Self-Hosting Vaultwarden: Setup, Hardening, and Backup for Your Password Vault

A password manager is the one self-hosted app where “good enough” isn’t good enough. Every other app on your stack going down for a night is an inconvenience. Your vault going down, or worse, becoming unrecoverable, is every credential you have locked behind a box you can no longer reach. That raises the bar for how carefully you set this one up compared to, say, a media server or a dashboard. Vaultwarden makes the bar easy to clear, it’s a small, mature, low-resource app, but only if you actually do the hardening and backup steps instead of just running the container and calling it done. ...

September 10, 2026 · 7 min

Ceph in Proxmox: When Hyperconverged Storage Actually Makes Sense at Home

Ceph shows up in every “how do I get real shared storage for my Proxmox cluster” conversation, and for good reason, it’s the one option that’s fully native, fully integrated into the Proxmox web UI, and genuinely production-grade software running underneath some very large real-world deployments. It’s also the option most likely to leave a home cluster worse off than before you added it, because Ceph’s design assumptions (plenty of nodes, plenty of network, plenty of dedicated drives) don’t bend easily to a 3-node home lab built from whatever hardware was on hand. Here’s what Ceph actually is inside Proxmox, what it needs to run well, and when it’s the right call instead of the simpler alternatives. ...

September 7, 2026 · 8 min

Self-Hosted VPN: WireGuard vs Tailscale vs ZeroTier for Homelab Remote Access

At some point every homelab operator wants to reach their stuff from outside the house, checking on a download, pulling up Jellyfin at a friend’s, hitting the Proxmox web UI from a coffee shop. The wrong way to do this is punching holes in your router’s firewall and forwarding ports straight to internal services. The right way is a VPN that puts your remote device on the same private network as your homelab, so nothing is exposed to the internet at all. WireGuard, Tailscale, and ZeroTier are the three tools homelabbers reach for most, and they’re not really three competing options for the same job, they’re two different approaches with WireGuard sitting underneath one of them. ...

September 6, 2026 · 7 min

Proxmox GPU Passthrough: VM PCIe Passthrough vs LXC Device Passthrough

Buying the right GPU for your homelab is one decision. Getting Proxmox to actually hand that GPU to a VM or container is a separate one, and it’s where a lot of people get stuck, because Proxmox actually supports two completely different ways to do it, and picking the wrong one for the job means either a fight with IOMMU groups you didn’t need to have, or a container that can’t do what you needed a full GPU for. Here’s what each path actually requires, and how to pick between them. ...

September 3, 2026 · 7 min

Immich vs PhotoPrism: Picking a Self-Hosted Photo Backup That Actually Replaces Google Photos

Google Photos used to be the easy answer: unlimited storage, decent search, an app that just worked. That deal is gone, storage now counts against your Google One quota, prices have crept up, and the underlying trade was always the same one every free cloud photo service makes: your entire photo library, including the ones you’d rather not have scanned by an ad-tech company’s ML pipeline, lives on someone else’s servers under someone else’s terms. Immich and PhotoPrism are the two projects that have actually closed the gap between “self-hosted” and “something you’d trust with 15 years of family photos.” Picking between them comes down to a few real differences, not just which one has a nicer logo. ...

September 2, 2026 · 7 min

Proxmox Clustering: When a Multi-Node Cluster Is Actually Worth It at Home

Proxmox makes joining a second node to a cluster look almost too easy, one command on the joining node and you’re done, centralized management across both boxes in the web UI. What that quick setup doesn’t make obvious is how much more you need to build on top of it before a cluster gives you the thing most people actually want from one: automatic failover when a node dies. This is the gap that catches people, they cluster two or three nodes, assume they now have redundancy, and find out during an actual outage that a VM doesn’t restart anywhere because nothing was wired up to make that happen. Here’s what clustering actually gets you, what it costs, and an honest read on whether it’s worth doing in a home setup versus running solid standalone nodes. ...

August 30, 2026 · 8 min

Pi-hole vs AdGuard Home: Picking a Self-Hosted DNS Ad Blocker for Your Homelab

Browser extensions block ads on the device they’re installed on. A phone that isn’t running one, a smart TV, a game console, a guest’s laptop on your Wi-Fi, none of that gets covered. Network-level DNS blocking fixes that by sitting between every device on your network and the internet, and refusing to resolve requests to known ad and tracker domains before they ever load. It’s one of the easiest wins in self-hosting: low resource cost, immediate and visible results, and it protects every device on the network without touching a single one of them individually. Pi-hole and AdGuard Home are the two dominant tools for doing this yourself, and picking between them comes down to a handful of real differences, not just branding. ...

August 29, 2026 · 7 min

Proxmox Networking: Bridges, Bonds, and VLANs for Your Homelab

Proxmox sets up a single bridge during install, vmbr0, hands every VM and container a virtual NIC on it, and most homelabs never touch networking again after that. That’s fine right up until you want to keep your NAS traffic off the same broadcast domain as a VM you don’t fully trust, or you add a second NIC and aren’t sure whether to bond it or split it out, or you’re staring at a VLAN dropdown in the VM hardware tab with no idea what happens if you fill it in wrong. None of this is complicated once you see the shape of it, but Proxmox’s networking config is also one of the few places where a bad change locks you out of the box that’s hosting the config, so it’s worth understanding before you’re mid-edit over SSH. ...

August 26, 2026 · 7 min

Backing Up Your Self-Hosted Stack: Restic and Borg for Docker Volumes and Configs

A Proxmox Backup Server job backs up entire VMs and containers, which covers you if a whole box dies. It does not, by itself, give you a clean, restorable copy of the actual data living inside your self-hosted apps, the Vaultwarden vault, the Paperless-ngx document store, the dozen docker-compose.yaml files and their bind-mounted config directories that took real time to get right. If your backup strategy stops at the hypervisor layer, you’re covered against hardware death but not against the more common failure: a bad update, a fat-fingered docker compose down -v, or a config file you meant to edit and instead overwrote. This is where an app-level backup tool earns its place alongside whatever you’re already doing at the VM/container level. ...

August 25, 2026 · 6 min

LXC vs VM: Choosing the Right Proxmox Container Type for Your Homelab Workload

Proxmox hands you two completely different ways to run a workload, LXC containers and full VMs, and the “New CT” and “Create VM” buttons sit right next to each other in the UI like the choice barely matters. It matters. Pick the wrong one for a given workload and you’ll either waste resources you didn’t need to waste, or hit a wall six months in when something a container fundamentally can’t do turns out to be exactly what you needed. Here’s how to actually decide, workload by workload, instead of defaulting to whichever one you set up first. ...

August 25, 2026 · 6 min