~/tech-stack

The server rack

A complete map of the homelab: three physical nodes, four virtualized instances, 28+ Docker services, and a full Omada SDN network — all orchestrated from a single workstation.

All systems operational

Network architecture

OMADA SDN — Unified Topology ~/network

Omada SDN Controller

Centralized Network Management

TrueNAS

Storage

ZFS storage backend & offsite sync

Workstation

Windows 11

Daily driver & homelab management

Omada Hardware

Network

Router, PoE+ switch, Wi-Fi 6 APs

Proxmox

Hypervisor

Virtualization host — 4 active VMs

Home Assistant Smart home automation hub
PlexAI Node Media · Local AI · Photo stack
ARR Stack Automated media pipeline
Exit Node Encrypted Tailscale egress

An encrypted Tailscale mesh provides peer-to-peer remote access, while a Cloudflare Tunnel publishes sports.duncanantoniuk.com with zero open inbound ports — everything else stays private behind Zero Trust.

Physical hardware

Main Workstation

Daily driver, development & homelab management

Windows 11
CPU
AMD Ryzen 7 9700X — 8C / 16T
Memory
64 GB DDR5
GPU
AMD Radeon RX 9070 XT — 16 GB
Storage
1.82 TB NVMe SSD

Proxmox VE Server

Hypervisor host · Virtualization & compute node

Proxmox VE
CPU
Intel Core i5-9600K — 6C
Memory
32 GB DDR4
GPU Passthrough
NVIDIA GTX 1660 Ti → PlexAI Node
Workloads
4 Active VMs (HAOS · PlexAI · ARR · Exit)

TrueNAS SCALE

Storage backend · ZFS pools · Automated cloud sync

TrueNAS SCALE
CPU
Intel Core i5-8400 — 6C
Memory
24 GB DDR4
Fast Storage
NVMe SSD ZFS pool (databases & app data)
Media Pool
2 TB HDD ZFS pool (media library)
Offsite Backup
Nightly encrypted cloud push

Omada SDN

TP-Link enterprise network stack · Isolated subnets

Omada SDN
Router & Controller
ER605 + OC200 hardware controller
Managed Switch
SG2210MP (8-port PoE+)
Wi-Fi 6 APs
EAP650 + EAP655-Wall mesh
Subnet Isolation
Trusted main · Isolated IoT · Work subnet
Overlay & Ingress
Tailscale mesh · Cloudflare Tunnels

Virtual instances & containers

Compute host — PlexAI

GPU passthrough

Ubuntu Server · Dedicated PCIe GPU

Flagship compute instance. Media streaming, local LLM inference, self-hosted photo AI, and automation — fully containerized.

  • Jellyfin Media server · NVENC GPU hardware streaming
  • Ollama Local LLMs · CUDA GPU inference engine
  • LiteLLM Unified AI proxy (Gemini · DeepSeek · GPT)
  • Open WebUI Private chat interface · SearXNG RAG search
  • Immich Self-hosted photo library · AI face search
  • n8n Visual workflow & AI agent automation
  • SearXNG Private metasearch · RAG web data source
  • Mercury Web content extractor for AI pipelines
  • Tdarr Overnight H.264 → H.265 NVENC batch transcode
  • Homepage Unified service dashboard
  • Sports Tracker Next.js live sports score application
  • Cloudflared Encrypted Cloudflare Tunnel connector

Media pipeline — ARR stack

VPN protected

Ubuntu Server · Dedicated high-speed NVMe staging

Automated media management. Usenet-first processing with Real-Debrid fast-lane resolution and VPN-isolated fallback.

Automated processing pipeline

  1. Seerr (request)
  2. Radarr / Sonarr
  3. SABnzbd (Usenet P1)
  4. or rdt-client (Real-Debrid)
  5. or qBittorrent (VPN)
  6. TrueNAS ZFS Storage
  • Sonarr TV show automation · search & organizing
  • Radarr Movie automation · search & organizing
  • Prowlarr Indexer aggregator · API synchronization
  • SABnzbd Usenet direct unpack downloader
  • rdt-client Real-Debrid direct HTTPS downloader
  • qBittorrent VPN-routed torrent fallback client
  • Seerr User-facing media request portal
  • FlareSolverr CAPTCHA resolution service
  • Gluetun Dedicated VPN gateway with killswitch
  • Recyclarr Automated TRaSH Guides quality profile sync

Home Assistant OS

HAOS

Dedicated smart home VM

Lutron Caséta
IoT Subnet
Sonos Integration
Main Subnet
Tailscale Node
Remote Control

Tailscale Exit Node

VPN

Secure traffic egress instance

Role
Tailscale Exit Node
Function
Encrypted Travel Traffic
Travel Router
Encrypted WireGuard Mesh

Hermes AI Agent

TrueNAS

Dedicated automation VM

Host Storage
Fast NVMe ZVol
Allocated RAM
4 GiB
Purpose
Local AI Agent Worker

GPU resource scheduling

Multiple services share 1× NVIDIA GPU — priority queue prevents VRAM exhaustion
  1. Priority P1 Jellyfin NVENC

    Real-time video hardware transcoding — unthrottled streaming

  2. Priority P1 Ollama CUDA

    Interactive LLM inference — low-latency CUDA execution

  3. Priority P2 Open WebUI

    RAG vector formatting & UI rendering

  4. Priority P3 Immich Server

    Photo thumbnails & preview generation

  5. Priority P3 Immich ML throttled

    Face & object recognition · worker-throttled to preserve VRAM

  6. Priority P4 Tdarr Node off-peak

    H.264 → H.265 batch transcode · NVENC chip only · off-peak window

Public services

sports.duncanantoniuk.com Next.js live sports dashboard · Jets · Bombers · F1 · Whitecaps · Goldeyes
Additional private services (media, automation) Cloudflare Tunnel · zero exposed ports