Video summary
In September 2026, the creator provides an updated overview of their self-hosted hardware and software ecosystem, clarifying that their power consumption remains manageable because most equipment operates only when needed for specific tasks. The core philosophy behind this setup is the preservation of personal data, which necessitates hosting all applications locally rather than relying on cloud services. While acknowledging the popularity of Proxmox as a hypervisor, the creator maintains a lab environment that includes both Proxmox and XCP-ng, utilizing each for different consulting scenarios and testing purposes. A significant update involves a new, "vibe-coded" application designed to handle UPS monitoring and graceful server shutdowns; this tool uses limited-scope API tokens to ensure that even if compromised, it can only perform a shutdown function without gaining full root access, thereby enhancing security while simplifying infrastructure management.
The storage and containerization strategy relies heavily on TrueNAS for managing robust ZFS storage systems and backups, offering a user-friendly alternative to command-line-only administration for those who prefer a graphical interface. For running applications, Docker containers are managed primarily via the command line, though the creator also utilizes UniFi equipment, including NAS systems and Protect cameras, which run locally without forcing cloud subscriptions. Network security has shifted away from pfSense at the head of the network to a setup driven entirely by UniFi, with EngineX Proxy Manager handling reverse proxy tasks and Netbird serving as the primary solution for remote access, complemented by Tailscale for client connectivity. Additionally, the creator employs Apache Guacamole for browser-based remote desktop sessions and has transitioned from Synology cameras to UniFi Protect to maintain a local, subscription-free surveillance ecosystem that offers advanced features without external dependencies.
To ensure system visibility and security, the infrastructure is monitored using Netdata for real-time metrics and Graylog for centralized log management, while NetAlertX automates network discovery and alerting. For forensic analysis, tools like Crates are used to examine packet captures and binary files, and Chasm Workspaces provide ephemeral browser environments that prevent tracking when investigating suspicious links or browsing privately. The creator has also adopted Paperless NGX to digitize paperwork following the sale of their managed services business, alongside SyncThing for continuous file synchronization across devices. Privacy is further emphasized through FreshRSS for aggregating content without algorithmic interference and a local Open Web UI instance running large language models, allowing the user to avoid enterprise AI services and maintain control over their data processing.
Finally, the creator manages personal assets like motorcycles using Garage for service tracking and utilizes Homer as a centralized dashboard that integrates live status updates from various services into a single landing page without requiring complex YAML configurations. Documentation is handled through a combination of Joplin notes stored locally on each device to ensure availability even if the server goes down, along with markdown files and icons added directly to the Homer dashboard. The creator uses Debian for its long-term stability and muscle memory after two decades of use, though they are currently testing CachyOS on their Framework laptop for gaming purposes. Throughout the video, the creator encourages community debate regarding software choices, inviting viewers to discuss trade-offs and alternatives on their forums while maintaining a pragmatic approach that balances open-source flexibility with the reliability required for a personal lab environment.
Read the full video transcript
It is September of 2026 and yes, I am
working on an updated hardware tour
because there's been a lot of questions
about my rack setup and all the
different things in it. Now, first thing
I want to say is no, my power bill is
not insane because most of the stuff is
turned off because it is a lab that I
turn on on an as needed basis. There's
of course a lot of core things that stay
on because there's a lot of apps I do
self-host. And that's what I want to
talk about first because when you look
at a giant rack of things, you always
want to know, well, what's running on
that rack? And it's probably one of the
number one questions when I had posted
some pictures. So that's what I'm going
to do is make that really simple to
break down all the things I'm
self-hosting because the most important
thing in ATR to me is my data. And the
fact that I host all of it is well where
the questions start coming in of what
software using to do that. You'll find
in description a link to my forum post
which will make a lot of people happy
that don't want to listen to a talking
head wearing a tact verbose shirt. Be
verbose about the software I'm running.
No need to shove the transcript into an
LLM. This is linked down below with
links to all the different software I'm
using and many of the videos and
tutorials I have on it, including an
overview of a lot of software I did in
March of 2026. Most of the software is
the same. There's a few changes here and
there, but I've got the video linked and
the other forum post back to the March
2026 video. This is a little bit more
expanded because it starts out with
hypervisors and storage. I like XCPNG
and I like Proxmox. And it seems that
when I talk about Proxmox or XCPNG,
people seem to assume I must dislike the
other. Honestly, I do consulting on
both. So, I have both of them in my lab
and they both serve their purpose.
