CPU
RAM
Disk
Rx ·Tx ·

Case study

Self-hosted infra

Backend · Infra · Self-hosting

A single Raspberry Pi, several isolated apps in Docker Compose, one front door with automatic TLS. IoT is just one tenant.

Role
Architect & ops
Stack
Raspberry Pi · Docker Compose · Nginx Proxy Manager · Let's Encrypt
Status
In production
The context

Several projects, one machine. Rather than scatter them, I built a shared self-hosted base on a Raspberry Pi: each app lives in its own Docker Compose project, isolated, but shares the infra that matters.

No third-party cloud. Everything runs locally, behind a single front door.

Homelab topology: Raspberry Pi, NPM for HTTPS (saikali.fr, you.saikali.fr, genealogie.saikali.fr, linky.saikali.fr archived, ha.saikali.fr), WireGuard UDP for the VPN, internal services in Docker Compose.
FIG. 01 Service map.
Security

Every exposed service is graded by two public tools:

These are two independent layers, each tested on its own domain.

securityheadersQualys SSL Labs saikali.fr A+ A+ ha.saikali.fr A A+ genealogie.saikali.fr A+ A+ you.saikali.fr A+ A+

The three apps served by my own code are A+ on both axes.
Home Assistant caps at A on headers: its frontend needs unsafe-eval in the CSP, which can't be removed without breaking it. NPM still gives it a CSP, HSTS preload and the same A+ TLS as the rest.

IT security is a full-time job of its own, built on tracking vulnerabilities, following CVEs, incident response. I don't claim to cover it. But engineering experience means thinking about it anyway: I set a solid baseline (hardened headers, TLS, firewall, Docker isolation) and I measure it. I treat it as incomplete and keep working on it.

What it delivers
Controlled entry points

Two inbound paths:

HTTPS for the services worth exposing publicly: NPM manages Let's Encrypt certificates and their renewal, then routes to each Compose stack.

WireGuard over direct UDP for private LAN access from outside, SSH included.

UFW closes everything else.

Continuous Integration/Continuous Delivery

Every project follows the same template: CI (quality, lint, tests, build) then CD on the self-hosted runner. New project? Same pipeline, no exception.

Docker Compose Isolation

Each Compose stack runs in its own Docker network. No cross-project traffic by default: only NPM talks to the services it proxies.

Infrastructure, live Raspberry Pi 4B · 8 GB · SSD
CPU
RAM ·
Disk ·
TEMP ·
UPTIME ·
Rx ·
Tx ·
Let's talk

Reverse proxy, TLS, service isolation, a machine that holds up for years. If running a lean system in production speaks to you, let's talk.

This site is the proof: served by the infra it describes.

Get in touch →

References

  • [01]
    Nginx Proxy Manager

    The lab's front door. A simple interface over Nginx to route domains and manage Let's Encrypt certificates without hand-editing config. The right middle ground between raw Nginx and an over-engineered setup.

  • [02]
    Home Assistant

    The home-automation platform at the heart of the IoT stack, one of the lab's tenants. Everything runs locally, not a byte to a third-party cloud, and the integration ecosystem covers nearly all hardware on the market.

  • [03]
    securityheaders.com

    A scanner for security HTTP headers: CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy. Grades from A+ to F based on which headers are present and how coherent they are. Built by Scott Helme, now part of Snyk.

  • [04]
    Qualys SSL Labs

    The reference test for TLS configuration: protocol versions, cipher suites, certificate chain, forward secrecy, known flaws. Grades from A+ to F.