Lab

The homelab behind the projects: layered network paths, VPN-protected traffic, and scheduled automation.

THE LAB

Layered on purpose.

Public traffic stops at the edge first. Nothing reaches the lab without crossing an encrypted hop, and the most sensitive traffic rides a VPN. This site isn't served from the lab at all.

TOPOLOGY

How traffic flows

HTTPSencrypted tunnelVPNinternal onlySSH (lab)Visitorbrowser · appEdge networkTLS · filteringidentity check onadmin pathsTHIS SITEPortfoliostatic · at edgeLab gatewaytunnel endpointHOMELAB MEDIAMedia appsstreaming · requestsAutomationwatchdog · digestVPNoutside netTeam chatdaily reportVAULTWARDENPassword vaultisolated VMOff-siteencryptedSEPARATE PATHS · NEVER TOUCH THE LAB GATEWAYSSH TUNNELLab clientpractice toolJump hostsingle entry pointLab targetisolated subnetVAULT SYNCLaptopnotes vaultPrivate repoversion historyOther devicespull changesDRIVER UPDATERWindows PCscheduled taskUpdate servicevendor driversRestore pointbefore installTRADING RESEARCHMarket data30-minute barsCloud routinehourly · key injectedPrivate repotrade log · workbookDesktophourly pulltunnelhostingmanagenightlySSHGit over HTTPSHTTPSHTTPS · pulled each hourpushpull
HOW IT STAYS UP

Boring on purpose.

Compose files, an environment template, and every custom script live in a repo that doubles as the rebuild guide.

  1. 01Public services sit behind an edge network and an encrypted tunnel.
  2. 02Media hosting and management leave the network only through a VPN.
  3. 03A socket proxy allow-lists the Docker API calls tooling may make.
  4. 04A watchdog restarts stalled services. Scheduled jobs throttle heavy work.
  5. 05A daily digest reports health, usage, and changes.
  6. 06Research jobs run on a cloud schedule. The lab only pulls their results.