They're both excellent open source
hypervisors. I do recommend them. But a
common question that came up when I had
posted pictures of my rack, and I do
realize Proxmox is the most popular
HomeLab software out there for sure that
PVE UPS was a solution to a problem
people are asking about. It's something
I've only started testing recently. It
does work. Yes, it appears to be
vibecoded, but it's really simple. And I
think the person writing it, and even
though they're co-authoring it with some
AI, actually understands good security
practices because what caught my eye was
this little app that simply talks to NUT
or SNMP to listen to your UPS to do a
graceful shutdown. And here is the app
if you want to know what it looks like.
But the more important part to me was
they're using an API token that will
talk to the server and do a graceful
shutdown. Now the API token is limited
in scope and they have instructions on
how to set this up to only have shutdown
permissions. So you're not worried about
the vibe coded app doing anything
terrible, but could certainly be
annoying by shutting down. So if this
app were to go rogue, it doesn't have
full SSH root access to your Proxmox
server. It has an API it calls that says
I can only do one thing and that thing
is shut this thing off. Uh you set the
triggers and thresholds. You put in the
UPS. It's got a pretty simple visual and
you can have it shut down multiple
Proxmox systems and talk to multiple
UPS's. I might do a video on it as I
test it more. But if you're looking for
an easy solution, that one is uh well
one I found that I seem to have no
problems running and uh I've tested the
graceful shutdown. It's worked every
time. True. I do a lot of trance videos.
You'll find a whole playlist linked
here. I'm really a big fan of ZFS and
Trudess is probably the easiest way to
manage it. There's a lot of people that
say, "Well, just do it from the command
line and that's fine, but I know not
everyone loves managing everything from
the command line." Tress is the good in
between in my opinion for running ZFS in
a very robust way. Maybe some Docker
containers and things you want near the
edge of your storage while
simultaneously
not having to learn all the command
line. So, Trunass has been my go-to. It
runs well all the storage and all the
backups in my back end of well
everything in my rack. Not that I don't
try other systems. Trunass is pretty
much my primary though for well where
this video is being edited in a lot of
my data.
Docker containers. This is where I host
a lot of these applications and talk
about I've got a video on how I run
Docker which is mostly from the command
line but I break that down in that
video. So that's linked as well. I will
mention because it's not listed here
because it's going to get some of its
own videos, but I have a lot of UniFi
equipment which I'm going to get into,
but also I do use some of the UniFi NAS
systems as well. So, they're listed as
in it's under the UniFi equipment, but I
know it could technically go under the
hardware and storage because I do have
some of those as well, but I don't have
a whole lot of videos on them yet. So,
those are in use, but I just didn't link
to them because I don't have a video
link. And I think people are aware that
UniFi makes a NAS. The head of my
network though has changed. I did a
recent video called the status of
pfSense here in 2026. It's not that I
have abandoned pfSense, but I no longer
have it at the head of my network. I do
have several pfSense boxes that are set
up and running in my lab when and that
is for consulting when I turn them on. I
keep testing things and sometimes
playing out scenarios to help clients
with well some interesting rule sets
they may want to create or VPNs that
they're setting up. So, I still do
consulting on PFSense, but it's not what
I run my primary network with. And I'll
probably do an updated video on how I do
the different lab VLANs and everything
else because it was already done
partially if you watch my other videos
with UniFi and PFSense at the head end.
Now, it's just UniFi at the head end.
And most of that lab stuff still exists
in much the same way. Uh, EngineX proxy
manager, that has been my go-to because
sometimes people ask if you got rid of
pfSense, what are you using if you're
not using haroxy anymore? Uh, EngineX
Proxy Manager works great. No problems.
Uh, Netbird for remote access. I really
like Net Bird because you can fully
self-host it. And yes, I still use
Tailscale because I like testing it out
and I like keeping up with what they're
up to and I have a lot of clients using
Tailscale, but Netbird is my primary
go-to. So, that's the one that made the
list here. Uh, but no problems. I don't
see any issues with Tailscale. But the
self-hosting of Tailscale is still done
with a third-party tool. To best of my
knowledge, Headscale exists, but tail
scale primarily is meant to be hosted
with tail scale versus Net Bird is a
complete solution, which is why I like
it. Apache guacamole. I don't use this
too often, but it's kind of fun to have.
