Your homelab, as a Git repository.
Free tools, real configs, and learning materials for self-hosting with GitOps.
The Map · App Cookbook · Real Repos · Explore · Community
Most homelabs that last end up as a Git repo: every VM, cluster, and app is described in files, and a machine makes reality match them. This list is organized like that repo. Each folder below is a layer you will build, with the free tools for it, links to how experienced homelabbers do it in the wild, and what to read first. Within each layer, the first entries are what most home-ops repos use today.
[!TIP] > New to this? Work through 00 to 03 in order, then take one app from 10 Apps all the way to production before you add a second.
home-ops/
├── infrastructure/ 01 hypervisors, VMs, host config
├── talos/ bootstrap/ 02 operating system and cluster bootstrap
├── kubernetes/
│ ├── flux/ 03 the GitOps engine
│ ├── apps/network/ 05 ingress, DNS, certificates, remote access
│ ├── components/ 06 storage and backups
│ ├── apps/observability/ 07 metrics, logs, uptime
│ ├── apps/security/ 08 single sign-on
│ └── apps/<your-app>/ 10 the app cookbook
├── .sops.yaml 04 secrets, encrypted in Git
├── .renovaterc.json5 09 automated updates
└── .github/workflows/ 09 CI for your cluster
| 00 Hardware | 01 Infrastructure | 02 Bootstrap | 03 GitOps |
|---|---|---|---|
| 04 Secrets | 05 Network | 06 Storage | 07 Observability |
| 08 Identity | 09 Automation | 10 Apps | Real Repos |
The loop you are building:
flowchart LR A[Renovate opens a PR] --> B[CI renders the diff] B --> C[You review and merge] C --> D[Flux reconciles] D --> E[Cluster matches Git] E -. new upstream release .-> A
the rack · Small, quiet, and low-power beats big and loud.
- Project TinyMiniMicro - 1L business mini PCs as homelab nodes.
- ServeTheHome - Reviews of servers, mini PCs, and networking gear.
- geerlingguy/mini-rack - Builds and parts for 10-inch mini racks.
- geerlingguy/sbc-reviews - Benchmarks and power data for single-board computers.
- Matt Gadient: 7 W Idle Server - Low-power build guide covering C-states and ASPM.
- Powertop - Diagnose and tune idle power consumption.
infrastructure/ · Hypervisors, VM templates, and host configuration, all from code.
- Proxmox VE - Debian-based KVM and LXC hypervisor.
- OpenTofu - Open-source infrastructure as code, a fork of Terraform.
- bpg/terraform-provider-proxmox - The most complete OpenTofu and Terraform provider for Proxmox.
- Telmate/terraform-provider-proxmox - The original Proxmox provider.
- Packer Proxmox Plugin - Build Proxmox VM templates with Packer.
- cloud-init - First-boot configuration for VM templates.
- Ansible - The
community.generalcollection, including Proxmox modules. - lae/ansible-role-proxmox - Install and cluster Proxmox with Ansible.
- community-scripts/ProxmoxVE - One-line scripts to create LXCs and VMs on Proxmox.
- ChristianLempa/boilerplates - Templates for Packer, Terraform, Ansible, Compose, and Kubernetes.
- NixOS - Declarative, reproducible Linux for hosts that are not Kubernetes nodes.
- Incus - Community fork of LXD for system containers and VMs.
- Harvester - Open-source HCI built on Kubernetes, KubeVirt, and Longhorn.
- TrueNAS - ZFS-based NAS operating system.
In the wild
- joryirving — terraform/
- Mafyuh — terraform/
- bjw-s — ansible/
- khuedoan — metal/
Read
talos/ bootstrap/ · An OS built for Kubernetes, and the first few charts that bring a cluster to life.
- Talos Linux - Immutable, API-driven OS built only for Kubernetes.
- onedr0p/cluster-template - The most common starting point for a Talos and Flux home cluster.
- siderolabs/terraform-provider-talos - Generate and apply Talos machine configs from OpenTofu.
- talstomize - Kustomize-style patching for Talos configs.
- topf - Talos cluster orchestrator.
- tuppr - Controller that upgrades Talos and Kubernetes from Git.
- Helmfile - Install the first charts (CNI, Flux) before GitOps takes over.
