Home-lab AI infrastructure
Two home machines — a server and an AI brain — running local AI, a personal cloud, backups and monitoring.
Layout
| Machine | Role |
|---|---|
| Server | Web (this site and the chat), personal cloud storage, backups, monitoring |
| AI brain | Local language models, image generation, chat gateway |
The two machines talk only over a private network (Tailscale), and only the paths that must be public are opened to the internet. Admin screens are reachable from the home network only.
Operating principles
- No secrets in the repository — configuration is snapshotted to Git every day, but passwords and tokens are excluded at collection time and checked again right before upload.
- A way back before every change — take a snapshot first; move things aside instead of deleting them.
- Integrity ledger — hashes of important files are recorded so silent changes can be detected.
- Never fail silently — alerts fire when a service stops or free space drops below 10%.
- Docs follow the system — a checker compares documentation with the real configuration every day.
Lessons
- Every public address you open is one more thing to defend. Separating admin functions as internal-only from day one is the cheapest option.
- A backup is trustworthy only once you have restored from it.