Case study
Self-hosted infra
Backend · Infra · Self-hosting
A single Raspberry Pi, several isolated apps in Docker Compose, one front door with automatic TLS. IoT is just one tenant.
Several projects, one machine. Rather than scatter them, I built a shared self-hosted base on a Raspberry Pi: each app lives in its own Docker Compose project, isolated, but shares the infra that matters.
No third-party cloud. Everything runs locally, behind a single front door.
Every exposed service is graded by two public tools:
- securityheaders.com for the HTTP headers
- Qualys SSL Labs for the TLS setup
These are two independent layers, each tested on its own domain.
The three apps served by my own code are A+ on both axes.
Home Assistant caps at A on headers: its frontend needs unsafe-eval in the CSP, which can't be removed without breaking it. NPM still gives it a CSP, HSTS preload and the same A+ TLS as the rest.
IT security is a full-time job of its own, built on tracking vulnerabilities, following CVEs, incident response. I don't claim to cover it. But engineering experience means thinking about it anyway: I set a solid baseline (hardened headers, TLS, firewall, Docker isolation) and I measure it. I treat it as incomplete and keep working on it.
Two inbound paths:
HTTPS for the services worth exposing publicly: NPM manages Let's Encrypt certificates and their renewal, then routes to each Compose stack.
WireGuard over direct UDP for private LAN access from outside, SSH included.
UFW closes everything else.
Every project follows the same template: CI (quality, lint, tests, build) then CD on the self-hosted runner. New project? Same pipeline, no exception.
Each Compose stack runs in its own Docker network. No cross-project traffic by default: only NPM talks to the services it proxies.
Reverse proxy, TLS, service isolation, a machine that holds up for years. If running a lean system in production speaks to you, let's talk.
This site is the proof: served by the infra it describes.
Get in touch →References
-
[01]
Nginx Proxy Manager
The lab's front door. A simple interface over Nginx to route domains and manage Let's Encrypt certificates without hand-editing config. The right middle ground between raw Nginx and an over-engineered setup.
-
[02]
Home Assistant
The home-automation platform at the heart of the IoT stack, one of the lab's tenants. Everything runs locally, not a byte to a third-party cloud, and the integration ecosystem covers nearly all hardware on the market.
-
[03]
securityheaders.com
A scanner for security HTTP headers: CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy. Grades from A+ to F based on which headers are present and how coherent they are. Built by Scott Helme, now part of Snyk.
-
[04]
Qualys SSL Labs
The reference test for TLS configuration: protocol versions, cipher suites, certificate chain, forward secrecy, known flaws. Grades from A+ to F.