- k3s - Lightweight Kubernetes for any Linux host.
- timothystewart6/k3s-ansible - HA k3s with kube-vip and MetalLB.
- kind - Throwaway local clusters for testing manifests.
In the wild
- onedr0p — talos/
- onedr0p — bootstrap/helmfile/
- buroa — talos/
kubernetes/flux/ · Git is the source of truth. A controller in the cluster makes reality match it.
- Flux - GitOps controller used by most home-ops repos.
- Flux Operator - Install and upgrade Flux itself declaratively.
- Argo CD - GitOps controller with a web UI and app-of-apps pattern.
- bjw-s app-template - One Helm chart to deploy almost any container.
- Kustomize - Template-free overlays for Kubernetes manifests.
- home-operations/containers - Rootless, semantically versioned app images.
- Reloader - Restart workloads when ConfigMaps or Secrets change.
In the wild
- onedr0p — kubernetes/flux/
- khuedoan — system/ (Argo CD)
Read
.sops.yaml · Secrets live in Git encrypted, or in a password manager the cluster can read.
- SOPS - Encrypt values in YAML so they can be committed.
- age - Simple file encryption, the usual SOPS backend.
- External Secrets Operator - Sync secrets from Bitwarden, 1Password, Vault, and others.
In the wild
- szinn — .sops.yaml
- xunholy — .sops.yaml
- onedr0p — external-secrets/
Read
kubernetes/apps/network/ · Get traffic in safely, with real certificates and no open ports.
In the cluster
- Cilium - eBPF CNI with load balancing, Gateway API, and BGP.
- Envoy Gateway - Gateway API implementation built on Envoy.
- cert-manager - Automate Let's Encrypt certificates.
- external-dns - Create DNS records from routes and ingresses.
- MetalLB - LoadBalancer services for bare-metal clusters.
- Spegel - Peer-to-peer image mirror inside the cluster.
- Traefik - Reverse proxy with service discovery and automatic TLS.
- Caddy - Web server and reverse proxy with automatic HTTPS.
At the edge
- Cloudflare Tunnel - Expose services without opening ports.
- Tailscale - WireGuard mesh VPN with a free personal plan.
- Headscale - Self-hosted Tailscale control server.
- NetBird - Open-source, self-hostable WireGuard mesh VPN.
- Pangolin - Self-hosted tunneled reverse proxy with SSO.
- WireGuard - Fast, modern VPN protocol.
- OPNsense - Open-source firewall and router.
- pfSense CE - FreeBSD-based firewall and router.
- Blocky - Stateless DNS proxy and ad-blocker that suits Kubernetes.
- AdGuard Home - Network-wide ad and tracker blocking DNS.
- Pi-hole - DNS sinkhole for ad blocking.
In the wild
- onedr0p — network/
Watch
kubernetes/components/ · Replicated volumes, databases, and backups you have actually restored.
- Rook - Ceph storage orchestration for Kubernetes.
- Longhorn - Distributed block storage for Kubernetes.
- Piraeus Operator - LINSTOR and DRBD replicated storage.
- OpenEBS - Container-attached storage engines.
- CloudNativePG - PostgreSQL operator with backups and failover.
- VolSync - Replicate and back up PVCs with restic or kopia.
- kopiur - Kopia-native Kubernetes backup operator.
- Velero - Back up and restore cluster resources and volumes.
- Restic - Fast, encrypted backups to many backends.
- Kopia - Fast, encrypted backups with a UI.
- Borg - Deduplicating, encrypted backups.
In the wild
- onedr0p — components/kopiur/
- xunholy — components/volsync/
- onedr0p — rook-ceph/
Read
- Storage on Talos Linux with LINSTOR and DRBD
- Self-Hosting a Container Registry on k3s with zot
- Perfect Media Server
kubernetes/apps/observability/ · Know it broke before your family does.
- kube-prometheus-stack - Prometheus, Alertmanager, and Grafana in one chart.
- VictoriaMetrics - Lightweight Prometheus-compatible metrics and logs.
- Grafana Loki - Log aggregation that pairs with Grafana.
- Gatus - Health checks and status page configured in YAML.
- gatus-sidecar - Generate Gatus checks from routes and services.
- kromgo - README badges from PromQL queries.
