This repo documents and tracks the configuration powering my self-hosted home lab, running on TrueNAS with a mix of VMs and Docker/Kubernetes apps.
💡 Why? I built this because I'm anti-subscription and believe in actually owning what I pay for. No monthly fees, no data handed off to some company, no features locked behind a paywall. Everything here runs on my hardware, under my control the way it should be.
| Machine | Specs | Purpose |
|---|---|---|
| TrueNAS Server | i3 (4th gen), 24 GB DDR3, 250 GB HDD + 2 TB HDD + 1 TB HDD | NAS + App Host (TrueNAS Apps / Docker) |
| Proxmox Server 1 | i5 (4th gen), 16 GB DDR3, 250 GB HDD + 256 GB SSD | VMs: Kali Purple, Windows, TrueNAS |
| Proxmox Server 2 | Lenovo ThinkServer RD630, 2× E5-2640, 8 GB RAM, 250 GB SSD | Additional VMs |
All apps below are deployed via TrueNAS Apps (Helm/Kubernetes-backed) and are currently running.
Self-hosted photo and video backup solution. Replaced Photoprism as the primary photo management platform. Immich offers automatic mobile backups, facial recognition, smart search, and a clean Google Photos-style UI.
- Port:
30041 - Containers:
server,pgvecto,machine-learning,redis,pgvecto_upgrade,permissions - Source: immich-app/immich · immich.app
- Note: Running as root (UID/GID 0) — review Immich security precautions before exposing externally.
Open-source media server for streaming your personal library. Handles movies, TV shows, music, and live TV with no mandatory account or telemetry. Acts as the free alternative to Plex with full local control.
- RAM: ~221 MB
- Source: jellyfin/jellyfin
Lightweight, self-hosted music streaming server compatible with the Subsonic API. Stream your personal music library from anywhere using any Subsonic-compatible client (Symfonium, Ultrasonic, etc.).
- RAM: ~189 MB
- Source: navidrome/navidrome
Feature-rich media server with a polished UI, client apps on virtually every platform, and optional Plex Pass features (hardware transcoding, mobile sync, live TV). Running alongside Jellyfin for flexibility.
- RAM: ~237 MB
- Source: plex.tv
Zero-config VPN built on WireGuard. Creates a private mesh network between all your devices so you can securely access your home lab from anywhere without opening ports or managing firewall rules.
- RAM: ~61 MB
- Source: tailscale/tailscale
- Google Wi-Fi — Main router / mesh
- TP-Link 5-Port Gigabit Switch — Local switching
- Cisco Linksys Gigabit Router — Running in bridge mode
- Tailscale — Remote access VPN (WireGuard-based mesh)
docker-compose/ # Legacy or supplementary compose files
├── arm.yml # Auto Ripping Machine
├── jellyfin.yml
├── navidrome.yml
├── plex.yml
├── arr-stack.yml # Sonarr, Radarr, Homarr
├── pihole.yml
├── nginx-proxy.yml
├── ollama.yml
└── stable-diffusion.yml
Note: Primary app deployments have migrated to TrueNAS Apps (Helm charts). Docker Compose files are retained for reference or auxiliary services.
Disclaimer: All UUIDs, API keys, and internal IPs have been scrubbed for privacy. Replace with your own values before deploying.