Proxmox Permissions and API Tokens: Giving Out Access Without Giving Out Root

Most single-operator homelabs run everything as root@pam. You log in as root, every VM shows up, every setting is reachable, and that’s fine right up until you want someone else to have access too, a roommate who wants to spin up their own VM, a family member who needs to restart one container, or a script that needs to talk to the API without holding the keys to the entire cluster. At that point “just use my login” stops being a reasonable answer, and Proxmox’s actual permission system, which almost nobody touches because the default single-user setup never forces you to, becomes worth understanding. ...

October 5, 2026 · 6 min

Encrypting Your Data Hoard: LUKS vs ZFS Native Encryption vs VeraCrypt

Most data hoarding advice is about keeping data alive: redundancy, checksums, off-site copies. Almost none of it is about keeping that data private if a drive leaves your control. And drives leave your control more often than people think - a failed disk goes back to the manufacturer under warranty, a drive gets sold or handed off once you upgrade capacity, a laptop or external drive gets lost or stolen. If none of that data was encrypted, every one of those events is a potential data breach, not just an inconvenience. ...

October 3, 2026 · 7 min

Proxmox Firewall: Locking Down Your Homelab at the Datacenter, Node, and VM Level

Proxmox ships with a real, iptables-backed firewall built into the platform, and most homelabs never turn it on. It’s not enabled by default at any level, so unless you’ve gone looking for it in the UI, there’s a good chance your VMs and containers are sitting behind nothing but whatever VLAN segmentation you’ve set up, if any. That’s often fine. It stops being fine the moment you’re running something internet-facing, or you want one VM to be reachable only from your management network and nowhere else, or a compromised guest shouldn’t be able to freely talk to everything else on its VLAN just because they share a broadcast domain. This is what the built-in firewall is actually for, and it’s worth understanding the shape of it before you flip it on. ...

September 19, 2026 · 7 min

Self-Hosting Vaultwarden: Setup, Hardening, and Backup for Your Password Vault

A password manager is the one self-hosted app where “good enough” isn’t good enough. Every other app on your stack going down for a night is an inconvenience. Your vault going down, or worse, becoming unrecoverable, is every credential you have locked behind a box you can no longer reach. That raises the bar for how carefully you set this one up compared to, say, a media server or a dashboard. Vaultwarden makes the bar easy to clear, it’s a small, mature, low-resource app, but only if you actually do the hardening and backup steps instead of just running the container and calling it done. ...

September 10, 2026 · 7 min

Self-Hosted VPN: WireGuard vs Tailscale vs ZeroTier for Homelab Remote Access

At some point every homelab operator wants to reach their stuff from outside the house, checking on a download, pulling up Jellyfin at a friend’s, hitting the Proxmox web UI from a coffee shop. The wrong way to do this is punching holes in your router’s firewall and forwarding ports straight to internal services. The right way is a VPN that puts your remote device on the same private network as your homelab, so nothing is exposed to the internet at all. WireGuard, Tailscale, and ZeroTier are the three tools homelabbers reach for most, and they’re not really three competing options for the same job, they’re two different approaches with WireGuard sitting underneath one of them. ...

September 6, 2026 · 7 min

Self-Hosted Authentication: Picking an SSO Layer for Your Homelab with Authentik or Authelia

Run five self-hosted apps and you’ve got five separate logins, five separate password resets, and five separate places an old account can quietly stay active after you meant to lock someone out. Once you cross that threshold, a single sign-on layer stops being a nice-to-have and starts being the thing that keeps your homelab’s security model from turning into a pile of unrelated logins nobody’s actually tracking. Here’s what an SSO layer buys you, and how the two most common self-hosted options actually differ. ...

August 25, 2026 · 6 min