- Uptime Kuma - Uptime monitoring with a web UI.
- Homepage - Dashboard with service widgets and Kubernetes discovery.
In the wild
kubernetes/apps/security/ · One login for every app, ideally with passkeys.
- Authentik - Identity provider with OIDC, SAML, LDAP, and proxy auth.
- Pocket ID - Simple passkey-only OIDC provider.
- Authelia - Lightweight forward-auth and OIDC portal.
In the wild
- joryirving — authentik/
- joryirving — Authentik as code
.renovaterc.json5 .github/workflows/ · Updates arrive as pull requests, and CI shows exactly what will change.
- Renovate - Dependency update PRs for images, charts, and providers.
- home-operations/renovate-presets - Shared Renovate config for home-ops repos.
- flate - Validate and render Flux resources offline, in CI.
- konflate - Pull request review tool that shows rendered Flux diffs.
- mise - Pin every CLI tool version in the repo.
- just - Command runner for repeatable ops tasks.
- Task - YAML-based task runner, common in older home-ops repos.
In the wild
- onedr0p — .renovaterc.json5
- buroa — .renovate/
- buroa — flate workflow
- xunholy — flux-local workflow
kubernetes/apps/<your-app>/ · The point of all this. For each app, browse dozens of real deployments on kubesearch.dev, then copy the one closest to your setup.
| App | What it does | Real deployments |
|---|---|---|
| Home Assistant | Home automation | kubesearch · onedr0p |
| Immich | Photo and video backup | kubesearch · szinn |
| Jellyfin | Media server | kubesearch · bjw-s |
| Paperless-ngx | Document archive with OCR | kubesearch · bjw-s |
| Vaultwarden | Bitwarden-compatible password manager | kubesearch |
| Nextcloud | Files, calendar, and contacts | kubesearch · bjw-s |
| Audiobookshelf | Audiobooks and podcasts | kubesearch · bjw-s |
| Navidrome | Music streaming | kubesearch · bjw-s |
| Frigate | NVR with object detection | kubesearch · bjw-s |
| Zigbee2MQTT | Zigbee devices without vendor hubs | kubesearch · xunholy |
| ESPHome | Firmware for DIY sensors | kubesearch |
| Actual | Personal budgeting | kubesearch · bjw-s |
| Mealie | Recipes and meal planning | kubesearch |
| Karakeep | Bookmarks with AI tagging | kubesearch · bjw-s |
| Linkding | Minimal bookmark manager | kubesearch |
| Miniflux | RSS reader | kubesearch |
| Memos | Lightweight notes | kubesearch |
| Syncthing | Peer-to-peer file sync | kubesearch |
| Atuin | Synced shell history | kubesearch · onedr0p |
| Forgejo | Self-hosted Git forge | kubesearch · bjw-s |
| Open WebUI | Chat UI for local LLMs | kubesearch · joryirving |
| Ollama | Run LLMs locally | kubesearch · xunholy |
| n8n | Workflow automation | kubesearch · xunholy |
More apps
- doco-cd - Deploy Docker Compose stacks from Git on push or poll.
- Komodo - Build and deploy Compose stacks across many servers from Git.
- Renovate for Docker - The same update PRs, for
compose.yamlimage tags.
In the wild
- bjw-s — docker/ with doco-cd
The best documentation in this hobby is other people's Git history. Start where the last column points.