So, I keep it in my lab and maintain
when I need to have access through a web
browser to something that might be RDP
or SSH. I've done a video on that.
Rustes is a real go-to for me for
managing well my studio computer and
occasionally if I have to have some
Windows systems set up security
monitoring unifi protect I've moved off
of some of the Synology cameras. I liked
Synology for a long time. The challenge
I had and I've done a recent video you
can find comparing the two. Uh Synology
looks the same as it did six or seven
years ago when I started doing videos on
it. It's changed extremely little and
well a lot of people are looking for a
lot more advanced features. But locally
with no subscriptions is how people want
those features. That's the part that
really comes back to the self-hosted
Unifi and I've covered this before. They
do not despite what people say force you
into the cloud. It is stored locally. I
do have the AI key that is run locally.
I've done videos on it. I have some more
upcoming videos with some of the UniFi
camera equipment. I like that it's run
locally. I know there's some open source
tools out there. Fri's cool, but it,
man, it's just not as uh complete of an
ecosystem, and you can probably tune it
to get it to do a lot of great things. I
just haven't put the time into setting
up something like Fri. So, while I
applaud those that have, my middle
ground solution just to keep the cameras
working fine has been Unifi Protect. I
know some people may not like that it
locks you into an ecosystem, but on the
other side, um it just works. So, that
is trade-offs and I completely
understand those trade-offs, but it's
hard finding good quality stuff that you
can host locally when it comes to
security cameras. And trust me, I'd be
the first to jump on it if something
existed that I could just store on my
churn and have all the easy to use
features I have with UniFi Protect. I
feel free to flame me in the comments on
those uh trade-offs on that, but the
fact that it's all done locally and can
lock it down locally makes it fine for
me. Centralized log management, Grey
Log, been talking about it for a number
of years. I still use grey log. I pump
the logs to all the things into grey
log. Great central place to do it. It's
been a little while since I did an
updated video on it, but there's not a
ton of changes. It's all kind of minor.
So, even my older video is accurate with
the exception of there might be some
changes in the way the docker compos
file is pulled. And I say that in the
video that this is for this version of
grey log. Please check their
documentation for their latest dockers.
I think they may have added a couple
things since I did that video. Uh, net
data for real time infrastructure
monitoring. Love net data. Been using it
for years. It's still a great way to
real time see what's going on with your
truness, your hypervisor, your docker
containers. It's very, very useful. Net
Alert X. This is something people ask a
lot about. Now, my video is also from
about a year ago, so there's been some
changes to the way they do their Docker
file. Uh, I don't know if it needs an
updated video because the tool itself
works the same. The Docker Compose file
is well going to be a little different
than the one in my video, but Net Alert
X is great for discovering devices on
your network using tools like end mapap
to map all those devices, see what ports
are open, etc., and create a place of
documentation.
This is a one that doesn't have its own
video, but so crates is pretty cool.
It's a standalone web application for
analyzing pcap, log, and binary files. I
did link a video that I used it in. So
if you want to see it in use for pulling
pcap files, I have that website in
GitHub. It's done by Doug Burke. Uh Doug
Burks is the guy who created Security
Onion. And so he's got a long history of
working in the space doing this. This is
way easier to set up than Security
Onion, which I do have a video on, but I
don't actively run it in my network, so
I didn't list it as uh something I
self-host. I have set it up. It's
something I build rebuild in the lab
from time to time to poke at. Same with
Wazu. I think those are cool, but
there's a lot more in depth that goes to
those. Uh, this is just a way to poke at
some PECAP files if you need to. Chasm
workspaces I use a lot. So, this is
truly one of the self-hosted apps that
every time I want to fire something up
and not be tracked. I spin up those
temporary chasm workspaces to stop
things from tracking me because it's
spinning up an ephemeral browser. What
that means is it is a way to have things
that are automatically pushed out over
VPN. I've got a whole video on Chasm.
