$ systemctl status homelab.elic

DevOps & Infrastructure

I run a production-style homelab the way an engineering team runs infrastructure: hypervisor virtualization, container workloads, databases, and centralized identity, all self-maintained. This is where I turn architectural theory into reliable, self-healing systems.

Deploy pipeline

Homelab stack

Identity
Authentik SSO / IdP
Services
NextcloudPaperless-ngxGitea
Data
PostgreSQLRedis
Runtime
Docker Compose
Platform
Proxmox VELinux

Infrastructure skills

Strong (Interview-Ready · Daily Drivers)

  • TypeScript & JavaScript'23
  • Next.js & React 19'24
  • Flutter & Dart'24
  • Python'22
  • Docker & Docker Compose'24
  • Proxmox VE & Linux'23
  • PostgreSQL'24
  • Git & GitHub Actions'23

Working Knowledge (Applied in Production & Labs)

  • Authentik (SSO / IdP)'25
  • Supabase & PostgreSQL'24
  • Redis'25
  • Ansible & Meraki API'26
  • Active Directory & Windows Server'25
  • TCP/IP & VLAN Routing'23
  • Nmap & Recon Tooling'24
  • Tailwind CSS'23

Familiar (Explored & Evaluated)

  • WebAssembly & PDF.js'25
  • Firebase & Firestore'24
  • Web Crypto API'26
  • Edge AI & PyTorch'26
  • ZFS Storage Pools'25
  • Traefik & Nginx'25
  • ISACA IT Governance'24
  • Bash & PowerShell'23

Featured infrastructure work

~/case-studies/homelab.md

active
DevOps & Infrastructure

Homelab Infrastructure & Self-Hosting

Jun 2026 – Present

A production-grade self-hosted infrastructure cluster hosting 15+ containerized services, split-horizon DNS, and automated backups on Proxmox VE.

// problem statement
Public cloud environments abstract away underlying hypervisors, storage, and networking layers. I needed bare-metal control to master enterprise virtualization, container orchestration, and failover mechanics.
// engineering solution
Engineered a multi-node Proxmox VE cluster hosting Nextcloud, Gitea, Paperless-ngx, and Vaultwarden via Docker Compose. Implemented PostgreSQL and Redis data backends, split-horizon DNS routing, and Authentik for centralized SSO/OIDC identity management.
// key outcome & impact
Maintains 15+ containerized daily productivity services with automated ZFS snapshot backups, split-horizon DNS routing, and centralized Authentik SSO authentication, eliminating reliance on third-party cloud tools.

System Architecture & Data Flow

                Public Internet / Local Network
                               │
                     Cloudflare DNS / Proxy
                               │
               Traefik Reverse Proxy (*.elic01.dev)
                               │
               ┌───────────────┴───────────────┐
               ▼                               ▼
        Authentik SSO (IdP)          Containerized Services
      (OAuth2 / OIDC / LDAP)       (Nextcloud, Gitea, Immich)
               │                               │
               └───────────────┬───────────────┘
                               ▼
                      Proxmox VE Cluster
                    (5x EliteDesk Nodes)
                               │
               ┌───────────────┴───────────────┐
               ▼                               ▼
       PostgreSQL / Redis              ZFS / PBS Backups

Key Technical Highlights:

  • 5-Node Bare-metal Proxmox VE cluster running on AMD Ryzen hardware.
  • Split-horizon DNS architecture resolving *.elic01.dev with wildcard Let’s Encrypt certificates.
  • Centralized Authentik identity provider protecting Nextcloud, Paperless-ngx, and Gitea.
  • Automated Proxmox Backup Server (PBS) scheduled snapshots and deduplicated storage retention.
  • Proxmox VE
  • Docker
  • Docker Compose
  • PostgreSQL
  • Redis
  • Authentik
  • Linux
  • ZFS

~/case-studies/cisco-meraki-ansible.md

shipped
DevOps & Infrastructure

Cisco Meraki Ansible Automation

Aug 2026

Infrastructure-as-Code (IaC) playbooks that automate multi-site VLAN provisioning, firewall policy rollout, and configuration compliance checks across Cisco Meraki hardware.

// problem statement
Configuring enterprise network appliances manually via GUI dashboards introduces human error, configuration drift across branch sites, and slow rollback times during network incidents.
// engineering solution
Engineered modular Ansible playbooks that interface directly with the Cisco Meraki REST API to push declarative firewall rules, manage SSID profiles, and enforce VLAN policies from Git repositories.
// key outcome & impact
Automated multi-site network configuration via declarative playbooks, reducing manual dashboard provisioning steps to a single executable script with complete Git-based change tracking.

System Architecture & Data Flow

Git Repository (IaC) ──► Ansible Engine ──► Meraki REST API ──► Enterprise Edge Hardware
 (declarative YAML)        (playbook tasks)   (HTTPS / Token)       (VLANs, SSIDs, Firewall)

Key Technical Highlights:

  • Declarative Infrastructure-as-Code eliminates manual configuration drift across branch sites.
  • Automated VLAN allocation, guest isolation, and egress filtering rules.
  • Full Git revision history enabling instant rollback during network configuration incidents.
  • Python
  • Ansible
  • Cisco Meraki API
  • YAML
  • DevOps
  • Network Automation