About this project

Homelab-Ops is a documented reference architecture for running a self-hosted Kubernetes platform on a single Intel i5 mini PC (16GB RAM, 256GB NVMe, 1TB SATA) under Proxmox VE 8, with supporting cloud resources in Oracle Cloud Infrastructure and Google Cloud Platform. Key capabilities described in the README: - Networking: Cloudflare Zero Trust Anycast tunnels (cloudflared) provide outbound-only QUIC ingress, avoiding port forwarding behind CGNAT; Traefik handles in-cluster routing. Tailscale ephemeral mesh is used for administrative access and CI runners. - GitOps delivery: Flux CD v2 with Kustomize reconciles platform and application layers from Git, with ordered dependencies (platform before apps). Mozilla SOPS with Age encrypts secrets in Git, decrypted in-cluster. - Storage and data: dual-tier storage separates NVMe for OS, K3s state and PostgreSQL from a 1TB SATA disk for documents and media. CloudNativePG operator manages PostgreSQL lifecycle, failover and WAL archiving. - Resilience: an independent OCI VM runs Uptime Kuma for out-of-band health checks; Terraform state is stored in OCI object storage with remote locking; nightly encrypted Restic backups follow the 3-2-1 rule. - Application fleet: cloudflared, CloudNativePG, Homepage, Prometheus/Grafana, kwatch, MkDocs docs, n8n, a PDF generator microservice, Paperless-ngx, BookOrbit, Audiobookshelf, Miniflux, Linkding, and Ryot/wger. - Documentation: 16 ADRs, seven execution-phase manuals, and engineering guides covering Proxmox setup and recovery, Terraform modularization, secret hydration, K3s optimization, and WAN debugging. The repository is primarily an infrastructure-as-code and documentation project (Terraform, Ansible, Kubernetes manifests) rather than a packaged application. It is suited to platform engineers and homelab operators looking for a worked example of GitOps, zero-trust ingress and hybrid-cloud resilience on constrained hardware.