I've got everything routed so it always
goes out different IP addresses based on
the VPN settings that are in each one of
the workspaces and it's wonderful for
being able to click that shady link
someone sent me because man, people send
me a lot of fishing links and I really
want to know where they go. Like I'm
completely aware that this is a fishing
link. So I throw it in Chasm. I want to
see what it's going to do and where it's
going to go, but I don't want to be
impacted by it or have it even tied to
my own IP address. Chasm is great for
that. Chasm is good for things you want
to look up that you don't want in your
browser history, etc. Definitely check
out Chasm. Paper list NGX. So, I was
resistant to using this for a while and
when I sold off the managed services
side of my business is now why I want to
use it. I used to create so much
paperwork that I didn't want to try to
scan all of it because there's just with
a company with a lot of people, there's
just a lot of paperwork and there's a
lot of paperwork to scan. So, uh, I kind
of resisted and have it all in drawers.
There's actually a lot less paperwork
here for me just doing the consulting
side of the world. So, uh, I've now
moved to this because it's easy now to
get rid of all the paper and put it in
paperless NGX. I haven't done a video on
it, but for those looking for a good way
to scan, create these PDFs, index them,
OCR them, I really think this has been
great. I've been putting a lot more
paperwork in it, and once I'm done, I'll
probably do a video on it as a topic.
Uh, Sync Thing, continuous file
synchronization between devices. I've
got videos on how I use this for
real-time backups. Sync thing I run on
my Trass servers. It works well. So, it
runs on Trass and then connects to my
local desktop. So, anytime I save some
type of business document, it is
immediately synced to all the places
that I want it synced. Image photo
backup. I love Image. Been using it for
a little while. They've uh been coming
up with new versions and feature
enhancements. I don't know that I need
to do a new video on it. I have an old
video on it that is still very accurate
for getting it set up and the overall
features that it has. They just have a
few more features. So, uh check the
change log on that. Joplain open- source
note-taking to-do applications with
endnryption that syncs to your own
storage. Note-taking is something that
is well apparently vibe coded about
every other day. Someone has a new
note-taking app that they're showcasing
in some place on Reddit or wherever. Uh
Japa has been around a long time and I
stick with it because it's open source.
It's got a good user base. It has a lot
of features. It doesn't have the most
flashy interface that some of the new
ones have, but the fact that it's open
source and I can self-host the back end.
And even if you don't want to self-host
the back end, the backend is fully
encrypted. So the storage of it can be
hosted places where you may not trust.
So if you were to host this yourself in
a cloud or with the Joplin cloud, you're
encrypting it before it leaves. So it's
one of those respecting of the privacy,
still giving you some data sovereignty
where you have control of all your data.
And being that it's open source and been
around for a while, it's uh got some
good market trust in my opinion. But use
what makes you happy is what I tell
people when it comes to note-taking. The
most important part is having a process
for it. But Joplin, it's my second
brain. Been using it for a while. If
you're not familiar with the term second
brain, look up how to build a second
brain. There's a book on the topic uh to
help get you started because more
importantly than any of the note
takingaking apps you choose is having a
process by which you take notes so you
can find information later. because some
people get into the problem of I'm going
to save everything and that's not
helpful. information and AI ah fresh RSS
self-hostable RSS aggregator really
think fresh RSS is the way to view the
internet now more so than ever when I
started using it uh RSS makes the
internet bearable is basically what I
would describe because as everything is
so algorithmically driven I just want a
feed of the latest updates from certain
places so whether it's blog posts even
YouTube videos that I don't want to be
forced fed from an algorithm by uh I can
just list the creators in there And I've
got instructions and you can find plenty
of details on fresh RSS plus plugins of
how to pull RSS feeds or scrape websites
with it. So you can actually have a
concise list of the things you're
interested in pulled on a regular basis.
Seg privacy respecting meta search
engine. I cover this in my video that I
have above. It's a pretty neat way to
put a bunch of search engines together
and do a meta search to pull data. uh
because all these companies and Google
used to be so good for search and their
AI search has become well hot garbage.
Um this is a way kind of around a lot of
that and it's not just a search it's
doing several things. Not a perfect
solution. Someone will point out
problems they may have or it may not
return exactly the data you're looking
for. Uh but that's actually the same
problem we're having at Google. So
searches unfortunately become worse in
the AI era. Uh this at least is a little
bit of comping against it. uh open web
UI plus a lama pairing that runs large
language models entirely on local
hardware. I'm probably going to do some
upcoming videos on this because I'm
working with a friend on some pretty big
uh self-hosted projects to get away from
any of the enterprise frontier AI and
use local self-hosted models that we
have control over. Um this is where
comes in and it's a great way to
self-host AI.
