Peira Labs
  • Start Here
  • Field Notes
  • Topics
  • Playbooks
  • Glossary
  • About
  • Start Here
  • Field Notes
  • Topics
  • Playbooks
  • Glossary
  • About
  • Search
  • Subscribe by email
  • RSS Feed
← All topics
#security

9 articles

#networking#self-hosted

How to Set Up Traefik with Let's Encrypt

A hands-on walkthrough: deploy Traefik v3 with Docker, get automatic browser-trusted HTTPS from Let's Encrypt, redirect all HTTP to HTTPS, and route your first service to a clean domain using labels.

Jul 17, 2026·4 min readRead →
#self-hosted#automation

Why Auto-Syncing Your Notes Repo Will Corrupt It

Blanket auto-sync corrupts a canonical knowledge base. Replace it with a controlled write: lock, validate, commit, refresh projections, verify, unlock — so every change is atomic and every projection stays coherent.

Jul 15, 2026·5 min readRead →
#self-hosted#security

Share Your Vault Across Machines Without Split-Brain

Your laptop, your cluster, and your agents all need the vault — but only one copy can be authoritative. Use a direct mount for editing and a read-only forced-command SSH reader for everyone else.

Jul 15, 2026·4 min readRead →
#self-hosted#getting-started

Already Made a Mess of Your Notes? Here's the Fix

Already have split-brain repos, a secret in history, and pages moved on a whim? The recovery playbook: quarantine divergent copies, pick one authority, reconcile, and rebuild every projection clean.

Jul 15, 2026·4 min readRead →
#security#self-hosted

Never Commit a Secret to Your Knowledge Base

Never commit a password to your knowledge base — and if you already have, scrubbing it from the working tree isn't enough. Here's the store-pointers-not-values rule and the Git history purge.

Jul 15, 2026·6 min readRead →
#networking#self-hosted

What Is Traefik? Reverse Proxies Explained for Homelabs

What a reverse proxy does, why every homelab needs one, and how Traefik gives your self-hosted services clean HTTPS URLs with automatic certificates instead of a mess of IP addresses and ports.

Jul 8, 2026·3 min readRead →
#proxmox#infrastructure

Proxmox Firewall: Securing a Home Cluster with Zone-Based Rules

A practical guide to the Proxmox built-in firewall — cluster-level rules, node-level rules, container-level rules, IPSET groups for your trusted subnets, and the exact rule order that keeps your cluster safe without locking yourself out.

Jul 6, 2026·6 min readRead →
#proxmox#infrastructure

Proxmox Security Hardening: SSH Keys, Firewall, and Locking Down a New Cluster

Essential security configuration for a new Proxmox cluster — SSH key-based authentication, disabling password login, configuring the built-in firewall, securing the web UI, and the audit steps to verify nothing is exposed that shouldn't be.

Jul 6, 2026·13 min readRead →
#proxmox#lxc

Vaultwarden on Proxmox LXC: Self-Hosted Bitwarden-Compatible Password Manager

Deploy Vaultwarden (the lightweight Bitwarden-compatible server) in an unprivileged Proxmox LXC container with HTTPS, automatic backups, and mobile client access via Tailscale.

Jul 6, 2026·6 min readRead →
Peira Labs

Peira Labs (say PAY-rah) — homelab infrastructure, documented honestly.

Content

Start HereAll Field NotesPlaybooksTopicsGlossaryRSS Feed

Site

The LabAboutPrivacy Policy

Around the web

ServeTheHomePerfect Media Serverselfh.stAwesome Self-HostedTRaSH Guides

© 2026 Peira Labs. All rights reserved.

This site contains affiliate links. As an Amazon Associate I earn from qualifying purchases.