Pangolin / Newt
Used for authenticated web publication and private resources. Newt links the site without forwarding every internal service directly through the firewall.
Layered virtualisation, segmented networking, private access and observable services.
The platform runs both KVM virtual machines and LXC containers. I use it for resource allocation, service isolation, snapshots, backups, migrations and recovery work.
Recent work includes upgrading to the Proxmox VE 9 generation, diagnosing UEFI and storage failures, moving guests between machines, and planning safe migrations away from risky storage layouts.
Proxmox case studyUsed for authenticated web publication and private resources. Newt links the site without forwarding every internal service directly through the firewall.
Used for trusted mesh connectivity, subnet access and exit-node routing. It also supports the LAN bridge design so remote devices can reach private services.
SIP/RTP, TURN and other non-web protocols are handled with protocol-aware firewall rules, public VPS services and explicit port policy—not forced through an HTTP reverse proxy.
The Zabbix LXC monitors hosts, services and network behaviour. I have worked through database connectivity failures, backup problems, alert-template encoding issues and agent deployment.
Wazuh provides endpoint security and centralised event analysis. I maintain the VM, indexer/dashboard stack and agents, including resource tuning such as Java heap changes.
My screenshots document both the Docker side and the Proxmox LXC/KVM side of the lab, connecting the architecture diagram to the systems I actually operate.
Hawser provides an at-a-glance operational view of hosts, containers and health.
Separate Docker-VM hosts keep experiments and application groups divided instead of pushing every service into one box.
Examples visible in the screenshots include Immich, Home Assistant, Navidrome, i-spy, SearXNG and WordPress.
View screenshots →Everything documented here runs on real hardware I own and maintain — not rented cloud instances. The lab has evolved steadily since 2016, from an early FreeNAS box into the layered Proxmox, networking and container environment it is today.


The lab is supported by systems I assemble, upgrade and troubleshoot myself. These machines are used for administration, development, testing and local workloads.






These sanitised captures connect the architecture diagrams and project write-ups to the systems I actively operate.


