CP1500AVRLCD. Ten minutes of runtime on the current load, which is more than enough for Proxmox to notice the power event and gracefully shut the guests down.

That's it. No rack-mount servers, no screaming 1U fans, no separate compute/storage/GPU boxes. One machine that does compute, one machine that holds bytes, and a router that keeps both from burning down.

Hypervisor: Proxmox, and why I stopped fighting it

Proxmox 8.2 is the layer everything else sits on. I spent two weekends in 2022 trying to like ESXi, then Broadcom happened, and I haven't looked back.

Two things make Proxmox quietly excellent for home use:

  1. LXC is a first-class citizen. Full VMs are there when I need them, but I default to LXC containers for anything that's going to live long-term — Home Assistant, Tailscale, Traefik, the Jellyfin server. LXC boots in under a second, consumes <100 MB overhead, and snapshots behave like git tags. Docker gets containers that talk to each other. LXC gets me containers that feel like separate machines.
  2. PVE snapshots + ZFS is the best cheap time machine I've ever used. Before I upgrade anything, zfs snapshot rpool/data/subvol-xxx@before-upgrade. After: if it works, I zfs destroy the snapshot. If it doesn't, zfs rollback and the whole container is back in thirty seconds. I have broken Home Assistant and Jellyfin updates this way more times than I care to admit, and recovered each time without touching a keyboard.

I'll cover the full Proxmox-vs-ESXi decision in a dedicated post under Virtualization.

Networking: Tailscale does the job pfSense didn't

I ran pfSense for years. It was fine. Then I started working from more places and wanted friction-free access to my services without opening a single port on the ISP router. Tailscale 1.70 replaced my VPN in a single afternoon and I haven't touched it since.

What I like:

  • No port forwards. The ISP box doesn't even know the services exist.
  • MagicDNS. http://home-assistant.tail-XXXX.ts.net just resolves everywhere I'm signed in.
  • Subnet router mode. A tiny LXC container running tailscale up --advertise-routes=10.0.0.0/24 means I can reach every local device — TVs, printers, the UPS's web UI — from anywhere, without installing Tailscale on those devices.
  • ACLs in JSON. My laptop can reach *:*, my mother-in-law's phone can reach jellyfin.tail-XXXX.ts.net:443 and nothing else.

Tailscale isn't the endgame for everyone. If you need hundreds of nodes or strict on-prem-only compliance, look at Headscale or WireGuard directly. For a household, it's the fastest possible path from "I want to watch my movies on vacation" to "it works."

More on the exact subnet-router build and ACL policy is coming under Networking.

Containers: Docker first, Podman sometimes

I run Docker 27 with Compose V2 for 90% of services. The other 10% — the ones I want fully rootless, or the ones I'm experimenting with — run under Podman via systemd quadlets.

My compose-file discipline is simple:

# ~/stacks/media/compose.yml (excerpt)
services:
  jellyfin:
    image: jellyfin/jellyfin:10.9.11
    restart: unless-stopped
    ports:
      - "8096:8096"
    volumes:
      - ./config:/config
      - /tank/media:/media:ro
    environment:
      - JELLYFIN_PublishedServerUrl=https://jellyfin.tail-XXXX.ts.net

Rules I follow:

  • Pin versions. latest is a great way to get surprised on a Tuesday. Every production service gets a specific tag, and I bump them manually with a snapshot first.
  • One compose file per service domain. Media, home-automation, monitoring, utilities each get their own directory with their own compose file, their own .env, their own backup target. Easier to reason about than one god-compose.
  • Read-only binds where possible. :ro on media, on config I don't need the container rewriting, on anything mounted from the NAS. Cuts blast radius if a container gets rooted.

The full "Docker Compose to Podman quadlets without downtime" migration is its own post under Containers.

The services that actually run

The stack below is what's live in the closet right now. Everything else I've tried is either decommissioned or on a branch I never merged.

Media

  • Jellyfin 10.9 for movies and TV. Four concurrent 1080p transcodes without the i9 breaking a sweat.
  • Immich 1.107 for photos. Replaced Google Photos for my household about a year ago. Face recognition is surprisingly good; the ML model runs on the same host without a GPU.
  • The *arr stack (Sonarr, Radarr, Prowlarr, qBittorrent) — legally-acquired content only, naturally. Traefik routes them so I never have to remember ports.

