𝔩𝔢𝔩𝕠𝔭𝔢𝔷
Theme

Homelab

Go Live Series

Taking a Homelab Live: Two Exposure Tiers, One Domain, and Reachability You Can Read from a Hostname

Overview

V2 built the cluster and V3 hardened it, but everything it serves still lives behind the walls. This series is about how services leave the homelab, or deliberately don't: a public tier for the things the internet should reach, a private tier with real HTTPS for the things only we should, and a naming architecture that makes the difference legible from the hostname alone. By the end, private services answer on a publicly trusted wildcard without a single port opening at home, public services stream through a tunnel we own, and TLS for both tiers terminates only at the homelab, so the path in between carries ciphertext it can never read. This is V3's hardening pointed outward: going live without loosening anything.

This article isn't ready yet

Check back soon for the full article.