This is a mono repository for @paulfantom home infrastructure and Kubernetes cluster. Project utilizes Infrastructure as Code to automate provisioning, operating, and updating self-hosted services.
Cluster is k3s provisioned on bare-metal hosts with latest LTS Ubuntu OS using a modified version of Ansible role provided by k3s project.
πΈ Click here to see Ansible playbooks and roles.
| Logo | Name | Description |
|---|---|---|
| GitHub Actions | CI system | |
| Ansible | Automate bare metal provisioning and configuration | |
| Ubuntu | Base OS for Kubernetes nodes | |
| K3s | Lightweight distribution of Kubernetes | |
| Kubernetes | Container-orchestration system, the backbone of this project | |
| Cilium | Kubernetes Networking | |
| kured | Kubernetes Reboot Daemon | |
| TopoLVM | Local storage based on LVM | |
| Flux | GitOps tool built to deploy applications to Kubernetes | |
| ExternalSecrets | Secrets and encryption management system | |
| cert-manager | Cloud native certificate management | |
| Cloudflare | DNS | |
| Traefik | Kubernetes Ingress Controller | |
| oauth2-proxy | Authentication proxy | |
| Prometheus | Systems monitoring and alerting toolkit | |
| Grafana | Operational dashboards | |
| Loki | Log aggregation system | |
| Alloy | Log and metric collector | |
| Cloudnative-pg | Postgres Controller | |
| Homer | Portal Site | |
| HomeAssistant | Home Automation System | |
| ESPhome | Microcontrollers Management | |
| Mealie | Cookbook | |
| Immich | Photo Management | |
| Paperless-ngx | Document Management | |
| Changedetection | Monitoring website changes | |
| Jellyfin | Multimedia System | |
| Plex | Multimedia System | |
| Game Server | Valheim Game Server | |
| Atuin | Shell History | |
| AND | MANY | OTHERS |
Flux bootstraps from k8s/bootstrap/, which applies the CRDs in k8s/crds/, the namespaces in k8s/namespaces/ and its umbrellas. One reconciles the manifests in k8s/platform/, a Kustomization per platform-<domain> namespace; each app's Kustomization is created beside its Namespace in k8s/namespaces/<app>/, reconciling k8s/apps/<app>/ as that namespace's own identity.
My home IP can change at any given time and in order to keep my WAN IP address up to date on Cloudflare I have configured DDNS on Unifi Dream Machine Pro.
A UniFi UNAS Pro serves the NFS shares. The unifi-nas storage class provisions
each claim as a subdirectory of a single share, so every PVC on it reports that
one volume's free space rather than its own -- see the excluded_from_alerts
Kyverno policy.
Mini-PCs, UniFi networking and a UNAS Pro. docs.thaum.xyz/reference/hardware has the nodes, their disks and what backs each volume group.
Project status: Alpha
- Common applications: Plex, Nextcloud, HomeAssistant, Ghost...
- Automated Kubernetes installation and management
- Monitoring and alerting
- Modular architecture, easy to add or remove features/components
- Automated certificate management
- Installing and managing applications using GitOps
- CI/CD platform
- Distributed storage
- Automatically update DNS records for exposed services
Any contributions you make, either big or small, are greatly appreciated.
If you find any security issue please ping me using email (paulfantom+security@gmail.com)
- Icons are provided by homelab-svg-assets.
Distributed under the MIT License. See LICENSE for more information.