Smart home

  • Home Assistant 2026.4 in its own LXC. Controls Zigbee (via a SkyConnect stick flashed to Zigbee2MQTT) and a handful of Z-Wave locks. Runs about forty automations; the ones I've documented all have a rollback note.
  • ESPHome for the DIY sensors — two temperature probes in the closet, one particulate sensor in the office, a mailbox detector on a CR123 battery that has held charge since January.

Sensor-drift benchmarks from six months of Home Assistant + ESPHome are queued under Home Automation.

Storage and backup

  • TrueNAS Scale on the NAS. Not doing anything clever — ZFS RAIDZ1, nightly scrubs, SMB + NFS shares, nothing fancy. Boring is the feature.
  • Borg 1.4 backing up the Proxmox host's ZFS datasets to the NAS, and from the NAS to Backblaze B2 via borg serve over an SSH tunnel.
  • Kopia on a few machines that I want to back up more aggressively (the laptop, the partner's laptop) because its block-level dedupe is sharper on a folder of Figma files than Borg's.

Full Borg vs. Restic vs. Kopia benchmarks on a 500 GB dataset are coming under Storage & Backup.

Security

  • Traefik 3 as the reverse proxy, reading labels directly off containers.
  • Authelia for SSO in front of anything that doesn't have its own good auth story. Two-factor via TOTP, session cookies scoped to the root domain.
  • Tailscale as the outer perimeter — nothing is exposed to the public internet. If it's not on the tailnet, it doesn't reach me.
  • Step-CA issuing short-lived internal certs so browsers stop yelling about self-signed.

Authelia + Traefik setup, in enough detail to deploy in a weekend, is queued under Security.

Hardware I'd pick again

After four years of this, the short list of hardware I'd buy again without hesitating:

  • Minisforum MS-01. Dense, quiet enough, thunderbolt on the front for eGPUs if I ever change my mind about that.
  • Jonsbo N2 or N3. Small-form NAS chassis that take 5–8 drives. The N2 fits in a cubby I had already.
  • GL.iNet Flint 2. The rare consumer router that runs vanilla OpenWrt well and doesn't cook itself.
  • Zooz 700-series Z-Wave stick + SkyConnect Zigbee stick. One radio per protocol; cheaper than fighting a combo stick.
  • CyberPower 1500VA line-interactive UPS. Cheap, loud beeper, survives a graceful shutdown script.

What I wouldn't buy again: any rack-mount 1U server in a residential apartment (the fan noise is real), anything made by a vendor that doesn't publish firmware update guides on a public URL.

The full minimum-viable rack build — four machines under $1,200 total, watt-per-workload rankings — is drafted for Hardware.

What I removed, and why

Restraint matters more than what you add. Recent cuts from the rack:

  • Nextcloud. I ran it for eighteen months. It worked, barely, and every upgrade felt like a bomb disposal. I replaced it with Immich (photos) + Syncthing (files) + a plain SSH-mounted folder for the occasional share. Smaller surface area, faster, and nothing has broken in nine months.
  • Mastodon. Running a single-user instance is fine until it isn't. Federation was more work than the posts I was making. I moved back to reading-only and my evenings improved.
  • Three-node Proxmox cluster. Covered above. Consolidation was the single biggest reliability win I've ever had.

If a service is adding more ops load than value, it's a candidate for removal. The goal of a homelab isn't to maximize the number of services running; it's to quietly deliver the ones that matter.

What comes next

The next ten essays on this site drill into individual layers of the stack above. In rough order:

  1. Proxmox vs. ESXi in 2026 for the home operator — the full migration notes.
  2. Tailscale subnet routers + ACLs in anger — the JSON policy file I actually use.
  3. From Docker Compose to Podman quadlets without downtime — the rollout plan, one service at a time.
  4. Immich vs. PhotoPrism on a 2 TB library — disk-I/O, CPU, and recognition-accuracy benchmarks.
  5. Borg, Restic, and Kopia on a 500 GB dataset — wall-clock times + bandwidth + dedupe ratios.

Subscribe to Dispatch if you'd rather get these in your inbox on Sunday mornings than check back. One email a week. One-click unsubscribe at the top of every issue.

Thanks for reading.

— Theo

# issues (0)

$ no issues filed yet. be the first — the form is below.

# add an issue

Comments are moderated. Links are capped. Be kind, be specific.