---
tags:
- devops
- l1
- flashcard-deck
- homelab
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Homelab](../../../../library/portal/topics.md) | **Domain:** DevOps & Tooling
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
homelab/c24d124e1a1e	homelab	easy	homelab, philosophy	What is the goal of a homelab in terms of fidelity?	Pattern fidelity, not scale fidelity. You don't need 1,500 servers to practice fleet management — you need 3-5 nodes with the same tooling patterns used in production.\n\nExample: a 3-node k3s cluster teaches node scheduling, pod affinity, and rolling updates — the same patterns used on 300-node production clusters.	training/library/topics/homelab/primer.md
homelab/34ad8bdafcfd	homelab	easy	homelab, hardware	What is the best bang-for-buck homelab hardware tier in 2025?	The Mid Tier ($300-$800): 3x Intel N100 mini PCs with 16GB RAM, NVMe SSDs, a VLAN-aware managed switch, and a small UPS. These are silent, low-power (~8W idle), and support Proxmox clustering with nested VMs.	training/library/topics/homelab/primer.md
homelab/766134fc894b	homelab	easy	homelab, k3s	What components does k3s ship with by default?	Traefik (ingress controller), CoreDNS (cluster DNS), Flannel (CNI), local-path provisioner (persistent volumes), and ServiceLB (LoadBalancer-type services using host ports).\n\nGotcha: k3s defaults are opinionated. Use --disable traefik --disable servicelb at install to practice with your own ingress controller.\n\nUnder the hood: k3s bundles everything into a single <50MB binary — ideal for edge and resource-constrained environments.	training/library/topics/homelab/primer.md
homelab/832bb2d7a927	homelab	medium	homelab, proxmox, virtualization	What is the difference between VMs and LXC containers in Proxmox, and when should you use each?	VMs are full virtual machines with their own kernel — use for Windows, appliances, or anything needing its own kernel. LXC containers are lightweight Linux containers — use for services like PiHole and Gitea. Proxmox also supports clustering (3+ nodes), live migration, templates, and multiple storage backends (local, NFS, Ceph, ZFS).	training/library/topics/homelab/primer.md
homelab/54514540f872	homelab	medium	homelab, networking, vlans	Why should you set up VLANs in a homelab, and what is a recommended VLAN layout?	Network segmentation is a production skill worth practicing. A recommended layout: VLAN 10 for management (Proxmox UI, switch), VLAN 20 for servers (VMs/containers), VLAN 30 for IoT/untrusted devices, VLAN 40 for Kubernetes pod network, VLAN 100 for WAN/Internet. IoT devices should never share a network with Proxmox management.	training/library/topics/homelab/primer.md
homelab/ca41331307b9	homelab	medium	homelab, services	What are the three tiers of essential self-hosted services for a homelab?	Tier 1 (Infrastructure): PiHole (DNS), WireGuard (VPN), Traefik/nginx (reverse proxy + TLS). Tier 2 (DevOps Practice): Gitea (Git), Prometheus + Grafana (monitoring), Loki (logs), ArgoCD (GitOps). Tier 3 (Production Patterns): Nextcloud (storage), Keycloak (SSO/OIDC), MinIO (S3-compatible), Vault (secrets).	training/library/topics/homelab/primer.md
homelab/bc0dbb7d3aad	homelab	medium	homelab, dns, pihole	Why should you set up PiHole or local DNS on day one of your homelab?	Accessing services by IP address is a recipe for confusion as your lab grows. PiHole serves dual purposes: ad blocking and local DNS resolution for lab services using entries like proxmox.lab.home, grafana.lab.home, etc. Point your DHCP server to use PiHole as primary DNS.	training/library/topics/homelab/primer.md
homelab/c29684bfcd06	homelab	hard	homelab, proxmox, cloud-init	How do you create a cloud-init VM template in Proxmox for fast provisioning?	Create a VM (qm create), import a cloud image disk (qm importdisk), configure the SCSI controller and boot disk (qm set --scsihw virtio-scsi-pci), add cloud-init drive (qm set --ide2 local-zfs:cloudinit), set serial console, configure IP (qm set --ipconfig0 ip=dhcp), then convert to template (qm template). Clone from template with qm clone for each new VM.	training/library/topics/homelab/primer.md
homelab/9da36ef9dfc4	homelab	hard	homelab, wireguard, vpn	What are the key components of a WireGuard VPN setup for accessing your homelab remotely?	Generate server and client key pairs (wg genkey/wg pubkey), create server config (/etc/wireguard/wg0.conf) with PrivateKey, Address (e.g., 10.200.0.1/24), ListenPort (51820), PostUp/PostDown iptables rules for NAT masquerade, and Peer section with client's PublicKey and AllowedIPs. Enable with systemctl, and port-forward 51820/UDP on your router to the WireGuard host.	training/library/topics/homelab/primer.md
homelab/06f32ac4b675	homelab	hard	homelab, pitfalls	What are the two most costly pitfalls when buying enterprise salvage hardware for a homelab?	(1) Not checking power costs — a $150 Dell R730 can add $20-50/month to your power bill at 120-400W draw. (2) Over-engineering on day one — you don't need Ceph, 10GbE, and a three-node HA Proxmox cluster to start. Begin with one node and one k3s install. Complexity is the enemy of learning.	training/library/topics/homelab/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Homelab & Learning Infrastructure](../../../../library/topics/homelab/index.md) (Topic Pack, L0) — Homelab

<!-- wiki:related:end -->