| Repo | Stack | Start reading at |
|---|---|---|
| onedr0p/home-ops | Talos · Flux · Rook | talos/, then kubernetes/flux/ |
| bjw-s-labs/home-ops | Talos · Flux · Compose | docker/ for GitOps without Kubernetes |
| buroa/home-ops | Talos · Flux | .renovate/ for update automation |
| catdevsecops/home-automated-infrastructure | Raspberry Pi · Talos · Argo CD · Terraform | terraform/bootstrap/, with the write-up |
| joryirving/home-ops | Talos · Flux · OpenTofu | terraform/ for managing apps as code |
| szinn/k8s-homelab | Talos · Flux | kubernetes/main/components/ |
| xunholy/k8s-gitops | Talos · Flux | kubernetes/components/ |
| khuedoan/homelab | Argo CD · Ansible | metal/ → system/ → platform/ |
| billimek/k8s-gitops | Flux | One of the original Flux home clusters |
| toboshii/home-ops | Flux | A smaller cluster, easier to read end to end |
| Mafyuh/iac | OpenTofu · Ansible · Kubernetes | terraform/ |
| zimmertr/TJs-Kubernetes-Service | Proxmox · Talos · OpenTofu | Kubernetes on Proxmox, fully automated |
| christianlempa/homelab | Docker · Terraform | Configs behind Christian Lempa's videos |
| JamesTurland/JimsGarage | Proxmox · k3s | Scripts behind Jim's Garage videos |
| TechHutTV/homelab | Proxmox · Docker | Beginner-friendly guides and Compose files |
| ironicbadger/infra | Ansible · Nix | Infrastructure from the Self-Hosted podcast host |
| ryan4yin/nix-config | Nix | Multi-host flake configuration |
| EmergentMind/nix-config | Nix | Multi-host NixOS configuration |
| bradfitz/homelab | Notes | Design notes from Tailscale's Brad Fitzpatrick (2020) |
Find more on kubesearch.dev, which indexes hundreds of home-ops repos.
- So, you want to start self-hosting? Part 2 - Install Immich, Audiobookshelf, and Home Assistant.
- What's Actually Running in My Homelab? - Techno Tim's tour of 50+ self-hosted services.
- Ansible 101 - Jeff Geerling's free video series.
- khuedoan/homelab docs - How a fully automated homelab fits together.
- Kubernetes the Hard Way - Bootstrap Kubernetes by hand to learn the internals.
- Ansible for DevOps - Example code from Jeff Geerling's book.
- iximiuz Labs - Browser-based Linux, container, and Kubernetes playgrounds.
- Killercoda - Free interactive Kubernetes and Linux scenarios.
- roadmap.sh DevOps - Visual DevOps learning roadmap.
- Ben Gauger - Proxmox and OpenTofu.
- Clay Cavaleiro - Talos, Argo CD, and Home Assistant on Raspberry Pi.
- Jeff Geerling - Ansible, Raspberry Pi clusters, and hardware.
- Nick Cunningham - Homelab and self-hosting write-ups.
- noted.lol - Self-hosted app reviews and guides.
- Pim Widdershoven - Talos, Kubernetes, and storage.
- Techno Tim Docs - Copy-paste configs for Techno Tim videos.
- The Thought Process - A home server series built on k3s.
- TheOrangeOne - Self-hosting and infrastructure.
- Virtualization Howto - Proxmox, Kubernetes, and home server tutorials.
- apalrd's adventures - Proxmox, IPv6, and deep dives.
- Christian Lempa - DevOps-flavored homelab tutorials.
- Craft Computing - Server hardware and virtualization.
- DB Tech - Self-hosted app walkthroughs.
- Dreams of Autonomy - Terminal and self-hosting workflows.
- Hardware Haven - Budget and low-power builds.
- Jeff Geerling - Hardware, SBCs, and Ansible.
- Jim's Garage - k3s, Proxmox, and self-hosting.
- Lawrence Systems - pfSense, TrueNAS, and networking.
- Mischa van den Burg - Kubernetes homelab and DevOps careers.
- Raid Owl - Homelab hardware and software.
- TechHut - Linux and homelab.
- Techno Tim - Homelab, Kubernetes, and self-hosting.
- Virtualization Howto - Video companion to the blog.
- Wolfgang's Channel - Power-efficient servers and NixOS.
- selfh.st - Weekly self-hosting newsletter.
- Self-Hosted - Weekly podcast on self-hosting and homelabs.
- Home Operations Discord - Where most of the repos above are discussed.
- r/homelab - The main homelab subreddit.
- r/selfhosted - Self-hosting discussion.
- r/Proxmox - Proxmox discussion.
- r/minilab - Small-form-factor homelabs.
- Proxmox Forum - Official Proxmox support forum.
- ServeTheHome Forums - Server hardware discussion.
- Lawrence Systems Forums - Networking, firewalls, and storage.
Related lists
- awesome-selfhosted
- awesome-proxmox-ve
- awesome-kubernetes
- awesome-gitops
- awesome-sysadmin
- awesome-tf
- awesome-sre
- awesome-scalability