Uses

The hardware, software and homelab behind the work. What runs where, and what it is for.

Homelab

Six boxes, one rack shelf, a lot of runbooks. The lab is where I practise the things I get paid for: segmentation, backups that restore, monitoring that pages, and writing down what broke.

  1. Firewall

    OPNsense

    Dell OptiPlex 7090 Micro

    Router-on-a-stick for the VLANs, Kea DHCP, AdGuard Home for DNS, Tailscale subnet router. Config is Terraform-managed with the XML backed up to git hourly.

  2. Home automation

    Home Assistant

    Dell OptiPlex 7090 Micro, 1 TB NVMe

    Home Assistant OS on bare metal. Frigate NVR, EMQX, Nginx Proxy Manager, Cloudflare Tunnel, the UniFi controller and around thirty add-ons.

  3. Hypervisor

    Proxmox VE

    Dell OptiPlex 7090, i7-11700T, 32 GB

    LXC containers for the media stack, a Paper Minecraft server for friends, Homepage, Audiobookshelf and a NixOS container.

  4. Storage

    Synology NAS

    NFS for media libraries, camera recordings, weekly Proxmox backups and nightly config archives.

  5. Network

    Ubiquiti UniFi

    2x USW Enterprise 8 PoE

    10G SFP+ link between switches, PoE for the access point, VLAN-segmented (servers, IoT, security, guests) with the firewall owning every gateway.

  6. Wi-Fi

    Aerohive AP550

    Per-user pre-shared keys map each device to its VLAN, so an IoT gadget lands on the IoT network without a separate SSID.

Software and services

Media
Jellyfin with Intel QSV hardware transcoding, Audiobookshelf, Pinchflat for archiving YouTube channels
Observability
Uptime Kuma, Grafana, InfluxDB, Telegraf on the firewall, Beszel, webhooks into Home Assistant for phone alerts
Self-hosted apps
SparkyFitness (nutrition and training), TREK (travel planner) behind Cloudflare Tunnel and Access, Homepage dashboard, Audiobookshelf
Infrastructure as code
Terraform for OPNsense, UniFi and Nginx Proxy Manager. Nix flakes for the workstation (NixOS) and the laptop (nix-darwin, nix-homebrew). sops-nix for secrets. Everything in git.
Remote access
Tailscale everywhere. Cloudflare Tunnel and Access for the few things that need a public URL. No inbound port forwards.
Documentation
Obsidian vault with a runbook per system, incident write-ups for every outage, and a decisions log. Published internally as a Quartz wiki.

AI

Local models
MacBook Pro M5 Max, 128 GB. MLX inference behind a LiteLLM proxy, currently running Qwen3-Coder-Next in 4-bit for agentic coding with opencode. Fully nix-managed, offline capable.
Hosted models
Claude Code for building and maintaining this site and for automation work. The site itself was designed and built with it, then reviewed against Anthropic's own frontend-design guidance.
Where it goes
Automating the repetitive parts of IT operations and, increasingly, detection and triage. Agents with a small, well-chosen tool surface beat agents with everything wired in.

On the road

Travel router
TP-Link Deco M5 running OpenWrt, dual uplink, tunnelling back home over Tailscale so hotel Wi-Fi gets the same DNS filtering and access as the house.

Last reviewed September 2026. Addresses, hostnames and anything else that would help someone find their way in are left out on purpose.

↑ ↓ navigate↵ openesc close

Keyboard shortcuts on nathanielroberts.tech

/ or Ctrl K
Search and commands
g then h
Home
g then b
Blog
g then p
Projects
g then u
Uses
g then a
About
g then c
Contact
t
Theme menu
`
Terminal (home page)
?
This list
Esc
Close