Security
12 guides about security for your home lab
-
Homelab Firewall Rules Best Practices
Learn how to design firewall rules for a segmented homelab network. Covers default deny policies, VLAN-based zone design, logging strategies, and common rule patterns for LAN, DMZ, IoT, and management networks.
-
Setting Up Frigate NVR in Your Homelab for Smart Camera Monitoring
Deploy Frigate NVR in your homelab with Docker Compose, Coral TPU acceleration, RTSP cameras, zones, masks, and Home Assistant integration.
-
Setting Up CrowdSec in Your Homelab: Community-Powered Intrusion Prevention
Deploy CrowdSec in your homelab for real-time intrusion detection and prevention. Covers installation, bouncer setup, custom scenarios, and integration with Traefik, Nginx, and firewalls.
-
Self-Hosted Secret Management with HashiCorp Vault
Deploy HashiCorp Vault in your homelab for centralized secret management. Covers Docker setup, KV secrets, PKI certificates, AppRole auth, and service integration.
-
SSL Certificate Management for Your Home Lab
A practical guide to managing SSL certificates in your homelab — Let's Encrypt with DNS challenges, internal CAs, wildcard certs, cert-manager, and automated renewal.
-
Identity Management Beyond SSO: LDAP, Authentik, and Centralized User Management
Set up centralized identity management for your homelab with LDAP, lldap, FreeIPA, and Authentik. Covers directory services, user provisioning, and integrating authentication across all your services.
-
Advanced Homelab Security: CrowdSec, Fail2ban, Network Segmentation, and Defense in Depth
Go beyond basic SSH hardening — deploy CrowdSec and Fail2ban for intrusion prevention, implement network segmentation with VLANs and firewall zones, and build a defense-in-depth security posture for your homelab.
-
pfSense vs OPNsense: Choosing a Firewall for Your Home Lab
A practical comparison of pfSense and OPNsense for home lab use — features, hardware requirements, UI design, and which one to pick for your setup.
-
Self-Hosted Password Management: Vaultwarden and Passbolt
Deploy a self-hosted password manager with Vaultwarden (Bitwarden-compatible) or Passbolt. Covers Docker deployment, HTTPS setup, browser extensions, mobile apps, emergency access, and backup strategies.
-
Homelab Network Security Audit: Scanning, Testing, and Hardening
Conduct a thorough security audit of your homelab network. Covers port scanning with Nmap, vulnerability assessment with OpenVAS, traffic analysis with Suricata, and a hardening checklist.
-
Authelia: Single Sign-On and 2FA for Your Home Lab
Set up Authelia for SSO and two-factor authentication in your homelab. Covers reverse proxy integration, access policies, OIDC, and comparison with Authentik and Keycloak.
-
Home Lab Security Hardening: A Practical Guide
Harden your home lab against real threats — SSH lockdown, firewall rules, automatic updates, network segmentation, secrets management, and common mistakes to avoid.