deimosRUNNING
deimos: Proxmox VE on an HP Z640
The main (and so far only) node. An Intel Xeon E5-2690 v4 with 14 cores and 28 threads, plus 32 GB of DDR4 ECC registered memory, running Proxmox VE. I manage it from the Proxmox web UI on port 8006.
Learned: giving every service its own guest makes mistakes cheap. Snapshot first, experiment second.
- Proxmox VE
- Xeon E5-2690 v4
- 14C / 28T
- 32 GB ECC RDIMM
media stackRUNNING
An automated media stack
It manages and streams media I own. I self-host it to run my own services, not to pirate, and building it has taught me a lot. Several small services talk to each other over their APIs: Prowlarr manages indexers, Radarr organises the film library, qBittorrent handles downloads, and FlareSolverr helps Prowlarr get past browser challenges.
Media stack services on deimos
| Service | Port | Status |
| Prowlarr | 9696 | up |
| Radarr | 7878 | up |
| qBittorrent | 8090 | up |
| FlareSolverr | 8191 | up |
| Gamarr | 5001 | inactive |
Learned: how services discover and authenticate to each other with API keys, and why one misconfigured port breaks the whole chain.
- Prowlarr
- Radarr
- qBittorrent
- FlareSolverr
jellyfinRUNNING
Jellyfin media server
A self-hosted media server on port 8096 that streams my own library to devices around the house. The end of the media stack's pipeline, and the bit everyone else at home actually notices.
Learned: transcoding is hard work for a CPU. 28 threads finally have something to do.
- Jellyfin
- port 8096
- self-hosted
deimos · next guestsPLANNED
Self-hosting roadmap
What's going on deimos next. Each one is useful day to day, and each teaches a different part of running services securely.
Planned self-hosted services
| Service | What it's for | What it teaches | Status |
| Gitea | My own Git server for lab configs, scripts and notes | Auth, SSH keys, backups | planned |
| Vaultwarden | A Bitwarden-compatible password manager | Secrets, TLS, 2FA | planned |
| Nginx Proxy Manager | One front door with HTTPS for every service | Certificates, reverse proxies | planned |
| WireGuard | VPN access from outside, with no open ports | Remote access done safely | planned |
| Authentik | Single sign-on in front of the web UIs | Identity, MFA | planned |
| Uptime Kuma | Alerts when a service goes down | Monitoring, alerting | planned |
| Immich | Self-hosted photo backup | Storage, 3-2-1 backups | planned |
| Homepage | A dashboard linking every service | Keeping things tidy | planned |
Rule for every new service: its own guest, a snapshot before changes, no default passwords, and never port-forwarded to the internet.
- Gitea
- Vaultwarden
- reverse proxy
- WireGuard
- SSO
pi-clusterPLANNED
Raspberry Pi cluster
A small stack of Raspberry Pis for always-on services and for learning lightweight Kubernetes, so not everything depends on deimos being up.
Goal: learn how distributed systems fail, on hardware that's cheap to break.
fw-01PLANNED
Firewall and segmented networks
Right now deimos and every service sit on the same flat network as the rest of the house. The next big project is a firewall VM and VLANs, so the lab, home devices and guests are kept apart.
Rule one: write the firewall rule down before applying it.
dns-01PLANNED
Pi-hole + Unbound, the Pi cluster's first job
Network-wide ad blocking and my own recursive DNS resolver, so I can see exactly what every device on the network asks for.
Because when something breaks, it's always DNS.
- Raspberry Pi
- Pi-hole
- Unbound
siem-01PLANNED
Wazuh SIEM watching the lab
A Proxmox guest on deimos collecting logs from every service, so I can practise writing detection rules, starting with alerts for failed logins to the Proxmox and service web UIs.
Goal: test every detection I write. An untested one is just a guess.
ad-labPLANNED
An isolated Active Directory lab
Windows Server evaluation VMs on deimos, a small domain and a few deliberately weak settings, fully offline, so I can see attacks like Kerberoasting from both sides and then fix them.
Good news: 14 cores and 32 GB leave room for a domain controller, a client and an attacker VM next to the media stack.
- Windows Server
- AD DS
- Group Policy