Home and garage. Now, this one's a home
and garage cuz I got home assistant
because it does everything and garage
for lube bloggers. So, I wasn't sure
where else to uh call this, but I did
pull up lube logger. It is a simple app.
I'm not going to do a full video on it.
Maybe someone has already, but I just
want to track things like service
records for my motorcycle. When did I do
the veil adjustments or when did I do
the oil filter change? Simple app, gets
the job done. Uh I listed a couple of my
motorcycles in here and that's how I
track them. Uh, but I thought I'd at
least list it because it's one of those
little things I didn't know I needed,
but it's come in very handy because I'm
uh really meticulous about service
records of my motorcycles
management tools. Homer dashboard and
landing page for everything else on this
list with integrations that pull live
status from services to links, drag and
drop configuration, no YAML to work
with. Uh, I like Homer. Did a video on
it a while ago. Might do another one
since V2 just came out. I've been
testing and it works well. And then
management like Docker. Uh, I like
managing things with Dockhand, but I
only use it and I've got a video on this
for managing updates and doing some of
the purging. I set up and that's that
Docker video I have linked up at the
top. Docker to be managed and set up
from the command line. That's my
preferred way to do it. Then it tools
just a collection of developer utilities
and formatterers and decoders. This is
listed in the other video, but then
someone pointed out and thank you
because the audience is very helpful
here uh to a fork of the project that's
way more in depth. So, it's actually got
the same name. It's pretty much the same
project, but that project kind of wasn't
getting updated. Not that it needed
updates. It's just a list of tools and
handiness, and someone linked to a more
in-depth one that is getting more
maintenance on it. Now, some people
might be asking, "What are you using for
documentation?" Or, "Why isn't Netbox in
the list?" Because I know it's really
popular. I don't need Netbox to document
my lab. It's pretty much overkill for
what I do. But, I think it's a great
tool if you want to use it, you want to
learn it, or you want to use it in a
business environment. It's definitely a
very robust documentation tool and
there's nothing wrong with it. It's just
not needed for the level of
documentation I need. I do most of my
things in Joplin notes and markdown and
the reason for that is really simple. If
your backend goes down and you're using
some self-hosted notes app that also
goes down with it, well, that would be a
pain. Joplin is a self-hosted notes app
where the notes are on each device you
have Joplin running on, whether it be a
phone or a laptop, a desktop, etc.
Therefore, if the backend goes down, you
have the last synchronized copy. And
because the copies are always
synchronized when a lab is up, and I
document the lab when it's up and
running, therefore, I always have a copy
of my notes. So, if it all goes down, I
can reference the markdown notes. Also,
anything I add to my lab, I always add
to the Homer dashboard as well. So,
that's also kind of my own documentation
for where things are, where they live. I
just add another icon to the Homer
dashboard. But, there's lots of opinions
that people will have. You can connect
me over at forums.lorsystems.com.
laurenssystems.com where you'll find a
link to the post with well all the
software listed in it. Feel free to
engage me there. Feel free to engage me
on socials and they're all linked over
on laurrensystems.com because I'm sure
someone will tell me the software I
chose is not the software I should have
chose, which I actually openly love the
healthy debates that come from this. I I
always have a lot of fun bantering with
people of why they chose what software.
Uh the forums I think is the best place
to do it. Social media is I don't know
maybe an okay place to do it as well.
arguing about, you know, which
hypervisor can beat up which hypervisor
is definitely a fun and lively debate
I'm willing to engage in. I'm less
willing to engage in Linux distro
arguments. I happen to like Debian. It
works fine for me. I know there's going
to be some heated opinions on Tom, why
did you choose Debian? And it's because
I've been using it for literally over 20
years now. So, I I kind of have some uh
apt to get muscle memory going on. But
there's other people that told me I
tried using some other things. And yes,
I have tried several other
distributions. I am currently using
Catchy OS on my framework laptop. So,
feel free to tell me you love or hate
it. But it actually works good for
gaming. So far, I haven't had any
problems, but I don't know if I'm going
to review it or not. That's uh certainly
catchy catchy or cashy. I don't know.
Let me also know in the comments on
that. Thanks for watching and take care
everyone.