Home lab, part 4: self-hosted media services
Part 3 covered the compute layer — two servers, bare metal, Docker straight on top. This post covers what's actually running on the day-only box for media: Plex, Navidrome, Kavita, and Audiobookshelf.
Part 3 covered the compute layer — two servers, bare metal, Docker straight on top. This post covers what's actually running on the day-only box for media: Plex, Navidrome, Kavita, and Audiobookshelf.
Part 3 covered the move to bare-metal Docker, and mentioned in passing that the always-on server runs n8n, Dockhand, and Caddy. This post is about that last one — specifically, about what it replaced: Nginx Proxy Manager, which sat in front of everything before this. Where it lives on the network is nothing new; it's still on the Trusted VLAN, in the Secure zone, per part 2 — nothing about the migration changed that.
Choosing Zorin OS Core across my entire three-machine mesh solved my initial operating system crisis. I finally had a unified, macOS-like GNOME desktop layout on my old Dell Latitude laptop, my low-powered ThinkCentre mini PC, and my high-spec Nvidia workstation.
It started at my day job. For years, I had been issued a 15-inch Dell XPS. To call it a "laptop" was a generous stretch of the imagination; it was a portable space heater. It was incredibly noisy, ran white-hot, and frequently threw thermal throttling tantrums. I reached a point where I had to physically elevate the chassis and point a literal desk fan at it just to keep it cool.
Then, the company upgraded us to M2 MacBook Airs.
Part 2 covered the network the Lab VLAN sits on. This post covers what's actually running inside it — and a decision I made and then partly reversed: standing up Proxmox on both servers, then tearing it back down in favour of running Docker straight on bare metal.
Part 1 covered the physical layer — where the gear lives and how it gets a wired connection. This post covers what's built on top of it: the gateway, the VLAN layout, and the firewall model that ties them together. Later posts move up the stack into the compute layer and the reverse proxy sitting in front of it.
When my wife and I moved into our current home seven years ago, I wanted the network gear tucked away in the loft rather than piled up behind the TV. Wiring the house for Ethernet turned out to be a bigger job than I'd expected, and since it wasn't urgent, it kept sliding down the to-do list. That changed last December, when a problem with the existing setup made it worth finally tackling properly.